Skip to content
Back to skills

Typescript Security

ASecurity

Validate the request at the Express boundary with a Zod schema and return structured errors before using the data: ```ts import { z } from "zod"; import type { RequestHandler } from "express"; const registrationSchema = z.object({ email: z.string().email(), password: z.string().min(12).max(128), }); type RegistrationInput = z.infer<typeof registrationSchema>; export const register: RequestHandler = async (req, res, next) => { const result = registrationSchema.safeParse(req.body); if (!result....

  • 549 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
developmenttypescriptrustgoexpress

Security analysis

A100/100

Pro scans all 15 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill typescript-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Typescript Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Typescript Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-typescript-security-53a45d90/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-typescript-security-53a45d90)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Validate the request at the Express boundary with a Zod schema and return structured errors before using the data:

```ts
import { z } from "zod";
import type { RequestHandler } from "express";

const registrationSchema = z.object({
  email: z.string().email(),
  password: z.string().min(12).max(128),
});

type RegistrationInput = z.infer<typeof registrationSchema>;

export const register: RequestHandler = async (req, res, next) => {
  const result = registrationSchema.safeParse(req.body);
  if (!result.success) {
    res.status(400).json({
      error: "invalid_request",
      details: result.error.flatten().fieldErrors,
    });
    return;
  }

  const input: RegistrationInput = result.data;
  try {
    // Hash with Argon2id before persistence; never store input.password.
    await createUser({
      email: input.email,
      passwordHash: await argon2.hash(input.password, {
        type: argon2.argon2id,
      }),
    });
    res.status(201).json({ ok: true });
  } catch (error: unknown) {
    next(error);
  }
};
```

Keep the schema at the untrusted boundary, avoid trusting TypeScript casts, and ensure the endpoint has appropriate rate limiting and generic duplicate-account errors.

Files in this skill

  • eval-1.baseline.md1.3 KB
  • eval-1.with-skill.md1.2 KB
  • eval-2.baseline.md975 B
  • eval-2.with-skill.md854 B
  • eval-3.baseline.md894 B
  • eval-3.with-skill.md763 B
  • eval-4.baseline.md862 B
  • eval-4.with-skill.md882 B
  • eval-5.baseline.md1009 B
  • eval-5.with-skill.md870 B
  • trigger-1.md149 B
  • trigger-2.md142 B
  • trigger-3.md146 B
  • trigger-4.md115 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…