Validate external data at runtime with a schema library

SkillFiles & storage

runtime-validation is a skill for reviewing code that handles data from fetch(), localStorage, process.env, or form submissions. It flags places where that incoming data is used without checking its shape first. This helps catch missing validation before it causes runtime errors or bad data handling.

Use Validate external data at runtime with a schema library in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Validate external data at runtime with a schema library and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Validate external data at runtime with a schema library skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Have the code you want reviewed available to the agent.

Validate external data at runtime with a schema libraryStart free

What your AI can do with it

  • Flags fetch() responses used without shape validation
  • Flags localStorage reads used without shape validation
  • Flags process.env access used without shape validation
  • Flags form submissions processed without shape validation
  • Reviews code for missing runtime validation of incoming data

Getting started

  1. Have the code you want reviewed available to the agent.
  2. Add the runtime-validation skill to your agent setup.
  3. Ask the agent to review code that calls fetch(), reads localStorage, accesses process.env, or processes form submissions.
  4. Read the flagged locations and add validation where the skill indicates it is missing.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/runtime-validation/SKILL.md and read by ahel’s review.

TypeScript gives you confidence at compile time, but data from the network, user input, and storage arrives at runtime as raw, untyped values. A backend schema change, a misconfigured API, or malicious input can produce data that does not match your TypeScript types — and the compiler will never warn you. Runtime validation with a schema library catches these mismatches at the boundary, surfaces clear error messages, and prevents type-unsafe data from propagating through your application.

Quick Reference

  • TypeScript types are compile-time only — they are completely erased at runtime
  • API responses can differ from their declared types without causing a compile error
  • A Zod schema simultaneously validates data and infers the TypeScript type
  • Validate at trust boundaries only — not inside every internal function call

Check

Identify all places in this code where external data enters the application (fetch calls, localStorage reads, env variable access, form submissions) and report which ones lack runtime schema validation.

Fix

Add Zod schemas to validate the external data entry points in this code. Show the schema definition, the validated type inference, and where to call .parse() or .safeParse().

Explain

Explain why TypeScript types do not protect against runtime data mismatches, how Zod bridges compile-time and runtime safety, and when to use .parse() versus .safeParse().

Code Review

Review all external data entry points in this file: API calls, storage reads, environment variable access, and form handling. Flag any location where data is cast to a TypeScript type without a preceding runtime validation step.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/javascript/runtime-validation

Signals

GitHub stars
74k
Forks
7k
Last commit
Oct 2026

Questions

What kind of data does it check?
It checks data from fetch() responses, localStorage reads, process.env access, and form submissions. It looks for places where that data is used without validating its shape.
Does it fix the code automatically?
No. It flags code that uses incoming data without validating its shape. You still need to add the validation yourself.
When should I use this skill?
Use it when reviewing code that calls fetch(), reads from localStorage, accesses process.env, or processes form submissions without explicitly validating the incoming data shape.
What does it not do?
It does not validate data at runtime itself. It only flags code where validation is missing so you can add it.
Advanced
Item type
skill
Key
runtime-validation
Source
github.com/thedaviddias/front-end-checklist