Parse `FormData` before touching storage or services, preferably with a Zod schema: ```ts const parsed = schema.safeParse({ title: formData.get('title') }) if (!parsed.success) return { error: 'Invalid title' } ``` Then authenticate and authorize the caller, call the DAL with `parsed.data`, and revalidate the exact tag/path changed by the mutation. Do not trust raw strings, hidden fields, or client-side validation as authorization.
Installs into .claude/skills of the current project.
Are you the author of Nextjs Server Actions?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-nextjs-server-actions-bafee088)
Parse `FormData` before touching storage or services, preferably with a Zod schema:
```ts
const parsed = schema.safeParse({ title: formData.get('title') })
if (!parsed.success) return { error: 'Invalid title' }
```
Then authenticate and authorize the caller, call the DAL with `parsed.data`, and revalidate the exact tag/path changed by the mutation. Do not trust raw strings, hidden fields, or client-side validation as authorization.