Skip to content
Back to skills

Common Security Audit

DSecurity

Treat this as a release gate, not just a grep exercise. The audit should produce evidence, owners, and remediation status for every finding.

  • 549 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 5, 2026
developmentrustgoshellsqlnodedockerapibackendsecurity

Works with

  • api

Security analysis

D50/100
  • criticalPipes output to a shell interpreter
  • criticalDownloads and executes remote scripts — classic supply chain attack

Pro scans all 11 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill common-security-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Common Security Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Common Security Audit
[![Security: D — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-common-security-audit-2f8ff249/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-common-security-audit-2f8ff249)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
# Node.js backend pre-launch security audit

Treat this as a release gate, not just a grep exercise. The audit should produce evidence, owners, and remediation status for every finding.

## P0 checks

- Scan tracked source, configuration, build output, and history for passwords, API keys, private keys, tokens, and connection strings. Exclude dependency/vendor directories and distinguish test fixtures from live credentials. Any real credential is P0: rotate it immediately, remove it from the repository and history, then move secret delivery to environment variables or a secret manager.
- Inspect logs and error paths for passwords, tokens, secrets, authorization headers, PII, request bodies, and stack traces. Add structured redaction before serialization and return sanitized production errors.
- Enumerate every route, including mounted routers and health/admin endpoints. Verify authentication and authorization at the route or router boundary; authentication alone is insufficient for tenant/owner checks. If more than 20% of routes are unguarded, the skill treats that as P0.

## Injection and entry-point checks

Search for raw SQL concatenation/interpolation, shell execution (`child_process`, `exec`, `spawn`), unsafe template/HTML sinks, path joins using user input, outbound HTTP requests (SSRF), unsafe deserialization, and file upload handling. Confirm parameterized queries, strict command allowlists, canonicalized paths constrained to an intended directory, URL scheme/host allowlists, safe parsers, and size/type limits. Review Dockerfiles and deployment manifests for `latest`, root/privileged execution, host networking, `curl | sh`, and untrusted remote `ADD`.

## Business logic and platform checks

- For every `findById`/`findOne`/`findByPk`, prove the query also enforces tenant, owner, or subject authorization; otherwise treat it as a possible BOLA/IDOR.
- Validate JWT signature, algorithm, issuer/audience, expiry, key rotation, and rejection of weak/default keys.
- Reject uncontrolled property spreading from request bodies (mass assignment); use allowlisted DTOs and server-owned fields.
- Add rate limits, CSRF protection where cookie-authenticated, secure cookie flags, CORS allowlists, security headers, request size limits, and production-safe debug settings.
- Run `npm audit --audit-level=high` and review whether high/critical advisories are reachable and fixed or explicitly risk-accepted.

## Evidence and release criteria

Record commands, commit/version, route inventory, findings with severity and exploitability, and retest results. Do not go live with any P0, exploitable P1, unrotated secret, unverified authorization boundary, or high/critical dependency with an available fix. A clean result requires both automated scans and targeted manual tests using separate users/tenants, malformed inputs, unauthorized object IDs, and production-like configuration.

Files in this skill

  • eval-1.baseline.md3.4 KB
  • eval-1.with-skill.md2.8 KB
  • eval-2.baseline.md2.3 KB
  • eval-2.with-skill.md1.9 KB
  • eval-3.baseline.md2.7 KB
  • eval-3.with-skill.md2.5 KB
  • trigger-1.md145 B
  • trigger-2.md166 B
  • trigger-3.md147 B
  • trigger-4.md162 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…