What problem does it solve?
This Skill provides expert knowledge of web application security for Node.js/Express apps, covering OWASP Top 10 vulnerabilities, input validation, authentication, authorization, API security, secrets management, security headers, and secure coding practices. It helps teams design, review, and implement defense-in-depth strategies to reduce risk.
Core Features & Use Cases
- Comprehensive guidance on preventing common vulnerabilities, implementing secure authentication and authorization, validating input, and applying security headers.
- Practical patterns & examples for secure coding in Node.js/Express, API security, and secrets management.
- Use Case: When building or reviewing a web app, use this Skill to identify risks, propose mitigations, and implement secure defaults.
Quick Start
Ask the web-security-expert to assess a Node.js/Express app for OWASP Top 10 risks and return a prioritized remediation plan with ready-to-adapt code samples.