Skip to content
Back to skills

Url Validation Security

ASecurity

Use when validating a user-provided or externally-sourced URL before it reaches `AVPlayer`, `URLSession`, or a `WKWebView` — building a positive- allowlist URL validator, or reviewing existing networking/media code for missing URL validation.

  • 3 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 2, 2026
developmentjavascriptjavaswiftsecurity

Security analysis

A100/100

Scanned September 2, 2026

npx -y skills add patrickserrano/lacquer --skill url-validation-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Url Validation Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Url Validation Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/patrickserrano-url-validation-security/badge)](https://www.skillsdirectory.com/skills/patrickserrano-url-validation-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: url-validation-security
description: >
  Use when validating a user-provided or externally-sourced URL before it
  reaches `AVPlayer`, `URLSession`, or a `WKWebView` — building a positive-
  allowlist URL validator, or reviewing existing networking/media code for
  missing URL validation.
---

# URL Validation Security Posture

Validate **every** user-provided URL through a positive-allowlist validator
before it reaches `AVPlayer`, `URLSession`, or a `WKWebView`. Validate at
**both** the manager and service boundaries (the duplication is intentional
defense-in-depth). Known limitation: homograph / IDN look-alike hosts are not
detected.

The validator parses once via `URLComponents` and asserts: http/https scheme
only, non-empty host, no userinfo (credentials), a UTF-8 **byte-length** cap,
and rejection of C0 controls / DEL / literal & percent-encoded null bytes. The
dangerous-scheme denylist is redundant belt-and-suspenders.

```swift
enum SecureURLValidator {
    /// Returns true only when the URL satisfies every required property.
    /// Known limitation: homograph / IDN look-alike hosts are not detected.
    nonisolated static func validate(_ urlString: String) -> Bool {
        guard !urlString.isEmpty else { return false }
        guard urlString.utf8.count <= 2048 else { return false }
        guard !urlString.unicodeScalars.contains(where: { $0.value < 0x20 || $0.value == 0x7F }) else { return false }
        guard !urlString.contains("\0"), !urlString.lowercased().contains("%00") else { return false }
        let dangerous = ["javascript:", "data:", "file:", "vbscript:"]
        guard !dangerous.contains(where: { urlString.lowercased().hasPrefix($0) }) else { return false }
        guard let components = URLComponents(string: urlString) else { return false }
        guard let scheme = components.scheme?.lowercased(), ["http", "https"].contains(scheme) else { return false }
        guard components.user == nil, components.password == nil else { return false }
        guard let host = components.host, !host.isEmpty else { return false }
        return true
    }
}
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…