Url validation security
Skill patrickserrano/lacquer/profiles/ios/skills/url-validation-security
Go CLI + profile templates that standardize how Claude Code works across every project
npx -y skills add patrickserrano/lacquer --skill url-validation-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use when validating a user-provided or externally-sourced URL before it reaches `AVPlayer`, `URLSession`, or a `WKWebView` — building a positive- allowlist URL validator, or reviewing existing networking/media code for missing URL validation.
SKILL.md
2.1 KB, 416 tokens by cl100k_base, as published. Nobody here has run it
URL Validation Security Posture
Validate every user-provided URL through a positive-allowlist validator
before it reaches AVPlayer, URLSession, or a WKWebView. Validate at
both the manager and service boundaries (the duplication is intentional
defense-in-depth). Known limitation: homograph / IDN look-alike hosts are not
detected.
The validator parses once via URLComponents and asserts: http/https scheme
only, non-empty host, no userinfo (credentials), a UTF-8 byte-length cap,
and rejection of C0 controls / DEL / literal & percent-encoded null bytes. The
dangerous-scheme denylist is redundant belt-and-suspenders.
enum SecureURLValidator {
/// Returns true only when the URL satisfies every required property.
/// Known limitation: homograph / IDN look-alike hosts are not detected.
nonisolated static func validate(_ urlString: String) -> Bool {
guard !urlString.isEmpty else { return false }
guard urlString.utf8.count <= 2048 else { return false }
guard !urlString.unicodeScalars.contains(where: { $0.value < 0x20 || $0.value == 0x7F }) else { return false }
guard !urlString.contains("\0"), !urlString.lowercased().contains("%00") else { return false }
let dangerous = ["javascript:", "data:", "file:", "vbscript:"]
guard !dangerous.contains(where: { urlString.lowercased().hasPrefix($0) }) else { return false }
guard let components = URLComponents(string: urlString) else { return false }
guard let scheme = components.scheme?.lowercased(), ["http", "https"].contains(scheme) else { return false }
guard components.user == nil, components.password == nil else { return false }
guard let host = components.host, !host.isEmpty else { return false }
return true
}
}
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.