Node.js / JavaScript security code review
SkillDatabases & dataSecurity review of Node.js / JavaScript code, dangerous sinks and Express/framework pitfalls. Load when reviewing a Node/JS codebase/PR, on package.json + Express/Next/Nest, or "review this Node app". Signals: child_process, eval, Function, prototype pollution, JWT, Mongoose/Sequelize.
Use Node.js / JavaScript security code review in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Node.js / JavaScript security code review and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Node.js / JavaScript security code review skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/code-review/code-review-nodejs/SKILL.md and read by Ahel’s review.
When it applies
Reading Node/JS source (Express, Next.js, NestJS, a package). Language companion to
code-review-methodology — the exact sinks and framework gotchas to grep and trace.
Sinks & patterns (grep, then trace to user input)
- Command exec:
child_process.exec/execSyncwith user input (useexecFile/spawnw/ arg array); template strings in commands. - Code eval:
eval,new Function,vm.runIn…,setTimeout("string")— RCE. - Prototype pollution: recursive merge/
Object.assign/lodash.merge/set,JSON.parseinto object merges, query parsers —__proto__/constructorkeys (→web-prototype-pollution). - SQL/NoSQL: string-built SQL; Mongo queries taking raw
req.body/req.query(operator injection{$gt:''}); Sequelize.query()/literal. - SSRF:
axios/fetch/http.get/requeston a user URL. - Path/upload:
fs.readFile/sendFile/path.joinwith user paths;res.sendFiletraversal. - XSS (server + client):
res.sendof unescaped input; DOM sinksinnerHTML,document.write,dangerouslySetInnerHTML(React),v-html(Vue). - Deserialization:
node-serialize/funcster(unserialize RCE), untrustedJSON→object merge.
Framework specifics
- Express: missing
helmet/CSP, over-broadcors(),req.query/req.paramsinto sinks, weak sessionsecret, no per-object authz (IDOR/BOLA),app.useorder bypassing auth middleware. - JWT:
jsonwebtokenwithalgorithmsnot pinned (alg confusion /none), weak secret (→web-auth-jwt), secret in code. - Next.js/SSR:
getServerSidePropstrusting client input; API routes missing auth; SSRF in image/proxy. - Mass assignment: spreading
req.bodyinto a model/create(→api-mass-assignment).
Method
rg -n "child_process|eval\(|new Function|innerHTML|dangerouslySetInnerHTML|\.merge\(|__proto__|node-serialize";
run njsscan . and semgrep --config auto; trace user input to each sink.
Gotchas
- Client-side
innerHTML/v-html= DOM XSS even in a "backend" review — check the front-end too. - Mongo operator injection needs input validation/casting, not just parameterization.
References
njsscan; Semgrep JS/TS rules; OWASP Node.js & NodeGoat; Express security best practices.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
code-review-nodejs-noorqureshi- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptsetup-ts-deep-modules
Skill · mattpocock
The pick for TypeScripttypescript-pro
Skill · jeffallan
The pick for TypeScriptnodejs-backend-patterns
Skill · wshobson
The pick for Noderun-node-tests
Skill · hiroro-work
The pick for Node