avoid-eval

Installation
SKILL.md

Never use eval() or unsafe dynamic code execution

eval() and its equivalents are the root cause of some of the most severe XSS vulnerabilities. If any user-controlled string reaches eval(), an attacker can execute arbitrary JavaScript in your users' browsers — stealing sessions, making requests as the user, or redirecting to malicious sites. Content Security Policy (CSP) blocks eval() but not new Function(), and there is never a legitimate use case that can't be solved without it.

Quick Reference

  • eval() executes arbitrary strings as code — any user input passed to it is a critical security hole
  • new Function() is equally dangerous and not caught by CSP eval restrictions
  • setTimeout('code', delay) and setInterval('code', delay) also evaluate strings — use function references instead
  • Use JSON.parse() instead of eval() for parsing JSON

Check

Search this codebase for any use of eval(), new Function(), or setTimeout/setInterval with string arguments.

Fix

Replace eval() calls with safe alternatives: JSON.parse for data, object lookups for dynamic dispatch, and Function references for timers.

Installs
6
GitHub Stars
73.9K
First Seen
Aug 11, 2026
avoid-eval — thedaviddias/front-end-checklist