client-side-security

Installation
SKILL.md

Client-Side Web Security

Protect browser clients against code injection, request forgery, UI redress, cross-site leaks, and unsafe third-party scripts with layered, context-aware controls.

XSS Prevention (Context-Aware)

  • HTML context: prefer textContent. If HTML is required, sanitize with a vetted library (e.g., DOMPurify) and strict allow-lists.
  • Attribute context: always quote attributes and encode values.
  • JavaScript context: do not build JS from untrusted strings; avoid inline event handlers; use addEventListener.
  • URL context: validate protocol/domain and encode; block javascript: and data URLs where inappropriate.
  • Redirects/forwards: never use user input directly for destinations; use server-side mapping (ID to URL) or validate against trusted domain allow-lists.
  • CSS context: allow-list values; never inject raw style text from users.

Example sanitization:

Installs
2
GitHub Stars
52
First Seen
Jul 18, 2026
client-side-security — redhatproductsecurity/prodsec-skills