Rule reference

25 security rules for Node apps and agent config

Each page shows the trigger, confidence, and fix. Examples come from tested fixtures, and framework variants use the APIs the scanner detected.

25 rules, 214 framework and host fixes

  1. 15 Application rulesFramework-aware checks for Node source.
  2. 10 Agent rulesHooks, MCP, instructions, and editor config.
  3. 214 Verified variantsEach example comes from a fixture the tests assert on.
Generated from compiled rule metadata and tested fixtures
npx owlwarden scan          # your app
npx owlwarden vet .         # your agent's config

Application source

15 rules that read the code in your repository. 9 of 10 OWASP Top 10 (2021) categories have at least one rule, and the ones that do not are listed too.

Agent and editor configuration

10 rules that read the files your agent loads out of the working tree. See what that surface is and the ASI 2026 coverage.

What a rule page tells you

The trigger, impact, example, fix for the selected framework, taxonomy mapping, and commands to reproduce the check locally.