{"id":"3adc8b06-26a3-459e-8de3-e5b3dac1e695","slug":"clawhub-bovinphang-fec-security-review","name":"Frontend Security Review","description":"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.","canonicalUrl":"https://www.xpersona.co/agent/clawhub-bovinphang-fec-security-review","sourceUrl":"https://clawhub.ai/bovinphang/fec-security-review","homepage":"https://clawhub.ai/bovinphang/skills/fec-security-review","source":"CLAWHUB","vendor":{"slug":"clawhub","label":"Clawhub","url":"https://clawhub.ai/bovinphang/skills/fec-security-review"},"protocols":["OPENCLEW"],"capabilities":[],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":"2.9.0","freshnessAt":"2026-10-11T17:28:53.419Z","freshnessLabel":"Oct 11, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Oct 11, 2026"},{"label":"Vendor","value":"Clawhub"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"2.9.0"}],"factsPreview":[{"factKey":"vendor","category":"vendor","label":"Vendor","value":"Clawhub","href":"https://clawhub.ai/bovinphang/skills/fec-security-review","sourceUrl":"https://clawhub.ai/bovinphang/skills/fec-security-review","sourceType":"profile","confidence":"medium","observedAt":"2026-10-11T17:28:53.432Z","isPublic":true},{"factKey":"protocols","category":"compatibility","label":"Protocol compatibility","value":"OpenClaw","href":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-10-11T17:28:53.432Z","isPublic":true},{"factKey":"traction","category":"adoption","label":"Adoption signal","value":"1K downloads","href":"https://clawhub.ai/bovinphang/fec-security-review","sourceUrl":"https://clawhub.ai/bovinphang/fec-security-review","sourceType":"profile","confidence":"medium","observedAt":"2026-10-11T17:28:53.432Z","isPublic":true},{"factKey":"latest_release","category":"release","label":"Latest release","value":"2.9.0","href":"https://clawhub.ai/bovinphang/fec-security-review","sourceUrl":"https://clawhub.ai/bovinphang/fec-security-review","sourceType":"release","confidence":"medium","observedAt":"2026-09-27T03:40:19.132Z","isPublic":true},{"factKey":"handshake_status","category":"security","label":"Handshake status","value":"UNKNOWN","href":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true}],"highlights":["1K downloads","Trust evidence available"],"agentCard":{"name":"Frontend Security Review","description":"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.","source":"CLAWHUB","sourceId":"clawhub:s175m64gr8tsfc06cj22czzfys83mp52:fec-security-review","homepage":"https://clawhub.ai/bovinphang/skills/fec-security-review","repository":"https://clawhub.ai/bovinphang/fec-security-review","documentation":"https://www.xpersona.co/agent/clawhub-bovinphang-fec-security-review","protocols":["OPENCLEW"],"examples":[{"kind":"example","language":"markdown","snippet":"# Security Review Report\n\n> Generation time: YYYY-MM-DD HH:mm\n> Review tool: frontend-craft\n\n> Review mode: change / targeted / project\n> Target scope: paths or PR/commit\n> Reviewed: file or module inventory\n> Exclusions: paths and reasons\n> Unreviewed: remaining files or modules (state none if complete)\n> Completion: complete / partial\n> Verification: commands, results and reasons for skipped checks\n\n## CRITICAL / HIGH RISK (N items)\n- **[File:line number]** Risk description -> Repair suggestions\n\n## HIGH / Medium to high risk (N items)\n- ...\n\n## MEDIUM / medium risk (N items)\n- ...\n\n## LOW / low risk or recommended (N items)\n- ...\n\n## Passed security check\n- ...\n\n**Overall security level**: safe / risky / high risk and needs to be repaired"},{"kind":"example","language":"ts","snippet":"import DOMPurify from \"dompurify\";\n\nconst clean = DOMPurify.sanitize(dirtyHtml, {\n  ALLOWED_TAGS: [\"b\", \"i\", \"em\", \"strong\", \"a\", \"ul\", \"ol\", \"li\", \"p\", \"br\"],\n  ALLOWED_ATTR: [\"href\", \"title\"],\n  ALLOWED_URI_REGEXP: /^(https?|mailto):/i,\n});"}]}}