Agent skill

Experience Lwc Security Validate

by forcedotcom in forcedotcom/sf-skills

Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for…

Apache-2.0Auto-check passedFrontend & Design

Install Experience Lwc Security Validate

skills CLI
$ npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills experience-lwc-security-validate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/experience-lwc-security-validate .claude/skills/experience-lwc-security-validate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
experience-lwc-security-validate
GitHub stars
1.1k
Token cost
~2.6k tokens
SKILL.md length
1,238 words
Files
7 (incl. scripts, references)
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for…

  • Works in 8 steps: Scope the review → Read the knowledge bases → Walk the rule catalog → …
  • The user asks to review
  • SKILL.md covers When to Use, Prerequisites, Knowledge Bases and Workflow, plus 2 more sections
  • Runs Shell scripts from its folder

What it does

Experience Lwc Security Validate is an agent skill from forcedotcom/sf-skills. Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for LWCs, NOT a generic code-security pass. It produces either a severity-ranked finding list with code-level remediations or a SARIF 2.1.0 JSON score report keyed by the lws-001…lws-023b rule catalog. TRIGGER when the user asks to review, audit, or check an LWC component for LWS compliance issues and recommend fixes, score…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `examples/review-report.md`, `examples/score-report.sarif.json` and `references/lws-security-expert.md`).

It sits in Frontend & Design, covering Security review, Accessibility and Web application vulnerabilities. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • The user asks to review
  • Check an LWC component for LWS compliance issues and recommend fixes
  • Score a components LWS/security compliance
  • Find dangerous DOM APIs

Example prompts

  • “script”
  • “/experience-lwc-security-validate”

Requirements

  • A Bash shell

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Scope the review
  2. Read the knowledge bases
  3. Walk the rule catalog
  4. HTML template inspection (additional)
  5. Meta and configuration inspection (additional)
  6. Produce the report
  7. Apply fixes (review mode only)
  8. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Experience Lwc Security Validate loads about 2.6k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 253 tokens; SKILL.md has 1,238 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~253
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 1,238 words, ~2,646 tokens.

Download SKILL.mdSave it as .claude/skills/experience-lwc-security-validate/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
experience-lwc-security-validate
description
Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (`.js`, `.ts`, `.html`, `.css`, `.js-meta.xml`) — the canonical LWS/Product-Security review for LWCs, NOT a generic code-security pass. It produces either a severity-ranked finding list with code-level remediations or a SARIF 2.1.0 JSON score report keyed by the `lws-001`…`lws-023b` rule catalog. TRIGGER when the user asks to review, audit, or check an LWC component for LWS compliance issues and recommend fixes, score a component's LWS/security compliance, find dangerous DOM APIs or blocked sinks (`eval`, `Function`, `document.write`, `innerHTML`, `document.createElement('script')`, global-scope assignment to `window`/`globalThis`, unsafe URL schemes), or emit a SARIF security report. DO NOT TRIGGER for generic non-LWC security review, for building a new LWC (use experience-lwc-generate), accessibility (WCAG 2.2), RTL/i18n, or Apex/Aura/server-side review.
metadata.version
1.0
metadata.domains
Experience
metadata.relatedSkills
design-systems-slds-validate, dx-code-analyzer-run, experience-lwc-generate
<!-- adk-managed-skill -->

Reviewing LWS Security

Run a structured Lightning Web Security (LWS) and Product Security compliance pass over a Lightning Web Component. Two output modes:

  • Review mode (default) — severity-ranked findings + applied code fixes.
  • Score mode — SARIF 2.1.0 JSON report keyed by the LWS rule catalog (lws-001…lws-023b) for downstream gating, eval scoring, or CI ingest.

Both modes use the same detection rules from the references; only the output format differs.

When to Use

  • The user asks for a "security review", "LWS check", "pre-ship security audit", or "compliance pass" on a specific LWC → review mode.
  • The user asks to "score" a component's security or wants machine-readable findings to feed a gate or eval → score mode.
  • Preparing a component for release and needing a unified security report.
  • After implementing a fix, to verify no regression in security posture.

Do NOT use this skill for:

  • Building new components (use experience-lwc-generate).
  • Accessibility (apply WCAG 2.2 separately) or RTL review — out of scope.
  • Gating a fix behind a feature flag (apply feature-flag gating after fixes land).
  • Non-LWC security review (Apex, Aura, server-side) — out of scope.

Prerequisites

  • Component path (LWC bundle under modules/…).
  • Access to the component's JS/TS, HTML templates, CSS, and .js-meta.xml.
  • Output mode: review (default — find, fix, report) or score (find, emit SARIF JSON, do NOT modify code). Confirm with the user before starting if it isn't obvious from the request.

Knowledge Bases

Each reference is the source of truth. Do not summarize from memory — open the reference, apply the guidelines, and cite the specific section you used in the report.

  • Lightning Web Security (LWS) catalog: LWS Security Expert — blocked APIs and allowed alternatives.
  • Rule catalog (lws-001…lws-023b): Product Security Framework — for every rule the catalog gives the detection patterns and the canonical SARIF ruleId / level / message template. Score mode emits one SARIF result per match using these exact values.

Workflow

Step 1 — Scope the review

Collect the component path and identify the files to review. Include every file in the component bundle: .html, .js/.ts, .css, .js-meta.xml, and any child components owned by the same team that are invoked from the target.

Note any existing feature-flag gates — findings that require code changes must respect them.

Step 2 — Read the knowledge bases

Read LWS Security Expert and Product Security Framework top-to-bottom before judging. The LWS reference enumerates blocked DOM APIs and their allowed alternatives; the Product Security framework gives the severity taxonomy, the 23-rule SARIF catalog, and remediation patterns.

Step 3 — Walk the rule catalog

Run every rule in Product Security Framework (lws-001 through lws-023b) against the component bundle. For each rule:

  1. Apply the "How to Find the Issue" patterns verbatim. Do NOT shortcut — each rule lists obfuscation patterns (bracket notation, unicode escapes, Reflect.*, string concatenation) you must consider.
  2. For every match record: ruleId, level (error / warning from the catalog), file, startLine, startColumn (column 1 if unknown), message (use the catalog's message template, substituting any {placeholder} from the actual code).
  3. If a rule has the prerequisite "Only analyze files that import from 'lwc'" (lws-008), gate it via scripts/check-lwc-import.sh <file> — the script prints lwc-import=yes when a from 'lwc' import is present and lwc-import=no otherwise. Skip the rule for that file when the answer is no.

This catalog is the canonical detection list; the JS/TS, HTML, and .js-meta.xml bullets that follow are additional checks beyond the SARIF rules.

Step 4 — HTML template inspection (additional)

Walk each template for:

  • lwc:inner-html usage — verify the source is trusted.
  • Unescaped expressions feeding attributes LWS treats as sensitive (href, src, srcdoc, inline event handlers).
  • Direct style="…" with bound expressions — candidates for CSS class swaps.
  • Embedded <iframe> or <object> without sandboxing (Step 3 catches the srcdoc and protocol cases via lws-023a/lws-023b; this step catches missing sandbox attributes).
Step 5 — Meta and configuration inspection (additional)

Inspect .js-meta.xml for:

  • Over-broad API access (lightning__FlowScreen, lightning__AppPage, etc.) when the component doesn't need it.
  • Public properties exposed that contain sensitive data.
  • Missing capabilities restrictions for the target surface.

Inspect Apex bindings for:

  • @wire to Apex methods without @AuraEnabled(cacheable=true) where caching is safe.
  • Direct imperative calls that bypass permission checks.

Findings from Steps 4-5 use rule IDs lws-tpl-001…lws-tpl-NNN (HTML) and lws-meta-001…lws-meta-NNN (meta) — sequence numbers per finding within the report — so they don't collide with the SARIF catalog.

Step 6 — Produce the report

Pick the output format based on the mode confirmed in Prerequisites.

Review mode (default)

Use examples/review-report.md as the template — one bullet per finding under ## Security (LWS + Product), one totals line under ## Summary.

Severity ordering: Critical → High → Medium → Low (map SARIF error → High, warning → Medium unless the rule says otherwise). Cite the reference section that produced each finding (e.g., "Product Security § lws-001 document.createProcessingInstruction").

Show full SKILL.md (474 more words)Show less
Score mode

Emit a single SARIF 2.1.0 JSON document — and nothing else. No prose before or after. Do NOT write the JSON to a file; return it inline. Empty results array means no issues found.

Use examples/score-report.sarif.json as the shape reference — same top-level structure ($schema, version, runs[0].tool.driver.rules[], runs[0].results[]), populated with the actual rules that fired and the actual matches.

Rules:

  • ruleId matches a catalog entry exactly (lws-001…lws-023b, or the lws-tpl-* / lws-meta-* namespaces from Steps 4-5).
  • level is error for catalog rules marked level: error and warning for level: warning. No other values.
  • message.text uses the catalog's message template with placeholders substituted (e.g., replace {eventName} with the actual event name found in code).
  • One result per match. If a rule fires three times in a file, emit three results.
  • Include only rules that fired in tool.driver.rules; an empty results array still requires tool.driver.rules to be present (use []).
Step 7 — Apply fixes (review mode only)

Skip in score mode — score mode is read-only.

For each accepted finding:

  1. Edit the component files (HTML, JS/TS, CSS, meta.xml) to apply the fix.
  2. Preserve existing correct behavior and existing feature-flag gates. If a gate is already configured for the same concern, leave it untouched. New feature-flag gates for phased rollout are out of scope for this skill — apply them separately.
  3. Do NOT silently delete old code — preserve the original path where a gate is required.
  4. Do NOT weaken the security posture to make tests pass; fix the test if it depends on the insecure pattern.
Step 8 — Verify
  • Review mode: Re-run Step 3's catalog walk against the updated files; every fixed finding must no longer appear. Run Jest tests and any component-level security tests. If fixes touched Apex access patterns, confirm permissions with the server-side reviewer.
  • Score mode: Before returning, write the emitted SARIF to a temporary file and run scripts/validate-sarif.sh <path> — the script confirms the JSON parses, version is 2.1.0, every ruleId matches the catalog pattern (lws-NNN[a-z]? / lws-tpl-NNN / lws-meta-NNN) and is declared in tool.driver.rules, every level is error or warning, and every result has a physicalLocation.artifactLocation.uri + region.startLine. Fix any failure before returning the SARIF.

Cross-References

  • Related skills:
    • experience-lwc-generate — for authoring new LWC bundles that are security-compliant from the start.
    • design-systems-slds-validate — SLDS/design-system compliance pass (accessibility overlaps with WCAG 2.2 — run separately).
    • dx-code-analyzer-run — repo-wide static-analysis pass; use it alongside this skill for coverage beyond the LWS catalog.

Verification

  • Every catalog rule (lws-001…lws-023b) was evaluated against the bundle, not a hand-curated subset.
  • Every finding has either been applied (review mode) or surfaced in the SARIF result (score mode), or carries an explicit deferred note with a reason.
  • Each finding cites a specific catalog rule ID — no freeform "looks suspicious" entries.
  • No new XSS sinks, unsafe URL flows, or blocked DOM APIs introduced by the fixes.
  • Score-mode output is valid SARIF 2.1.0 JSON, returned inline, with no surrounding prose.

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/experience-lwc-security-validate of forcedotcom/sf-skills.

  • SKILL.md
  • examples/review-report.md
  • examples/score-report.sarif.json
  • references/lws-security-expert.md
  • references/security-analysis.md
  • scripts/check-lwc-import.sh
  • scripts/validate-sarif.sh

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Experience Lwc Security Validate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Experience Lwc Security Validate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Experience Lwc Security Validate this skillforcedotcom/sf-skills1.1k—~2.6kAutomated safety check: PassApache-2.0
Web Coderboshi-xixixi/TraeSkill2751 repos~5.2kAutomated safety check: PassMIT
Best Practicestech-leads-club/agent-skills7k—~3.2kAutomated safety check: PassMIT
Salesforce Component Standardsgithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Locale UI Patternsopenchamber/openchamber11k—~1.5kAutomated safety check: PassMIT
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Web Coder

    boshi-xixixi/TraeSkill

    Expert 10x engineer with comprehensive knowledge of web development, internet protocols, and web standards.

    275 GitHub starsUsed in 1 repo~5.2k tokens
    Frontend & DesignAuto-check passed
  • Best Practices

    tech-leads-club/agent-skills

    Apply modern web development best practices for security, compatibility, and code quality.

    7k GitHub stars~3.2k tokensUpdated 18 days ago
    Frontend & DesignAuto-check passed
  • Salesforce Component Standards

    github/awesome-copilot

    Official

    Quality standards for Salesforce Lightning Web Components (LWC), Aura components, and Visualforce pages.

    40k GitHub starsUsed in 1 repo~2.4k tokens
    Frontend & DesignAuto-check passed
  • Locale UI Patterns

    openchamber/openchamber

    A skill your agent uses when creating or modifying OpenChamber UI text, labels, buttons, placeholders, aria labels, empty states, toasts, dialogs, settings copy, navigation labels, or any…

    11k GitHub stars~1.5k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Instui Docs

    instructure/instructure-ui

    Look up authoritative Instructure UI (InstUI, @instructure/ui-) documentation — component APIs, props, theme variables, usage examples, and guides — by querying instructure.design's plaintext docs.

    482 GitHub stars~498 tokensUpdated yesterday
    Frontend & DesignAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated yesterday
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Questions about Experience Lwc Security Validate

What does Experience Lwc Security Validate do?

Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for…. Experience Lwc Security Validate is an agent skill from forcedotcom/sf-skills.xml) — the canonical LWS/Product-Security review for LWCs, NOT a generic code-security pass.

When should I use Experience Lwc Security Validate?

Experience Lwc Security Validate fits situations like: the user asks to review; check an LWC component for LWS compliance issues and recommend fixes; score a components LWS/security compliance; find dangerous DOM APIs.

How do I install Experience Lwc Security Validate in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a claude-code`. Or copy the skill folder (skills/experience-lwc-security-validate in forcedotcom/sf-skills) into .claude/skills/experience-lwc-security-validate in your project. Claude Code loads it when a task matches its description.

How do I install Experience Lwc Security Validate in Codex?

Run `npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a codex`. Or copy the skill folder (skills/experience-lwc-security-validate in forcedotcom/sf-skills) into .agents/skills/experience-lwc-security-validate in your project. Codex loads it when a task matches its description.

Can I use Experience Lwc Security Validate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill experience-lwc-security-validate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/experience-lwc-security-validate, .gemini/skills/experience-lwc-security-validate, .github/skills/experience-lwc-security-validate and .opencode/skills/experience-lwc-security-validate in your project.

What does Experience Lwc Security Validate need to run?

Going by SKILL.md and its folder, Experience Lwc Security Validate needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Experience Lwc Security Validate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Experience Lwc Security Validate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Experience Lwc Security Validate use?

Experience Lwc Security Validate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Experience Lwc Security Validate use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.

What are the alternatives to Experience Lwc Security Validate?

Skills that share tags, products or a category with Experience Lwc Security Validate: Web Coder (boshi-xixixi/TraeSkill, 275 stars), Best Practices (tech-leads-club/agent-skills, 7k stars), Salesforce Component Standards (github/awesome-copilot, 40k stars) and Locale UI Patterns (openchamber/openchamber, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Experience Lwc Security Validate?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.