About
This skill provides specialized security auditing for WebF applications that load remote content, focusing on identifying vulnerabilities in untrusted bundles and URL validation. It helps developers establish robust trust boundaries by reviewing allowlists, HTTPS enforcement, and native bridge interactions, ensuring that remote updates and external integrations comply with security best practices and platform guidelines. By leveraging MCP documentation, it provides prioritized remediation steps to mitigate risks like clickjacking and unauthorized script execution.