React native security
Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/react-native-security
🧠The right skill, one API call. AI agent skills registry with token-efficient skill resolution. 5,000+ skills from 500+ top repos.
npx -y skills add ComeOnOliver/skillshub --skill react-native-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
What its author says it does
Copied from the file, not written here
Secure storage, deep linking security, and certificate pinning for mobile. Use when implementing secure storage, certificate pinning, or deep link validation in React Native. (triggers: **/*.tsx, **/*.ts, security, keychain, secure-storage, deep-link, certificate-pinning)
SKILL.md
2.0 KB, 403 tokens by cl100k_base, as published. Nobody here has run it
React Native Security
Priority: P0 (CRITICAL)
Secure Storage
- Keychain/Keystore: Use
react-native-keychainfor tokens, passwords. - Never AsyncStorage: Not encrypted. Only for non-sensitive data.
- Biometric Auth: Use
react-native-biometricsfor Face ID/Touch ID.
Deep Linking
- Validate URLs: Check scheme and host before navigation.
- Sanitize Params: Never trust URL params. Validate and sanitize.
- Token Extraction: Avoid passing tokens in deep link URLs. Use secure code exchange.
Network Security
- HTTPS Only: Enforce via
NSAppTransportSecurity(iOS) andnetwork_security_config.xml(Android). - Certificate Pinning: Use
react-native-ssl-pinningfor high-security apps (banking, healthcare). Warning: Requires app update when certificates rotate. - No Secrets in Code: Use
.envfiles withreact-native-config. Add to.gitignore.
Code Obfuscation
- Hermes: Bytecode harder to reverse-engineer.
- ProGuard/R8: Enable on Android.
- Note: Obfuscation is a deterrent, not protection. Move sensitive logic to backend.
Data Handling
- PII Masking: Mask email/phone in logs and analytics.
- Clipboard: Clear sensitive data after paste.
- Screenshots: Block on sensitive screens with
react-native-screen-guard.
Anti-Patterns
- No Hardcoded Secrets: Use environment variables.
- No Sensitive Logs: Strip
console.login production. - No Plain HTTP: Always use HTTPS.
- No Client-Side Auth: Validate on backend.
References
See references/keychain-usage.md for Keychain, Biometrics, SSL Pinning, and PII Masking.