Avoid raw `innerHTML`; render text as escaped React content whenever possible. If trusted rich HTML is required, sanitize it with a well-maintained sanitizer such as DOMPurify before using `dangerouslySetInnerHTML`, and enforce a restrictive CSP. Store no secrets in the component, and treat the content as untrusted even if it came from an authenticated user.
Installs into .claude/skills of the current project.
Are you the author of Nextjs Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-nextjs-security-86664716)
Avoid raw `innerHTML`; render text as escaped React content whenever possible. If trusted rich HTML is required, sanitize it with a well-maintained sanitizer such as DOMPurify before using `dangerouslySetInnerHTML`, and enforce a restrictive CSP. Store no secrets in the component, and treat the content as untrusted even if it came from an authenticated user.