Input Validation And Sanitization

Use this skill when implementing any endpoint, form handler, CLI tool, or function that accepts external input. Validate and sanitize all untrusted data before processing — never assume input is safe.

gabrielmoreira Updated 17 repo stars

File contents

Input Validation and Sanitization

Validation principles:

  • Validate at the system boundary (API layer, form handler) — not deep in business logic.
  • Validate type, range, length, and format explicitly.
  • Reject unexpected input by default (allowlist > denylist).

SQL injection prevention: Always use parameterized queries or an ORM.

XSS prevention: Escape HTML output; use Content-Security-Policy headers; avoid innerHTML with user data.

Path traversal prevention: Resolve paths to canonical form and verify they are under the expected directory.

import os
base = '/allowed/dir'
canonical = os.path.realpath(os.path.join(base, user_input))
assert canonical.startswith(base + os.sep)

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/aiming-lab@MetaClaw/memory_data/skills/input-validation-and-sanitization commit 5a49126af0

Frequently asked questions

npx skillmds@latest add gabrielmoreira/input-validation-and-sanitization