Skip to content
Back to skills

Typescript Security

ASecurity

Store the JWT signing secret outside source control: use the deployment platform's secret manager in production, and an uncommitted `.env` file supplied through the environment for local development. Never put it in frontend code, a checked-in config file, or a JWT payload. ```ts const jwtSecret = process.env.JWT_SECRET; if (!jwtSecret) { throw new Error("JWT_SECRET is not configured"); } ``` Load it once during startup, restrict access to the service, rotate it through the secret manager, an...

  • 549 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
developmentgofrontend

Security analysis

A100/100

Pro scans all 15 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill typescript-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Typescript Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Typescript Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-typescript-security-1f169981/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-typescript-security-1f169981)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Store the JWT signing secret outside source control: use the deployment platform's secret manager in production, and an uncommitted `.env` file supplied through the environment for local development. Never put it in frontend code, a checked-in config file, or a JWT payload.

```ts
const jwtSecret = process.env.JWT_SECRET;
if (!jwtSecret) {
  throw new Error("JWT_SECRET is not configured");
}
```

Load it once during startup, restrict access to the service, rotate it through the secret manager, and use a key identifier/key rotation strategy when needed. Prefer an asymmetric `RS256`/`jose` setup for distributed verification; keep private keys in the secret manager and publish only the public key. Deliver browser tokens in `HttpOnly`, `Secure`, appropriately `SameSite` cookies and validate issuer, audience, expiry, and algorithm when verifying.

Files in this skill

  • eval-1.baseline.md1.3 KB
  • eval-1.with-skill.md1.2 KB
  • eval-2.baseline.md975 B
  • eval-2.with-skill.md854 B
  • eval-3.baseline.md894 B
  • eval-3.with-skill.md763 B
  • eval-4.baseline.md862 B
  • eval-4.with-skill.md882 B
  • eval-5.baseline.md1009 B
  • eval-5.with-skill.md870 B
  • trigger-1.md149 B
  • trigger-2.md142 B
  • trigger-3.md146 B
  • trigger-4.md115 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…