npx skills add ...
npx skills add c0x12c/ai-toolkit --skill js-security-audit
Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. Use when reviewing package.json or lockfiles, adding or upgrading npm dependencies, setting up CI security gates, hardening a new repo, or responding to a compromised package.
npx skills add c0x12c/ai-toolkit --skill js-security-audit
Run a 5-area security audit on a JS/TS project (npm, yarn, or pnpm). Produces a pass/fail report per area with file:line references.
.npmrc, lockfiles, 2FA, exact pinningnpm ci --ignore-scripts, lockfile-lint, audit gate)See
audit-checklist.mdfor the full MUST/SHOULD/SHOULDN'T list. Seeeslint-security.mdfor the SAST ESLint template and rules table. Seeincident-playbook.mdfor the 5-step compromised-dependency response. Seepackage-manager.mdfor npm/yarn/pnpm command equivalents and tooling.
Detect package manager first by checking which lockfile exists: package-lock.json (npm), yarn.lock (yarn), pnpm-lock.yaml (pnpm). Use the matching commands from package-manager.md.
Check .npmrc, lockfile presence, version pinning, .gitignore, scoped packages.
Run audit, scan lockfile diff for unexpected packages, check for latest tags and trivial deps.
Verify npm ci over npm install, --ignore-scripts with selective rebuild allowlist, audit gate, lockfile-lint, SHA-pinned actions, SBOM, ESLint security config.
Check .github/dependabot.yml, alert routing, P1 SLA on critical/high, grouping config.
Verify the team has a documented playbook, IOC monitoring, credential-rotation runbook.
latest tag in production deps, no npm audit gate in CI, missing 2FA on publishers.npmrc hardening, no Dependabot config, no SBOM generation, ESLint security config missingnpq pre-install vetting, no Socket.dev/Snyk integrationnpmjs.com for the package before installing, especially for less-common names from a chat suggestion.npm install vs npm ci matters in CI. npm install will rewrite the lockfile if the lockfile and package.json disagree, silently pulling new versions. npm ci fails the build instead. CI must use ci.--ignore-scripts blocks legitimate packages too. esbuild, sharp, prisma, bcrypt need their postinstall scripts to download binaries or generate clients. Use --ignore-scripts then npm rebuild <allowlist> — and document why each package is in the allowlist.actions/checkout@v4 follows the tag, which can be re-pointed to malicious code (it has happened). Use the full 40-char SHA with a comment showing the tag.registry.npmjs.org, is a red flag — investigate before merging.min-release-age is npm v11+. On older npm, mention it as a SHOULD but don't fail the audit.Math.random() are predictable. Force crypto.randomInt(). The Notion guideline calls this out as a real finding from c0x12c codebases.The skill needs Bash to run npm audit and friends. To avoid prompts on every audit, add these to your ~/.claude/settings.json (or project .claude/settings.json):
This keeps the audit commands silent while leaving everything else (write operations, deletes, etc.) gated behind a prompt.
Produces an audit report:
## JS Security Audit: {repo}
### Overall: Pass | Fail
| Area | Status | Critical | Warnings | Info |
|--------------------|----------|----------|----------|------|
| Project Setup | Pass | 0 | 1 | 0 |
| Dependency Hygiene | Fail | 1 | 0 | 0 |
| CI/CD Pipeline | Pass | 0 | 2 | 1 |
| Dependabot | Warning | 0 | 1 | 0 |
| Incident Response | Info | 0 | 0 | 1 |
### Critical Findings
- **[Dependency Hygiene]** `lodash` pinned to `latest` in package.json:24
- Fix: Replace with exact version `"lodash": "4.17.21"`
- Reason: `latest` resolves at install time, defeating lockfile guarantees
### Warnings
- **[Project Setup]** `.npmrc` missing `ignore-scripts=true`
- File: `.npmrc:1`
- Fix: Add `ignore-scripts=true` and use `npm rebuild` for allowlisted packages
### Remediation Priority
1. Fix critical findings before merging
2. Address warnings in next sprint
3. Info items as time permits