Agent skill

Frontend Security Coder

by aiskillstore in aiskillstore/marketplace

Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns.

No licenceAuto-check passedSecurity

Install Frontend Security Coder

skills CLI
$ npx skills add aiskillstore/marketplace --skill frontend-security-coder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace frontend-security-coder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sickn33/frontend-security-coder .claude/skills/frontend-security-coder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
frontend-security-coder
GitHub stars
430
Used in
6 other repos
Token cost
~3k tokens
SKILL.md length
1,270 words
Files
2
Skills in repo
1,085
Repo updated
First seen
Licence
None found

At a glance

Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns.

  • Works in 9 steps: Assess client-side security requirements… → Implement secure DOM manipulation using… → Configure Content Security Policy with… → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers Use this skill when, Do not use this skill when, Instructions and Purpose, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Frontend Security Coder is an agent skill from aiskillstore/marketplace. Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `skill-report.json`).

It sits in Security, covering Web application vulnerabilities. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

When your agent uses it

  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/frontend-security-coder”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Assess client-side security requirements including threat model and user interaction patterns
  2. Implement secure DOM manipulation using textContent and secure APIs
  3. Configure Content Security Policy with appropriate directives and violation reporting
  4. Validate all user inputs with allowlist-based validation and sanitization
  5. Implement clickjacking protection with frame detection and busting techniques
  6. Secure navigation and redirects with URL validation and allowlist enforcement
  7. Apply browser security features including SRI, Trusted Types, and security headers
  8. Handle authentication securely with proper token storage and session management
  9. Test security controls with both automated scanning and manual verification

What it can do on your machine

Read from SKILL.md and the folder at commit 4ac52da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Frontend Security Coder loads about 3k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 1,270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,270 words (~2,952 tokens).

“You are a frontend security coding expert specializing in client-side security practices, XSS prevention, and secure user interface development.”

— opening of SKILL.md by aiskillstore
name
frontend-security-coder
risk
unknown
source
community
date_added
2026-02-27

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in skills/sickn33/frontend-security-coder of aiskillstore/marketplace.

  • SKILL.md
  • skill-report.json

Open the folder on GitHubat commit 4ac52da

Used in 6 other repositories

We found 21 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 6 other GitHub owners. This page covers the copy in aiskillstore/marketplace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Frontend Security Coder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Frontend Security Coder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Frontend Security Coder this skillaiskillstore/marketplace4306 repos~3kAutomated safety check: PassNone
Salesforce Component Standardsgithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Experience Lwc Security Validateforcedotcom/sf-skills1.1k—~2.6kAutomated safety check: PassApache-2.0
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11617 repos~3.1kAutomated safety check: NotesMIT

Similar skills

  • Salesforce Component Standards

    github/awesome-copilot

    Official

    Quality standards for Salesforce Lightning Web Components (LWC), Aura components, and Visualforce pages.

    40k GitHub starsUsed in 1 repo~2.4k tokens
    Frontend & DesignAuto-check passed
  • Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for…

    1.1k GitHub stars~2.6k tokensUpdated 5 days ago
    Frontend & DesignAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 17 repos~3.1k tokens
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed

More from aiskillstore/marketplace

All 1,085 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 2 repos~697 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 1 repo~598 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Investigating Codebases

    aiskillstore/marketplace

    Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…

    430 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: notes

Questions about Frontend Security Coder

What does Frontend Security Coder do?

Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns. Frontend Security Coder is an agent skill from aiskillstore/marketplace. Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns.

When should I use Frontend Security Coder?

Frontend Security Coder fits situations like: tasks that involve Web application vulnerabilities.

How do I install Frontend Security Coder in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill frontend-security-coder -a claude-code`. Or copy the skill folder (skills/sickn33/frontend-security-coder in aiskillstore/marketplace) into .claude/skills/frontend-security-coder in your project. Claude Code loads it when a task matches its description.

How do I install Frontend Security Coder in Codex?

Run `npx skills add aiskillstore/marketplace --skill frontend-security-coder -a codex`. Or copy the skill folder (skills/sickn33/frontend-security-coder in aiskillstore/marketplace) into .agents/skills/frontend-security-coder in your project. Codex loads it when a task matches its description.

Can I use Frontend Security Coder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill frontend-security-coder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/frontend-security-coder, .gemini/skills/frontend-security-coder, .github/skills/frontend-security-coder and .opencode/skills/frontend-security-coder in your project.

What does Frontend Security Coder need to run?

SKILL.md names no scripts, command-line tools or credentials: Frontend Security Coder is instructions for the agent only.

Does Frontend Security Coder access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Frontend Security Coder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Frontend Security Coder use?

No licence was found for Frontend Security Coder or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Frontend Security Coder use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Frontend Security Coder?

Skills that share tags, products or a category with Frontend Security Coder: Salesforce Component Standards (github/awesome-copilot, 40k stars), Experience Lwc Security Validate (forcedotcom/sf-skills, 1.1k stars), Security And Hardening (penpot/penpot, 61k stars) and Security Auditor (eigent-ai/eigent, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Frontend Security Coder?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,085 skills in this directory. The repository was last updated on October 7, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.