Skip to content
Back to skills

Typescript Security

ASecurity

Do not fetch `process.env.API_URL` until it has been parsed and checked against an explicit allow-list. Environment configuration is not automatically trusted, and unrestricted URLs create an SSRF risk: ```ts const rawApiUrl = process.env.API_URL; if (!rawApiUrl) { throw new Error("API_URL is required"); } const apiUrl = new URL(rawApiUrl); const allowedOrigins = new Set(["https://api.example.com"]); if (apiUrl.protocol !== "https:" || !allowedOrigins.has(apiUrl.origin)) { throw new Error("AP...

  • 549 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
developmentrustapi

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 15 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill typescript-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Typescript Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Typescript Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-typescript-security-80b39e59/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-typescript-security-80b39e59)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Do not fetch `process.env.API_URL` until it has been parsed and checked against an explicit allow-list. Environment configuration is not automatically trusted, and unrestricted URLs create an SSRF risk:

```ts
const rawApiUrl = process.env.API_URL;
if (!rawApiUrl) {
  throw new Error("API_URL is required");
}

const apiUrl = new URL(rawApiUrl);
const allowedOrigins = new Set(["https://api.example.com"]);
if (apiUrl.protocol !== "https:" || !allowedOrigins.has(apiUrl.origin)) {
  throw new Error("API_URL is not an allowed HTTPS origin");
}

const response = await fetch(apiUrl, {
  redirect: "error",
});
if (!response.ok) {
  throw new Error(`API request failed: ${response.status}`);
}
```

Keep credentials out of the URL, validate any path/query inputs separately, and enforce the same destination policy server-side rather than relying on a client-side check.

Files in this skill

  • eval-1.baseline.md1.3 KB
  • eval-1.with-skill.md1.2 KB
  • eval-2.baseline.md975 B
  • eval-2.with-skill.md854 B
  • eval-3.baseline.md894 B
  • eval-3.with-skill.md763 B
  • eval-4.baseline.md862 B
  • eval-4.with-skill.md882 B
  • eval-5.baseline.md1009 B
  • eval-5.with-skill.md870 B
  • trigger-1.md149 B
  • trigger-2.md142 B
  • trigger-3.md146 B
  • trigger-4.md115 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…