Skills Plugins MCP Prompt Model 博客 我的中心

nestjs-security

Implement JWT authentication, RBAC guards, Helmet hardening, and Argon2 hashing in NestJS. Use when adding auth strategies, role-based access control, CSRF protection, or security headers.

DeepseekModel キュレーション済みスキル 品質 優秀 · 90 v1.0.0

取得

https://deepseekmodel.com/api/download.php?id=hoangnguyen0403-agent-skills-standard-skills-nestjs-nestjs-security-skill-md&format=skill
ダウンロード .skill 標準形式。system_prompt と model_config を収録し、任意の Agent で利用可能
.skill ファイルの system_prompt フィールドの実際の内容。
name nestjs-security description Implement JWT authentication, RBAC guards, Helmet hardening, and Argon2 hashing in NestJS. Use when adding auth strategies, role-based access control, CSRF protection, or security headers. metadata {"triggers":{"files":["**/*.guard.ts","**/*.strategy.ts","**/auth/**"],"keywords":["Passport","JWT","AuthGuard","CSRF","Helmet"]}} NestJS Security Standards Priority: P0 (CRITICAL) Workflow: Secure NestJS Application Add Helmet — app.use(helmet()) in main.ts for HSTS, CSP headers. Configure JWT strategy — Use passport-jwt with RS256; validate iss and aud claims. Bind global AuthGuard — Register as APP_GUARD ; use @Public() for open routes. Add throttling — Enable @nestjs/throttler with Redis store for rate limiting. Hash with Argon2id — Replace bcrypt with argon2.hash(password, { type: argon2.argon2id }) . Verify — Run npm audit --prod and test that unauthenticated requests return 401. Global Auth Guard Example See implementation examples Argon2id Hashing Example See implementation examples Authentication (JWT) Strategy : Use @nestjs/passport with passport-jwt . Algorithm : Enforce RS256 (preferred) or HS256 . Reject none . Claims : Validate iss and aud . Tokens : Short access (15m), Long httponly refresh (7d). MFA : Require 2FA for admin panels. Authorization (RBAC) Deny by default : Bind AuthGuard globally (APP_GUARD). Bypass : Create @Public() decorator for open routes. Roles : Use Reflector.getAllAndOverride for Method/Class merge. Cryptography Hashing : Use Argon2id , not Bcrypt. See implementation . Encryption : Use AES-256-GCM with KMS rotation. See implementation . Hardening Helmet : Mandatory. Enable HSTS, CSP. CORS : Explicit origins only. No * . Throttling : Use Redis-backed @nestjs/throttler in production. CSRF : Required for cookie-based auth. See implementation . Data Protection Sanitization : Use ClassSerializerInterceptor + @Exclude() . Validation : ValidationPipe({ whitelist: true }) to prevent mass assignment. Audit : Log mutations (Who, What, When). See implementation . Secrets Management CI/CD : Run npm audit --prod in pipelines. Runtime : Inject via vault (AWS Secrets Manager / HashiCorp Vault), not .env . Anti-Patterns No Shadow APIs : Audit routes regularly; disable /docs in production. No SSRF : Allowlist domains for all outgoing HTTP requests. No SQLi : Use ORM; avoid raw query() with string concatenation. No XSS : Sanitize HTML input with dompurify . References Implementation Examples common/security-standards
このスキルを起動するキーワード。クリックでコピーできます。

このスキルにはトリガーワードがありません。

ダウンロードした .skill に含まれるフィールド。
フィールド 説明
formatフォーマット識別子(skill/v1)
skill_idスキル固有 ID
nameスキル名
versionバージョン
description説明
categoryカテゴリ(配列)
trigger_wordsトリガーワード
tagsタグ
sourceソース
source_urlソース URL(本ページ)
exported_atエクスポート日時(ダウンロード毎)
system_promptシステムプロンプト本文
model_configモデル設定:provider / model / temperature / max_tokens / top_p
examplesサンプル
install_guide各プラットフォームの導入説明(Coze / Dify / Claude / カスタム)
同じスキルを各プラットフォーム形式で出力できます。
.skill 標準形式。system_prompt と model_config を収録し、任意の Agent で利用可能 ダウンロード
.skillpro 拡張形式。scripts / tools / dependencies / hooks を含む ダウンロード
.json 純粋な JSON 出力。system_prompt とモデル設定のみ ダウンロード
Coze frontmatter 付き Markdown。Coze へのインポート用 ダウンロード
Dify Dify DSL。アプリ作成後にそのままインポート ダウンロード

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

验证码 --

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。