eslint-plugin-openai-security
OpenAI SDK security — API-key exposure and untrusted prompt content
AI-Optimized Security
Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.
Install
npm install -D eslint-plugin-openai-securityLive from GitHub
This content is fetched directly from README.md on GitHub and cached for 1 hour.
Note on branding: this row omits the OpenAI mark. OpenAI's logo is not available under a permissive licence, so we don't reproduce it.
⭐ If this plugin caught a real bug for you, star the repo — it's the signal that keeps these rules maintained.
Description
Security rules for openai.
Every rule gates on the SDK actually being imported, so the plugin stays silent in files that don't use it.
- Why — a linter nobody reads protects nothing. We would rather miss a finding than spend your attention on one that was never real.
- How — evidence, not names. A rule fires on what the code does, resolved through the AST and ESLint's own scope analysis.
- What — every finding carries its fix, in prose for a human and as structured JSON for an agent. Security rules add a CWE mapping and, where assigned, a CVSS score.
That trade costs recall, and we measure it: methodology · results · a false positive is a bug.
Getting Started
- To check out the guide, visit eslint.interlace.tools. 📚
npm install eslint-plugin-openai-security --save-dev⚙️ Configuration Presets
| Preset | Description |
|---|---|
recommended | Enables every rule at error. |
strict | Same set as recommended; reserved for rules that are not yet safe by default. |
minimal | Same set as recommended; reserved for a reduced high-signal subset. |
Usage
// eslint.config.js
import openaiSecurity from 'eslint-plugin-openai-security';
export default [
openaiSecurity.configs.recommended,
];oxlint
Every rule runs on oxlint as well as ESLint:
{ "jsPlugins": ["eslint-plugin-openai-security/oxlint"] }📦 Compatibility
See the ESLint Version Support Policy for the full matrix.
Rules
Legend
| Icon | Description |
|---|---|
| 💼 | Recommended: Included in the recommended preset. |
| ⚠️ | Warns: Set to warn in recommended preset. |
| 🔧 | Auto-fixable: Automatically fixable by the --fix CLI option. |
| 💡 | Suggestions: Providing code suggestions in IDE. |
| 🚫 | Deprecated: This rule is deprecated. |
| 🟢 | Type-unaware: AST-only, runs in oxlint JS-plugin tier. |
| 🟡 | Type-aware (refining): pure-AST primary path; types refine precision. |
| 🟠 | Type-aware (graceful): requires TS program; silent without it. |
| Rule | CWE | OWASP | CVSS | Description | 🧠 | 💼 | ⚠️ | 🔧 | 💡 | 🚫 |
|---|---|---|---|---|---|---|---|---|---|---|
| no-browser-api-key-exposure | CWE-522 | A07:2021 | Forbid dangerouslyAllowBrowser, which exposes the OpenAI API key to the client | 🟢 | ||||||
| no-hardcoded-api-key | CWE-798 | A07:2021 | Forbid a literal API key in the OpenAI client options | 🟢 | ||||||
| no-untrusted-content-in-prompt | CWE-1427 | A03:2021 | Disallow untrusted content built into the OpenAI system prompt | 🟢 |
⭐ Support & follow
If this plugin caught a real bug for you, star the repo — stars are the signal that keeps the Interlace ESLint ecosystem maintained — and follow the writeups on Dev.to for the benchmarks and security research behind these rules.
🔗 Related ESLint Plugins
Part of the Interlace ESLint ecosystem — AI-native rules with LLM-optimized error messages:
Security
Code quality
| Plugin | Downloads | Description |
|---|---|---|
eslint-plugin-conventions | Team-specific habits and styles. | |
eslint-plugin-import-next | Fast cycle + import-graph analysis. | |
eslint-plugin-maintainability | Cognitive load and clean-code patterns. | |
eslint-plugin-modernization | ESNext migration + syntax evolution. | |
eslint-plugin-modularity | Structural integrity and DDD patterns. | |
eslint-plugin-operability | Production readiness and resource health. | |
eslint-plugin-react-a11y | React accessibility / WCAG. | |
eslint-plugin-react-features | React best practices and optimization. | |
eslint-plugin-reliability | Runtime stability and error safety. |
📄 License
MIT © Ofri Peretz
Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them — or follow the AI-code-security benchmarks behind them.