Skip to content
Back to skills

Typescript Security

ASecurity

The original `execSync` call is vulnerable because an environment value is interpolated into a shell command. Treat the value as untrusted, validate it against the refs permitted by CI, and use `execFileSync` with an argument array and no shell: ```ts import { execFileSync } from "node:child_process"; const baseRef = process.env.GITHUB_BASE_REF; if (!baseRef || !/^[A-Za-z0-9._/-]+$/.test(baseRef) || baseRef.includes("..")) { throw new Error("Invalid GITHUB_BASE_REF"); } const output = execFil...

  • 549 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 5, 2026
developmentrustshellnodegit

Security analysis

A100/100

Pro scans all 15 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill typescript-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Typescript Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Typescript Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-typescript-security-6d27db50/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-typescript-security-6d27db50)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
The original `execSync` call is vulnerable because an environment value is interpolated into a shell command. Treat the value as untrusted, validate it against the refs permitted by CI, and use `execFileSync` with an argument array and no shell:

```ts
import { execFileSync } from "node:child_process";

const baseRef = process.env.GITHUB_BASE_REF;
if (!baseRef || !/^[A-Za-z0-9._/-]+$/.test(baseRef) || baseRef.includes("..")) {
  throw new Error("Invalid GITHUB_BASE_REF");
}

const output = execFileSync(
  "git",
  ["diff", "--name-only", "--", `origin/${baseRef}...HEAD`],
  { encoding: "utf8", shell: false },
);
```

An allow-list matching the CI provider's branch/ref format is preferable to a broad character class. Keep the working directory explicit if needed, reject an absent value, and never switch to `shell: true` or string interpolation in `execSync`/`spawnSync`.

Files in this skill

  • eval-1.baseline.md1.3 KB
  • eval-1.with-skill.md1.2 KB
  • eval-2.baseline.md975 B
  • eval-2.with-skill.md854 B
  • eval-3.baseline.md894 B
  • eval-3.with-skill.md763 B
  • eval-4.baseline.md862 B
  • eval-4.with-skill.md882 B
  • eval-5.baseline.md1009 B
  • eval-5.with-skill.md870 B
  • trigger-1.md149 B
  • trigger-2.md142 B
  • trigger-3.md146 B
  • trigger-4.md115 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…