Web Coder
boshi-xixixi/TraeSkill
Expert 10x engineer with comprehensive knowledge of web development, internet protocols, and web standards.
Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for…
$ npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills experience-lwc-security-validate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/experience-lwc-security-validate .claude/skills/experience-lwc-security-validate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "experience-lwc-security-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-lwc-security-validate into .claude/skills/experience-lwc-security-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-lwc-security-validate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-lwc-security-validateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills experience-lwc-security-validate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/experience-lwc-security-validate .agents/skills/experience-lwc-security-validate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "experience-lwc-security-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-lwc-security-validate into .agents/skills/experience-lwc-security-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-lwc-security-validate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills experience-lwc-security-validate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/experience-lwc-security-validate .cursor/skills/experience-lwc-security-validate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "experience-lwc-security-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-lwc-security-validate into .cursor/skills/experience-lwc-security-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-lwc-security-validate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/experience-lwc-security-validate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills experience-lwc-security-validate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/experience-lwc-security-validate .gemini/skills/experience-lwc-security-validate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "experience-lwc-security-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-lwc-security-validate into .gemini/skills/experience-lwc-security-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-lwc-security-validate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills experience-lwc-security-validateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/experience-lwc-security-validate .github/skills/experience-lwc-security-validate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "experience-lwc-security-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-lwc-security-validate into .github/skills/experience-lwc-security-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-lwc-security-validate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills experience-lwc-security-validate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/experience-lwc-security-validate .opencode/skills/experience-lwc-security-validate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "experience-lwc-security-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-lwc-security-validate into .opencode/skills/experience-lwc-security-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-lwc-security-validate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
experience-lwc-security-validateUse this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for…
Experience Lwc Security Validate is an agent skill from forcedotcom/sf-skills. Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for LWCs, NOT a generic code-security pass. It produces either a severity-ranked finding list with code-level remediations or a SARIF 2.1.0 JSON score report keyed by the lws-001…lws-023b rule catalog. TRIGGER when the user asks to review, audit, or check an LWC component for LWS compliance issues and recommend fixes, score…
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `examples/review-report.md`, `examples/score-report.sarif.json` and `references/lws-security-expert.md`).
It sits in Frontend & Design, covering Security review, Accessibility and Web application vulnerabilities. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Experience Lwc Security Validate loads about 2.6k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 253 tokens; SKILL.md has 1,238 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 1,238 words, ~2,646 tokens.
.claude/skills/experience-lwc-security-validate/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.<!-- adk-managed-skill -->
Run a structured Lightning Web Security (LWS) and Product Security compliance pass over a Lightning Web Component. Two output modes:
lws-001…lws-023b) for downstream gating, eval scoring, or CI ingest.Both modes use the same detection rules from the references; only the output format differs.
Do NOT use this skill for:
experience-lwc-generate).modules/…)..js-meta.xml.review (default — find, fix, report) or score (find, emit SARIF JSON, do NOT modify code). Confirm with the user before starting if it isn't obvious from the request.Each reference is the source of truth. Do not summarize from memory — open the reference, apply the guidelines, and cite the specific section you used in the report.
lws-001…lws-023b): Product Security Framework — for every rule the catalog gives the detection patterns and the canonical SARIF ruleId / level / message template. Score mode emits one SARIF result per match using these exact values.Collect the component path and identify the files to review. Include every file in the component bundle: .html, .js/.ts, .css, .js-meta.xml, and any child components owned by the same team that are invoked from the target.
Note any existing feature-flag gates — findings that require code changes must respect them.
Read LWS Security Expert and Product Security Framework top-to-bottom before judging. The LWS reference enumerates blocked DOM APIs and their allowed alternatives; the Product Security framework gives the severity taxonomy, the 23-rule SARIF catalog, and remediation patterns.
Run every rule in Product Security Framework (lws-001 through lws-023b) against the component bundle. For each rule:
Reflect.*, string concatenation) you must consider.ruleId, level (error / warning from the catalog), file, startLine, startColumn (column 1 if unknown), message (use the catalog's message template, substituting any {placeholder} from the actual code).scripts/check-lwc-import.sh <file> — the script prints lwc-import=yes when a from 'lwc' import is present and lwc-import=no otherwise. Skip the rule for that file when the answer is no.This catalog is the canonical detection list; the JS/TS, HTML, and .js-meta.xml bullets that follow are additional checks beyond the SARIF rules.
Walk each template for:
lwc:inner-html usage — verify the source is trusted.href, src, srcdoc, inline event handlers).style="…" with bound expressions — candidates for CSS class swaps.<iframe> or <object> without sandboxing (Step 3 catches the srcdoc and protocol cases via lws-023a/lws-023b; this step catches missing sandbox attributes).Inspect .js-meta.xml for:
lightning__FlowScreen, lightning__AppPage, etc.) when the component doesn't need it.capabilities restrictions for the target surface.Inspect Apex bindings for:
@wire to Apex methods without @AuraEnabled(cacheable=true) where caching is safe.Findings from Steps 4-5 use rule IDs lws-tpl-001…lws-tpl-NNN (HTML) and lws-meta-001…lws-meta-NNN (meta) — sequence numbers per finding within the report — so they don't collide with the SARIF catalog.
Pick the output format based on the mode confirmed in Prerequisites.
Use examples/review-report.md as the template — one bullet per finding under ## Security (LWS + Product), one totals line under ## Summary.
Severity ordering: Critical → High → Medium → Low (map SARIF error → High, warning → Medium unless the rule says otherwise). Cite the reference section that produced each finding (e.g., "Product Security § lws-001 document.createProcessingInstruction").
Emit a single SARIF 2.1.0 JSON document — and nothing else. No prose before or after. Do NOT write the JSON to a file; return it inline. Empty results array means no issues found.
Use examples/score-report.sarif.json as the shape reference — same top-level structure ($schema, version, runs[0].tool.driver.rules[], runs[0].results[]), populated with the actual rules that fired and the actual matches.
Rules:
ruleId matches a catalog entry exactly (lws-001…lws-023b, or the lws-tpl-* / lws-meta-* namespaces from Steps 4-5).level is error for catalog rules marked level: error and warning for level: warning. No other values.message.text uses the catalog's message template with placeholders substituted (e.g., replace {eventName} with the actual event name found in code).result per match. If a rule fires three times in a file, emit three results.tool.driver.rules; an empty results array still requires tool.driver.rules to be present (use []).Skip in score mode — score mode is read-only.
For each accepted finding:
scripts/validate-sarif.sh <path> — the script confirms the JSON parses, version is 2.1.0, every ruleId matches the catalog pattern (lws-NNN[a-z]? / lws-tpl-NNN / lws-meta-NNN) and is declared in tool.driver.rules, every level is error or warning, and every result has a physicalLocation.artifactLocation.uri + region.startLine. Fix any failure before returning the SARIF.experience-lwc-generate — for authoring new LWC bundles that are security-compliant from the start.design-systems-slds-validate — SLDS/design-system compliance pass (accessibility overlaps with WCAG 2.2 — run separately).dx-code-analyzer-run — repo-wide static-analysis pass; use it alongside this skill for coverage beyond the LWS catalog.lws-001…lws-023b) was evaluated against the bundle, not a hand-curated subset.© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in skills/experience-lwc-security-validate of forcedotcom/sf-skills.
Open the folder on GitHubat commit e5164d9
Experience Lwc Security Validate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Experience Lwc Security Validate this skillforcedotcom/sf-skills | 1.1k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Web Coderboshi-xixixi/TraeSkill | 275 | 1 repos | ~5.2k | Automated safety check: Pass | MIT | |
| Best Practicestech-leads-club/agent-skills | 7k | — | ~3.2k | Automated safety check: Pass | MIT | |
| Salesforce Component Standardsgithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Locale UI Patternsopenchamber/openchamber | 11k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Django Access Reviewgetsentry/skills | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 |
boshi-xixixi/TraeSkill
Expert 10x engineer with comprehensive knowledge of web development, internet protocols, and web standards.
tech-leads-club/agent-skills
Apply modern web development best practices for security, compatibility, and code quality.
github/awesome-copilot
Quality standards for Salesforce Lightning Web Components (LWC), Aura components, and Visualforce pages.
openchamber/openchamber
A skill your agent uses when creating or modifying OpenChamber UI text, labels, buttons, placeholders, aria labels, empty states, toasts, dialogs, settings copy, navigation labels, or any…
getsentry/skills
Django access control and IDOR security review. An agent skill from getsentry/skills.
instructure/instructure-ui
Look up authoritative Instructure UI (InstUI, @instructure/ui-) documentation — component APIs, props, theme variables, usage examples, and guides — by querying instructure.design's plaintext docs.
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Categories
Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for…. Experience Lwc Security Validate is an agent skill from forcedotcom/sf-skills.xml) — the canonical LWS/Product-Security review for LWCs, NOT a generic code-security pass.
Experience Lwc Security Validate fits situations like: the user asks to review; check an LWC component for LWS compliance issues and recommend fixes; score a components LWS/security compliance; find dangerous DOM APIs.
Run `npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a claude-code`. Or copy the skill folder (skills/experience-lwc-security-validate in forcedotcom/sf-skills) into .claude/skills/experience-lwc-security-validate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a codex`. Or copy the skill folder (skills/experience-lwc-security-validate in forcedotcom/sf-skills) into .agents/skills/experience-lwc-security-validate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/experience-lwc-security-validate, .gemini/skills/experience-lwc-security-validate, .github/skills/experience-lwc-security-validate and .opencode/skills/experience-lwc-security-validate in your project.
Going by SKILL.md and its folder, Experience Lwc Security Validate needs a shell for the scripts in its folder. Our summary lists: A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Experience Lwc Security Validate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Experience Lwc Security Validate: Web Coder (boshi-xixixi/TraeSkill, 275 stars), Best Practices (tech-leads-club/agent-skills, 7k stars), Salesforce Component Standards (github/awesome-copilot, 40k stars) and Locale UI Patterns (openchamber/openchamber, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.