nodejs-auth-and-security-review
Installation
SKILL.md
Node.js Auth and Security Review
When to use
Invoke when adding login, token, or session handling to a Node.js service that has the scaffold baseline, wiring an OAuth2/OIDC provider or JWT verification, defining the authorization model, hardening the HTTP surface (headers, CSRF, rate limiting), or running an OWASP-style review before release.
Do not use for: the service shell, validated config, logging, or error tiers (use nodejs-service-scaffold), OpenTelemetry/metrics/SLO wiring (use nodejs-observability-readiness), queue or event integration (use nodejs-queue-and-event-integration), or performance and resilience gating (use nodejs-performance-and-resilience).
Inputs
Required:
- A service with the
nodejs-service-scaffoldbaseline (principal-provider seam, validated config, error tiers present). - Approved
architecture/securitydecisions on auth provider, session vs token strategy, and secret handling — or explicit confirmation they are intentionally deferred.
Optional: