Sota javascript typescript
Skill martinholovsky/SOTA-skills/skills/sota-javascript-typescript
State-of-the-Art (2026) AI/LLM engineering skills/agents for building and auditing software — 40+ domain & language skills, BUILD/AUDIT modes, audit checklists.
npx -y skills add martinholovsky/SOTA-skills --skill sota-javascript-typescriptAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 8 stars8 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
State-of-the-art JavaScript and TypeScript engineering (2026) for both writing and auditing code. Covers strict TypeScript configuration and type design, language idioms and pitfalls, async patterns, Node.js backends, JS/TS-specific security (XSS, prototype pollution, supply chain, injection), frontend/React and Node performance, and testing/tooling. Use whenever building, reviewing, refactoring, or security-auditing code involving JavaScript, TypeScript, Node, npm, React, frontend code, tsconfig, package.json, vitest, or any .ts/.tsx/.js/.mjs files.
SKILL.md
7.9 KB, as published. Nobody here has run it
SOTA JavaScript / TypeScript Engineering
Purpose
This skill encodes 2026 state-of-the-art for JS/TS so generated code is strict, secure, and fast by default — and so audits of existing code find the bug classes that actually bite: untyped boundaries, floating promises, XSS sinks, prototype pollution, supply-chain gaps, event-loop blocking, and leak-prone listeners. It has two operating modes; pick one explicitly at the start of a task.
Baseline assumptions (mid-2026): TypeScript ≥5.9 strict (6.0 = last JS-based compiler; 7.0 Go-native stable since July 2026, shipped as the regular typescript package — frameworks embedding the compiler API via Volar, e.g. Vue/Angular/Astro/Svelte, stay on 6.0 until a stable plugin API lands), ESM-first, Node LTS ≥22 (24 = active LTS; Node 26 ships Temporal by default), ES2024+ available, React 19.2-era with Server Components and React Compiler 1.0 where relevant, vitest 4 + flat-config ESLint (v9/v10).
BUILD mode (writing or modifying code)
- Read the relevant rules files first (index below) for the area you're touching. Don't generate from memory what a rules file specifies.
- Defaults unless the codebase dictates otherwise: strict tsconfig (rules/01), ESM,
unknownoverany, discriminated unions for state, zod/valibot parse at every untrusted boundary,??/?.discipline, AbortController on cancellable ops, pino logging in services, Web APIs over deps. - Match the host codebase for style, framework, and structure — but do not replicate its security bugs or
any-sprawl into new code. New code meets the bar even in old repos. - Boundary rule: every input from outside the type system (HTTP, env, JSON.parse, storage, postMessage, DB without typed client) is parsed with a schema before use. No
as Ton external data. - Finish the job: new code compiles under
tsc --noEmit, passes lint, and ships with behavior-level tests (rules/07). Handle the error path of every async call — no floating promises. - When a requirement conflicts with a rule (e.g., legacy CJS, jest), follow the codebase and note the deviation; don't silently half-apply both.
AUDIT mode (reviewing existing code)
Scope first (frontend? Node service? library?), then read the matching rules files and run their audit checklists — each ends with grep/eslint hunt patterns. Validate findings: confirm attacker-controlled data actually reaches the sink, confirm the perf issue is on a hot path. No speculative findings.
Severity conventions:
- CRITICAL — remotely exploitable now: untrusted input reaching eval/innerHTML/exec/SQL, auth bypass, secrets exfiltratable via XSS.
- HIGH — exploitable with conditions, or guaranteed-corruption bug class: missing boundary validation, prototype-pollution-prone merge of request data, floating promises dropping errors, tokens in localStorage, unbounded request bodies, float money math, sync crypto blocking the loop.
- MEDIUM — weakened posture or latent defect: missing strict tsconfig flags, no graceful shutdown, missing CSP/timeouts,
||vs??on falsy-valid values, index keys on mutable lists, unbounded caches, missing supply-chain controls. - LOW — hygiene/debt: dead deps,
hasOwnProperty, console.log in services, snapshot sprawl, missing memoization on profiled-hot paths.
Finding format:
[SEVERITY] Title (CWE-xxx if security)
File: path/to/file.ts:42
Issue: what is wrong, in one or two sentences
Evidence: the offending snippet
Impact: what an attacker/user/operator experiences
Fix: concrete change (code if short)
Order the report CRITICAL→LOW, deduplicate repeated patterns into one finding with a file list, and end with the top 3 systemic recommendations (e.g., "enable noUncheckedIndexedAccess", "adopt MSW", "add zod to route boundaries").
Rules index
| File | Read this when... |
|---|---|
| rules/01-typescript-config-and-types.md | touching tsconfig; designing types/interfaces; seeing any/casts; modeling state; validating input shape; setting up a library or monorepo; deciding zod-vs-types questions |
| rules/02-language-idioms.md | writing any JS/TS logic: equality, ??/?., array methods, immutability, Map/Set, error classes and Result types, generators, dates (Temporal), money/number precision |
| rules/03-async-patterns.md | anything with promises/async: combinator choice, floating promises, AbortController/timeouts, event-loop ordering, top-level await, workers, streams, async race conditions |
| rules/04-node-backend.md | building/auditing Node services: runtime choice, dropping deps for built-ins, env config, HTTP hardening (timeouts/body limits), graceful shutdown, process error policy, pino |
| rules/05-security.md | any security-relevant code or audit: XSS sinks, CSP, prototype pollution, npm supply chain, ReDoS, token storage/JWT, postMessage, child_process injection, SSRF |
| rules/06-performance.md | bundle size, React re-renders/keys/RSC, virtualization, debounce/throttle, memory leaks, Node event-loop blocking, profiling before optimizing |
| rules/07-testing-and-tooling.md | writing tests or setting up tooling: vitest, testing-library behavior testing, MSW, Playwright, ESLint flat + typescript-eslint strict, knip, publint/attw, CI gates. Test strategy — suite shape, TDD, doubles, test data, flake policy — lives in sota-testing; load it for any build that writes logic. This file owns JS/TS runner mechanics only. |
For a full audit, read 01→07 in order; security-focused audits prioritize 05, 01, 03, 04.
Top 10 non-negotiables
strict: true+noUncheckedIndexedAccessin every tsconfig; noany, no@ts-ignore—unknown+ narrowing,@ts-expect-errorwith reason.- Parse, don't cast, at boundaries: zod/valibot on every HTTP body/query, env var, JSON.parse, webhook, postMessage payload. Types inside, schemas at the edge.
- No floating promises: every promise awaited or explicitly
.catch-handled;@typescript-eslint/no-floating-promisesas error.allSettledfor independent work; bounded concurrency. - Discriminated unions for state, exhaustive
switchwithneverdefault — no boolean-soup interfaces with optional data/error pairs. ===always;??/?.over||/&&for null-handling; immutable updates (toSorted,structuredClone, spread) on shared data.- Errors are
Errorsubclasses withcause; never throw strings; never swallow with empty catch; Node policy = log fatally then exit on uncaught. - XSS sinks are forbidden by default: no
innerHTML/dangerouslySetInnerHTMLwith non-constant input unless DOMPurify-sanitized at render; no eval family ever; CSP on HTML responses. - No secrets in localStorage; no shell interpolation: httpOnly cookies for tokens;
execFile/spawnarray-args, neverexecwith template strings; parameterized SQL. - Supply chain controlled: committed lockfile +
npm ci, install scripts disabled/allowlisted, update cooldown, minimal deps — prefer platform built-ins (fetch, node:test, crypto.randomUUID). - AbortController + timeouts on all I/O; never block the event loop (>50ms CPU → worker; no
*Syncin request paths); listeners and intervals always cleaned up.