Agent skill

openwebf-security-remote-content

Review security risks and mitigations for remote WebF content (untrusted bundles, URL allowlists, HTTPS, trust boundaries, clickjacking). Use when the user mentions untrusted remote bundles, bundle URL validation/allowlists, or remote updates risk.

Stars 163
Forks 31

Install this agent skill to your Project

npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/data/openwebf-security-remote-content

SKILL.md

OpenWebF Security: Remote Content & Trust Boundaries

Instructions

  1. Identify trust boundaries:
    • remote bundle URLs
    • user-generated content
    • bridge/native plugins
  2. Review how URLs are constructed and validated (allowlists, HTTPS, pinning/versioning).
  3. Use MCP docs (“Security”, “Store Guidelines”) as the baseline for recommendations.
  4. Provide remediation steps ordered by severity; do not modify files by default.

If the user is primarily asking about store policy/compliance for remote updates, prefer openwebf-security-store-guidelines.

More:

Didn't find tool you were looking for?

Be as detailed as possible for better results