Skip to content
Back to skills

Analyze Js

ASecurity

Analyze JavaScript files for API endpoints, secrets, URLs, emails, sensitive files, and bundler versions

  • 9 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added February 6, 2026
securityjavascriptgojavabashnodeawstestingapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Scanned February 12, 2026

npx -y skills add xrip/claude-skill-analyze-js --skill analyze-js --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Analyze Js?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Analyze Js
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/xrip-analyze-js/badge)](https://www.skillsdirectory.com/skills/xrip-analyze-js)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md

---
name: analyze-js
description: Analyze JavaScript files for API endpoints, secrets, URLs, emails, sensitive files, and bundler versions
examples:
  - analyze-js bundle.js
  - analyze-js src/
  - analyze-js --verbose dist/
---

# JS Analyzer Skill

Analyzes JavaScript files for security-relevant information using `npx js-analyzer-cli`.
Works in any project without installation.

## Command

```bash
npx js-analyzer-cli [OPTIONS] <paths...>
```

## Detection Categories

- **endpoints**: REST APIs, GraphQL, OAuth, admin panels
- **urls**: External links, cloud storage, WebSockets
- **secrets**: API keys, tokens, JWT, credentials (auto-masked)
- **emails**: Valid addresses (test emails filtered)
- **files**: Sensitive file references (.env, configs, backups)
- **bundlers**: Detected bundlers with versions (Webpack, Vite, Rollup, etc.)

Auto-filters noise: build artifacts, module imports, XML namespaces.

## Options

- `--verbose` - Show progress details
- `--format=json` - JSON output (default: toon)
- `--pretty` - Pretty print JSON
- `--no-recursive` - Skip subdirectories

## Directory Scanning

Default behavior:
- Finds `.js`, `.jsx`, `.mjs` files
- Skips `node_modules/` and hidden dirs
- Recursive by default

## Output Format

TOON format (default) - compact, LLM-optimized:
```
summary:
  total: 18
  endpoints: 4
  secrets: 1
findings:
  endpoints[4	]{value	location}:
    /api/v1/users	bundle.js:42:15
    /admin/dashboard	bundle.js:234:12
  secrets[1	]{value	location}:
    AKIA...MPLE (AWS Key)	bundle.js:312:25
```

Location format: `file:line:column` (clickable in IDEs)

## How to Present Results

Start with summary, highlight critical findings (secrets, admin endpoints), group by category.

Example:
```
📊 Analysis: bundle.js (18 findings)

🔴 Critical:
• AWS Key at bundle.js:312:25
• Admin endpoint at bundle.js:234:12

Endpoints (4): /api/v1/users (bundle.js:42:15), /admin/dashboard (bundle.js:234:12), ...
Bundler: Webpack 5.88.2
```

## Usage Flow

1. Identify paths
2. Add flags if needed
3. Run: `npx js-analyzer-cli [flags] <paths>`
4. Parse and present

Note: First run downloads package (~2s), then cached.

## Security

For authorized testing only: pentesting, bug bounties, own applications, security audits.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…