> angular-security

Security best practices for Angular (XSS, CSP, Route Guards). Use when implementing XSS protection, Content Security Policy, or auth guards in Angular. (triggers: **/*.ts, **/*.html, DomSanitizer, innerHTML, bypassSecurityTrust, CSP)

fetch
$curl "https://skillshub.wtf/HoangNguyen0403/agent-skills-standard/angular-security?format=md"
SKILL.mdangular-security

Security

Priority: P0 (CRITICAL)

Principles

  • XSS Prevention: Angular sanitizes by default. Do NOT use innerHTML unless absolutely necessary.
  • Bypass Security: Avoid DomSanitizer.bypassSecurityTrust... unless the content source is trusted.
  • Route Guards: Protect all sensitive routes with CanActivateFn.

Guidelines

  • CSP: Configure Content Security Policy headers on the server.
  • HTTP: Use Interceptors to attach secure tokens (HttpOnly cookies preferred over LocalStorage tokens).
  • Secrets: NEVER store secrets (API keys) in Angular code.

References

Related Topics

common/security-standards | components

🚫 Anti-Patterns

  • Do NOT use standard patterns if specific project rules exist.
  • Do NOT ignore error handling or edge cases.

┌ stats

installs/wk0
░░░░░░░░░░
github stars341
██████████
first seenMar 17, 2026
└────────────

┌ repo

HoangNguyen0403/agent-skills-standard
by HoangNguyen0403
└────────────

┌ tags

└────────────