Skip to content
Back to skills

Subresource Integrity

ASecurity

Use when reviewing templates, rendered HTML, or shared components related to Add Subresource Integrity to external scripts. Validate the final browser-facing markup, not just the source framework abstraction.

  • 74,358 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
developmentjavascriptrustgojavafrontend

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 5, 2026

npx -y skills add thedaviddias/Front-End-Checklist --skill subresource-integrity --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Subresource Integrity?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Subresource Integrity
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/thedaviddias-subresource-integrity/badge)](https://www.skillsdirectory.com/skills/thedaviddias-subresource-integrity)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: subresource-integrity
description: "Use when reviewing templates, rendered HTML, or shared components related to Add Subresource Integrity to external scripts. Validate the final browser-facing markup, not just the source framework abstraction."
metadata:
  category: html
  priority: high
  difficulty: intermediate
  estimatedTime: "15"
  source: frontendchecklist.io
  url: https://frontendchecklist.io/rules/html/subresource-integrity
---

# Add Subresource Integrity to external scripts

When you load JavaScript from a CDN, you're trusting that CDN completely — if it's compromised, attackers can serve malicious JavaScript to all your users. SRI adds a cryptographic hash to the tag; the browser refuses to execute the script if the hash doesn't match the downloaded content, protecting users even if the CDN is compromised or the URL is hijacked.

## Quick Reference

- Add integrity="sha384-..." to <script> and <link> tags loading from CDNs
- Always pair integrity with crossorigin="anonymous"
- Generate hashes with openssl or online tools — CDN providers usually supply them
- SRI blocks execution if the file hash doesn't match, preventing CDN compromise attacks

## Check

Find all external <script> and <link rel=stylesheet> tags in this HTML that load from CDNs and don't have integrity attributes. List each one.

## Fix

Add appropriate integrity and crossorigin attributes to external CDN resources. Generate the SHA-384 hashes for each resource.

## Explain

Explain Subresource Integrity, how it protects against CDN compromise, how to generate SRI hashes, and its limitations.

## Code Review

Review templates, server-rendered HTML, and shared components that output markup related to Add Subresource Integrity to external scripts. Flag exact elements, attributes, and routes where the rendered HTML violates the rule.

---

For full implementation details, code examples, and framework-specific guidance,
see `references/rule.md`.

Rule page: https://frontendchecklist.io/rules/html/subresource-integrity

Files in this skill

  • SKILL.md2 KB
  • references/rule.md3.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…