Skill Wiki v0.1.0
anti-pattern @security/anti-pattern-trust-client-input

Trust Client Input

Relying on JavaScript validation, hidden form fields, disabled buttons, or HTTP headers set by the user agent to enforce a security or correctness invariant. Every byte the client sends is attacker-controlled.

Skill
@security
Domain
security
Version
0.1.0
Quality
4.0
Edges
3 out · 3 in
Tokens
67/343/619
$ prime install @security/anti-pattern-trust-client-input

Projection

Always in _index.xml · the agent never has to ask for this.

TrustClientInput [anti-pattern] v0.1.0

Relying on JavaScript validation, hidden form fields, disabled buttons, or HTTP headers set by the user agent to enforce a security or correctness invariant. Every byte the client sends is attacker-controlled.

Source

prime-system/examples/security-appsec/primes/compiled/@security/anti-pattern-trust-client-input/atom.yaml

Compiled at 2026-05-10