{"id":"3adc8b06-26a3-459e-8de3-e5b3dac1e695","entityType":"agent","slug":"clawhub-bovinphang-fec-security-review","name":"Frontend Security Review","canonicalUrl":"https://www.xpersona.co/agent/clawhub-bovinphang-fec-security-review","canonicalPath":"/agent/clawhub-bovinphang-fec-security-review","generatedAt":"2026-10-11T20:59:58.634Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T17:28:53.432Z","emptyReason":null},"description":"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check. Skill: Frontend Security Review Owner: bovinphang Summary: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check. Tags: latest:2.9.0 Version history: v2.9.0 | 2026-09-27T03:40:19.132Z |","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s175m64gr8tsfc06cj22czzfys83mp52:fec-security-review","sourceUrl":"https://clawhub.ai/bovinphang/fec-security-review","homepage":"https://clawhub.ai/bovinphang/skills/fec-security-review","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/bovinphang/fec-security-review","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/bovinphang/skills/fec-security-review","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, pay"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:28:53.432Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:28:53.432Z","emptyReason":null},"stars":null,"forks":null,"downloads":1018,"packageName":null,"latestVersion":"2.9.0","tractionLabel":"1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:28:53.419Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T17:28:53.432Z","lastCrawledAt":"2026-10-11T17:28:53.419Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T17:28:53.419Z","lastVerifiedAt":null,"highlights":[{"version":"2.9.0","createdAt":"2026-09-27T03:40:19.132Z","changelog":"- Major update: Expanded review modes and clarified review scope selection. - Added support for Change review, Targeted review, and Project review, with precise mode selection and scoping rules. - Updated trigger description to support English keywords. - Rewrote and clarified user instructions, including explicit exclusion/inclusion rules, reporting requirements, and expected outputs. - Added detailed guidance for recording review context, partial completions, and outcome reporting. - LICENSE file added; skill-card.md removed.","fileCount":9,"zipByteSize":8938},{"version":"2.6.0","createdAt":"2026-06-07T14:34:26.397Z","changelog":"- Removed the file: skill-card.md. - Minor wording adjustments in SKILL.md; \"Detailed References\" section renamed to \"详细参考\", with no substantial changes to procedure or constraints. - No functional changes to review criteria or expected outputs.","fileCount":8,"zipByteSize":7262},{"version":"2.4.0","createdAt":"2026-06-01T09:49:03.253Z","changelog":"- Skill renamed to \"fec-security-review\" and triggers clarified. - Comprehensive front-end security audit procedure and risk categories defined. - References added for detailed XSS, CSP, sensitive data, CSRF, dependency, and validation checks. - Standard report template and security checklist files introduced. - Updated output expectations for report grading and file naming. - Outdated skill-card.md file removed.","fileCount":8,"zipByteSize":7328}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s175m64gr8tsfc06cj22czzfys83mp52:fec-security-review","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T20:59:58.632Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bovinphang-fec-security-review/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T17:28:53.432Z","emptyReason":null},"readme":"Skill: Frontend Security Review\n\nOwner: bovinphang\n\nSummary: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.\n\nTags: latest:2.9.0\n\nVersion history:\n\nv2.9.0 | 2026-09-27T03:40:19.132Z | user\n\n- Major update: Expanded review modes and clarified review scope selection.\n- Added support for Change review, Targeted review, and Project review, with precise mode selection and scoping rules.\n- Updated trigger description to support English keywords.\n- Rewrote and clarified user instructions, including explicit exclusion/inclusion rules, reporting requirements, and expected outputs.\n- Added detailed guidance for recording review context, partial completions, and outcome reporting.\n- LICENSE file added; skill-card.md removed.\n\nv2.6.0 | 2026-06-07T14:34:26.397Z | user\n\n- Removed the file: skill-card.md.\n- Minor wording adjustments in SKILL.md; \"Detailed References\" section renamed to \"详细参考\", with no substantial changes to procedure or constraints.\n- No functional changes to review criteria or expected outputs.\n\nv2.4.0 | 2026-06-01T09:49:03.253Z | user\n\n- Skill renamed to \"fec-security-review\" and triggers clarified.\n- Comprehensive front-end security audit procedure and risk categories defined.\n- References added for detailed XSS, CSP, sensitive data, CSRF, dependency, and validation checks.\n- Standard report template and security checklist files introduced.\n- Updated output expectations for report grading and file naming.\n- Outdated skill-card.md file removed.\n\nArchive index:\n\nArchive v2.9.0: 9 files, 8938 bytes\n\nFiles: LICENSE (1089b), metadata.json (1820b), package.json (1065b), README.md (1120b), references/report-template.md (1151b), references/security-checklist.md (2453b), skill-card.md (1792b), SKILL.md (5499b), _meta.json (138b)\n\nFile v2.9.0:SKILL.md\n\n---\nname: fec-security-review\ndescription: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.\n---\n\n# Front-end security review\n\n## Review modes and coverage\n\nUser-specified scope takes precedence over the default. Use the following three review modes:\n\n- **Change review**: only when recent changes, current edits, staged changes, a PR or a commit are explicitly requested or clearly established by the active task, review those changes and necessary context. For local changes, inspect staged and unstaged diffs and relevant untracked project files within the requested scope; a staged-only request reviews only staged changes. If there are no changes, report that there is nothing to review; do not switch to recent commits or expand scope automatically.\n- **Targeted review**: when files or directories are specified, inventory and review existing code in that scope, including unchanged code; no Git diff is required.\n- **Project review (default)**: when no scope or change context is specified, or when the entire project is requested, inventory project-owned frontend code, related tests, configuration and dependency declarations, then review in module batches, including unchanged code; no Git diff is required.\n\nSelect scope before collecting diffs. A file/directory alone means full review of that scope; a path combined with an explicit change request restricts incremental review to that path. An unqualified invocation defaults to project review even if Git changes exist. At review start, state the selected mode and target scope. When automatically delegating review after edits, pass the current change scope explicitly; do not trigger project review merely because the reviewer was called.\n\nExclude dependency directories, build outputs, caches, generated files and third-party code by default, and record exclusions. Keep the frontend responsibility boundary; this is not a backend audit. A nonexistent target or a scope with no relevant files must be reported explicitly, not replaced with another scope.\n\nMerge findings with the same root cause across batches. Report **review mode, target scope, reviewed files/modules, exclusions, unreviewed files/modules, completion status and verification commands/results**. If context or execution limits prevent completion, mark the review partial and list remaining modules; never claim complete project coverage. Reading callers for context or running project-wide lint/typecheck does not count as manual review of those files.\n\nChange reviews retain merge recommendations. Targeted and project reviews use a risk assessment (Low / Medium / High, with blocking findings), not a claim of merge readiness. Preserve severity levels, evidence requirements and report filenames. Output reports only unless repairs are explicitly requested.\n\n## Purpose\n\nIdentify client-side security risks in front-end code and recommend actionable fixes.\n\n## Procedure\n\n1. First confirm the review areas: user input, dynamic HTML, URL jump, authentication status, RBAC, file upload, payment/deletion and other sensitive operations, third-party scripts and dependencies.\n2. Search for high-risk patterns: `dangerouslySetInnerHTML`, `v-html`, `innerHTML`, `document.write`, dynamic script, unverified redirect, and plain text token.\n3. Review by risk type: XSS, CSP, sensitive data, CSRF, dependencies, input validation, file upload, open redirection, authentication authorization and third-party scripts.\n4. Use the boundary model to determine responsibility: The client can only improve the experience and reduce misuse. Authentication, authorization, upload trust and sensitive operations must be finalized by the server.\n5. High-risk issues are marked as blocking merges; front-end verification can only improve the experience and cannot be used as the only security boundary.\n6. Output a hierarchical security report; see [references/report-template.md](references/report-template.md) for the report format.\n\n## Detailed reference\n\n- Load [references/security-checklist.md](references/security-checklist.md) when XSS, CSP, sensitive data, CSRF, dependencies and input validation details are required.\n- When writing a security review report, load [references/report-template.md](references/report-template.md).\n\n## Constraints\n\n- Don't bypass security mechanisms to facilitate development.\n- Don't rely on front-end validation as your only line of security.\n- Do not trust any data coming from the client.\n- High-risk issues must be marked as blocking merges when found.\n- Separated from general code quality review: This skill focuses on threats, attack surfaces, and data breaches.\n- Do not mechanically equate dependence on audit results with exploitable vulnerabilities; judgments need to be made based on the running path, exposure surface and repair cost.\n- Do not treat hidden buttons, front-end route guards, or local role fields as authorization boundaries; APIs, SSR loaders, server actions, and sensitive operations must have server-side arbitration.\n\n## Expected Output\n\nOutput a CRITICAL/HIGH/MEDIUM/LOW graded security review report. Each issue is associated with a specific file and line number, and repair suggestions are given; the report is saved as `reports/security-review-YYYY-MM-DD-HHmmss.md`.\n\nFile v2.9.0:README.md\n\n# Front-end security review\n\nReview browser-side XSS, CSRF, token exposure, unsafe DOM usage, and third-party risks.\n\n## Skill\n\n- ID: `fec-security-review`\n- Category: `review-quality`\n- Version: `2.9.0`\n- Source: `skills/fec-security-review/SKILL.md`\n\n## Description\n\nUse when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.\n\n## Usage\n\nInstall or import this package with any skill runtime that understands the standard `SKILL.md` layout. The canonical source remains the Frontend Craft repository.\n\n## Packaged Files\n\n- [references/report-template.md](references/report-template.md)\n- [references/security-checklist.md](references/security-checklist.md)\n\n## Optional Related Packages\n\n- `@bovinphang/fec-code-review`\n- `@bovinphang/fec-accessibility-check`\n- `@bovinphang/fec-browser-storage`\n- `@bovinphang/fec-dependency-upgrade`\n- `@bovinphang/fec-route-protection`\n\n## License\n\nMIT\n\nFile v2.9.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b0nh7hvj1pffeqc8y0dqwwh83m726\",\n  \"slug\": \"fec-security-review\",\n  \"version\": \"2.9.0\",\n  \"publishedAt\": 1790480419132\n}\n\nFile v2.9.0:references/report-template.md\n\n# Security review report template\n\n```markdown\n# Security Review Report\n\n> Generation time: YYYY-MM-DD HH:mm\n> Review tool: frontend-craft\n\n> Review mode: change / targeted / project\n> Target scope: paths or PR/commit\n> Reviewed: file or module inventory\n> Exclusions: paths and reasons\n> Unreviewed: remaining files or modules (state none if complete)\n> Completion: complete / partial\n> Verification: commands, results and reasons for skipped checks\n\n## CRITICAL / HIGH RISK (N items)\n- **[File:line number]** Risk description -> Repair suggestions\n\n## HIGH / Medium to high risk (N items)\n- ...\n\n## MEDIUM / medium risk (N items)\n- ...\n\n## LOW / low risk or recommended (N items)\n- ...\n\n## Passed security check\n- ...\n\n**Overall security level**: safe / risky / high risk and needs to be repaired\n```\n\nAfter the review is completed, save the report to `reports/security-review-YYYY-MM-DD-HHmmss.md` and inform the user of the report path.\n\nRetain merge recommendations for change review; use risk assessments for targeted and project reviews. For partial reviews, conclusions apply only to reviewed scope and do not establish project-wide approval.\n\nFile v2.9.0:references/security-checklist.md\n\n# Front-end security review checklist\n\n## XSS\n\n- `dangerouslySetInnerHTML` and `v-html` must have explicit reason and input sanitization.\n- User input must not be inserted directly into the DOM, `innerHTML`, `document.write`.\n- URL parameters must not be used directly in page rendering.\n- Dynamically generated `<script>` tags must be sourced.\n- Rich text uses libraries such as DOMPurify and configures tags, attributes, and protocol whitelists.\n\n```ts\nimport DOMPurify from \"dompurify\";\n\nconst clean = DOMPurify.sanitize(dirtyHtml, {\n  ALLOWED_TAGS: [\"b\", \"i\", \"em\", \"strong\", \"a\", \"ul\", \"ol\", \"li\", \"p\", \"br\"],\n  ALLOWED_ATTR: [\"href\", \"title\"],\n  ALLOWED_URI_REGEXP: /^(https?|mailto):/i,\n});\n```\n\n## Safe redirection\n\n```ts\nfunction safeRedirect(url: string): string {\n  if (url.startsWith(\"/\") && !url.startsWith(\"//\")) return url;\n  return \"/dashboard\";\n}\n```\n\n## CSP\n\n- It is recommended to verify with `Content-Security-Policy-Report-Only` first.\n- `default-src 'self'`, `object-src 'none'`, `frame-ancestors 'none'`, `base-uri 'self'` are common bottom lines.\n- Avoid `'unsafe-eval''; inline scripts take precedence over nonce.\n\n```http\nContent-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self';\n```\n\n## Sensitive data\n\n- It is prohibited to hard-code API Key, Secret, and password on the front end.\n- LocalStorage/sessionStorage/IndexedDB is prohibited from storing plain text tokens, passwords, and credit card information.\n- Prohibit URL query parameters from passing token or password.\n- Console.log or error reports are prohibited from carrying private data.\n- Token priority httpOnly + Secure + SameSite cookie.\n\n## CSRF\n\n- Change operations must carry CSRF tokens or use equivalent backend protection.\n- Do not use GET for critical operations.\n- Check whether the backend verifies `Origin` / `Referer`.\n\n## Dependencies and third-party scripts\n\n- Regularly review dependency security bulletins.\n- Disallow script loading from unofficial CDNs unless SRI and source vetted.\n- Dynamically loading third-party scripts must have business necessity and a downgrade strategy.\n\n## Input verification and file upload\n\n- Front-end verification is not a security boundary, and the back-end must be verified twice.\n- File uploads verify MIME, size, extension and content; don't just look at the extension.\n- Pay attention to ReDoS risks in regular verification.\n\nFile v2.9.0:skill-card.md\n\n## Description:\n\nReviews frontend code for XSS, CSRF, sensitive-data exposure, unsafe DOM usage, authentication risks, and third-party dependency risks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[bovinphang](https://clawhub.ai/user/bovinphang)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nFrontend developers and security reviewers use this skill to assess changes, selected files, or a project for browser-side security risks and receive prioritized findings with repair suggestions.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: An unscoped review may inspect the entire frontend project and save a report under reports/.\n\nMitigation: Specify files or directories for a narrower review and check the report before sharing it.\n\n## Reference(s):\n\n- [Security review checklist](references/security-checklist.md)\n- [Security review report template](references/report-template.md)\n- [Frontend Craft project homepage (package metadata)](https://github.com/bovinphang/frontend-craft)\n- [ClawHub skill listing](https://clawhub.ai/bovinphang/skills/fec-security-review)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, Security review guidance]\n\n**Output Format:** [Markdown report]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Severity-ranked findings with file and line references, repair suggestions, review scope, and completion status; saved under reports/.]\n\n## Skill Version(s):\n\n2.9.0 (source: ClawHub release and package.json)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v2.9.0:metadata.json\n\n{\n  \"id\": \"fec-security-review\",\n  \"name\": \"Front-end security review\",\n  \"category\": \"review-quality\",\n  \"tags\": [\n    \"xss\",\n    \"csrf\",\n    \"csp\",\n    \"security\",\n    \"owasp\",\n    \"dompurify\"\n  ],\n  \"summary\": \"Review browser-side XSS, CSRF, token exposure, unsafe DOM usage, and third-party risks.\",\n  \"version\": \"2.9.0\",\n  \"license\": \"MIT\",\n  \"homepage\": \"https://github.com/bovinphang/frontend-craft\",\n  \"repository\": \"https://github.com/bovinphang/frontend-craft\",\n  \"keywords\": [\n    \"review-quality\",\n    \"xss\",\n    \"csrf\",\n    \"csp\",\n    \"security\",\n    \"owasp\",\n    \"dompurify\"\n  ],\n  \"platforms\": [\n    \"skills-cli\",\n    \"skillreg\",\n    \"claude-code\",\n    \"codex\",\n    \"cursor\",\n    \"opencode\",\n    \"openclaw\",\n    \"generic-skill-runtime\"\n  ],\n  \"description\": \"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.\",\n  \"source\": \"skills/fec-security-review\",\n  \"references\": [\n    \"references/report-template.md\",\n    \"references/security-checklist.md\"\n  ],\n  \"relations\": {\n    \"relatedSkills\": [\n      \"fec-code-review\",\n      \"fec-accessibility-check\",\n      \"fec-browser-storage\",\n      \"fec-dependency-upgrade\",\n      \"fec-route-protection\"\n    ],\n    \"boundaryWorkflows\": [\n      \"Use a general code review workflow for architecture, maintainability, and broad quality review.\",\n      \"Use an accessibility workflow for accessibility-only concerns.\",\n      \"Use a browser storage workflow for storage strategy; keep sensitive data leakage risks in the security workflow.\"\n    ],\n    \"capabilityTags\": [\n      \"security\",\n      \"review\",\n      \"frontend\"\n    ]\n  }\n}\n\nFile v2.9.0:package.json\n\n{\n  \"name\": \"@bovinphang/fec-security-review\",\n  \"version\": \"2.9.0\",\n  \"description\": \"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.\",\n  \"type\": \"module\",\n  \"license\": \"MIT\",\n  \"author\": {\n    \"name\": \"Bovin Phang\",\n    \"email\": \"pengbaowen@msn.com\"\n  },\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"https://github.com/bovinphang/frontend-craft\",\n    \"directory\": \"skills/fec-security-review\"\n  },\n  \"homepage\": \"https://github.com/bovinphang/frontend-craft\",\n  \"keywords\": [\n    \"agent-skill\",\n    \"frontend-craft\",\n    \"review-quality\",\n    \"xss\",\n    \"csrf\",\n    \"csp\",\n    \"security\",\n    \"owasp\",\n    \"dompurify\"\n  ],\n  \"files\": [\n    \"SKILL.md\",\n    \"references\",\n    \"scripts\",\n    \"data\",\n    \"assets\",\n    \"metadata.json\",\n    \"README.md\",\n    \"LICENSE\"\n  ],\n  \"publishConfig\": {\n    \"access\": \"public\"\n  }\n}\n\nFile v2.9.0:LICENSE\n\nMIT License\r\n\r\nCopyright (c) 2025 Bovin Phang\r\n\r\nPermission is hereby granted, free of charge, to any person obtaining a copy\r\nof this software and associated documentation files (the \"Software\"), to deal\r\nin the Software without restriction, including without limitation the rights\r\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\r\ncopies of the Software, and to permit persons to whom the Software is\r\nfurnished to do so, subject to the following conditions:\r\n\r\nThe above copyright notice and this permission notice shall be included in all\r\ncopies or substantial portions of the Software.\r\n\r\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\r\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\r\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\r\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\r\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\r\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\r\nSOFTWARE.\n\nArchive v2.6.0: 8 files, 7262 bytes\n\nFiles: metadata.json (1765b), package.json (1060b), README.md (1065b), references/report-template.md (534b), references/security-checklist.md (2105b), skill-card.md (2214b), SKILL.md (2381b), _meta.json (138b)\n\nFile v2.6.0:SKILL.md\n\n---\nname: fec-security-review\ndescription: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include 安全审查, 安全检查.\n---\n\n# 前端安全审查\n\n## Purpose\n\n识别前端代码中的客户端安全风险，并给出可执行修复建议。\n\n## Procedure\n\n1. 先确认审查面：用户输入、动态 HTML、URL 跳转、认证态、RBAC、文件上传、支付/删除等敏感操作、第三方脚本和依赖。\n2. 搜索高危模式：`dangerouslySetInnerHTML`、`v-html`、`innerHTML`、`document.write`、动态 script、未校验 redirect、明文 token。\n3. 按风险类型审查：XSS、CSP、敏感数据、CSRF、依赖、输入校验、文件上传、开放重定向、认证授权和第三方脚本。\n4. 用边界模型判断责任：客户端只能改善体验和减少误用，鉴权、授权、上传信任和敏感操作必须由服务端最终裁决。\n5. 高危问题标记为阻塞合并；前端校验只能改善体验，不能作为唯一安全边界。\n6. 输出分级安全报告；报告格式见 [references/report-template.md](references/report-template.md)。\n\n## 详细参考\n\n- 需要 XSS、CSP、敏感数据、CSRF、依赖和输入校验细节时，加载 [references/security-checklist.md](references/security-checklist.md)。\n- 撰写安全审查报告时，加载 [references/report-template.md](references/report-template.md)。\n\n## Constraints\n\n- 不要为了方便开发而绕过安全机制。\n- 不要依赖前端校验作为唯一安全防线。\n- 不要信任任何来自客户端的数据。\n- 发现高危问题时必须标记为阻塞合并。\n- 与通用代码质量 review 分工：本 skill 关注威胁、攻击面和数据泄露。\n- 不把依赖审计结果机械等同为可利用漏洞；需要结合运行路径、暴露面和修复成本判断。\n- 不把隐藏按钮、前端路由守卫或本地角色字段当作授权边界；API、SSR loader、server action 和敏感操作必须有服务端裁决。\n\n## Expected Output\n\n输出 CRITICAL/HIGH/MEDIUM/LOW 分级安全审查报告，每个问题关联具体文件和行号，给出修复建议；报告保存为 `reports/security-review-YYYY-MM-DD-HHmmss.md`。\n\nFile v2.6.0:README.md\n\n# 前端安全审查\n\nFrontend Craft skill for 前端安全审查.\n\n## Skill\n\n- ID: `fec-security-review`\n- Category: `review-quality`\n- Version: `2.6.0`\n- Source: `skills/fec-security-review/SKILL.md`\n\n## Description\n\nUse when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include 安全审查, 安全检查.\n\n## Usage\n\nInstall or import this package with any skill runtime that understands the standard `SKILL.md` layout. The canonical source remains the Frontend Craft repository.\n\n## Packaged Files\n\n- [references/report-template.md](references/report-template.md)\n- [references/security-checklist.md](references/security-checklist.md)\n\n## Optional Related Packages\n\n- `@bovinphang/fec-code-review`\n- `@bovinphang/fec-accessibility-check`\n- `@bovinphang/fec-browser-storage`\n- `@bovinphang/fec-dependency-upgrade`\n- `@bovinphang/fec-route-protection`\n\n## License\n\nMIT\n\nFile v2.6.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b0nh7hvj1pffeqc8y0dqwwh83m726\",\n  \"slug\": \"fec-security-review\",\n  \"version\": \"2.6.0\",\n  \"publishedAt\": 1780842866397\n}\n\nFile v2.6.0:references/report-template.md\n\n# 安全审查报告模板\n\n```markdown\n# 安全审查报告\n\n> 生成时间: YYYY-MM-DD HH:mm\n> 评审工具: frontend-craft\n\n## CRITICAL / 高危 (N项)\n- **[文件:行号]** 风险描述 -> 修复建议\n\n## HIGH / 中高危 (N项)\n- ...\n\n## MEDIUM / 中危 (N项)\n- ...\n\n## LOW / 低危或建议 (N项)\n- ...\n\n## 已通过的安全检查\n- ...\n\n**整体安全等级**: 安全 / 存在风险 / 高危需修复\n```\n\n审查完成后，将报告保存到 `reports/security-review-YYYY-MM-DD-HHmmss.md`，并告知用户报告路径。\n\nFile v2.6.0:references/security-checklist.md\n\n# 前端安全审查清单\n\n## XSS\n\n- `dangerouslySetInnerHTML` 和 `v-html` 必须有明确理由和输入净化。\n- 用户输入不得直接插入 DOM、`innerHTML`、`document.write`。\n- URL 参数不得直接用于页面渲染。\n- 动态生成的 `<script>` 标签必须审查来源。\n- 富文本使用 DOMPurify 等库，并配置标签、属性、协议白名单。\n\n```ts\nimport DOMPurify from \"dompurify\";\n\nconst clean = DOMPurify.sanitize(dirtyHtml, {\n  ALLOWED_TAGS: [\"b\", \"i\", \"em\", \"strong\", \"a\", \"ul\", \"ol\", \"li\", \"p\", \"br\"],\n  ALLOWED_ATTR: [\"href\", \"title\"],\n  ALLOWED_URI_REGEXP: /^(https?|mailto):/i,\n});\n```\n\n## 安全重定向\n\n```ts\nfunction safeRedirect(url: string): string {\n  if (url.startsWith(\"/\") && !url.startsWith(\"//\")) return url;\n  return \"/dashboard\";\n}\n```\n\n## CSP\n\n- 推荐先用 `Content-Security-Policy-Report-Only` 验证。\n- `default-src 'self'`、`object-src 'none'`、`frame-ancestors 'none'`、`base-uri 'self'` 是常见底线。\n- 避免 `'unsafe-eval'`；内联脚本优先 nonce。\n\n```http\nContent-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self';\n```\n\n## 敏感数据\n\n- 禁止前端硬编码 API Key、Secret、密码。\n- 禁止 localStorage/sessionStorage/IndexedDB 存明文 token、密码、信用卡信息。\n- 禁止 URL query 参数传 token 或密码。\n- 禁止 console.log 或错误上报携带隐私数据。\n- Token 优先 httpOnly + Secure + SameSite cookie。\n\n## CSRF\n\n- 变更操作必须携带 CSRF token 或使用同等后端防护。\n- 关键操作不要使用 GET。\n- 检查后端是否校验 `Origin` / `Referer`。\n\n## 依赖与第三方脚本\n\n- 定期审查依赖安全公告。\n- 禁止从非官方 CDN 加载脚本，除非有 SRI 和来源审查。\n- 动态加载第三方脚本必须有业务必要性和降级策略。\n\n## 输入校验与文件上传\n\n- 前端校验不是安全边界，后端必须二次校验。\n- 文件上传校验 MIME、大小、扩展名和内容；不能只看扩展名。\n- 正则校验注意 ReDoS 风险。\n\nFile v2.6.0:skill-card.md\n\n## Description:\n\nUse when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[bovinphang](https://clawhub.ai/user/bovinphang)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers and engineers use this skill to review frontend code for client-side security risks and receive prioritized remediation guidance. It is suited to web application reviews involving XSS, CSRF, CSP, sensitive data handling, file upload, authentication, authorization, dependency, and third-party script risks.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill reads project code during review and can create a Markdown report under reports/.\n\nMitigation: Run it only in repositories where code inspection and report creation are acceptable, and review generated findings before acting on them.\n\nRisk: Security review guidance may miss context that only backend controls or deployment policy can prove.\n\nMitigation: Use the report as review guidance and confirm critical authorization, CSRF, upload, and sensitive-operation controls on the server side.\n\n## Reference(s):\n\n- [Security Checklist](references/security-checklist.md)\n- [Report Template](references/report-template.md)\n- [ClawHub Skill Page](https://clawhub.ai/bovinphang/skills/fec-security-review)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Markdown, Files, Guidance]\n\n**Output Format:** [Markdown security review report]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [The skill expects findings to be ranked CRITICAL, HIGH, MEDIUM, or LOW and saved as a timestamped report under reports/.]\n\n## Skill Version(s):\n\n2.6.0 (source: release evidence, package.json, metadata.json, README.md)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v2.6.0:metadata.json\n\n{\n  \"id\": \"fec-security-review\",\n  \"name\": \"前端安全审查\",\n  \"category\": \"review-quality\",\n  \"tags\": [\n    \"xss\",\n    \"csrf\",\n    \"csp\",\n    \"security\",\n    \"owasp\",\n    \"dompurify\"\n  ],\n  \"summary\": \"Frontend Craft skill for 前端安全审查.\",\n  \"version\": \"2.6.0\",\n  \"license\": \"MIT\",\n  \"homepage\": \"https://github.com/bovinphang/frontend-craft\",\n  \"repository\": \"https://github.com/bovinphang/frontend-craft\",\n  \"keywords\": [\n    \"review-quality\",\n    \"xss\",\n    \"csrf\",\n    \"csp\",\n    \"security\",\n    \"owasp\",\n    \"dompurify\"\n  ],\n  \"platforms\": [\n    \"skills-cli\",\n    \"skillreg\",\n    \"claude-code\",\n    \"codex\",\n    \"cursor\",\n    \"opencode\",\n    \"openclaw\",\n    \"generic-skill-runtime\"\n  ],\n  \"description\": \"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include 安全审查, 安全检查.\",\n  \"source\": \"skills/fec-security-review\",\n  \"references\": [\n    \"references/report-template.md\",\n    \"references/security-checklist.md\"\n  ],\n  \"relations\": {\n    \"relatedSkills\": [\n      \"fec-code-review\",\n      \"fec-accessibility-check\",\n      \"fec-browser-storage\",\n      \"fec-dependency-upgrade\",\n      \"fec-route-protection\"\n    ],\n    \"boundaryWorkflows\": [\n      \"Use a general code review workflow for architecture, maintainability, and broad quality review.\",\n      \"Use an accessibility workflow for accessibility-only concerns.\",\n      \"Use a browser storage workflow for storage strategy; keep sensitive data leakage risks in the security workflow.\"\n    ],\n    \"capabilityTags\": [\n      \"security\",\n      \"review\",\n      \"frontend\"\n    ]\n  }\n}\n\nFile v2.6.0:package.json\n\n{\n  \"name\": \"@bovinphang/fec-security-review\",\n  \"version\": \"2.6.0\",\n  \"description\": \"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include 安全审查, 安全检查.\",\n  \"type\": \"module\",\n  \"license\": \"MIT\",\n  \"author\": {\n    \"name\": \"Bovin Phang\",\n    \"email\": \"pengbaowen@msn.com\"\n  },\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"https://github.com/bovinphang/frontend-craft\",\n    \"directory\": \"skills/fec-security-review\"\n  },\n  \"homepage\": \"https://github.com/bovinphang/frontend-craft\",\n  \"keywords\": [\n    \"agent-skill\",\n    \"frontend-craft\",\n    \"review-quality\",\n    \"xss\",\n    \"csrf\",\n    \"csp\",\n    \"security\",\n    \"owasp\",\n    \"dompurify\"\n  ],\n  \"files\": [\n    \"SKILL.md\",\n    \"references\",\n    \"scripts\",\n    \"data\",\n    \"assets\",\n    \"metadata.json\",\n    \"README.md\",\n    \"LICENSE\"\n  ],\n  \"publishConfig\": {\n    \"access\": \"public\"\n  }\n}\n\nArchive v2.4.0: 8 files, 7328 bytes\n\nFiles: metadata.json (1765b), package.json (1050b), README.md (1085b), references/report-template.md (534b), references/security-checklist.md (2105b), skill-card.md (2379b), SKILL.md (2393b), _meta.json (138b)\n\nFile v2.4.0:SKILL.md\n\n---\nname: fec-security-review\ndescription: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include 安全审查, 安全检查.\n---\n\n# 前端安全审查\n\n## Purpose\n\n识别前端代码中的客户端安全风险，并给出可执行修复建议。\n\n## Procedure\n\n1. 先确认审查面：用户输入、动态 HTML、URL 跳转、认证态、RBAC、文件上传、支付/删除等敏感操作、第三方脚本和依赖。\n2. 搜索高危模式：`dangerouslySetInnerHTML`、`v-html`、`innerHTML`、`document.write`、动态 script、未校验 redirect、明文 token。\n3. 按风险类型审查：XSS、CSP、敏感数据、CSRF、依赖、输入校验、文件上传、开放重定向、认证授权和第三方脚本。\n4. 用边界模型判断责任：客户端只能改善体验和减少误用，鉴权、授权、上传信任和敏感操作必须由服务端最终裁决。\n5. 高危问题标记为阻塞合并；前端校验只能改善体验，不能作为唯一安全边界。\n6. 输出分级安全报告；报告格式见 [references/report-template.md](references/report-template.md)。\n\n## Detailed References\n\n- Load [references/security-checklist.md](references/security-checklist.md) for XSS, CSP, sensitive data, CSRF, dependency, and input validation details.\n- Load [references/report-template.md](references/report-template.md) when writing the security review report.\n\n## Constraints\n\n- 不要为了方便开发而绕过安全机制。\n- 不要依赖前端校验作为唯一安全防线。\n- 不要信任任何来自客户端的数据。\n- 发现高危问题时必须标记为阻塞合并。\n- 与通用代码质量 review 分工：本 skill 关注威胁、攻击面和数据泄露。\n- 不把依赖审计结果机械等同为可利用漏洞；需要结合运行路径、暴露面和修复成本判断。\n- 不把隐藏按钮、前端路由守卫或本地角色字段当作授权边界；API、SSR loader、server action 和敏感操作必须有服务端裁决。\n\n## Expected Output\n\n输出 CRITICAL/HIGH/MEDIUM/LOW 分级安全审查报告，每个问题关联具体文件和行号，给出修复建议；报告保存为 `reports/security-review-YYYY-MM-DD-HHmmss.md`。\n\nFile v2.4.0:README.md\n\n# 前端安全审查\n\nFrontend Craft skill for 前端安全审查.\n\n## Skill\n\n- ID: `fec-security-review`\n- Category: `review-quality`\n- Version: `2.4.0`\n- Source: `skills/fec-security-review/SKILL.md`\n\n## Description\n\nUse when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include 安全审查, 安全检查.\n\n## Usage\n\nInstall or import this package with any skill runtime that understands the standard `SKILL.md` layout. The canonical source remains the Frontend Craft repository.\n\n## Packaged Files\n\n- [references/report-template.md](references/report-template.md)\n- [references/security-checklist.md](references/security-checklist.md)\n\n## Optional Related Packages\n\n- `@frontend-craft/fec-code-review`\n- `@frontend-craft/fec-accessibility-check`\n- `@frontend-craft/fec-browser-storage`\n- `@frontend-craft/fec-dependency-upgrade`\n- `@frontend-craft/fec-route-protection`\n\n## License\n\nMIT\n\nFile v2.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b0nh7hvj1pffeqc8y0dqwwh83m726\",\n  \"slug\": \"fec-security-review\",\n  \"version\": \"2.4.0\",\n  \"publishedAt\": 1780307343253\n}\n\nFile v2.4.0:references/report-template.md\n\n# 安全审查报告模板\n\n```markdown\n# 安全审查报告\n\n> 生成时间: YYYY-MM-DD HH:mm\n> 评审工具: frontend-craft\n\n## CRITICAL / 高危 (N项)\n- **[文件:行号]** 风险描述 -> 修复建议\n\n## HIGH / 中高危 (N项)\n- ...\n\n## MEDIUM / 中危 (N项)\n- ...\n\n## LOW / 低危或建议 (N项)\n- ...\n\n## 已通过的安全检查\n- ...\n\n**整体安全等级**: 安全 / 存在风险 / 高危需修复\n```\n\n审查完成后，将报告保存到 `reports/security-review-YYYY-MM-DD-HHmmss.md`，并告知用户报告路径。\n\nFile v2.4.0:references/security-checklist.md\n\n# 前端安全审查清单\n\n## XSS\n\n- `dangerouslySetInnerHTML` 和 `v-html` 必须有明确理由和输入净化。\n- 用户输入不得直接插入 DOM、`innerHTML`、`document.write`。\n- URL 参数不得直接用于页面渲染。\n- 动态生成的 `<script>` 标签必须审查来源。\n- 富文本使用 DOMPurify 等库，并配置标签、属性、协议白名单。\n\n```ts\nimport DOMPurify from \"dompurify\";\n\nconst clean = DOMPurify.sanitize(dirtyHtml, {\n  ALLOWED_TAGS: [\"b\", \"i\", \"em\", \"strong\", \"a\", \"ul\", \"ol\", \"li\", \"p\", \"br\"],\n  ALLOWED_ATTR: [\"href\", \"title\"],\n  ALLOWED_URI_REGEXP: /^(https?|mailto):/i,\n});\n```\n\n## 安全重定向\n\n```ts\nfunction safeRedirect(url: string): string {\n  if (url.startsWith(\"/\") && !url.startsWith(\"//\")) return url;\n  return \"/dashboard\";\n}\n```\n\n## CSP\n\n- 推荐先用 `Content-Security-Policy-Report-Only` 验证。\n- `default-src 'self'`、`object-src 'none'`、`frame-ancestors 'none'`、`base-uri 'self'` 是常见底线。\n- 避免 `'unsafe-eval'`；内联脚本优先 nonce。\n\n```http\nContent-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self';\n```\n\n## 敏感数据\n\n- 禁止前端硬编码 API Key、Secret、密码。\n- 禁止 localStorage/sessionStorage/IndexedDB 存明文 token、密码、信用卡信息。\n- 禁止 URL query 参数传 token 或密码。\n- 禁止 console.log 或错误上报携带隐私数据。\n- Token 优先 httpOnly + Secure + SameSite cookie。\n\n## CSRF\n\n- 变更操作必须携带 CSRF token 或使用同等后端防护。\n- 关键操作不要使用 GET。\n- 检查后端是否校验 `Origin` / `Referer`。\n\n## 依赖与第三方脚本\n\n- 定期审查依赖安全公告。\n- 禁止从非官方 CDN 加载脚本，除非有 SRI 和来源审查。\n- 动态加载第三方脚本必须有业务必要性和降级策略。\n\n## 输入校验与文件上传\n\n- 前端校验不是安全边界，后端必须二次校验。\n- 文件上传校验 MIME、大小、扩展名和内容；不能只看扩展名。\n- 正则校验注意 ReDoS 风险。\n\nFile v2.4.0:skill-card.md\n\n## Description: <br>\nUse when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[bovinphang](https://clawhub.ai/user/bovinphang) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill to review frontend code for client-side security risks and produce a prioritized report with file-level findings and remediation guidance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill is intended for frontend review assistance and may not cover backend, infrastructure, malware, or production incident analysis. <br>\nMitigation: Pair its findings with a broader application-security review when backend authorization, infrastructure controls, malware, or incident response are in scope. <br>\nRisk: The artifact focuses on client-side checks, where frontend validation cannot be the sole security boundary. <br>\nMitigation: Verify that authentication, authorization, sensitive operations, upload trust, and data validation are enforced server-side. <br>\n\n\n## Reference(s): <br>\n- [Security Checklist](references/security-checklist.md) <br>\n- [Report Template](references/report-template.md) <br>\n- [ClawHub Release Page](https://clawhub.ai/bovinphang/fec-security-review) <br>\n- [Frontend Craft Repository](https://github.com/bovinphang/frontend-craft) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [analysis, markdown, guidance] <br>\n**Output Format:** [Markdown report with CRITICAL/HIGH/MEDIUM/LOW findings, file and line references, and remediation guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The expected report path is reports/security-review-YYYY-MM-DD-HHmmss.md.] <br>\n\n## Skill Version(s): <br>\n2.4.0 (source: server release metadata, README, metadata.json, package.json) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v2.4.0:metadata.json\n\n{\n  \"id\": \"fec-security-review\",\n  \"name\": \"前端安全审查\",\n  \"category\": \"review-quality\",\n  \"tags\": [\n    \"xss\",\n    \"csrf\",\n    \"csp\",\n    \"security\",\n    \"owasp\",\n    \"dompurify\"\n  ],\n  \"summary\": \"Frontend Craft skill for 前端安全审查.\",\n  \"version\": \"2.4.0\",\n  \"license\": \"MIT\",\n  \"homepage\": \"https://github.com/bovinphang/frontend-craft\",\n  \"repository\": \"https://github.com/bovinphang/frontend-craft\",\n  \"keywords\": [\n    \"review-quality\",\n    \"xss\",\n    \"csrf\",\n    \"csp\",\n    \"security\",\n    \"owasp\",\n    \"dompurify\"\n  ],\n  \"platforms\": [\n    \"skills-cli\",\n    \"skillreg\",\n    \"claude-code\",\n    \"codex\",\n    \"cursor\",\n    \"opencode\",\n    \"openclaw\",\n    \"generic-skill-runtime\"\n  ],\n  \"description\": \"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include 安全审查, 安全检查.\",\n  \"source\": \"skills/fec-security-review\",\n  \"references\": [\n    \"references/report-template.md\",\n    \"references/security-checklist.md\"\n  ],\n  \"relations\": {\n    \"relatedSkills\": [\n      \"fec-code-review\",\n      \"fec-accessibility-check\",\n      \"fec-browser-storage\",\n      \"fec-dependency-upgrade\",\n      \"fec-route-protection\"\n    ],\n    \"boundaryWorkflows\": [\n      \"Use a general code review workflow for architecture, maintainability, and broad quality review.\",\n      \"Use an accessibility workflow for accessibility-only concerns.\",\n      \"Use a browser storage workflow for storage strategy; keep sensitive data leakage risks in the security workflow.\"\n    ],\n    \"capabilityTags\": [\n      \"security\",\n      \"review\",\n      \"frontend\"\n    ]\n  }\n}\n\nFile v2.4.0:package.json\n\n{\n  \"name\": \"@frontend-craft/fec-security-review\",\n  \"version\": \"2.4.0\",\n  \"description\": \"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include 安全审查, 安全检查.\",\n  \"type\": \"module\",\n  \"license\": \"MIT\",\n  \"author\": {\n    \"name\": \"Bovin Phang\",\n    \"email\": \"pengbaowen@msn.com\"\n  },\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"https://github.com/bovinphang/frontend-craft\",\n    \"directory\": \"skills/fec-security-review\"\n  },\n  \"homepage\": \"https://github.com/bovinphang/frontend-craft\",\n  \"keywords\": [\n    \"agent-skill\",\n    \"frontend-craft\",\n    \"review-quality\",\n    \"xss\",\n    \"csrf\",\n    \"csp\",\n    \"security\",\n    \"owasp\",\n    \"dompurify\"\n  ],\n  \"files\": [\n    \"SKILL.md\",\n    \"references\",\n    \"scripts\",\n    \"data\",\n    \"metadata.json\",\n    \"README.md\",\n    \"LICENSE\"\n  ],\n  \"publishConfig\": {\n    \"access\": \"public\"\n  }\n}","readmeExcerpt":"Skill: Frontend Security Review Owner: bovinphang Summary: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check. Tags: latest:2.9.0 Version history: v2.9.0 | 2026-09-27T03:40:19.132Z | ","codeSnippets":[],"executableExamples":[{"language":"markdown","snippet":"# Security Review Report\n\n> Generation time: YYYY-MM-DD HH:mm\n> Review tool: frontend-craft\n\n> Review mode: change / targeted / project\n> Target scope: paths or PR/commit\n> Reviewed: file or module inventory\n> Exclusions: paths and reasons\n> Unreviewed: remaining files or modules (state none if complete)\n> Completion: complete / partial\n> Verification: commands, results and reasons for skipped checks\n\n## CRITICAL / HIGH RISK (N items)\n- **[File:line number]** Risk description -> Repair suggestions\n\n## HIGH / Medium to high risk (N items)\n- ...\n\n## MEDIUM / medium risk (N items)\n- ...\n\n## LOW / low risk or recommended (N items)\n- ...\n\n## Passed security check\n- ...\n\n**Overall security level**: safe / risky / high risk and needs to be repaired"},{"language":"ts","snippet":"import DOMPurify from \"dompurify\";\n\nconst clean = DOMPurify.sanitize(dirtyHtml, {\n  ALLOWED_TAGS: [\"b\", \"i\", \"em\", \"strong\", \"a\", \"ul\", \"ol\", \"li\", \"p\", \"br\"],\n  ALLOWED_ATTR: [\"href\", \"title\"],\n  ALLOWED_URI_REGEXP: /^(https?|mailto):/i,\n});"},{"language":"ts","snippet":"function safeRedirect(url: string): string {\n  if (url.startsWith(\"/\") && !url.startsWith(\"//\")) return url;\n  return \"/dashboard\";\n}"},{"language":"http","snippet":"Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self';"},{"language":"markdown","snippet":"# 安全审查报告\n\n> 生成时间: YYYY-MM-DD HH:mm\n> 评审工具: frontend-craft\n\n## CRITICAL / 高危 (N项)\n- **[文件:行号]** 风险描述 -> 修复建议\n\n## HIGH / 中高危 (N项)\n- ...\n\n## MEDIUM / 中危 (N项)\n- ...\n\n## LOW / 低危或建议 (N项)\n- ...\n\n## 已通过的安全检查\n- ...\n\n**整体安全等级**: 安全 / 存在风险 / 高危需修复"},{"language":"ts","snippet":"import DOMPurify from \"dompurify\";\n\nconst clean = DOMPurify.sanitize(dirtyHtml, {\n  ALLOWED_TAGS: [\"b\", \"i\", \"em\", \"strong\", \"a\", \"ul\", \"ol\", \"li\", \"p\", \"br\"],\n  ALLOWED_ATTR: [\"href\", \"title\"],\n  ALLOWED_URI_REGEXP: /^(https?|mailto):/i,\n});"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: fec-security-review\ndescription: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.\n---\n\n# Front-end security review\n\n## Review modes and coverage\n\nUser-specified scope takes precedence over the default. Use the following three review modes:\n\n- **Change review**: only when recent changes, current edits, staged changes, a PR or a commit are explicitly requested or clearly established by the active task, review those changes and necessary context. For local changes, inspect staged and unstaged diffs and relevant untracked project files within the requested scope; a staged-only request reviews only staged changes. If there are no changes, report that there is nothing to review; do not switch to recent commits or expand scope automatically.\n- **Targeted review**: when files or directories are specified, inventory and review existing code in that scope, including unchanged code; no Git diff is required.\n- **Project review (default)**: when no scope or change context is specified, or when the entire project is requested, inventory project-owned frontend code, related tests, configuration and dependency declarations, then review in module batches, including unchanged code; no Git diff is required.\n\nSelect scope before collecting diffs. A file/directory alone means full review of that scope; a path combined with an explicit change request restricts incremental review to that path. An unqualified invocation defaults to project review even if Git changes exist. At review start, state the selected mode and target scope. When automatically delegating review after edits, pass the current change scope explicitly; do not trigger project review merely because the reviewer was called.\n\nExclude dependency directories, build outputs, caches, generated files and third-party code by default, and record exclusions. Keep the frontend responsibility boundary; this is not a backend audit. A nonexistent target or a scope with no relevant files must be reported explicitly, not replaced with another scope.\n\nMerge findings with the same root cause across batches. Report **review mode, target scope, reviewed files/modules, exclusions, unreviewed files/modules, completion status and verification commands/results**. If context or execution limits prevent completion, mark the review partial and list remaining modules; never claim complete project coverage. Reading callers for context or running project-wide lint/typecheck does not count as manual review of those files.\n\nChange reviews retain merge recommendations. Targeted and project reviews use a risk assessment (Low / Medium / High, with blocking findings), not a claim of merge readiness. Preserve severity levels, evidence requirements and report filenames. Output reports only unles"},{"path":"README.md","content":"# Front-end security review\n\nReview browser-side XSS, CSRF, token exposure, unsafe DOM usage, and third-party risks.\n\n## Skill\n\n- ID: `fec-security-review`\n- Category: `review-quality`\n- Version: `2.9.0`\n- Source: `skills/fec-security-review/SKILL.md`\n\n## Description\n\nUse when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check.\n\n## Usage\n\nInstall or import this package with any skill runtime that understands the standard `SKILL.md` layout. The canonical source remains the Frontend Craft repository.\n\n## Packaged Files\n\n- [references/report-template.md](references/report-template.md)\n- [references/security-checklist.md](references/security-checklist.md)\n\n## Optional Related Packages\n\n- `@bovinphang/fec-code-review`\n- `@bovinphang/fec-accessibility-check`\n- `@bovinphang/fec-browser-storage`\n- `@bovinphang/fec-dependency-upgrade`\n- `@bovinphang/fec-route-protection`\n\n## License\n\nMIT"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7b0nh7hvj1pffeqc8y0dqwwh83m726\",\n  \"slug\": \"fec-security-review\",\n  \"version\": \"2.9.0\",\n  \"publishedAt\": 1790480419132\n}"},{"path":"references/report-template.md","content":"# Security review report template\n\n```markdown\n# Security Review Report\n\n> Generation time: YYYY-MM-DD HH:mm\n> Review tool: frontend-craft\n\n> Review mode: change / targeted / project\n> Target scope: paths or PR/commit\n> Reviewed: file or module inventory\n> Exclusions: paths and reasons\n> Unreviewed: remaining files or modules (state none if complete)\n> Completion: complete / partial\n> Verification: commands, results and reasons for skipped checks\n\n## CRITICAL / HIGH RISK (N items)\n- **[File:line number]** Risk description -> Repair suggestions\n\n## HIGH / Medium to high risk (N items)\n- ...\n\n## MEDIUM / medium risk (N items)\n- ...\n\n## LOW / low risk or recommended (N items)\n- ...\n\n## Passed security check\n- ...\n\n**Overall security level**: safe / risky / high risk and needs to be repaired\n```\n\nAfter the review is completed, save the report to `reports/security-review-YYYY-MM-DD-HHmmss.md` and inform the user of the report path.\n\nRetain merge recommendations for change review; use risk assessments for targeted and project reviews. For partial reviews, conclusions apply only to reviewed scope and do not establish project-wide approval."},{"path":"references/security-checklist.md","content":"# Front-end security review checklist\n\n## XSS\n\n- `dangerouslySetInnerHTML` and `v-html` must have explicit reason and input sanitization.\n- User input must not be inserted directly into the DOM, `innerHTML`, `document.write`.\n- URL parameters must not be used directly in page rendering.\n- Dynamically generated `<script>` tags must be sourced.\n- Rich text uses libraries such as DOMPurify and configures tags, attributes, and protocol whitelists.\n\n```ts\nimport DOMPurify from \"dompurify\";\n\nconst clean = DOMPurify.sanitize(dirtyHtml, {\n  ALLOWED_TAGS: [\"b\", \"i\", \"em\", \"strong\", \"a\", \"ul\", \"ol\", \"li\", \"p\", \"br\"],\n  ALLOWED_ATTR: [\"href\", \"title\"],\n  ALLOWED_URI_REGEXP: /^(https?|mailto):/i,\n});\n```\n\n## Safe redirection\n\n```ts\nfunction safeRedirect(url: string): string {\n  if (url.startsWith(\"/\") && !url.startsWith(\"//\")) return url;\n  return \"/dashboard\";\n}\n```\n\n## CSP\n\n- It is recommended to verify with `Content-Security-Policy-Report-Only` first.\n- `default-src 'self'`, `object-src 'none'`, `frame-ancestors 'none'`, `base-uri 'self'` are common bottom lines.\n- Avoid `'unsafe-eval''; inline scripts take precedence over nonce.\n\n```http\nContent-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self';\n```\n\n## Sensitive data\n\n- It is prohibited to hard-code API Key, Secret, and password on the front end.\n- LocalStorage/sessionStorage/IndexedDB is prohibited from storing plain text tokens, passwords, and credit card information.\n- Prohibit URL query parameters from passing token or password.\n- Console.log or error reports are prohibited from carrying private data.\n- Token priority httpOnly + Secure + SameSite cookie.\n\n## CSRF\n\n- Change operations must carry CSRF tokens or use equivalent backend protection.\n- Do not use GET for critical operations.\n- Check whether the backend verifies `Origin` / `Referer`.\n\n## Dependencies and third-party scripts\n\n- Regularly review dependency security bulletins.\n- Disallow script loading from unofficial CDNs unless SRI and source vetted.\n- Dynamically loading third-party scripts must have business necessity and a downgrade strategy.\n\n## Input verification and file upload\n\n- Front-end verification is not a security boundary, and the back-end must be verified twice.\n- File uploads verify MIME, size, extension and content; don't just look at the extension.\n- Pay attention to ReDoS risks in regular verification."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check. Skill: Frontend Security Review Owner: bovinphang Summary: Use when reviewing frontend security risks such as XSS, CSRF, sensitive data exposure, unsafe DOM APIs, untrusted user input, authentication/token handling, payment flows, file upload, CSP, dependency risk, or third-party scripts; Chinese triggers include security review, security check. Tags: latest:2.9.0 Version history: v2.9.0 | 2026-09-27T03:40:19.132Z |","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1457,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T17:28:53.432Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T17:28:53.432Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T20:59:58.634Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}