Skip to content
Back to skills

Web Security

ASecurity

Enforce web security and avoid security vulnerabilities

  • 207 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 4, 2026
securityrustsqlapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 13 files and shows the line behind each finding

Scanned September 4, 2026

npx -y skills add NeverSight/skills_feed --skill web-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Web Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Web Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/neversight-web-security/badge)](https://www.skillsdirectory.com/skills/neversight-web-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: web-security
description: Enforce web security and avoid security vulnerabilities
---

# Web Security

We treat **web security as a core requirement**, not an afterthought.
Assume hostile input and untrusted environments by default.

## Core Principles

- **NEVER** trust user input
- **ALWAYS** validate and sanitize data at boundaries
- Prefer secure defaults over configurability

## XSS & Injection

- **AVOID** `dangerouslySetInnerHTML` and raw HTML injection
- Escape and encode dynamic content properly
- Never interpolate untrusted data into HTML, CSS, or JS contexts
- Ensure SQL injection protection

## Authentication & Authorization

- Do not store secrets or tokens in insecure locations
- **AVOID** localStorage for sensitive credentials when possible
- Use HTTP-only, secure cookies where applicable
- Always enforce authorization on the server

## Browser Security APIs

- Respect CORS, CSP, and browser security boundaries
- Use Content Security Policy to restrict script and resource execution
- Avoid inline scripts and styles when CSP is enabled

## Data Handling

- Minimize data exposure
- Do not log sensitive information

## Dependencies & Supply Chain

- Avoid unnecessary packages
- Treat third-party code as untrusted input

## General Principles

- Simplicity reduces attack surface
- If unsure, choose the more restrictive option

Files in this skill

  • SKILL.md1.3 KB
  • description_ar.txt68 B
  • description_cn.txt40 B
  • description_de.txt73 B
  • description_en.txt56 B
  • description_es.txt72 B
  • description_fr.txt74 B
  • description_it.txt69 B
  • description_ja.txt86 B
  • description_ko.txt63 B
  • description_ru.txt124 B
  • description_tw.txt40 B
  • stats.json66 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…