What I like to do when I start testing node apps, before doing anything else, is to look at the 3rd party installed dependencies of the app. All the dependencies should be listed in a file called package.json.
more here...........http://blog.securityinnovation.com/blog/2014/10/code-assisted-penetration-testing-of-a-nodejs-app.html
more here...........http://blog.securityinnovation.com/blog/2014/10/code-assisted-penetration-testing-of-a-nodejs-app.html