Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Security Headers CSP Auditor

    1

    Audit HTTP security headers and CSP strings for misconfigurations, weak values, and dangerous CORS patterns.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    Security Headers CSP Auditor

    Security Headers CSP Auditor

    Example session with this skill installed

    I just ran curl -I on my site and got these headers. Is this CSP actually protecting me or is it just fluff? [pasted headers containing CSP with unsafe-inline and missing HttpOnly on cookies]

    • Read your context and instructions
    • Compiled the security headers csp

    Your CSP is currently ineffective against XSS because it includes 'unsafe-inline' in script-src. I recommend implementing a nonce-based policy. Also, your session cookie lacks the HttpOnly flag, meaning a successful XSS could steal the session token. Fix these two first.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Identify XSS bypasses in existing Content-Security-Policy strings.Detect dangerous CORS configurations that allow credentialed cross-origin access.Verify session cookie flags for HttpOnly, Secure, and SameSite compliance.Generate specific remediation syntax for weak HSTS and Referrer-Policy values.

    About this skill

    The problem

    Security headers are often present but misconfigured, providing a false sense of security while leaving sites vulnerable to XSS, clickjacking, and session hijacking. Manually auditing complex CSP strings and CORS configurations is error-prone and time-consuming.

    What it does

    • Analyzes raw HTTP response headers for missing or weak security configurations.
    • Performs deep directive-by-directive audits of Content-Security-Policy (CSP) to flag bypasses like unsafe-inline or over-broad wildcards.
    • Identifies dangerous CORS patterns, specifically the origin-reflection plus credentials trap.
    • Audits Set-Cookie flags for session protection, including HttpOnly, Secure, and SameSite.
    • Prioritizes findings based on exploitability, moving beyond simple presence-checks to evaluate actual value effectiveness.

    Why this beats prompting it yourself

    General-purpose LLMs often report a header as "safe" just because the key exists. This skill uses specific logic to detect subtle CSP bypasses and invalid CORS combinations that standard prompts miss. It provides exact syntax for nonce-based or hash-based remediations rather than generic advice.

    Use cases

    • Auditing a production site by pasting raw headers from browser DevTools.
    • Hardening CSP for an application that currently uses unsafe-inline.
    • Verifying session cookie security flags during a security review.
    • Debugging CORS errors that might be masking serious misconfigurations.

    Known limitations

    Requires raw header data or curl output to be provided by the user, as it cannot directly fetch headers from a URL. Focused on HTTP response-level security, not application-layer logic vulnerabilities.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 month ago

    • Passed all security checks, Safe to install

    Listed1 month ago
    Updated23 days ago

    What's inside

    Frequently Asked Questions