Back to skills
SKILL.md
Typescript Security
ASecurityValidate the request at the Express boundary with a Zod schema and return structured errors before using the data: ```ts import { z } from "zod"; import type { RequestHandler } from "express"; const registrationSchema = z.object({ email: z.string().email(), password: z.string().min(12).max(128), }); type RegistrationInput = z.infer<typeof registrationSchema>; export const register: RequestHandler = async (req, res, next) => { const result = registrationSchema.safeParse(req.body); if (!result....
- 549 stars
- 0 votes
- 0 copies
- 1 view
- Added September 5, 2026
Security analysis
100/100Pro scans all 15 files and shows the line behind each finding
npx -y skills add HoangNguyen0403/agent-skills-standard --skill typescript-security --agent claude-codeAre you the author of Typescript Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-typescript-security-53a45d90)Validate the request at the Express boundary with a Zod schema and return structured errors before using the data:
```ts
import { z } from "zod";
import type { RequestHandler } from "express";
const registrationSchema = z.object({
email: z.string().email(),
password: z.string().min(12).max(128),
});
type RegistrationInput = z.infer<typeof registrationSchema>;
export const register: RequestHandler = async (req, res, next) => {
const result = registrationSchema.safeParse(req.body);
if (!result.success) {
res.status(400).json({
error: "invalid_request",
details: result.error.flatten().fieldErrors,
});
return;
}
const input: RegistrationInput = result.data;
try {
// Hash with Argon2id before persistence; never store input.password.
await createUser({
email: input.email,
passwordHash: await argon2.hash(input.password, {
type: argon2.argon2id,
}),
});
res.status(201).json({ ok: true });
} catch (error: unknown) {
next(error);
}
};
```
Keep the schema at the untrusted boundary, avoid trusting TypeScript casts, and ensure the endpoint has appropriate rate limiting and generic duplicate-account errors.
Files in this skill
- eval-1.baseline.md
- eval-1.with-skill.md
- eval-2.baseline.md
- eval-2.with-skill.md
- eval-3.baseline.md
- eval-3.with-skill.md
- eval-4.baseline.md
- eval-4.with-skill.md
- eval-5.baseline.md
- eval-5.with-skill.md
- trigger-1.md
- trigger-2.md
- trigger-3.md
- trigger-4.md
Attribution
Comments
Loading comments…