security-reactnative
Security - React Native 0.85+ Best Practices. Use when reviewing security, implementing auth, or hardening code.
Works with
--- name: security-reactnative description: Security - React Native 0.85+ Best Practices. Use when reviewing security, implementing auth, or hardening code. license: MIT --- # Security - React Native 0.85+ Best Practices Ce skill fournit les bonnes pratiques de sécurité pour React Native 0.85+ avec la New Architecture. ## Principes clés - **Sécurité native** : Keychain (iOS) / Keystore (Android) pour les secrets sensibles (pas AsyncStorage) - **HTTPS uniquement** : ATS (iOS) et Network Security Config (Android) strictes - **JSI synchrone** : validation côté natif des appels TurboModules - **Expo SecureStore** : abstraction sécurisée cross-platform pour les tokens ## Spécificités React Native 0.85+ - **TurboModules sécurisés** : validation des inputs côté natif avant traitement JSI - **Bridge legacy supprimé** : pas de risques de sérialisation JSON vulnérable - **Fabric** : rendu natif isolé du thread JS (limite les injections UI) - **Hermes obligatoire** : bytecode natif (protection contre le reverse engineering du bundle JS) ## Anti-patterns critiques - ❌ Stocker des tokens dans AsyncStorage (plaintext) - ❌ HTTP non sécurisé en production - ❌ Code PIN/biométrie sans SecureStore - ❌ Deep links non validés (injection de navigation) - ❌ WebView sans validation de l'origine **Sources :** [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/), [RN Security Best Practices](https://reactnative.dev/docs/security)
More Mobile skills
animation-vocabulary
emilkowalski/skills
Reverse-lookup glossary that turns a vague description of a web animation or motion effect into its exact term ("the bouncy thing when a popover opens" → Pop in; "the iOS rubber-band scroll" → Rubber-banding). Use when the user asks "what's it called when…", or describes a motion effect without knowing its name and wants the right word to prompt an AI or designer with. For naming an effect, not designing or building one.
xcode-project-setup
firebase/agent-skills
Safely modifies Xcode projects (.pbxproj) to add Swift Packages and link files. Use this skill whenever an iOS project needs dependencies installed (e.g. Firebase, Alamofire).
cross-border-ecommerce
nexscope-ai/ecommerce-skills
Cross-border e-commerce expansion advisor. Scores target markets on 8 weighted dimensions (market size, ecommerce penetration, competition, regulatory complexity, logistics infrastructure, payment ecosystem, cultural distance, IP protection), compares 5 fulfillment models with cost and transit data, provides country-by-country tax/duty compliance guides (EU VAT/IOSS, UK VAT, US sales tax, CA GST, AU GST, JP consumption tax), maps local payment preferences by market, and builds a phased expansion roadmap. No API key required.

