Lifestyle & Tools
#security
nestjs-security
Implement JWT authentication, RBAC guards, Helmet hardening, and Argon2 hashing in NestJS. Use when adding auth strategies, role-based access control, CSRF protection, or security headers.
DeepseekModel
Curated skill
Quality Excellent · 90
v1.0.0
Get
https://deepseekmodel.com/api/download.php?id=hoangnguyen0403-agent-skills-standard-skills-nestjs-nestjs-security-skill-md&format=skill
Download .skill
Standard format with system_prompt and model_config, ready for any agent framework
The actual content of the system_prompt field in the .skill file.
name nestjs-security description Implement JWT authentication, RBAC guards, Helmet hardening, and Argon2 hashing in NestJS. Use when adding auth strategies, role-based access control, CSRF protection, or security headers. metadata {"triggers":{"files":["**/*.guard.ts","**/*.strategy.ts","**/auth/**"],"keywords":["Passport","JWT","AuthGuard","CSRF","Helmet"]}} NestJS Security Standards Priority: P0 (CRITICAL) Workflow: Secure NestJS Application Add Helmet — app.use(helmet()) in main.ts for HSTS, CSP headers. Configure JWT strategy — Use passport-jwt with RS256; validate iss and aud claims. Bind global AuthGuard — Register as APP_GUARD ; use @Public() for open routes. Add throttling — Enable @nestjs/throttler with Redis store for rate limiting. Hash with Argon2id — Replace bcrypt with argon2.hash(password, { type: argon2.argon2id }) . Verify — Run npm audit --prod and test that unauthenticated requests return 401. Global Auth Guard Example See implementation examples Argon2id Hashing Example See implementation examples Authentication (JWT) Strategy : Use @nestjs/passport with passport-jwt . Algorithm : Enforce RS256 (preferred) or HS256 . Reject none . Claims : Validate iss and aud . Tokens : Short access (15m), Long httponly refresh (7d). MFA : Require 2FA for admin panels. Authorization (RBAC) Deny by default : Bind AuthGuard globally (APP_GUARD). Bypass : Create @Public() decorator for open routes. Roles : Use Reflector.getAllAndOverride for Method/Class merge. Cryptography Hashing : Use Argon2id , not Bcrypt. See implementation . Encryption : Use AES-256-GCM with KMS rotation. See implementation . Hardening Helmet : Mandatory. Enable HSTS, CSP. CORS : Explicit origins only. No * . Throttling : Use Redis-backed @nestjs/throttler in production. CSRF : Required for cookie-based auth. See implementation . Data Protection Sanitization : Use ClassSerializerInterceptor + @Exclude() . Validation : ValidationPipe({ whitelist: true }) to prevent mass assignment. Audit : Log mutations (Who, What, When). See implementation . Secrets Management CI/CD : Run npm audit --prod in pipelines. Runtime : Inject via vault (AWS Secrets Manager / HashiCorp Vault), not .env . Anti-Patterns No Shadow APIs : Audit routes regularly; disable /docs in production. No SSRF : Allowlist domains for all outgoing HTTP requests. No SQLi : Use ORM; avoid raw query() with string concatenation. No XSS : Sanitize HTML input with dompurify . References Implementation Examples common/security-standards
Keywords that activate this skill. Click one to copy it.
This skill does not provide trigger words.
The downloaded .skill package contains the following fields.
| Field | Description |
|---|---|
| format | Format tag (skill/v1) |
| skill_id | Unique skill ID |
| name | Skill name |
| version | Version |
| description | Description |
| category | Categories (array) |
| trigger_words | Trigger words |
| tags | Tags |
| source | Source |
| source_url | Source URL (this page) |
| exported_at | Exported at (set per download) |
| system_prompt | System prompt body |
| model_config | Model config: provider / model / temperature / max_tokens / top_p |
| examples | Examples |
| install_guide | Import guide for Coze / Dify / Claude / custom frameworks |
The same skill can be exported in different platform formats.