You’re right—auth tokens should not be stored in `localStorage`. Use `HttpOnly; Secure; SameSite=Lax` cookies set by the server, and send requests with credentials enabled. Add CSRF protection for state-changing requests. This User correction is a learning-log trigger: append one proposed `Iteration` entry to `AGENTS_LEARNING.md` describing the `localStorage` mistake and the cookie-based approach. It is not a `Pre-write` auto-fix.
Pro scans all 14 files and shows the line behind each finding
Scanned 9/24/2026
npx -y skills add HoangNguyen0403/agent-skills-standard --skill common-learning-log --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Common Learning Log?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-common-learning-log-5759dd43)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
You’re right—auth tokens should not be stored in `localStorage`. Use `HttpOnly; Secure; SameSite=Lax` cookies set by the server, and send requests with credentials enabled. Add CSRF protection for state-changing requests.
This User correction is a learning-log trigger: append one proposed `Iteration` entry to `AGENTS_LEARNING.md` describing the `localStorage` mistake and the cookie-based approach. It is not a `Pre-write` auto-fix.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!