UI Security Sandbox

This skill should be used when hardening an agent UI — authoring the narrowest _meta.ui.csp allowlists, the iframe sandbox and proxy-origin model, treating structuredContent as untrusted input, prompt-injection through rendered data, host-mediated navigation, secrets handling, and the pre-ship security checklist.

thelobbi 621ed22 7.6 KB Updated

File contents

thelobbi/claude/tree/main/plugins/mcp-apps-studio/skills/ui-security-sandbox commit 621ed2261d

Frequently asked questions

npx skillmds add thelobbi/ui-security-sandbox