Communitygithub.com

YepAPI/skills

Error security — safe error responses, correlation IDs, no stack trace leaks in production.

Qu'est-ce que skills ?

skills is a Claude Code agent skill that error security — safe error responses, correlation IDs, no stack trace leaks in production.

Compatible avec~Claude Code~Codex CLI~Cursor
npx skills add https://github.com/YepAPI/skills/tree/HEAD/skills/error-security

Demander à votre IA préférée

Ouvre une nouvelle conversation avec cette compétence d'agent déjà préchargée.

Documentation

Error Security

Rules

  • Never leak stack traces, database errors, or file paths to clients in production
  • Return generic error messages with a unique error ID: { error: "Something went wrong", errorId: "abc123" }
  • Log full error details server-side with the same correlation ID for debugging
  • Use different error detail levels: development (full stack trace) vs production (safe message + ID)
  • Catch all unhandled errors with global error handlers — never let raw errors reach the client
  • Sanitize error messages from third-party services before forwarding to clients
  • Return proper HTTP status codes: 400 (bad input), 401 (unauthenticated), 403 (forbidden), 404 (not found), 500 (server error)
// Express error handler middleware
import { randomUUID } from "node:crypto";

app.use((err: Error, req: Request, res: Response, next: NextFunction) => {
  const errorId = randomUUID();

  // Log full details server-side
  console.error({ errorId, message: err.message, stack: err.stack, url: req.url });

  // Return safe response to client
  const statusCode = (err as any).statusCode || 500;
  res.status(statusCode).json({
    error: statusCode >= 500 ? "Internal server error" : err.message,
    errorId,
    ...(process.env.NODE_ENV === "development" && { stack: err.stack }),
  });
});
// Next.js error boundary — safe production errors
export default function GlobalError({ error, reset }) {
  return (
    <div>
      <h2>Something went wrong</h2>
      <p>Error ID: {error.digest}</p>
      <button onClick={reset}>Try again</button>
    </div>
  );
}

Avoid

  • Returning err.message directly — database errors leak table names, column names, and query structure
  • Stack traces in production responses — they reveal file paths, dependencies, and internal architecture
  • Generic 500 for everything — use proper status codes so clients can handle errors appropriately
  • Logging errors without correlation IDs — makes production debugging nearly impossible
  • Swallowing errors silently — always log, even if the response is generic

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

YepAPI/skills

WCAG 2.1 AA — semantic HTML, keyboard navigation, screen readers.

YepAPI/skills

CRUD generators, data tables, user management, role-based access, and bulk operations.

YepAPI/skills

Tool-use patterns, multi-step reasoning, agent orchestration, and structured outputs.

YepAPI/skills

Chat UI components, streaming responses with AI SDK, context window management, and RAG patterns.

YepAPI/skills

Monitor what ChatGPT and Gemini say about your brand using YepAPI.

YepAPI/skills

Web analytics integration — event tracking, custom dashboards, privacy-first.

YepAPI/skills

Framer Motion — transitions, scroll animations, layout animations.

YepAPI/skills

OpenAPI 3.1 from Zod schemas, interactive docs with Swagger/Scalar, versioning, and example requests for every endpoint.

YepAPI/skills

Authentication security — bcrypt/argon2 hashing, brute force protection, secure password resets.

YepAPI/skills

Session auth, social providers, CSRF protection, and secure cookie patterns.

YepAPI/skills

Queue workers with BullMQ/Inngest/Trigger.dev, job retries, dead letter queues, concurrency.

YepAPI/skills

Link building research and backlink audit using YepAPI.

YepAPI/skills

MDX blog setup, RSS feed generation, sitemap.xml, structured data/JSON-LD, and related posts.

YepAPI/skills

Redis caching, CDN cache headers, stale-while-revalidate, cache invalidation, React Query.

YepAPI/skills

Recharts/Chart.js data visualization — bar, line, area, pie charts.

YepAPI/skills

Commander.js, interactive prompts with Clack, spinners, colors, config files, exit codes, and npm publishing.

YepAPI/skills

cmdk integration, Cmd+K trigger, fuzzy search, grouped actions, keyboard navigation, and dynamic action registration.

YepAPI/skills

Threaded comments, @mentions, reactions, moderation queue, optimistic UI, and cursor pagination.

YepAPI/skills

Competitive analysis between domains using YepAPI.

YepAPI/skills

Experiment setup, variant splitting, statistical significance, and feature flag integration.

Skills associés