JsAnalyzer provides static analysis for JavaScript files, focusing on identifying security vulnerabilities. This AI agent skill can be triggered via various commands to perform comprehensive security scans, detecting elements such as URLs, paths, sources, sinks, postMessage handlers, and secrets.
What this skill does
Initiates a security scan when a user requests to analyze JavaScript files or security aspects.
Begins with parallel analyses in Phases 1 to 3, using specialized agents such as js-grep-analyzer, js-tool-runner, and js-architecture-analyzer.
Transitions to more focused analyses in Phase 4 with agents like source-sink-tracer, postmessage-analyzer, api-investigator, and secrets-analyzer.
Completes with a synthesis phase that compiles results into a summary report.
Who it is for
Developers tasked with ensuring JavaScript security within their projects.
Security teams seeking automated tools to enhance their review processes.
AI coding agent users, specifically those using tools like Claude Code, Cursor, and Codex.
Use cases
Performing security audits on JavaScript files found within projects to identify and rectify vulnerabilities.
Assisting teams in developing secure applications by reducing manual code review efforts through automation.
Enhancing existing security workflows with AI-driven analysis for complex JavaScript architectures.
Technical details
Operates using an orchestrator pattern that delegates analysis tasks to multiple specialized agents.
Includes agent tools like js-grep-analyzer, source-sink-tracer, and secrets-analyzer for focused analysis tasks.
Designed for compatibility with AI coding platforms such as Claude Code, Cursor, and Codex.
For authorised security testing, defensive research and educational use only.
Source & Licence
This package is built on open-source work published by SecurityTalent (SecurityTalent/bugskill-ai) and distributed under MIT. The original licence text and copyright notice are included in your download.
Personal and commercial use, modification and redistribution are permitted, provided the original copyright and licence notice are retained.
Your purchase covers curation, licence verification, packaging, documentation and instant delivery. It does not grant exclusive rights to the underlying open-source code, which remains available under its original licence.
Delivery & Support
Delivery: instant — a secure download link is emailed to you as soon as payment is confirmed.
Format: ZIP archive containing the skill files, documentation and the original licence.
Updates: updates are included only where stated on this page.
Refunds
This is a digital product delivered immediately after purchase. By completing your order you request immediate delivery and acknowledge that, once the download has been accessed, the statutory right to cancel no longer applies to the extent permitted by law. Refund requests are handled in accordance with our published Refund Policy.
Claude, Codex, Gemini and Cursor are trademarks of their respective owners. MCP Cart is an independent marketplace and is not affiliated with, endorsed by, or sponsored by any of them. Compatibility references describe interoperability only.