> nextjs-security
Core security standards for App Router and Server Actions. Use when securing Next.js App Router routes, Server Actions, or API endpoints. (triggers: app/**/actions.ts, middleware.ts, action, boundary, sanitize, auth, jose)
curl "https://skillshub.wtf/HoangNguyen0403/agent-skills-standard/nextjs-security?format=md"Next.js Security
Priority: P0 (CRITICAL)
Structure
app/
├── lib/
│ └── validation.ts # Shared Zod schemas
└── middleware.ts # Auth & Headers
Implementation Guidelines
- Action Safety: Validate all
FormDataor JSON input using Zod. - Data Boundaries: Never pass whole DB objects to Client Components.
- Server-Only: Mark sensitive logic files with
'use server-only'. - CSRF: Modern Next.js manages this, but ensure unique session origins.
- Middleware Guarding: Use
middleware.tsfor global route protection. - Sanitization: Sanitize HTML if bypassing default React escaping.
Anti-Patterns
- Raw Props: No leaking DB fields: Use DTOs for client data.
- Client Secrets: No process.env in client: Mark as
NEXT_PUBLIC_only if safe. - Unvalidated Actions: No raw JSON actions: Always validate schema.
- Logic in Layouts: No auth in shared Layouts: Insecure; use Middleware.
References
> related_skills --same-repo
> typescript-tooling
Development tools, linting, and build config for TypeScript. Use when configuring ESLint, Prettier, Jest, Vitest, tsconfig, or any TS build tooling. (triggers: tsconfig.json, .eslintrc.*, jest.config.*, package.json, eslint, prettier, jest, vitest, build, compile, lint)
> typescript-security
Secure coding practices for TypeScript. Use when validating input, handling auth tokens, sanitizing data, or managing secrets and sensitive configuration. (triggers: **/*.ts, **/*.tsx, validate, sanitize, xss, injection, auth, password, secret, token)
> typescript-language
Modern TypeScript standards for type safety and maintainability. Use when working with types, interfaces, generics, enums, unions, or tsconfig settings. (triggers: **/*.ts, **/*.tsx, tsconfig.json, type, interface, generic, enum, union, intersection, readonly, const, namespace)
> typescript-best-practices
Idiomatic TypeScript patterns for clean, maintainable code. Use when writing or refactoring TypeScript classes, functions, modules, or async logic. (triggers: **/*.ts, **/*.tsx, class, function, module, import, export, async, promise)