Skip to content
Back to skills

Example 4 Security Validation

ASecurity

Sub-skill of testing-production: Example 4: Security Validation.

  • 17 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 9, 2026
developmenttypescriptgonodetestingapidatabasesecurity

Works with

  • api

Security analysis

A100/100

Scanned September 9, 2026

npx -y skills add vamseeachanta/workspace-hub --skill example-4-security-validation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Example 4 Security Validation?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Example 4 Security Validation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/vamseeachanta-example-4-security-validation/badge)](https://www.skillsdirectory.com/skills/vamseeachanta-example-4-security-validation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: testing-production-example-4-security-validation
description: 'Sub-skill of testing-production: Example 4: Security Validation.'
version: 1.0.0
category: development
type: reference
scripts_exempt: true
---

# Example 4: Security Validation

## Example 4: Security Validation


```typescript
describe('Security Validation', () => {
  it('should enforce authentication on protected routes', async () => {
    const response = await request(app)
      .get('/api/protected')
      .expect(401);

    expect(response.body.error).toBe('Authentication required');
  });

  it('should validate and sanitize input', async () => {
    const maliciousInput = '<script>alert("xss")</script>';

    const response = await request(app)
      .post('/api/users')
      .send({ name: maliciousInput })
      .set('Authorization', `Bearer ${validToken}`)
      .expect(400);

    expect(response.body.error).toContain('Invalid input');
  });

  it('should use HTTPS in production', () => {
    if (process.env.NODE_ENV === 'production') {
      expect(process.env.FORCE_HTTPS).toBe('true');
    }
  });

  it('should have proper health check endpoint', async () => {
    const response = await request(app)
      .get('/health')
      .expect(200);

    expect(response.body).toMatchObject({
      status: 'healthy',
      timestamp: expect.any(String),
      uptime: expect.any(Number),
      dependencies: {
        database: 'connected',
        cache: 'connected',
        external_api: 'reachable'
      }
    });
  });
});
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…