new-tab
Installation
SKILL.md
External Link Security
A malicious site opened via target='_blank' can use window.opener.location to silently redirect your original tab to a phishing page — the user switches back and sees a fake login screen on what appears to be your domain.
Quick Reference
- Always add
rel="noopener noreferrer"to any<a target="_blank">link noopenerprevents the new tab from accessingwindow.openerand redirecting your pagenoreferreradditionally suppresses theRefererheader sent to the destination site- Modern browsers (Chrome 88+, Firefox 79+) implicitly add
noopenerfor cross-origin_blanklinks, but explicit markup is required for older browsers and same-origin links - ESLint rule
jsx-a11y/anchor-is-validandeslint-plugin-securitycan enforce this automatically
Check
Find all anchor elements with target='_blank' in the HTML and JSX source. Verify each one includes rel='noopener noreferrer' (or at minimum rel='noopener'). Flag any external links opening in a new tab that are missing this attribute.
Fix
Add rel='noopener noreferrer' to all elements. In React/JSX this is rel="noopener noreferrer". Configure an ESLint rule to prevent this from recurring.