Skip to content
Back to skills

Code Review Nodejs

ASecurity

Security review of Node.js / JavaScript code — dangerous sinks and Express/framework pitfalls. Load when reviewing a Node/JS codebase/PR, on package.json + Express/Next/Nest, or "review this Node app". Signals: child_process, eval, Function, prototype pollution, JWT, Mongoose/Sequelize.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentsjavascriptrustgojavasqlreactvuenextjsnodenodejs

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add NoorQureshi/SploitAgent --skill code-review-nodejs --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Review Nodejs?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Review Nodejs
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-code-review-nodejs/badge)](https://www.skillsdirectory.com/skills/noorqureshi-code-review-nodejs)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-review-nodejs
description: >
  Security review of Node.js / JavaScript code — dangerous sinks and Express/framework pitfalls.
  Load when reviewing a Node/JS codebase/PR, on package.json + Express/Next/Nest, or "review this
  Node app". Signals: child_process, eval, Function, prototype pollution, JWT, Mongoose/Sequelize.
domain: code-review
type: reference
stability: learning
modes: [bugbounty, defense, pentest]
severity: info
cwe: [CWE-94, CWE-78, CWE-1321, CWE-89]
tools: [semgrep, njsscan, ripgrep]
schema_version: 1
---

# Node.js / JavaScript security code review

## When it applies
Reading Node/JS source (Express, Next.js, NestJS, a package). Language companion to
`code-review-methodology` — the exact sinks and framework gotchas to grep and trace.

## Sinks & patterns (grep, then trace to user input)
- **Command exec**: `child_process.exec`/`execSync` with user input (use `execFile`/`spawn` w/ arg array);
  template strings in commands.
- **Code eval**: `eval`, `new Function`, `vm.runIn…`, `setTimeout("string")` — RCE.
- **Prototype pollution**: recursive merge/`Object.assign`/`lodash.merge`/`set`, `JSON.parse` into
  object merges, query parsers — `__proto__`/`constructor` keys (→ `web-prototype-pollution`).
- **SQL/NoSQL**: string-built SQL; Mongo queries taking raw `req.body`/`req.query` (operator injection
  `{$gt:''}`); Sequelize `.query()`/`literal`.
- **SSRF**: `axios`/`fetch`/`http.get`/`request` on a user URL.
- **Path/upload**: `fs.readFile`/`sendFile`/`path.join` with user paths; `res.sendFile` traversal.
- **XSS (server + client)**: `res.send` of unescaped input; DOM sinks `innerHTML`, `document.write`,
  `dangerouslySetInnerHTML` (React), `v-html` (Vue).
- **Deserialization**: `node-serialize`/`funcster` (unserialize RCE), untrusted `JSON`→object merge.

## Framework specifics
- **Express**: missing `helmet`/CSP, over-broad `cors()`, `req.query`/`req.params` into sinks, weak
  session `secret`, no per-object authz (IDOR/BOLA), `app.use` order bypassing auth middleware.
- **JWT**: `jsonwebtoken` with `algorithms` not pinned (alg confusion / `none`), weak secret
  (→ `web-auth-jwt`), secret in code.
- **Next.js/SSR**: `getServerSideProps` trusting client input; API routes missing auth; SSRF in image/proxy.
- **Mass assignment**: spreading `req.body` into a model/`create` (→ `api-mass-assignment`).

## Method
`rg -n "child_process|eval\(|new Function|innerHTML|dangerouslySetInnerHTML|\.merge\(|__proto__|node-serialize"`;
run `njsscan .` and `semgrep --config auto`; trace user input to each sink.

## Gotchas
- Client-side `innerHTML`/`v-html` = DOM XSS even in a "backend" review — check the front-end too.
- Mongo operator injection needs input validation/casting, not just parameterization.

## References
njsscan; Semgrep JS/TS rules; OWASP Node.js & NodeGoat; Express security best practices.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…