React security
Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/react-security
🧠The right skill, one API call. AI agent skills registry with token-efficient skill resolution. 5,000+ skills from 500+ top repos.
npx -y skills add ComeOnOliver/skillshub --skill react-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
What its author says it does
Copied from the file, not written here
Security practices for React (XSS, Auth, Dependencies). Use when preventing XSS, securing auth flows, or auditing third-party dependencies in React. (triggers: **/*.tsx, **/*.jsx, dangerouslySetInnerHTML, token, auth, xss)
SKILL.md
1.8 KB, 384 tokens by cl100k_base, as published. Nobody here has run it
React Security
Priority: P0 (CRITICAL)
Preventing vulnerabilities in client-side apps.
Implementation Guidelines
- XSS Prevention: Never use
dangerouslySetInnerHTMLwithout sanitization. UseDOMPurify.sanitize(input)for all user-provided HTML. Avoidjavascript:protocols inhreforsrc. - Authentication: Store JWT/Sessions in
HttpOnlyandSecurecookies to prevent theft via XSS. Never store secrets inlocalStorageor in the built JS bundle. - Data Flow: Escape all serialized state if injecting into the HTML (e.g., in SSR). Use a Content Security Policy (CSP) to restrict script sources and prevent inline execution.
- CSRF Protection: Use CSRF tokens for state-changing requests (PUT/POST/DELETE). Implement SameSite=Strict cookies where applicable.
- Input Sanitization: Always validate and sanitize user inputs on the backend. Frontend validation is for UX only.
- Dependency Management: Run
npm audit/pnpm auditregularly. Pin specific dependency versions and usenpm-check-updates. - Security Headers: Ensure the server sends
X-Frame-Options: DENY,X-Content-Type-Options: nosniff, andPermissions-Policy.
Anti-Patterns
- No
eval(): RCE risk. - No Serialized State: Don't inject JSON into DOM without escaping.
- No Client Logic for Permissions: Backend must validate.
References
See references/REFERENCE.md for DOMPurify usage, CSP headers, OAuth2/JWT auth patterns, and CSRF protection.