← Browse

@thedaviddias/javascript-inline

B

Use when reviewing scripts, client components, bundles, or runtime behavior related to Avoid inline JavaScript. Inspect both source code and the browser execution path so fixes target the real bottleneck or bug.

skillclaude

Install

agr install @thedaviddias/javascript-inline --target claude

Writes 1 file into .claude/skills/, pinned to git-40d0a612.

  • .claude/skills/javascript-inline/SKILL.md

Document


name: javascript-inline description: "Use when reviewing scripts, client components, bundles, or runtime behavior related to Avoid inline JavaScript. Inspect both source code and the browser execution path so fixes target the real bottleneck or bug." metadata: category: javascript priority: high difficulty: beginner estimatedTime: "15" source: frontendchecklist.io url: https://frontendchecklist.io/en/rules/javascript/javascript-inline

Avoid inline JavaScript

Inline JavaScript breaks browser caching, violates Content Security Policy (CSP), and creates unmaintainable spaghetti code mixing markup with behavior.

Quick Reference

  • Move onclick/onmouseover handlers to external JS files
  • Use addEventListener instead of inline event handlers
  • Exception: critical above-the-fold JS can be inlined
  • External files enable browser caching across pages

Check

Verify that JavaScript code is not mixed with HTML markup using external script files and proper separation of concerns for better maintainability and performance.

Fix

Move inline JavaScript to external files, implement proper event handling, and use modern JavaScript patterns for DOM interaction.

Explain

Explain why separating JavaScript from HTML improves maintainability, enables caching, reduces security risks, and follows best practices for separation of concerns.

Code Review

Review scripts, client components, and browser execution paths related to Avoid inline JavaScript. Flag exact imports, event handlers, runtime side effects, or blocking operations that violate the rule, and state how the change should be verified in the browser.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/javascript/javascript-inline

Trustgrade B

  • passBody integrity

    Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.

  • passType matchnot applicable to this artifact type

    Whether the artifact is really the kind of thing its metadata claims it is.

  • passFreshness

    How long since the source repository was last pushed to.

  • passPrompt injection

    Scans the artifact's own text for instructions aimed at your agent rather than at you.

  • warnLicenseno SPDX license detected

    Whether the source repository declares an SPDX license permissive enough to redistribute.

How the grade is calculated

Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:

  • Aevery check passed
  • Bone warning
  • Ctwo warnings
  • Dprompt injection or body integrity failed, or three warnings
  • Fone of those failed, and something else is wrong

These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.

Versions

  • git-40d0a612b0852026-07-31