react-security

Installation
SKILL.md

React Security

Priority: P0 (CRITICAL)

Preventing vulnerabilities in client-side apps.

Implementation Guidelines

  • XSS Prevention: Never use dangerouslySetInnerHTML without sanitization. Use DOMPurify.sanitize(input) for all user-provided HTML. Avoid javascript: protocols in href or src.
  • Authentication: Store JWT/Sessions in HttpOnly and Secure cookies to prevent theft via XSS. Never store secrets in localStorage or in the built JS bundle.
  • Data Flow: Escape all serialized state if injecting into the HTML (e.g., in SSR). Use a Content Security Policy (CSP) to restrict script sources and prevent inline execution.
  • CSRF Protection: Use CSRF tokens for state-changing requests (PUT/POST/DELETE). Implement SameSite=Strict cookies where applicable.
  • Input Sanitization: Always validate and sanitize user inputs on the backend. Frontend validation is for UX only.
  • Dependency Management: Run npm audit / pnpm audit regularly. Pin specific dependency versions and use npm-check-updates.
  • Security Headers: Ensure the server sends X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and Permissions-Policy.

Anti-Patterns

Installs
1
GitHub Stars
60
First Seen
Jun 12, 2026
react-security — comeonoliver/skillshub