sdcorejs-review-security-nestjs
CommunityAudit NestJS security before release
Software Engineering#sql injection#security audit#cors#owasp top 10#nestjs#secrets handling#broken access control
Authorsdcorejs
Version1.0.0
Installs0
System Documentation
What problem does it solve?
Prevents common NestJS backend security regressions by systematically auditing permissions, guard order, injection risks, CORS, secrets, rate limiting, and sensitive data handling before shipping.
Core Features & Use Cases
- Cross-track + NestJS-specific baseline: Runs the shared
review/security/shared.mdfirst, then adds NestJS checks like@HasPermissionon write endpoints andAuthGuardvsZodValidationGuardorder. - Targeted vulnerability detection: Flags likely issues for Broken Access Control (A01), Injection (A03), permissive CORS, missing upload limits, weak JWT secret handling, missing rate limits, potential secrets logging, mass assignment patterns, and soft-delete leakage.
- Actionable audit output: Produces Critical/Important/Minor findings and requires a mandatory manual section tested in a production-like configuration.
Quick Start
Run the skill when you need a pre-release NestJS security gate by invoking it with the request "security review nestjs".
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: sdcorejs-review-security-nestjs Download link: https://github.com/sdcorejs/sdcorejs-agent/archive/main.zip#sdcorejs-review-security-nestjs Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.