Harden Angular apps against XSS, CSP violations, and unauthorized access.

MITAuto-check passedSecurity

Install Angular Security

skills CLI
$ npx skills add HoangNguyen0403/agent-skills-standard --skill angular-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HoangNguyen0403/agent-skills-standard angular-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HoangNguyen0403/agent-skills-standard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/angular/angular-security .claude/skills/angular-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
angular-security
GitHub stars
572
Token cost
~608 tokens
SKILL.md length
243 words
Files
3 (incl. references)
Skills in repo
211
Repo updated
First seen
Licence
MIT

At a glance

Harden Angular apps against XSS, CSP violations, and unauthorized access.

  • Implementing XSS protection
  • SKILL.md covers Priority: P0 (CRITICAL), Principles, Guidelines and Anti-Patterns, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Content Security Policy

What it does

Angular Security is an agent skill from HoangNguyen0403/agent-skills-standard. Harden Angular apps against XSS, CSP violations, and unauthorized access. Use when implementing XSS protection, Content Security Policy, or auth guards in Angular.

Its SKILL.md is about 610 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `evals/evals.json` and `references/security-best-practices.md`).

It sits in Security, covering Web application vulnerabilities. It works with Angular. The repository describes itself as: A collection of Agent Skills Standard and Best Practice for Programming Languages, Frameworks that help our AI Agent follow best practies on frameworks and programming laguages. The licence is MIT.

When your agent uses it

  • Implementing XSS protection
  • Content Security Policy
  • Auth guards in Angular

Example prompts

  • “/angular-security”

What it can do on your machine

Read from SKILL.md and the folder at commit b529c2d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Angular Security loads about 608 tokens when it runs, and up to ~767 if it reads all its reference files. Until then it costs about 45 tokens; SKILL.md has 243 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~608
With references · SKILL.md plus every file in references/, read only if the agent opens them
~767

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HoangNguyen0403/agent-skills-standard at commit b529c2d, republished under its MIT licence (© HoangNguyen0403). 243 words, ~608 tokens.

Download SKILL.mdSave it as .claude/skills/angular-security/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
angular-security
description
Harden Angular apps against XSS, CSP violations, and unauthorized access. Use when implementing XSS protection, Content Security Policy, or auth guards in Angular.

Security

Priority: P0 (CRITICAL)

Principles

  • XSS Prevention: Angular sanitizes interpolated values by default — {{ userInput }} safe. NOT use innerHTML unless absolutely necessary (e.g., trusted static CMS content). For user-generated content, display as text with {{ content }} — never as HTML.
  • Trusted HTML APIs: Mark HTML as trusted only for content you control (e.g., vetted CMS headers). Never mark user-provided data as trusted. Prefer DomSanitizer.sanitize(SecurityContext.HTML, content) and review every trust-marking call as a potential XSS vector.
  • Route Guards: Protect all sensitive routes with functional CanActivateFn (e.g., inject(Router).createUrlTree(['/login'])). Apply with canActivate: [authGuard].

Guidelines

  • CSP: Configure CSP headers on server (not in Angular source). Use nonce-based CSP with script-src 'nonce-{nonce}' and avoid unsafe-inline/unsafe-eval.
  • HTTP: Use Interceptors to attach secure tokens. Use HttpOnly cookies managed by server — not localStorage or sessionStorage because they accessible via XSS.
  • Secrets: Never store API keys or secrets in Angular source code or bundle.

Anti-Patterns

  • No trust-marking on user input: Trust Angular's sanitization; reserve trusted HTML APIs for verified static content only.
  • No localStorage for tokens: Use HttpOnly cookies via interceptors for auth tokens.
  • No secrets in source: Never embed API keys or secrets in Angular bundle code.

References

CSP and secret checklist

  • Use a server-generated, per-response nonce in script-src 'nonce-{nonce}'; do not use a static nonce.
  • Keep controlled provenance explicit: trust-mark only controlled and verified or vetted static CMS content.
  • Do not put API keys or other secrets in the compiled bundle.

Canonical response anchors

  • Additional task-grounded exact anchors: {{ content }}

© HoangNguyen0403, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/angular/angular-security of HoangNguyen0403/agent-skills-standard.

  • SKILL.md
  • evals/evals.json
  • references/security-best-practices.md

Open the folder on GitHubat commit b529c2d

Compare with similar skills

Angular Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Angular Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Angular Security this skillHoangNguyen0403/agent-skills-standard572—~608Automated safety check: PassMIT
Frontend Mobile Security Xss Scanaiskillstore/marketplace4337 repos~2.4kAutomated safety check: PassNone
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Fix Strix Security Findingsusestrix/strix68k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Frontend Mobile Security Xss Scan

    aiskillstore/marketplace

    You are a frontend security specialist focusing on Cross-Site Scripting (XSS) vulnerability detection and prevention.

    433 GitHub starsUsed in 7 repos~2.4k tokens
    SecurityAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    68k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed

More from HoangNguyen0403/agent-skills-standard

All 211 skills in this repo
  • Subagent-Driven Development

    HoangNguyen0403/agent-skills-standard

    Runs a multi-task implementation plan by sending each task to a fresh implementer subagent, reviewing it independently, then reviewing the whole branch.

    572 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • draw.io Architecture Diagramming

    HoangNguyen0403/agent-skills-standard

    Draws architecture diagrams as editable draw.io files from a JSON spec, with a fixed house style, one C4 level per diagram and evidence-tagged shapes.

    572 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Android Navigation 3 Guide

    HoangNguyen0403/agent-skills-standard

    Implements and migrates to Jetpack Navigation 3 in Compose: NavDisplay, typed route objects, a state-list back stack, deep links, multiple back stacks and dialog scenes.

    572 GitHub stars~687 tokensUpdated today
    Auto-check passed
  • Angular HttpClient Standards

    HoangNguyen0403/agent-skills-standard

    Sets rules for Angular HTTP code: functional interceptors, typed requests, services that own every call, and httpResource for reactive data loading in Angular 17+.

    572 GitHub stars~652 tokensUpdated today
    Auto-check passed
  • Angular Tooling

    HoangNguyen0403/agent-skills-standard

    Angular CLI usage, code generation, build configuration, and bundle optimization.

    572 GitHub stars~743 tokensUpdated today
    Auto-check passed
  • Common Code Review

    HoangNguyen0403/agent-skills-standard

    Conduct high-quality, persona-driven code reviews. An agent skill from HoangNguyen0403/agent-skills-standard.

    572 GitHub stars~772 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Angular Security

What does Angular Security do?

Harden Angular apps against XSS, CSP violations, and unauthorized access. Angular Security is an agent skill from HoangNguyen0403/agent-skills-standard. Harden Angular apps against XSS, CSP violations, and unauthorized access.

When should I use Angular Security?

Angular Security fits situations like: implementing XSS protection; content Security Policy; auth guards in Angular.

How do I install Angular Security in Claude Code?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill angular-security -a claude-code`. Or copy the skill folder (skills/angular/angular-security in HoangNguyen0403/agent-skills-standard) into .claude/skills/angular-security in your project. Claude Code loads it when a task matches its description.

How do I install Angular Security in Codex?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill angular-security -a codex`. Or copy the skill folder (skills/angular/angular-security in HoangNguyen0403/agent-skills-standard) into .agents/skills/angular-security in your project. Codex loads it when a task matches its description.

Can I use Angular Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HoangNguyen0403/agent-skills-standard --skill angular-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/angular-security, .gemini/skills/angular-security, .github/skills/angular-security and .opencode/skills/angular-security in your project.

What does Angular Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Angular Security is instructions for the agent only.

Does Angular Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Angular Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Angular Security use?

Angular Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Angular Security use?

About 608 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 159 tokens, read only when the agent opens those files.

What are the alternatives to Angular Security?

Skills that share tags, products or a category with Angular Security: Frontend Mobile Security Xss Scan (aiskillstore/marketplace, 433 stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars) and Code Audit (3stoneBrother/code-audit, 892 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Angular Security?

HoangNguyen0403 (a GitHub user) maintains it in HoangNguyen0403/agent-skills-standard, which has 572 GitHub stars. The repository holds 211 skills in this directory. The repository was last updated on October 9, 2026.

Source: HoangNguyen0403/agent-skills-standard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.