Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Javascript Pro

ASecurity

Idiomatic modern JavaScript: ES2022+ features, async patterns, modules, and runtime behavior mastery. Use when writing, reviewing, or debugging JavaScript.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsjavascripttypescriptgojavanodeexpressdebuggingapi

Works with

cliapi

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill javascript-pro --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Javascript Pro?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Javascript Pro
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-javascript-pro/badge)](https://www.skillsdirectory.com/skills/aicodedecode-javascript-pro)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: javascript-pro
description: Idiomatic modern JavaScript: ES2022+ features, async patterns, modules, and runtime behavior mastery. Use when writing, reviewing, or debugging JavaScript.
category: development
---

# JavaScript Pro

## Overview

Modern JavaScript (ES2022+) is **a capable, expressive language** — but its flexibility (dynamic
typing, `this` quirks, coercion, event loop) punishes the casual. Professional JavaScript means
knowing the runtime deeply (event loop, promises, modules), writing in modern idioms (not 2012
jQuery-era patterns), handling async structurally, and choosing when types (TypeScript/JSDoc) are
worth it.

The through-line: master the event loop and the module system, write async as linear code, and
respect the dynamism — validate at boundaries.

## When to use

- Writing or reviewing JavaScript (Node.js or browser).
- Debugging async issues, `this` binding, or coercion bugs.
- Choosing module patterns, async styles, or language features.
- Structuring Node.js applications and CLIs.
- Deciding between JS and TypeScript for a project.

## Core concepts

- **The event loop.** Call stack, microtasks (promises — run before rendering/macrotasks),
  macrotasks (timers, I/O). `await` yields; long synchronous blocks freeze everything. This model
  explains 90% of "why did this run in that order" bugs — learn it once, deeply.
- **Promises and async/await.** `async` functions return promises; `await` linearizes async code;
  `Promise.all` for parallel independent work, `Promise.allSettled` when partial failure is OK,
  `Promise.race`/`any` for timeouts/first-wins. Unhandled rejections crash Node — always handle.
- **Modules (ESM).** `import`/`export`, one module per concern, explicit dependency graph.
  Default vs named exports (prefer named — greppable, refactorable); no circular imports
  (restructure when they appear); dynamic `import()` for code splitting and conditional loading.
- **`this`, arrow functions, and binding.** Arrow functions capture lexical `this`; method
  shorthand and classes have dynamic `this`. In callbacks, prefer arrows or explicit binding —
  `this` surprises are a design smell, not a rite of passage.
- **Equality and coercion.** `===` always (except deliberate `== null` checks); know the falsy
  set (`0`, `""`, `null`, `undefined`, `NaN`, `false`); optional chaining (`?.`) and nullish
  coalescing (`??`) for safe access with correct defaults (`??` doesn't swallow `0`/`""` like
  `||` does).
- **Iterators and modern syntax.** `for...of`, destructuring, spread/rest, generators for lazy
  sequences, `Map`/`Set` over objects-as-maps (key types, no prototype pollution), `structuredClone`
  for deep copies, top-level await in modules.

## Practical workflow

1. **Set up the runtime right.** Node.js LTS, `"type": "module"` for ESM, strict linting
   (ESLint recommended config), and decide the types question: TypeScript for teams/long-lived
   code, JSDoc for small scripts.
2. **Write async linearly.** `async`/`await` throughout; parallelize independent promises;
   `AbortController` for cancellation (fetch, timeouts); never mix callbacks and promises in new code.
3. **Structure Node apps.** `src/` by feature; thin entry (`index.js`/`cli.js`); pure functions
   separated from I/O; dependency injection (or simple factories) for testability; graceful
   shutdown (close servers, flush, exit codes meaningful).
4. **Handle errors explicitly.** `try/catch` at boundaries; custom Error subclasses with context
   (`cause` chaining); validate external input (zod); fail fast on programmer errors, recover
   gracefully on operational ones.
5. **Test behavior.** Node's built-in test runner or Vitest/Jest; test pure logic heavily, I/O at
   boundaries with fakes; watch for timer/promise flakes (fake timers, explicit awaits).
6. **Know the platform APIs.** `fetch` (undici in Node), `URL`/`URLSearchParams`, `crypto`
   (webcrypto), streams for large data, `worker_threads` for CPU parallelism — the stdlib is
   deeper than most reach.

Idiomatic snippets:

```js
// Parallel independent work; allSettled tolerates partial failure
const results = await Promise.allSettled(urls.map(fetchJson));
const ok = results.filter(r => r.status === "fulfilled").map(r => r.value);

// Cancellation with AbortController
const ctrl = new AbortController();
const timeout = setTimeout(() => ctrl.abort(), 5_000);
try {
  const res = await fetch(url, { signal: ctrl.signal });
  return await res.json();
} finally {
  clearTimeout(timeout);
}

// ?? for defaults that respect 0/""
const port = Number(process.env.PORT ?? 3000);
```

## Common pitfalls

- **Callback-era patterns.** Nested callbacks, `var`, `function` expressions where arrows fit,
  manual promise construction (`new Promise`) around already-promise APIs. Write 2024 JS, not 2012.
- **Floating promises.** Not awaiting/returning promises — errors vanish, ordering breaks, Node
  warns about unhandled rejections. Every promise is awaited, returned, or explicitly handled.
- **`==` and truthiness traps.** `"" == false`, `[] == false` — coercion bugs. `===`, and `??`
  over `||` for defaults.
- **Mutating shared state across awaits.** `await` points interleave — code after `await` runs
  later, and shared objects may have changed. Treat awaits as yield points; don't assume continuity.
- **Blocking the event loop.** Synchronous crypto, JSON.parse of huge payloads, or regex
  catastrophic backtracking on the main thread. Offload (worker threads) or chunk the work.
- **Circular imports.** Module A imports B imports A — works until it silently doesn't (partial
  initialization). Restructure: extract shared bits to module C.
- **console.log debugging as the only tool.** Learn the debugger (`node --inspect`, browser
  devtools) — breakpoints and async stack traces beat print archaeology for real bugs.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →