Skip to content
Back to skills

Backend Security Expert

ASecurity

Use when Backend security auditing for modern server-side architectures. Focuses on Next.js Server Actions, Node.js/Edge APIs, JWT & Session architectures, ORM injection (Prisma/Drizzle), and RBAC implementation.

  • 5 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
ai-agentstypescriptrustgobashsqlnextjsnoderailsawsgcp

Works with

  • api

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add Harmitx7/tribunal-kit --skill backend-security-expert --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Backend Security Expert?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Backend Security Expert
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/harmitx7-backend-security-expert-tribunal-kit/badge)](https://www.skillsdirectory.com/skills/harmitx7-backend-security-expert-tribunal-kit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: backend-security-expert
description: "Use when Backend security auditing for modern server-side architectures. Focuses on Next.js Server Actions, Node.js/Edge APIs, JWT & Session architectures, ORM injection (Prisma/Drizzle), and RBAC implementation."
version: 5.0.0
last-updated: 2026-09-13
skills:
  - frontend-security-expert
  - api-security-auditor
  - vulnerability-scanner
tools: Read, Grep, Glob, Bash, Edit, Write
scripts-binding:
  - .agent/scripts/lint_runner.js
  - .agent/scripts/verify_all.js
---

# Backend Security Expert β€” Modern Server Architectures

---

## πŸ› οΈ Technical Architecture & Reference Recipes

---

## 2026 Backend Security & Cryptography Invariants

1. **Timing-Safe Equality**:
   ```ts
   import { timingSafeEqual } from 'node:crypto';
   function verifySecret(provided: string, expected: string): boolean {
     const bufA = Buffer.from(provided);
     const bufB = Buffer.from(expected);
     if (bufA.length !== bufB.length) return false;
     return timingSafeEqual(bufA, bufB);
   }
   ```
2. **SSRF Guardrails on Webhooks**: Never allow user-submitted URLs to hit AWS/GCP metadata services (`169.254.169.254`) or loopback (`localhost`). Validate IP address after DNS resolution before connecting.
3. **Mass Assignment Prevention**: Never pass `req.body` directly into database inserts. Explicitly pick allowed attributes via Zod schemas (`schema.parse(req.body)`).
4. **JWT Verification Security**: Always specify `algorithms: ['HS256']` explicitly to prevent the notorious `alg: "none"` vulnerability.

## Hallucination Traps (Read First)

- ❌ Recommending session tokens without algorithm enforcement β†’ βœ… Always verify JWT algorithms (`alg: "HS256"`)
- ❌ String equality `token === expectedToken` β†’ βœ… Use `crypto.timingSafeEqual` to prevent timing attacks
- ❌ Treating ORMs as automatically injection-proof β†’ βœ… Prisma and Drizzle are vulnerable if raw SQL is dynamically interpolated
- ❌ Assuming Next.js Server Actions are private internal functions β†’ βœ… Server Actions are public HTTP endpoints
- ❌ Fetching user-supplied URLs without private IP filtering β†’ βœ… Block RFC 1918 and link-local ranges to prevent SSRF

---

## 1. Next.js Server Actions & Edge APIs

Server Actions create implicit API endpoints. They must be treated like raw REST routes.

- **Authentication**: Validate the session ID/token at the very top of _every_ Server Action.
- **Input Validation**: Parse all inputs using Zod. Do not trust TypeScript types, as they do not exist at runtime.
- **Rate Limiting**: Apply `@upstash/ratelimit` or similar to prevent brute force and abuse on public-facing actions.

## 2. Authentication & Authorization (RBAC)

- **Role-Based Access**: Check if the authenticated user has permission to perform the specific action, not just if they are logged in.
- **IDOR Prevention**: Always verify that the resource being modified belongs to the user requesting the modification (e.g., `WHERE userId = session.userId`).
- **Secrets Management**: Never hardcode API keys. Ensure they are loaded from `.env` and fail loudly if missing.

## 3. Database & ORM Security

- **NoSQL/ORM Injection**: Avoid passing raw JSON or objects directly into query constraints (e.g., MongoDB `$where` or Prisma raw queries).
- **Mass Assignment**: Never destructure user input directly into a database create/update call. Explicitly pick the fields allowed to be updated.
- **Query Depth**: For GraphQL backends, always implement depth limiting and cost analysis to prevent query-based DDoS.

## 4. Headers & Server Hardening

- **CORS**: Never use wildcard `Access-Control-Allow-Origin: *` for authenticated routes.
- **Security Headers**: Ensure Helmet (or equivalent Next.js headers config) is active for HSTS, X-Frame-Options, and Content-Type-Options.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…