agentCLAWHUBUnverified

Frontend Security Review

Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check. Skill: Frontend Security Review Owner: bovinphang Summary: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check. Tags: latest:2.9.0 Version history: v2.9.0 | 2026-09-27T03:40:19.132Z |

OpenClaw

Rank

62

Safety

84

Downloads

1.0k

Updated

Oct 11, 2026

Version

2.9.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1K downloadsadoption · observed Oct 11, 2026
Latest release
2.9.0release · observed Sep 27, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s175m64gr8tsfc06cj22czzfys83mp52:fec-security-review
  1. Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/snapshot"

Run-check

$0.02 USD

1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.

Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.

Documentation

CLAWHUB

38,229 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: fec-security-review
description: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.
---

# Front-end security review

## Review modes and coverage

User-specified scope takes precedence over the default. Use the following three review modes:

- **Change review**: only when recent changes, current edits, staged changes, a PR or a commit are explicitly requested or clearly established by the active task, review those changes and necessary context. For local changes, inspect staged and unstaged diffs and relevant untracked project files within the requested scope; a staged-only request reviews only staged changes. If there are no changes, report that there is nothing to review; do not switch to recent commits or expand scope automatically.
- **Targeted review**: when files or directories are specified, inventory and review existing code in that scope, including unchanged code; no Git diff is required.
- **Project review (default)**: when no scope or change context is specified, or when the entire project is requested, inventory project-owned frontend code, related tests, configuration and dependency declarations, then review in module batches, including unchanged code; no Git diff is required.

Select scope before collecting diffs. A file/directory alone means full review of that scope; a path combined with an explicit change request restricts incremental review to that path. An unqualified invocation defaults to project review even if Git changes exist. At review start, state the selected mode and target scope. When automatically delegating review after edits, pass the current change scope explicitly; do not trigger project review merely because the reviewer was called.

Exclude dependency directories, build outputs, caches, generated files and third-party code by default, and record exclusions. Keep the frontend responsibility boundary; this is not a backend audit. A nonexistent target or a scope with no relevant files must be reported explicitly, not replaced with another scope.

Merge findings with the same root cause across batches. Report **review mode, target scope, reviewed files/modules, exclusions, unreviewed files/modules, completion status and verification commands/results**. If context or execution limits prevent completion, mark the review partial and list remaining modules; never claim complete project coverage. Reading callers for context or running project-wide lint/typecheck does not count as manual review of those files.

Change reviews retain merge recommendations. Targeted and project reviews use a risk assessment (Low / Medium / High, with blocking findings), not a claim of merge readiness. Preserve severity levels, evidence requirements and report filenames. Output reports only unles

README.md

# Front-end security review

Review browser-side XSS, CSRF, token exposure, unsafe DOM usage, and third-party risks.

## Skill

- ID: `fec-security-review`
- Category: `review-quality`
- Version: `2.9.0`
- Source: `skills/fec-security-review/SKILL.md`

## Description

Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.

## Usage

Install or import this package with any skill runtime that understands the standard `SKILL.md` layout. The canonical source remains the Frontend Craft repository.

## Packaged Files

- [references/report-template.md](references/report-template.md)
- [references/security-checklist.md](references/security-checklist.md)

## Optional Related Packages

- `@bovinphang/fec-code-review`
- `@bovinphang/fec-accessibility-check`
- `@bovinphang/fec-browser-storage`
- `@bovinphang/fec-dependency-upgrade`
- `@bovinphang/fec-route-protection`

## License

MIT

_meta.json

{
  "ownerId": "kn7b0nh7hvj1pffeqc8y0dqwwh83m726",
  "slug": "fec-security-review",
  "version": "2.9.0",
  "publishedAt": 1790480419132
}

references/report-template.md

# Security review report template

```markdown
# Security Review Report

> Generation time: YYYY-MM-DD HH:mm
> Review tool: frontend-craft

> Review mode: change / targeted / project
> Target scope: paths or PR/commit
> Reviewed: file or module inventory
> Exclusions: paths and reasons
> Unreviewed: remaining files or modules (state none if complete)
> Completion: complete / partial
> Verification: commands, results and reasons for skipped checks

## CRITICAL / HIGH RISK (N items)
- **[File:line number]** Risk description -> Repair suggestions

## HIGH / Medium to high risk (N items)
- ...

## MEDIUM / medium risk (N items)
- ...

## LOW / low risk or recommended (N items)
- ...

## Passed security check
- ...

**Overall security level**: safe / risky / high risk and needs to be repaired
```

After the review is completed, save the report to `reports/security-review-YYYY-MM-DD-HHmmss.md` and inform the user of the report path.

Retain merge recommendations for change review; use risk assessments for targeted and project reviews. For partial reviews, conclusions apply only to reviewed scope and do not establish project-wide approval.

references/security-checklist.md

# Front-end security review checklist

## XSS

- `dangerouslySetInnerHTML` and `v-html` must have explicit reason and input sanitization.
- User input must not be inserted directly into the DOM, `innerHTML`, `document.write`.
- URL parameters must not be used directly in page rendering.
- Dynamically generated `<script>` tags must be sourced.
- Rich text uses libraries such as DOMPurify and configures tags, attributes, and protocol whitelists.

```ts
import DOMPurify from "dompurify";

const clean = DOMPurify.sanitize(dirtyHtml, {
  ALLOWED_TAGS: ["b", "i", "em", "strong", "a", "ul", "ol", "li", "p", "br"],
  ALLOWED_ATTR: ["href", "title"],
  ALLOWED_URI_REGEXP: /^(https?|mailto):/i,
});
```

## Safe redirection

```ts
function safeRedirect(url: string): string {
  if (url.startsWith("/") && !url.startsWith("//")) return url;
  return "/dashboard";
}
```

## CSP

- It is recommended to verify with `Content-Security-Policy-Report-Only` first.
- `default-src 'self'`, `object-src 'none'`, `frame-ancestors 'none'`, `base-uri 'self'` are common bottom lines.
- Avoid `'unsafe-eval''; inline scripts take precedence over nonce.

```http
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self';
```

## Sensitive data

- It is prohibited to hard-code API Key, Secret, and password on the front end.
- LocalStorage/sessionStorage/IndexedDB is prohibited from storing plain text tokens, passwords, and credit card information.
- Prohibit URL query parameters from passing token or password.
- Console.log or error reports are prohibited from carrying private data.
- Token priority httpOnly + Secure + SameSite cookie.

## CSRF

- Change operations must carry CSRF tokens or use equivalent backend protection.
- Do not use GET for critical operations.
- Check whether the backend verifies `Origin` / `Referer`.

## Dependencies and third-party scripts

- Regularly review dependency security bulletins.
- Disallow script loading from unofficial CDNs unless SRI and source vetted.
- Dynamically loading third-party scripts must have business necessity and a downgrade strategy.

## Input verification and file upload

- Front-end verification is not a security boundary, and the back-end must be verified twice.
- File uploads verify MIME, size, extension and content; don't just look at the extension.
- Pay attention to ReDoS risks in regular verification.
Github ReposUpdated 2d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/bovinphang/skills/fec-security-review",
      "sourceUrl": "https://clawhub.ai/bovinphang/skills/fec-security-review",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T17:28:53.432Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T17:28:53.432Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1K downloads",
      "href": "https://clawhub.ai/bovinphang/fec-security-review",
      "sourceUrl": "https://clawhub.ai/bovinphang/fec-security-review",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T17:28:53.432Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.9.0",
      "href": "https://clawhub.ai/bovinphang/fec-security-review",
      "sourceUrl": "https://clawhub.ai/bovinphang/fec-security-review",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-27T03:40:19.132Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.9.0",
      "description": "- Major update: Expanded review modes and clarified review scope selection. - Added support for Change review, Targeted review, and Project review, with precise mode selection and scoping rules. - Updated trigger description to support English keywords. - Rewrote and clarified user instructions, including explicit exclusion/inclusion rules, reporting requirements, and expected outputs. - Added detailed guidance for recording review context, partial completions, and outcome reporting. - LICENSE file added; skill-card.md removed.",
      "href": "https://clawhub.ai/bovinphang/fec-security-review",
      "sourceUrl": "https://clawhub.ai/bovinphang/fec-security-review",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-27T03:40:19.132Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to Frontend Security Review and adjacent AI workflows.