◆ JavaScript

Secure input against XSS

This is real work, not a feature someone invented — it comes from real job ads and real questions people asked. Below are four ready AI prompts: get it done, make it easy for the next person to say yes to, work out the right move when you are stuck, and stop it coming back.

4prompts

The same task, four prompts

today's deadline · the next reviewer · the stuck moment · the pattern
AExecute — do the immediate taskWe must stop reflected XSS on the comment widget before the production push. Sanitize…+
We must stop reflected XSS on the comment widget before the production push. Sanitize user-submitted comment text so any angle brackets, script tags, and event-attribute syntax are escaped when rendered, and apply a strong Content-Security-Policy that disallows inline scripts. Verify by posting a comment containing <script>alert('xss')</script> and confirming it renders as text.
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
BImprove — make it easier to acceptBefore I send this XSS fix to security review, make approval obvious: show the original input…+
Before I send this XSS fix to security review, make approval obvious: show the original input and the escaped output side by side, summarize which characters we escape and which we allow (e.g., basic Markdown), highlight where we apply server-side escaping vs client-only, and call out any remaining places that still render raw HTML like admin previews.
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
CDecide — diagnose the stuck momentAn admin reported that a stored comment containing an iframe rendered as active HTML on the…+
An admin page rendered a saved comment as active HTML.
An admin reported that a stored comment containing an iframe rendered as active HTML on the admin preview page, but on the public site the same comment is escaped. I’m worried we missed server-side escaping on the admin route or that a legacy render path bypasses the sanitizer. I don’t know whether the unsafe output comes from stored HTML or a separate rendering pipeline. What tests and quick checks would confirm whether this is a rendering-path bug or bad storage, and what immediate change should I make to stop admin users seeing executable markup?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
DBecome — change the patternOver multiple incidents we find XSS only in rare admin views and old templates: public pages…+
We keep finding XSS holes in admin and legacy pages.
Over multiple incidents we find XSS only in rare admin views and old templates: public pages are fine but legacy renderers bypass the sanitizer. We spend emergency cycles patching them as they appear. Which two consistent practices will prevent these regressions going forward — what to add to the template system or CI and what developer habit to enforce on review?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?

Questions people actually ask

honest answers, no sign-up

Every task here was seen in the real world. Someone doing the job named it, a real job ad asked for it, or a lot of people asked about it online.

If nothing real showed a task, it is not on the page. That is the whole rule.

They are the same job approached four ways, because what you need depends on where you are.

Get it done today. Make it easy for the next person to say yes to. Work out the right move when you are stuck. Learn the pattern so the job stops coming back.

For most of these jobs it can carry the heavy thinking - draft it, sort it, check it, rehearse it with you.

It cannot sit in your chair, take the blame when a number is wrong, or notice what nobody wrote down. Let it do the first 80%. Keep the last 20% that is truly yours.

No. Copy any prompt and paste it into the AI you already use. No account, no score, no wall in the way.

Any of them. The prompts describe the work rather than naming a product, so they are not tied to one assistant.

That is also why they keep working when you switch.

Change it freely. Every prompt is a starting line, not a rule.

Put in your real numbers, your real names and your real deadline. The more you make it yours, the better the answer comes back.

The tasks come from real job ads, published job data and the questions people ask in public forums.

The steps come from JavaScript's own documentation, with practitioner sources for the traps the manual does not mention.

Push once. Ask it to sharpen the weakest part and to say what it assumed.

Most wrong answers come from a missing detail rather than a bad prompt - tell it the thing it could not know.