| name | openwebf-security-xss-sanitization |
| description | Review and mitigate XSS risks in WebF apps (sanitize HTML, validate input, avoid unsafe string rendering). Use when the user mentions XSS, sanitize HTML, innerHTML-like rendering, user-generated HTML, or “untrusted input”. |
| allowed-tools | Read, Grep, Glob, mcp__openwebf__docs_search, mcp__openwebf__docs_get_section, mcp__openwebf__docs_related |
OpenWebF Security: XSS & Input Sanitization
Instructions
- Identify sources of untrusted input (UGC, remote content, query params).
- Look for unsafe HTML string rendering patterns and missing sanitization.
- Recommend explicit sanitization and input validation strategies.
- Use MCP docs (“Security > Prevent XSS / Sanitize HTML / Validate Input”) to anchor recommendations.
- Provide fixes as minimal, concrete suggestions; do not modify files by default.
More: