Yes. Tokens in deep-link URLs can leak through OS logs, analytics, browser history, notification previews, referrers, screenshots, and copied links. Remove the token from the URL and use a short-lived one-time code that the app exchanges over HTTPS, then store the resulting credential in the platform keychain/keystore. Also whitelist the expected scheme and host, validate and sanitize route parameters, and never log the raw URL. Deep links should be treated as untrusted input, with the backen...
Scanned 9/5/2026
Install to Claude Code
npx -y skills add HoangNguyen0403/agent-skills-standard --skill react-native-security --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of React Native Security?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-react-native-security-74423a31)More formats (shields.io, HTML) on the badges page.
Yes. Tokens in deep-link URLs can leak through OS logs, analytics, browser history, notification previews, referrers, screenshots, and copied links. Remove the token from the URL and use a short-lived one-time code that the app exchanges over HTTPS, then store the resulting credential in the platform keychain/keystore.
Also whitelist the expected scheme and host, validate and sanitize route parameters, and never log the raw URL. Deep links should be treated as untrusted input, with the backend performing the final authorization check.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.