Nextjs Security Scan

Defensive security scan for Next.js App Router projects. Detects environment-variable leakage to the browser bundle, unauthenticated server actions, missing middleware auth, unsafe CORS on route handlers, and trust-boundary violations in revalidatePath/revalidateTag. Invoke when the user asks to "review", "audit", or "scan" a Next.js codebase, or when editing files under app/ or middleware.ts.

Dolphinllc d71ae63 5.8 KB Updated

File contents

Dolphinllc/claude-security-skills/tree/main/skills/defensive/web/nextjs-security-scan commit d71ae63534

Frequently asked questions

npx skillmds@latest add dolphinllc/nextjs-security-scan