React security
Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/react-security
Security practices for React (XSS, Auth, Dependencies). Use when preventing XSS, securing auth flows, or auditing third-party dependencies in React. (triggers: **/*.tsx, **/*.jsx, dangerouslySetInnerHTML, token, auth, xss)From its SKILL.md
npx -y skills add ComeOnOliver/skillshub --skill react-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
1.8 KB, 384 tokens by cl100k_base, as published. Nobody here has run it
React Security
Priority: P0 (CRITICAL)
Preventing vulnerabilities in client-side apps.
Implementation Guidelines
- XSS Prevention: Never use
dangerouslySetInnerHTMLwithout sanitization. UseDOMPurify.sanitize(input)for all user-provided HTML. Avoidjavascript:protocols inhreforsrc. - Authentication: Store JWT/Sessions in
HttpOnlyandSecurecookies to prevent theft via XSS. Never store secrets inlocalStorageor in the built JS bundle. - Data Flow: Escape all serialized state if injecting into the HTML (e.g., in SSR). Use a Content Security Policy (CSP) to restrict script sources and prevent inline execution.
- CSRF Protection: Use CSRF tokens for state-changing requests (PUT/POST/DELETE). Implement SameSite=Strict cookies where applicable.
- Input Sanitization: Always validate and sanitize user inputs on the backend. Frontend validation is for UX only.
- Dependency Management: Run
npm audit/pnpm auditregularly. Pin specific dependency versions and usenpm-check-updates. - Security Headers: Ensure the server sends
X-Frame-Options: DENY,X-Content-Type-Options: nosniff, andPermissions-Policy.
Anti-Patterns
- No
eval(): RCE risk. - No Serialized State: Don't inject JSON into DOM without escaping.
- No Client Logic for Permissions: Backend must validate.
References
See references/REFERENCE.md for DOMPurify usage, CSP headers, OAuth2/JWT auth patterns, and CSRF protection.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.