Secure password input fields

SkillWeb & browsing

password-field-security is a skill for AI agents that reviews Secure password input fields. It guides the agent through checking headers, forms, cookies, and third-party integrations, and validating the effective browser and HTTP behavior in a production-like environment.

Available today. Use it from your connected AI after setup.

Have an AI agent that can load skills.

Then ask your AI: use the Secure password input fields skill

What your AI can do with it

  • Review headers related to Secure password input fields
  • Review forms related to Secure password input fields
  • Review cookies related to Secure password input fields
  • Review third-party integrations related to Secure password input fields
  • Validate effective browser and HTTP behavior in a production-like environment

Getting started

  1. Have an AI agent that can load skills.
  2. Add the password-field-security skill to the agent's available skills.
  3. Ask the agent to review the headers, forms, cookies, or third-party integrations of the password input fields in question.
  4. Provide access to a production-like environment so the agent can validate the effective browser and HTTP behavior.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/password-field-security/SKILL.md and read by ahel’s review.

Properly implemented password fields improve security by working with password managers, helping users create strong passwords, and providing accessible controls for all users.

Quick Reference

  • Use type='password' with correct autocomplete attribute
  • Provide accessible show/hide toggle for password visibility
  • Show password strength indicator with requirements
  • Never store or transmit passwords in plain text
  • Support password managers with proper input names

Check

Verify password fields use type='password', have proper autocomplete values, and include accessible show/hide toggles.

Fix

Implement password fields with autocomplete='new-password' or 'current-password', accessible toggle buttons, and optional strength meters.

Explain

Explain security and UX best practices for password fields including autocomplete attributes and accessible reveal functionality.

Code Review

Review server config, headers, forms, and integration points related to Secure password input fields. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/security/password-field-security

Signals

GitHub stars
74k
Forks
7k
Last commit
Aug 2026

Questions

When should this skill be used?
Use it when reviewing headers, forms, cookies, or third-party integrations related to Secure password input fields.
Does it test in production?
No. It validates the effective browser and HTTP behavior in a production-like environment, not in production itself.
What does the agent check?
Headers, forms, cookies, and third-party integrations related to Secure password input fields.
Advanced
Item type
skill
Key
password-field-security
Source
github.com/thedaviddias/front-end-checklist