Agent skill

Stackblitz Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Threat-model a WebContainer or StackBlitz embed across host, runtime, user-code, filesystem, dependency, network, preview, secret, and persistence boundaries.

MITAuto-check: notesSecurity

Install Stackblitz Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill stackblitz-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace stackblitz-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/stackblitz-security-basics .claude/skills/stackblitz-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
stackblitz-security-basics
GitHub stars
2.8k
Token cost
~1.3k tokens
SKILL.md length
537 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Threat-model a WebContainer or StackBlitz embed across host, runtime, user-code, filesystem, dependency, network, preview, secret, and persistence boundaries.

  • Works in 6 steps: Map assets, actors, entrypoints, trust… → Classify code, files, dependencies,… → Identify abuse cases for path traversal,… → …
  • Preparing to execute untrusted code
  • SKILL.md covers Overview, Prerequisites, Tool Discipline and Current Contract, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Stackblitz Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Threat-model a WebContainer or StackBlitz embed across host, runtime, user-code, filesystem, dependency, network, preview, secret, and persistence boundaries. Use when preparing to execute untrusted code, enable private packages, or ship an interactive browser IDE. Trigger with "StackBlitz security review", "secure WebContainers", or "WebContainer threat model".

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Threat modeling and Security review. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Preparing to execute untrusted code
  • Enable private packages
  • Ship an interactive browser IDE
  • With StackBlitz security review

Example prompts

  • “StackBlitz security review”
  • “secure WebContainers”
  • “WebContainer threat model”
  • “/stackblitz-security-basics”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Glob, Grep, WebFetch, Write, Edit

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Map assets, actors, entrypoints, trust boundaries, data flows, and privileged operations.
  2. Classify code, files, dependencies, terminal input, previews, exports, and auth material by trust level.
  3. Identify abuse cases for path traversal, secret exposure, dependency compromise, runaway processes, network exfiltration, preview-to-host…
  4. Map existing preventive, detective, and recovery controls to each abuse case.
  5. Implement only the highest-value bounded control with tests for expected, hostile, and rollback paths.
  6. Record residual risk, production approval, monitoring, incident response, and the exact deployment/header verification.

What it can do on your machine

Read from SKILL.md and the folder at commit 23ea8d4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • WebFetch
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • webcontainers.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Stackblitz Security Basics loads about 1.3k tokens when it runs, and up to ~1.6k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 537 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:38
    - Never mount host secrets or ambient `.env` files into user-controlled projects; code running there may read them.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 23ea8d4, republished under its MIT licence (© jeremylongshore). 537 words, ~1,283 tokens.

Download SKILL.mdSave it as .claude/skills/stackblitz-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
stackblitz-security-basics
description
Threat-model a WebContainer or StackBlitz embed across host, runtime, user-code, filesystem, dependency, network, preview, secret, and persistence boundaries. Use when preparing to execute untrusted code, enable private packages, or ship an interactive browser IDE. Trigger with "StackBlitz security review", "secure WebContainers", or "WebContainer threat model".
allowed-tools
Read, Glob, Grep, WebFetch, Write, Edit
compatibility
Designed for Claude Code
argument-hint
[project-path] [trust-boundary]
version
1.7.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
saas, stackblitz, security, threat-modeling
model
inherit
effort
high

WebContainer Security Review

Overview

This skill produces a repo-grounded threat model and bounded hardening plan. Browser containment reduces host risk, but it does not make user code trustworthy, prevent all network activity, protect secrets mounted into the runtime, or replace host-page CSP and data-governance controls.

Prerequisites

  • A named application, data classification, and intended code/dependency sources
  • Identified owners for the host page, runtime lifecycle, auth, preview, persistence, and deployment headers
  • Permission to inspect security-sensitive configuration without reading secret values

Tool Discipline

Use Read, Glob, and Grep to trace input, filesystem, process, dependency, network, preview, auth, CSP, and persistence paths. Use WebFetch only for current official StackBlitz or WebContainers documentation. Use Write for an approved threat model and Edit only for narrow reviewed controls.

Current Contract

  • Treat mounted files, spawned commands, installed packages, terminal input, preview messages, and exported artifacts as untrusted flows.
  • Never mount host secrets or ambient .env files into user-controlled projects; code running there may read them.
  • Validate virtual paths component by component and reject traversal, absolute paths, ambiguous separators, duplicates, and dangerous overwrite targets.
  • Pin dependencies and preserve install provenance; browser execution does not remove package supply-chain risk.
  • Derive CSP and frame/connect allowances from observed official runtime behavior and the chosen embed mode; do not copy a universal permissive header.
  • Match cross-origin isolation headers and iframe requirements without weakening unrelated host protections.
  • Define retention and review for any saved or exported user project; the runtime filesystem alone is ephemeral.

Authentication

Keep commercial API keys in existing runtime secret bindings and configure them before boot. Organization auth for private packages is a separate user-authorized flow. Do not log auth parameters, tokens, cookies, private registry settings, or package contents.

Show full SKILL.md (258 more words)Show less

Workflow

  1. Map assets, actors, entrypoints, trust boundaries, data flows, and privileged operations.
  2. Classify code, files, dependencies, terminal input, previews, exports, and auth material by trust level.
  3. Identify abuse cases for path traversal, secret exposure, dependency compromise, runaway processes, network exfiltration, preview-to-host messaging, and persistence.
  4. Map existing preventive, detective, and recovery controls to each abuse case.
  5. Implement only the highest-value bounded control with tests for expected, hostile, and rollback paths.
  6. Record residual risk, production approval, monitoring, incident response, and the exact deployment/header verification.

Approval Boundaries

Require explicit approval before enabling arbitrary code, private packages, network-capable dependencies, host-preview messaging, project persistence/export, telemetry, or production CSP/header changes. Security review and commercial licensing are release gates, not inferred setup details.

Output

Return the trust-boundary diagram or table, abuse cases, current controls, gaps by severity, changes made or proposed, verification, data handling, release decision, rollback, and residual risk owner.

Error Handling

ConditionResponse
A secret is mounted into the runtimeStop, remove the flow, rotate if exposure occurred, and use a mediated service boundary.
User paths are concatenated directlyAdd component-safe normalization and hostile-path tests before writes.
CSP needs broad wildcardsInventory actual origins and redesign the integration rather than disabling protection.
Preview messages are trusted blindlyValidate origin, schema, direction, and allowed actions at the host boundary.

Examples

Before launching an AI coding playground, map prompts-to-files, package installation, process/network behavior, preview messaging, exports, and auth; then block secret mounting and add tested path and message validation.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/stackblitz-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit 23ea8d4

Compare with similar skills

Stackblitz Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Stackblitz Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Stackblitz Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: NotesMIT
Commit Security Scancodexstar69/bug-hunter519—~629Automated safety check: PassMIT
Auditing Code For Vulnerabilitiestrilwu/secskills156—~3.2kAutomated safety check: PassMIT
Threat Mitigation Mappingwshobson/agents40k8 repos~742Automated safety check: PassMIT
Audit Browser Security Boundariesnordstjernen-web/northstar-browser116—~920Automated safety check: PassGPL-3.0
Security Auditblueberrycongee/termcanvas406—~966Automated safety check: NotesMIT

Similar skills

  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    519 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    156 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

    40k GitHub starsUsed in 8 repos~742 tokens
    SecurityAuto-check passed
  • Audit Browser Security Boundaries

    nordstjernen-web/northstar-browser

    Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

    116 GitHub stars~920 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Security Audit

    blueberrycongee/termcanvas

    Security audit skill. An agent skill from blueberrycongee/termcanvas.

    406 GitHub stars~966 tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Security Review

    codexstar69/bug-hunter

    Run a focused STRIDE-based security review using Bug Hunter-native artifacts.

    519 GitHub stars~567 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Analyzing Text With NLP

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to perform natural language processing and text analysis using the nlp-text-analyzer plugin.

    2.8k GitHub starsUsed in 1 repo~819 tokens
    Auto-check passed
  • Building Neural Networks

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill allows AI assistant to construct and configure neural network architectures using the neural-network-builder plugin.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Detecting Data Anomalies

    jeremylongshore/tons-of-skills-marketplace

    Process identify anomalies and outliers in datasets using machine learning algorithms.

    2.8k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Explaining Machine Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill enables AI assistant to provide interpretability and explainability for machine learning models.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Optimizing Prompts

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill optimizes prompts for large language models (llms) to reduce token usage, lower costs, and improve performance.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed

Categories

Questions about Stackblitz Security Basics

What does Stackblitz Security Basics do?

Threat-model a WebContainer or StackBlitz embed across host, runtime, user-code, filesystem, dependency, network, preview, secret, and persistence boundaries. Stackblitz Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Threat-model a WebContainer or StackBlitz embed across host, runtime, user-code, filesystem, dependency, network, preview, secret, and persistence boundaries.

When should I use Stackblitz Security Basics?

Stackblitz Security Basics fits situations like: preparing to execute untrusted code; enable private packages; ship an interactive browser IDE; with StackBlitz security review.

How do I install Stackblitz Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill stackblitz-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/stackblitz-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/stackblitz-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Stackblitz Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill stackblitz-security-basics -a codex`. Or copy the skill folder (skills/.curated/stackblitz-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/stackblitz-security-basics in your project. Codex loads it when a task matches its description.

Can I use Stackblitz Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill stackblitz-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stackblitz-security-basics, .gemini/skills/stackblitz-security-basics, .github/skills/stackblitz-security-basics and .opencode/skills/stackblitz-security-basics in your project.

What does Stackblitz Security Basics need to run?

SKILL.md names no scripts, command-line tools or credentials: Stackblitz Security Basics is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Glob, Grep, WebFetch, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Stackblitz Security Basics access the network?

SKILL.md names 1 domain. As links in the text: webcontainers.io. This is read from the text; nothing was executed.

Is Stackblitz Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Stackblitz Security Basics use?

Stackblitz Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Stackblitz Security Basics use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 300 tokens, read only when the agent opens those files.

What are the alternatives to Stackblitz Security Basics?

Skills that share tags, products or a category with Stackblitz Security Basics: Commit Security Scan (codexstar69/bug-hunter, 519 stars), Auditing Code For Vulnerabilities (trilwu/secskills, 156 stars), Threat Mitigation Mapping (wshobson/agents, 40k stars) and Audit Browser Security Boundaries (nordstjernen-web/northstar-browser, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Stackblitz Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,821 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 8, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.