JS Analyzer — Security agent for Claude Code
JavaScript static analysis agent for client-side security review.
How to install JS Analyzer
Installs to ~/.claude/agents/h-mmer-pentest-agents-js-analyzer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/H-mmer/pentest-agents/HEAD/.claude/agents/js-analyzer.md -o ~/.claude/agents/h-mmer-pentest-agents-js-analyzer.md Restart Claude Code, or start a new session, for it to be picked up.
What JS Analyzer does
name: js-analyzer description: "JavaScript static analysis agent for client-side security review. Use for analyzing JS bundles, finding hardcoded secrets, tracing DOM XSS source-sink flows, identifying postMessage handlers, extracting API endpoints, and reviewing client-side access controls. Provide URLs or local JS file paths." tools: Bash, Read, Write, Edit, Glob, Grep, WebFetch, mcp__writeup-search__search_writeups, mcp__writeup-search__get_writeup, mcp__writeup-search__search_techniques,
Alternatives in Security
- Token Auditor — Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d 79.4k ★
- Protocol Reverse Engineering — Comprehensive techniques for capturing, analyzing, and documenting network protocols for security re 31.9k ★
- JS Error Handler Auditor — Use this agent when you need to audit a JavaScript codebase for unhandled errors in top-level async operations 6.1k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Webview Security Auditor
Static auditor for Android WebView and iOS WKWebView/SFSafariViewController configuration and bridge exposure:
GitHub Actions Auditor
Use this agent when you need to review GitHub Actions workflow files for issues, errors, inconsistencies, or p
SEO Planner
Use this agent when the user asks to plan, strategize, or audit their SEO content calendar. This includes anal
Redteam Source Code Analyzer
Source code security analyzer for CMS and web applications. Use this agent when the task requires reading repo
Function Analyzer
Performs ultra-granular per-function deep analysis for security audit context building. Use when analyzing den
Security Audit Analyzer
Комплексный анализ безопасности веб-приложений с JavaScript frontend и PHP backend. Проверка уязвимостей OWASP
Related Skills
Domxss
Confirm DOM XSS in a real headless browser — injects canary payloads into params + URL fragment and only repor
Hunt XSS
Active XSS hunt for an ingested program. Consumes webvuln-surface seeds (reflected params + DOM sinks) + optio
Sec Scan XSS
XSS 취약점 진단 — Persistent / Reflected / DOM / Redirect XSS — scan_xss.py + LLM 교차검증