agentsclimarketplace

React security

Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/react-security

🧠 The right skill, one API call. AI agent skills registry with token-efficient skill resolution. 5,000+ skills from 500+ top repos.

Install
npx -y skills add ComeOnOliver/skillshub --skill react-security

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Security practices for React (XSS, Auth, Dependencies). Use when preventing XSS, securing auth flows, or auditing third-party dependencies in React. (triggers: **/*.tsx, **/*.jsx, dangerouslySetInnerHTML, token, auth, xss)

SKILL.md

1.8 KB, 384 tokens by cl100k_base, as published. Nobody here has run it

React Security

Priority: P0 (CRITICAL)

Preventing vulnerabilities in client-side apps.

Implementation Guidelines

  • XSS Prevention: Never use dangerouslySetInnerHTML without sanitization. Use DOMPurify.sanitize(input) for all user-provided HTML. Avoid javascript: protocols in href or src.
  • Authentication: Store JWT/Sessions in HttpOnly and Secure cookies to prevent theft via XSS. Never store secrets in localStorage or in the built JS bundle.
  • Data Flow: Escape all serialized state if injecting into the HTML (e.g., in SSR). Use a Content Security Policy (CSP) to restrict script sources and prevent inline execution.
  • CSRF Protection: Use CSRF tokens for state-changing requests (PUT/POST/DELETE). Implement SameSite=Strict cookies where applicable.
  • Input Sanitization: Always validate and sanitize user inputs on the backend. Frontend validation is for UX only.
  • Dependency Management: Run npm audit / pnpm audit regularly. Pin specific dependency versions and use npm-check-updates.
  • Security Headers: Ensure the server sends X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and Permissions-Policy.

Anti-Patterns

  • No eval(): RCE risk.
  • No Serialized State: Don't inject JSON into DOM without escaping.
  • No Client Logic for Permissions: Backend must validate.

References

See references/REFERENCE.md for DOMPurify usage, CSP headers, OAuth2/JWT auth patterns, and CSRF protection.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.