Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs.
$ npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install GoogleChrome/modern-web-guidance-src privacy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/GoogleChrome/modern-web-guidance-src.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-src/privacy .claude/skills/privacy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "privacy" agent skill from https://github.com/GoogleChrome/modern-web-guidance-src/tree/main/skills-src/privacy into .claude/skills/privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/GoogleChrome/modern-web-guidance-src/tree/main/skills-src/privacyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install GoogleChrome/modern-web-guidance-src privacy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/GoogleChrome/modern-web-guidance-src.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills-src/privacy .agents/skills/privacy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "privacy" agent skill from https://github.com/GoogleChrome/modern-web-guidance-src/tree/main/skills-src/privacy into .agents/skills/privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install GoogleChrome/modern-web-guidance-src privacy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/GoogleChrome/modern-web-guidance-src.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills-src/privacy .cursor/skills/privacy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "privacy" agent skill from https://github.com/GoogleChrome/modern-web-guidance-src/tree/main/skills-src/privacy into .cursor/skills/privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/GoogleChrome/modern-web-guidance-src.git --path skills-src/privacy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install GoogleChrome/modern-web-guidance-src privacy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/GoogleChrome/modern-web-guidance-src.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills-src/privacy .gemini/skills/privacy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "privacy" agent skill from https://github.com/GoogleChrome/modern-web-guidance-src/tree/main/skills-src/privacy into .gemini/skills/privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install GoogleChrome/modern-web-guidance-src privacyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/GoogleChrome/modern-web-guidance-src.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills-src/privacy .github/skills/privacy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "privacy" agent skill from https://github.com/GoogleChrome/modern-web-guidance-src/tree/main/skills-src/privacy into .github/skills/privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install GoogleChrome/modern-web-guidance-src privacy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/GoogleChrome/modern-web-guidance-src.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills-src/privacy .opencode/skills/privacy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "privacy" agent skill from https://github.com/GoogleChrome/modern-web-guidance-src/tree/main/skills-src/privacy into .opencode/skills/privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
privacyAction-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs.
Privacy is an agent skill from GoogleChrome/modern-web-guidance-src. Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs. Use this skill when dealing with user data, cookies, tracking, third-party scripts, or browser privacy APIs.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with JavaScript. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c312847. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript, http and html).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Privacy loads about 2.1k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 730 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from GoogleChrome/modern-web-guidance-src at commit c312847, republished under its Apache-2.0 licence (© GoogleChrome). 730 words, ~2,136 tokens.
.claude/skills/privacy/SKILL.md (or your agent's skills folder).Web application architects and developers must treat privacy not as a compliance afterthought, but as a foundational architectural design requirement. Modern web platforms are shifting away from implicit tracking toward explicit, user-consented, browser-mediated identity and permission exchanges.
Reducing the digital footprint to limit breach exposure and foster user trust.
aria-describedby to link inputs to their explanations.Clear-Site-Data HTTP header upon logout to wipe client-side cookie caches and local storage.Send this header on the page after logout confirmation.
Clear-Site-Data: "cache", "cookies", "storage"<div>
<label for="email">Email address*</label>
<input id="email" type="email" name="email" required aria-describedby="whyemail">
<a href="#whyemail">Why do we need this?</a>
<aside id="whyemail">
We need this email to send password resets. We will not use it for marketing unless you opt-in.
</aside>
</div>Limiting leakage introduced by external scripts, embeds, and tracking pixels.
strict-origin-when-cross-origin or no-referrer) to prevent leaking sensitive URL query parameters.Permissions-Policy to lock down powerful APIs (geolocation, camera) globally or for subframes.Content-Security-Policy-Report-Only for continuous automated audits of where third-party scripts are attempting to send data.Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: accelerometer=(), camera=(), fullscreen=*Architecting for a web without unpartitioned third-party cookies.
Partitioned attribute for 1:1 embeds that do not share state across top-level sites.requestStorageAccess()) via direct user interaction (click/keypress).SameSite=None cookies as they are being systematically blocked by modern browser engines.Set-Cookie (HTTP)Set-Cookie: session_id=abc123; SameSite=None; Secure; Path=/; Partitioned; HttpOnlydocument.getElementById('login-btn').addEventListener('click', async () => {
try {
const hasAccess = await document.hasStorageAccess();
if (!hasAccess) {
await document.requestStorageAccess();
}
// Access granted: unpartitioned cookies are now attached to fetch()
} catch (err) {
console.error('Storage access denied', err);
}
});| Mechanism | Scope | Requires Interaction | Use Case |
|---|---|---|---|
| CHIPS | 1:1 Partitioned | No | Embeds (Maps, Widgets) |
| Storage Access API (SAA) | Cross-site | Yes | SSO Portals, Analytics |
| FedCM | Identity Federation | Yes | "Sign In with..." |
Heuristic Rule: Use CHIPS for isolated widgets (un-shared state), and SAA for shared identity state requiring explicit user consent.
Moving from opaque navigational redirects to explicit native UI-mediated federation.
try {
const credential = await navigator.credentials.get({
identity: {
providers: [{
configURL: "https://idp.example/fedcm.json",
clientId: "rp-client-id-123"
}]
}
});
authenticateWithBackend(credential.token);
} catch (error) {
console.error("FedCM login failed", error);
}Shifting from passive device broadcasting to explicit feature inspection.
'createImageBitmap' in window) over User-Agent string parsing.Accept-CH header.Vary header (e.g., Vary: Sec-CH-UA-Platform) if your server caches vary based on UA-CH.navigator.userAgent for non-critical logic.// AVOID: if (navigator.userAgent.includes("Chrome")) ...
if ('createImageBitmap' in window) {
// Use modern API
}Using unforgeable headers to reject unauthorized cross-origin requests server-side.
Sec-Fetch-Site, Sec-Fetch-Mode, and Sec-Fetch-Dest headers before processing state-changing requests.Sec-Fetch-Site) is cross-site and the mode is not navigate.app.use((req, res, next) => {
const site = req.get('Sec-Fetch-Site');
const mode = req.get('Sec-Fetch-Mode');
if (!site) return next(); // Fallback for legacy browsers
if (site === 'same-origin' || site === 'same-site') return next();
// Allow standard outside user navigations (GET link clicks)
if (site === 'cross-site' && mode === 'navigate' && req.method === 'GET') {
return next();
}
res.status(403).json({ error: 'Cross-origin request forbidden' });
});Querying capabilities before hitting users with automatic prompts.
navigator.permissions.query() before requesting access to powerful APIs (geolocation, camera).navigator.permissions.query({ name: 'geolocation' }).then((result) => {
if (result.state === 'granted') {
loadMap();
} else if (result.state === 'prompt') {
showPolitePermissionExplanation(); // trigger requestStorageAccess upon button click
}
});© GoogleChrome, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills-src/privacy of GoogleChrome/modern-web-guidance-src.
Open the folder on GitHubat commit c312847
Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Privacy this skillGoogleChrome/modern-web-guidance-src | 1.1k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Tailwindcss Developmentanonaddy/anonaddy | 4.9k | 10 repos | ~865 | Automated safety check: Pass | MIT | |
| Figma use_figma Plugin API Ruleswarpdotdev/warp | 65k | 4 repos | ~4.4k | Automated safety check: Pass | AGPL-3.0 | |
| GSAP Core Animationgreensock/gsap-skills | 16k | 4 repos | ~3.7k | Automated safety check: Pass | MIT | |
| JavaScript Concept Fact Checkerleonardomso/33-js-concepts | 67k | 1 repos | ~5k | Automated safety check: Pass | MIT |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
anonaddy/anonaddy
Always invoke when the user's message includes 'tailwind' in any form.
warpdotdev/warp
Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.
greensock/gsap-skills
Covers the GSAP core API for tweens, easing, staggers, defaults and matchMedia, and when to choose GSAP over CSS animations or other JavaScript animation libraries.
leonardomso/33-js-concepts
Verifies the technical accuracy of JavaScript concept pages by checking code examples, MDN and ECMAScript claims and external links through a five-phase method.
oso95/scroll-world
Builds a scroll-driven landing page where a pre-rendered camera flies through connected AI-generated scenes, using Higgsfield for stills and video clips.
GoogleChrome/modern-web-guidance-src
Downloads and analyzes the latest three distinct nightly evaluation runs (Claude Code, Codex CLI, and Jetski CLI) from the GCS remote dashboard to identify and flag unhealthy or low-performing tasks…
GoogleChrome/modern-web-guidance-src
Build and publish Chrome Extensions using Manifest V3 best practices.
GoogleChrome/modern-web-guidance-src
Run a document coherence, link integrity, and git repository status audit across repository markdown files using a dedicated subagent.
GoogleChrome/modern-web-guidance-src
Coding style, architectural conventions, and PR review standards for the modern-web-guidance-src (guidance) repository.
GoogleChrome/modern-web-guidance-src
Workflow for refactoring discipline-level guides (e.g., JavaScript, CSS) to remove "Common Knowledge" by generating and comparing against model-specific "Knowledge Mirrors".
GoogleChrome/modern-web-guidance-src
Best practices for creating expectations and grader files to evaluate guidance quality.
Works with
Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs. Privacy is an agent skill from GoogleChrome/modern-web-guidance-src. Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs.
Privacy fits situations like: dealing with user data; third-party scripts; browser privacy APIs.
Run `npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a claude-code`. Or copy the skill folder (skills-src/privacy in GoogleChrome/modern-web-guidance-src) into .claude/skills/privacy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a codex`. Or copy the skill folder (skills-src/privacy in GoogleChrome/modern-web-guidance-src) into .agents/skills/privacy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy, .gemini/skills/privacy, .github/skills/privacy and .opencode/skills/privacy in your project.
SKILL.md names no scripts, command-line tools or credentials: Privacy is instructions for the agent only. Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Privacy is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Privacy: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars) and GSAP Core Animation (greensock/gsap-skills, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
GoogleChrome (a GitHub organization) maintains it in GoogleChrome/modern-web-guidance-src, which has 1,134 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 7, 2026.
Source: GoogleChrome/modern-web-guidance-src on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.