Sast Eslint Security

🌐Community
by vchirrav · vlatest · Repository

Helps with ESLint, security as part of implementing security and authentication workflows.

Install on your platform

We auto-selected Claude Code based on this skill’s supported platforms.

1

Run in terminal (recommended)

terminal
claude mcp add vchirrav-sast-eslint-security npx -- -y @trustedskills/vchirrav-sast-eslint-security
2

Or manually add to ~/.claude/settings.json

~/.claude/settings.json
{
  "mcpServers": {
    "vchirrav-sast-eslint-security": {
      "command": "npx",
      "args": [
        "-y",
        "@trustedskills/vchirrav-sast-eslint-security"
      ]
    }
  }
}

Requires Claude Code (claude CLI). Run claude --version to verify your install.

About This Skill

What it does

This skill, vchirrav-sast-eslint-security, integrates static analysis security checks into your development workflow. It leverages ESLint to identify and remediate potential security vulnerabilities in JavaScript code. The tool helps enforce secure coding practices by flagging common issues like cross-site scripting (XSS) and injection flaws.

When to use it

  • During Code Reviews: Integrate the skill into automated code review processes to proactively catch security bugs before they reach production.
  • New Project Setup: Automatically configure ESLint with security rules when starting a new JavaScript project.
  • Refactoring Existing Codebases: Use the skill to scan and improve the security posture of older, potentially vulnerable code.
  • Continuous Integration/Continuous Delivery (CI/CD): Incorporate it into your CI/CD pipeline for automated security checks with every build.

Key capabilities

  • ESLint integration
  • Security vulnerability detection
  • Automated secure coding practices enforcement
  • Cross-site scripting (XSS) prevention
  • Injection flaw identification

Example prompts

  • "Run a security scan on this JavaScript file using ESLint."
  • "Find and fix potential XSS vulnerabilities in my codebase."
  • "Configure ESLint with recommended security rules for a new project."

Tips & gotchas

  • Requires Node.js and npm to be installed as it relies on ESLint.
  • The effectiveness of the skill depends on the quality and configuration of the ESLint ruleset used.

Tags

🛡️

TrustedSkills Verification

Unlike other registries that point to live repositories, TrustedSkills pins every skill to a verified commit hash. This protects you from malicious updates — what you install today is exactly what was reviewed and verified.

Security Audits

Gen Agent Trust HubPass
SocketPass
SnykPass

Details

Version
vlatest
License
Author
vchirrav
Installs
3

🌐 Community

Passed automated security scans.