Nextjs security
Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/nextjs-security
π§ The right skill, one API call. AI agent skills registry with token-efficient skill resolution. 5,000+ skills from 500+ top repos.
npx -y skills add ComeOnOliver/skillshub --skill nextjs-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
What its author says it does
Copied from the file, not written here
Core security standards for App Router and Server Actions. Use when securing Next.js App Router routes, Server Actions, or API endpoints. (triggers: app/**/actions.ts, middleware.ts, action, boundary, sanitize, auth, jose)
SKILL.md
2.1 KB, 460 tokens by cl100k_base, as published. Nobody here has run it
Next.js Security
Priority: P0 (CRITICAL)
Structure
app/
βββ lib/
β βββ validation.ts # Shared Zod schemas
βββ middleware.ts # Auth & Headers
Implementation Guidelines
- Next.js Middleware: Use
middleware.tsfor edge-side authentication, role-based access control (RBAC), and enforcing Security Headers (e.g.,Content-Security-Policy (CSP),X-XSS-Protection). - Server Actions: Always sanitize all inputs from
FormDataor JSON using Zod. Perform authentication checks (await auth()) inside every action to verify the caller. - Data Tainting: Use the
experimental_taintAPI (taintObjectReference) to ensure sensitive server objects (e.g., User withpasswordHash) never leak into a Client Component. - Route Handlers (
route.ts): Implement rate limiting to prevent brute-force or DoS attacks. Verify Origin/Referer headers to mitigate CSRF (Cross-Site Request Forgery). - Auth Tokens: strictly use
HttpOnly,Securecookies withSameSite: 'Lax'for session management. Never store tokens inlocalStorage. - Logic Isolation: use the
server-onlypackage to prevent backend-specific logic from being included in the client bundle. - Component Purity: Escape all user-provided content rendered in components. Never use
dangerouslySetInnerHTMLwithout a sanitizer likeDOMPurify.
Anti-Patterns
- No leaking DB fields to client: Use DTOs; never pass raw model objects.
- No
process.envin client bundles: Mark asNEXT_PUBLIC_only if safe to expose. - No unvalidated Server Action inputs: Always validate with Zod schema.
- No auth checks in shared Layouts: Auth in layouts is insecure; use Middleware.