Agent Plugins Marketplace
← All plugins

xss-prevention

v3.9.0

Prevents Cross-Site Scripting attacks through input sanitization, output encoding, and Content Security Policy. Use when handling user-generated content, implementing rich text editors, or securing web applications.

CodexClaude Code1 Skill

By Claude Skills MaintainersLicense: MIT227 GitHub starsUpdated last week

Directory evidence

Runtimes
Codex and Claude Code
Parsed components
1 skill or MCP entry
Source updated
Sep 28, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install xss-prevention for Codex and Claude Code

Installs for the current user
codex plugin marketplace add secondsky/claude-skills
codex plugin marketplace upgrade claude-skills
codex plugin add xss-prevention@claude-skills

Paste and run these commands in a terminal with Codex. They add and refresh the claude-skills catalog, then install this plugin.

Compatibility: the page URL and API slug “xss-prevention” remain stable.

  • Codex: xss-prevention@agent-plugin-marketplace → xss-prevention@claude-skills

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/secondsky/claude-skills

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/xss-prevention/.

Plugin files

plugins/xss-prevention/
├── .codex-plugin/plugin.json
├── .claude-plugin/plugin.json
└── skills/xss-prevention/SKILL.md

Included Skills1

xss-preventionskills/xss-prevention/SKILL.md

XSS attack prevention with input sanitization, output encoding, Content Security Policy. Use for user-generated content, rich text editors, web application security, or encountering stored XSS, reflected XSS, DOM manipulation, script injection errors.

Plugin manifests2

plugins/xss-prevention/.codex-plugin/plugin.json
{
  "name": "xss-prevention",
  "version": "3.9.0",
  "description": "Prevents Cross-Site Scripting attacks through input sanitization, output encoding, and Content Security Policy. Use when handling user-generated content, implementing rich text editors, or securing web applications.",
  "author": {
    "name": "Claude Skills Maintainers",
    "email": "[email protected]"
  },
  "license": "MIT",
  "repository": "https://github.com/secondsky/claude-skills",
  "keywords": [
    "xss-prevention",
    "xss",
    "prevention",
    "security",
    "vulnerability",
    "protection",
    "csrf"
  ],
  "skills": "./skills/",
  "interface": {
    "displayName": "XSS Prevention",
    "shortDescription": "Prevents Cross-Site Scripting attacks through input sanitization, output",
    "longDescription": "Prevents Cross-Site Scripting attacks through input sanitization, output encoding, and Content Security Policy. Use when handling user-generated content, implementing rich text editors, or securing web applications.",
    "developerName": "Claude Skills Maintainers",
    "category": "Security & Authentication",
    "capabilities": [
      "Read",
      "Write"
    ],
    "defaultPrompt": [
      "Help me with XSS Prevention.",
      "Show me best practices for XSS Prevention.",
      "Guide me through using XSS Prevention effectively."
    ]
  }
}
plugins/xss-prevention/.claude-plugin/plugin.json
{
  "name": "xss-prevention",
  "description": "Prevents Cross-Site Scripting attacks through input sanitization, output encoding, and Content Security Policy. Use when handling user-generated content, implementing rich text editors, or securing web applications.",
  "version": "3.9.0",
  "author": {
    "name": "Claude Skills Maintainers",
    "email": "[email protected]"
  },
  "license": "MIT",
  "repository": "https://github.com/secondsky/claude-skills",
  "keywords": [
    "xss-prevention",
    "xss",
    "prevention",
    "security",
    "vulnerability",
    "protection",
    "csrf"
  ]
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[xss-prevention on Agent Plugins Marketplace](https://pluginsmp.com/plugins/xss-prevention)