experience-lwc-security-validate
forcedotcom/sf-skillsUse this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (`.js`, `.ts`, `.html`, `.css`, `.js-meta.xml`)…
Scores out of 100 · grade A
2026-08-22Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score40/100
- 893 stars on the source repo.
Documented
15% of the score74/100
- No usage example or code block.
- 1,353-word body.
- Ships 6 bundled files.
Install
npx skills add forcedotcom/sf-skills/experience-lwc-security-validateWhat it says it does
Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (`.js`, `.ts`, `.html`, `.css`, `.js-meta.xml`) — the canonical LWS/Product-Security review for LWCs, NOT a generic code-security pass. It produces either a severity-ranked finding list with code-level remediations or a SARIF 2.1.0 JSON score report keyed by the `lws-001`…`lws-023b` rule catalog. TRIGGER when the user asks to review, audit, or check an LWC component for LWS compliance issues and recommend fixes, score a component's LWS/security compliance, find dangerous DOM APIs or blocked sinks (`eval`, `Function`, `document.write`, `innerHTML`, `document.createElement('script')`, global-scope assignment to `window`/`globalThis`, unsafe URL schemes), or emit a SARIF security report. DO NOT TRIGGER for generic non-LWC security review, for building a new LWC (use experience-lwc-generate), accessibility (WCAG 2.2), RTL/i18n, or Apex/Aura/server-side review.
Also in forcedotcom/sf-skills
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| dx-code-analyzer-configureforcedotcom/sf-skills | clean | Skill | 4,127 installs | today | |
| dx-code-analyzer-custom-rule-createforcedotcom/sf-skills | clean | Skill | 3,373 installs | today | |
| dx-org-manageforcedotcom/sf-skills | clean | Skill | 4,033 installs | today | |
| platform-metadata-api-context-getforcedotcom/sf-skills | clean | Skill | 4,286 installs | today | |
| platform-metadata-deployforcedotcom/sf-skills | clean | Skill | 4,451 installs | today | |
| agentforce-architecture-analyzeforcedotcom/sf-skills | clean | Skill | 4,102 installs | today |
Other security skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| release-openclaw-ciopenclaw/openclaw | No license | Security | 387k stars | today | |
| site-architecturecoreyhaines31/marketingskills | clean | Security | 94,902 installs | today | |
| cookbook-auditanthropics/claude-cookbooks | clean | Security | 52k stars | 2 days ago | |
| asocoreyhaines31/marketingskills | clean | Security | 46,665 installs | today | |
| openclaw-secret-scanning-maintaineropenclaw/openclaw | No license | Security | 387k stars | today | |
| graph-evolutiontrailofbits/skills | clean | Security | 2,860 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=forcedotcom%2Fsf-skills)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
