frontend-security
Installation
SKILL.md
Frontend Security Rules
CRITICAL: Token Storage
NEVER store tokens in localStorage or memory. Tokens are managed via HTTP-only cookies and sent automatically by the browser.
// ❌ FORBIDDEN
localStorage.setItem("token", jwt);
sessionStorage.setItem("token", jwt);
const token = "Bearer " + jwt;
// ✅ CORRECT: Cookies handle token transport automatically
// No token management code needed in frontend
CRITICAL: XSS Prevention
NEVER use innerHTML with untrusted content. Use framework bindings instead.