Works with the AI tools you already use
Security Headers CSP Auditor
Audit HTTP security headers and CSP strings for misconfigurations, weak values, and dangerous CORS patterns.
$5
Security Headers CSP Auditor
Example session with this skill installed
I just ran curl -I on my site and got these headers. Is this CSP actually protecting me or is it just fluff? [pasted headers containing CSP with unsafe-inline and missing HttpOnly on cookies]
- Read your context and instructions
- Compiled the security headers csp
Your CSP is currently ineffective against XSS because it includes 'unsafe-inline' in script-src. I recommend implementing a nonce-based policy. Also, your session cookie lacks the HttpOnly flag, meaning a successful XSS could steal the session token. Fix these two first.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Security headers are often present but misconfigured, providing a false sense of security while leaving sites vulnerable to XSS, clickjacking, and session hijacking. Manually auditing complex CSP strings and CORS configurations is error-prone and time-consuming.
What it does
- Analyzes raw HTTP response headers for missing or weak security configurations.
- Performs deep directive-by-directive audits of Content-Security-Policy (CSP) to flag bypasses like
unsafe-inlineor over-broad wildcards. - Identifies dangerous CORS patterns, specifically the origin-reflection plus credentials trap.
- Audits
Set-Cookieflags for session protection, includingHttpOnly,Secure, andSameSite. - Prioritizes findings based on exploitability, moving beyond simple presence-checks to evaluate actual value effectiveness.
Why this beats prompting it yourself
General-purpose LLMs often report a header as "safe" just because the key exists. This skill uses specific logic to detect subtle CSP bypasses and invalid CORS combinations that standard prompts miss. It provides exact syntax for nonce-based or hash-based remediations rather than generic advice.
Use cases
- Auditing a production site by pasting raw headers from browser DevTools.
- Hardening CSP for an application that currently uses
unsafe-inline. - Verifying session cookie security flags during a security review.
- Debugging CORS errors that might be masking serious misconfigurations.
Known limitations
Requires raw header data or curl output to be provided by the user, as it cannot directly fetch headers from a URL. Focused on HTTP response-level security, not application-layer logic vulnerabilities.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install