Nextjs security
Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/nextjs-security
Core security standards for App Router and Server Actions. Use when securing Next.js App Router routes, Server Actions, or API endpoints. (triggers: app/**/actions.ts, middleware.ts, action, boundary, sanitize, auth, jose)From its SKILL.md
npx -y skills add ComeOnOliver/skillshub --skill nextjs-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
2.1 KB, 460 tokens by cl100k_base, as published. Nobody here has run it
Next.js Security
Priority: P0 (CRITICAL)
Structure
app/
├── lib/
│ └── validation.ts # Shared Zod schemas
└── middleware.ts # Auth & Headers
Implementation Guidelines
- Next.js Middleware: Use
middleware.tsfor edge-side authentication, role-based access control (RBAC), and enforcing Security Headers (e.g.,Content-Security-Policy (CSP),X-XSS-Protection). - Server Actions: Always sanitize all inputs from
FormDataor JSON using Zod. Perform authentication checks (await auth()) inside every action to verify the caller. - Data Tainting: Use the
experimental_taintAPI (taintObjectReference) to ensure sensitive server objects (e.g., User withpasswordHash) never leak into a Client Component. - Route Handlers (
route.ts): Implement rate limiting to prevent brute-force or DoS attacks. Verify Origin/Referer headers to mitigate CSRF (Cross-Site Request Forgery). - Auth Tokens: strictly use
HttpOnly,Securecookies withSameSite: 'Lax'for session management. Never store tokens inlocalStorage. - Logic Isolation: use the
server-onlypackage to prevent backend-specific logic from being included in the client bundle. - Component Purity: Escape all user-provided content rendered in components. Never use
dangerouslySetInnerHTMLwithout a sanitizer likeDOMPurify.
Anti-Patterns
- No leaking DB fields to client: Use DTOs; never pass raw model objects.
- No
process.envin client bundles: Mark asNEXT_PUBLIC_only if safe to expose. - No unvalidated Server Action inputs: Always validate with Zod schema.
- No auth checks in shared Layouts: Auth in layouts is insecure; use Middleware.
References
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.