String concatenation with user input is SQL injection-prone. Validate the input at the request boundary and pass values separately through a parameterized query or a type-safe ORM: ```ts const query = z.object({ email: z.string().email() }); const parsed = query.safeParse(req.query); if (!parsed.success) { res.status(400).json({ error: "invalid_request" }); return; } const result = await pool.query<UserRow>( "SELECT id, email FROM users WHERE email = $1", [parsed.data.email], ); ``` Do not in...
Scanned 9/5/2026
Install to Claude Code
npx -y skills add HoangNguyen0403/agent-skills-standard --skill typescript-security --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Typescript Security?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-typescript-security-d9f6e55b)More formats (shields.io, HTML) on the badges page.
String concatenation with user input is SQL injection-prone. Validate the input at the request boundary and pass values separately through a parameterized query or a type-safe ORM:
```ts
const query = z.object({ email: z.string().email() });
const parsed = query.safeParse(req.query);
if (!parsed.success) {
res.status(400).json({ error: "invalid_request" });
return;
}
const result = await pool.query<UserRow>(
"SELECT id, email FROM users WHERE email = $1",
[parsed.data.email],
);
```
Do not interpolate `parsed.data.email` into the SQL string. Use Prisma/TypeORM query APIs where appropriate; if raw SQL is unavoidable, use the driver's parameter binding (or `Prisma.sql`), least-privileged database credentials, and no shell or dynamic execution.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.
Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation
SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.
Python backend development expertise for FastAPI, security patterns, database operations, Upstash integrations, and code quality. Use when: (1) Building REST APIs with FastAPI, (2) Implementing JWT/OAuth2 authentication, (3) Setting up SQLAlchemy/async databases, (4) Integrating Redis/Upstash caching, (5) Refactoring AI-generated Python code (deslopification), (6) Designing API patterns, or (7) Optimizing backend performance.
PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.