Submit forms over HTTPS
SkillDev toolsform-https is a skill for AI agents that reviews HTML forms, fetch() calls, and XMLHttpRequest calls to find endpoints submitting data over unencrypted HTTP. It explains why plain HTTP exposes credentials to interception and guides fixes such as switching URLs to HTTPS and adding HTTP-to-HTTPS redirects.
Available today. Use it from your connected AI after setup.
No other account needed.
Have the skill available to your AI agent alongside the HTML and JavaScript files to review.
Then ask your AI: use the Submit forms over HTTPS skill
What your AI can do with it
- Scan HTML form action attributes for http:// URLs
- Check fetch() and XMLHttpRequest calls for insecure endpoints
- Verify pages are on HTTPS so forms without an explicit action submit securely
- Explain how plain HTTP form submissions expose data in transit
- Guide fixes: switch URLs to https:// and add 301 HTTP-to-HTTPS redirects
- Review server config, headers, and integration points against the rule
Getting started
- Have the skill available to your AI agent alongside the HTML and JavaScript files to review.
- Ask the agent to review forms, fetch() calls, and XMLHttpRequest calls for http:// endpoints.
- Review the findings showing which endpoints submit data unencrypted.
- Apply the suggested fixes, such as replacing http:// URLs with https:// and adding HTTP-to-HTTPS redirects.
- See references/rule.md for full implementation details and framework-specific guidance.
What this skill tells your AI
The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/form-https/SKILL.md and read by ahel’s review.
A login form that posts credentials to an HTTP endpoint sends usernames and passwords as plain text over the network — anyone on the same Wi-Fi, the ISP, or a network proxy can read them without any special tools.
Quick Reference
- Every
<form action>URL must usehttps://— neverhttp:// - Forms without an explicit
actionattribute submit to the current page URL — ensure the page itself is on HTTPS - Check
fetch()andXMLHttpRequestcalls in JavaScript — data posted tohttp://endpoints is unencrypted - Browsers show a 'Not Secure' warning in the address bar when a form is on an HTTP page
- From Chrome 86+, autofill is disabled on HTTP forms to protect credentials
Check
Scan all HTML form elements for action attributes pointing to http:// URLs. Check all JavaScript fetch() and XMLHttpRequest calls for http:// endpoints. Verify the current page URL is HTTPS so forms without an explicit action submit securely.
Fix
Replace all http:// form action URLs with https:// equivalents. Ensure the web server redirects HTTP to HTTPS (301) so that forms on the page also benefit. For JavaScript API calls, update all endpoint URLs to use https://.
Explain
Explain why form submissions over HTTP expose user data in transit, how network attackers can intercept plain HTTP traffic, and what the browser security indicators look like on insecure forms.
Code Review
Review server config, headers, forms, and integration points related to Submit forms over HTTPS. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/form-https
Signals
- GitHub stars
- 74k
- Forks
- 7k
- Last commit
- Aug 2026
Questions
- What does form-https check?
- It scans HTML form action attributes, fetch() and XMLHttpRequest calls, and pages without explicit form actions to find any endpoints submitting data over unencrypted HTTP.
- Why is submitting forms over HTTP a problem?
- Data posted to http:// endpoints travels as plain text, so anyone on the same Wi-Fi, the ISP, or a network proxy can read usernames and passwords without special tools.
- How are insecure forms fixed?
- Replace http:// form action and JavaScript endpoint URLs with https:// equivalents, and ensure the web server redirects HTTP to HTTPS with a 301.
Advanced
- Item type
- skill
- Key
form-https- Source
- github.com/thedaviddias/front-end-checklist