API Security Hardening
secondsky/claude-skills
REST API security hardening with authentication, rate limiting, input validation, security headers.
A skill your agent uses when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit…
$ npx skills add cwinvestments/memstack --skill memstack-security-csp-headers -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cwinvestments/memstack memstack-security-csp-headers --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/csp-headers .claude/skills/memstack-security-csp-headers && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "memstack-security-csp-headers" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/security/csp-headers into .claude/skills/memstack-security-csp-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memstack-security-csp-headers", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cwinvestments/memstack/tree/master/skills/security/csp-headersType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cwinvestments/memstack --skill memstack-security-csp-headers -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cwinvestments/memstack memstack-security-csp-headers --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security/csp-headers .agents/skills/memstack-security-csp-headers && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "memstack-security-csp-headers" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/security/csp-headers into .agents/skills/memstack-security-csp-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memstack-security-csp-headers", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cwinvestments/memstack --skill memstack-security-csp-headers -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cwinvestments/memstack memstack-security-csp-headers --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security/csp-headers .cursor/skills/memstack-security-csp-headers && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "memstack-security-csp-headers" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/security/csp-headers into .cursor/skills/memstack-security-csp-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memstack-security-csp-headers", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cwinvestments/memstack.git --path skills/security/csp-headers--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cwinvestments/memstack --skill memstack-security-csp-headers -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cwinvestments/memstack memstack-security-csp-headers --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security/csp-headers .gemini/skills/memstack-security-csp-headers && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "memstack-security-csp-headers" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/security/csp-headers into .gemini/skills/memstack-security-csp-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memstack-security-csp-headers", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cwinvestments/memstack memstack-security-csp-headersInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cwinvestments/memstack --skill memstack-security-csp-headers -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security/csp-headers .github/skills/memstack-security-csp-headers && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "memstack-security-csp-headers" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/security/csp-headers into .github/skills/memstack-security-csp-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memstack-security-csp-headers", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cwinvestments/memstack --skill memstack-security-csp-headers -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cwinvestments/memstack memstack-security-csp-headers --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security/csp-headers .opencode/skills/memstack-security-csp-headers && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "memstack-security-csp-headers" agent skill from https://github.com/cwinvestments/memstack/tree/master/skills/security/csp-headers into .opencode/skills/memstack-security-csp-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memstack-security-csp-headers", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
memstack-security-csp-headersA skill your agent uses when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit…
Memstack Security Csp Headers is an agent skill from cwinvestments/memstack. Use this skill when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit, generate, or fix HTTP security headers for a web application. Do NOT use for API route audits or dependency scanning.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Secure coding. It works with NGINX. The repository describes itself as: Structured skill framework for Claude Code. 130 skills, persistent memory, TokenStack compression, localhost dashboard with 3-agent runner, real-time streaming, MCP tools.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 00370ce. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
opensslFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
googletagmanager.comres.cloudinary.comapi.stripe.comjs.stripe.comfonts.gstatic.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Memstack Security Csp Headers loads about 3.9k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 699 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Its licence (Proprietary) doesn't allow us to republish the file, so here is its outline and opening line. It has 699 words (~3,932 tokens).
“Audit existing security headers, identify overly permissive directives, and generate a production-ready Content-Security-Policy with companion headers.”
Just SKILL.md in skills/security/csp-headers of cwinvestments/memstack.
Open the folder on GitHubat commit 00370ce
Memstack Security Csp Headers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Memstack Security Csp Headers this skillcwinvestments/memstack | 423 | — | ~3.9k | Automated safety check: Pass | Proprietary | |
| API Security Hardeningsecondsky/claude-skills | 227 | — | ~718 | Automated safety check: Pass | MIT | |
| Phy Security HeadersLeoYeAI/openclaw-master-skills | 2.2k | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | |
| NIC Task Planningnginx/kubernetes-ingress | 5.1k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Cb Security HardeningBlkLeg/CircuitBreaker | 201 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT |
secondsky/claude-skills
REST API security hardening with authentication, rate limiting, input validation, security headers.
LeoYeAI/openclaw-master-skills
HTTP security header auditor that fetches response headers from any URL and grades them against OWASP, Mozilla Observatory, and Google standards.
nginx/kubernetes-ingress
Plans a change to the NGINX Ingress Controller before any code: acceptance criteria, security impact, affected layers, invariants, test surface and an ordered file list.
BlkLeg/CircuitBreaker
Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
rfc-st/humble
Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.
cwinvestments/memstack
A skill your agent uses when the user says 'SEO audit', 'site audit', 'check SEO', 'audit my site', 'SEO check', 'technical SEO', or is evaluating a website's search engine optimization health, meta…
cwinvestments/memstack
A skill your agent uses when the user says 'add schema', 'schema markup', 'JSON-LD', 'structured data', 'rich results', 'rich snippets', or is adding or fixing schema.org structured data for better…
cwinvestments/memstack
A skill your agent uses when the user says 'tokenstack', 'compression', 'token savings', 'proxy status', or asks about context window usage.
cwinvestments/memstack
A skill your agent uses when the user says 'save diary', 'log session', 'wrapping up', or at end of a productive session.
cwinvestments/memstack
A skill your agent uses when the user references past sessions, asks 'what did we do', 'do you remember', 'last session', 'recall', or 'continue from'.
cwinvestments/memstack
A skill your agent uses when the user says 'dispatch', 'send familiar', 'split task', or needs work split across parallel CC sessions.
Works with
Categories
A skill your agent uses when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit…. Memstack Security Csp Headers is an agent skill from cwinvestments/memstack. Use this skill when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit, generate, or fix HTTP security headers for a web application.
Memstack Security Csp Headers fits situations like: the user says CSP; content-Security-Policy; security headers; X-Frame-Options.
Run `npx skills add cwinvestments/memstack --skill memstack-security-csp-headers -a claude-code`. Or copy the skill folder (skills/security/csp-headers in cwinvestments/memstack) into .claude/skills/memstack-security-csp-headers in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cwinvestments/memstack --skill memstack-security-csp-headers -a codex`. Or copy the skill folder (skills/security/csp-headers in cwinvestments/memstack) into .agents/skills/memstack-security-csp-headers in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cwinvestments/memstack --skill memstack-security-csp-headers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/memstack-security-csp-headers, .gemini/skills/memstack-security-csp-headers, .github/skills/memstack-security-csp-headers and .opencode/skills/memstack-security-csp-headers in your project.
Going by SKILL.md and its folder, Memstack Security Csp Headers needs the command-line tools its instructions call (openssl).
SKILL.md names 5 domains. In commands or code: googletagmanager.com, res.cloudinary.com, api.stripe.com, js.stripe.com and fonts.gstatic.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Memstack Security Csp Headers carries a proprietary licence (declared in SKILL.md). It is published on GitHub, but it is not open source: read the licence file before using or sharing it.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Memstack Security Csp Headers: API Security Hardening (secondsky/claude-skills, 227 stars), Phy Security Headers (LeoYeAI/openclaw-master-skills, 2.2k stars), NIC Task Planning (nginx/kubernetes-ingress, 5.1k stars) and Cb Security Hardening (BlkLeg/CircuitBreaker, 201 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cwinvestments (a GitHub user) maintains it in cwinvestments/memstack, which has 423 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: cwinvestments/memstack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.