agentsclimarketplace

Xss prevention

Skill VRIL-LABS/skill-jam/skills/ai-ml/claude-skills-main/claude-skills-main/plugins/xss-prevention/skills/xss-prevention

Welcome to the skill-jam ☄️🏀

Install
npx -y skills add VRIL-LABS/skill-jam --skill xss-prevention

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

XSS attack prevention with input sanitization, output encoding, Content Security Policy. Use for user-generated content, rich text editors, web application security, or encountering stored XSS, reflected XSS, DOM manipulation, script injection errors.

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

5.5 KB, as published. Nobody here has run it

XSS Prevention

Overview

Implement comprehensive Cross-Site Scripting attack prevention through input sanitization, output encoding, Content Security Policy headers, and secure coding practices.

When to Use

  • User-generated content display
  • Rich text editors
  • Comment systems
  • Search functionality
  • Dynamic HTML generation
  • Template rendering scenarios

XSS Attack Types

TypeVectorDefense
ReflectedURL parametersOutput encoding
StoredDatabase contentInput sanitization
DOM-basedClient-side JSSafe DOM APIs
MutationHTML parser quirksStrict sanitization

Output Encoding (Node.js)

function encodeHTML(str) {
  return str
    .replace(/&/g, '&')
    .replace(/</g, '&lt;')
    .replace(/>/g, '&gt;')
    .replace(/"/g, '&quot;')
    .replace(/'/g, '&#x27;');
}

function encodeForAttribute(str) {
  return str.replace(/[^\w.-]/g, char =>
    `&#x${char.charCodeAt(0).toString(16)};`
  );
}

// Usage in templates
app.get('/profile', (req, res) => {
  const username = encodeHTML(req.query.name);
  res.send(`<h1>Welcome, ${username}</h1>`);
});

DOMPurify Sanitization

import DOMPurify from 'dompurify';

const config = {
  ALLOWED_TAGS: ['b', 'i', 'em', 'strong', 'a', 'p', 'br'],
  ALLOWED_ATTR: ['href', 'title'],
  ALLOW_DATA_ATTR: false
};

function sanitizeHTML(dirty) {
  return DOMPurify.sanitize(dirty, config);
}

// React component
function RichContent({ html }) {
  return (
    <div dangerouslySetInnerHTML={{ __html: sanitizeHTML(html) }} />
  );
}

Content Security Policy

// Express middleware
app.use((req, res, next) => {
  const nonce = crypto.randomBytes(16).toString('base64');
  res.locals.nonce = nonce;

  res.setHeader('Content-Security-Policy', [
    "default-src 'self'",
    `script-src 'self' 'nonce-${nonce}'`,
    "style-src 'self' 'unsafe-inline'",
    "img-src 'self' data: https:",
    "connect-src 'self' https://api.example.com",
    "frame-ancestors 'none'",
    "base-uri 'self'",
    "form-action 'self'"
  ].join('; '));

  next();
});

Safe DOM APIs

// DANGEROUS - avoid these
element.innerHTML = userInput;        // XSS risk
element.outerHTML = userInput;        // XSS risk
document.write(userInput);            // XSS risk
eval(userInput);                      // Code injection

// SAFE - use these instead
element.textContent = userInput;      // Escaped automatically
element.setAttribute('data-id', id);  // Safe for attributes
document.createTextNode(userInput);   // Creates safe text node

URL Validation

function isSafeURL(url) {
  try {
    const parsed = new URL(url);
    return ['http:', 'https:'].includes(parsed.protocol);
  } catch {
    return false;
  }
}

// Usage
const href = isSafeURL(userURL) ? userURL : '#';

Context-Specific Encoding

Different contexts require different encoding approaches:

  • HTML Entity Encoding: Safest option for text content
  • Attribute Encoding: For HTML attributes
  • JavaScript Escaping: For script contexts
  • URL Encoding: For URL parameters
  • CSS Escaping: For stylesheet contexts

Always encode output by the specific context where data will be rendered.

Additional Implementations

See references/python-sanitization.md for:

  • Python bleach library usage
  • Flask/Django template escaping
  • Server-side validation patterns

See references/nodejs-advanced.md for:

  • Complete XSSPrevention class with all methods
  • Express middleware (xssProtection)
  • React components (SafeText, SafeHTML, SafeLink, useSanitizedInput)
  • Helmet CSP configuration

Best Practices

✅ DO:

  • Encode output by default
  • Use templating engines with auto-escaping
  • Implement CSP headers
  • Sanitize rich content with allowlists
  • Validate URLs with protocol whitelisting
  • Use HTTPOnly cookies
  • Conduct regular security testing
  • Leverage secure frameworks

❌ DON'T:

  • Trust user input
  • Use unsafe functions (eval, innerHTML)
  • Disable security features for convenience
  • Rely solely on client-side validation
  • Use blocklists instead of allowlists
  • Skip context-specific encoding
  • Allow arbitrary script execution

Security Checklist

  • Encode all output by context (HTML, attribute, JS)
  • Sanitize HTML with allowlist (not blocklist)
  • Implement strict CSP headers
  • Use HTTPOnly cookies for sessions
  • Validate and sanitize URLs
  • Avoid innerHTML with user content
  • Regular security testing

Resources

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.