Agent skill

Checking HTTP Security Headers

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Audit a target's HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin trio (COOP, COEP, CORP).

MITAuto-check passedSecurity

Install Checking HTTP Security Headers

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-http-security-headers -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace checking-http-security-headers --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/checking-http-security-headers .claude/skills/checking-http-security-headers && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
checking-http-security-headers
GitHub stars
2.8k
Token cost
~1.6k tokens
SKILL.md length
460 words
Files
4 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Audit a target's HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin trio (COOP, COEP, CORP).

  • Works in 4 steps: Confirm authorization → Run the scanner → Interpret findings → …
  • : SOC2 / PCI auditor flagged missing security headers
  • SKILL.md covers Overview, When the skill produces findings, Prerequisites and Instructions, plus 4 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Checking HTTP Security Headers is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit a target's HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin trio (COOP, COEP, CORP). Use when: SOC2 / PCI auditor flagged "missing security headers" or a Mozilla Observatory grade is below B, OR you need HSTS preload eligibility for chrome://net-internals. Threshold: any missing required header on production HTML response, HSTS max-age below 31536000s (preload requirement), CSP with 'unsafe-inline' or 'unsafe-eval'…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/check_headers.py`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Secure coding. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • : SOC2 / PCI auditor flagged missing security headers
  • A Mozilla Observatory grade is below B
  • You need HSTS preload eligibility for chrome://net-internals
  • With: audit security headers

Example prompts

  • “missing security headers”
  • “unsafe-inline”
  • “unsafe-eval”
  • “/checking-http-security-headers”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Bash(python3:*), Bash(curl:*)

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Confirm authorization
  2. Run the scanner
  3. Interpret findings
  4. Cross-skill chaining

What it can do on your machine

Read from SKILL.md and the folder at commit 23ea8d4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(python3:*)
    • Bash(curl:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Checking HTTP Security Headers loads about 1.6k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 190 tokens; SKILL.md has 460 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~190
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 23ea8d4, republished under its MIT licence (© jeremylongshore). 460 words, ~1,553 tokens.

Download SKILL.mdSave it as .claude/skills/checking-http-security-headers/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
checking-http-security-headers
description
Audit a target's HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin trio (COOP, COEP, CORP). Use when: SOC2 / PCI auditor flagged "missing security headers" or a Mozilla Observatory grade is below B, OR you need HSTS preload eligibility for chrome://net-internals. Threshold: any missing required header on production HTML response, HSTS max-age below 31536000s (preload requirement), CSP with 'unsafe-inline' or 'unsafe-eval', X-Frame-Options absent AND CSP frame-ancestors absent (clickjacking), Cache-Control allowing public cache on authenticated endpoint. Trigger with: "audit security headers", "check csp", "hsts check", "header posture".
allowed-tools
Read, Bash(python3:*), Bash(curl:*)
compatibility
Designed for Claude Code
disallowed-tools
Bash(rm:*), Edit(/etc/*)
version
3.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, http-headers, csp, hsts, pentest

Checking HTTP Security Headers

Overview

HTTP response headers are the cheapest defense-in-depth layer most web apps ship. Each header closes one specific attack class — HSTS forces HTTPS, CSP blocks script injection, X-Frame-Options blocks clickjacking, etc. Missing headers don't break the app; they just leave the attack class open. This skill probes for the presence + value correctness of the canonical security-relevant headers.

When the skill produces findings

FindingSeverityThresholdAffected control
HSTS header missingHIGHNo Strict-Transport-Security on HTTPS responseOWASP A05:2021
HSTS max-age below preload thresholdMEDIUMmax-age under 31536000s (1y)hstspreload.org
HSTS includeSubDomains missing for preloadLOWpreload directive without includeSubDomainshstspreload.org
CSP header missingHIGHNo Content-Security-Policy headerOWASP A03:2021
CSP allows unsafe-inlineMEDIUMscript-src or style-src includes 'unsafe-inline'OWASP A03:2021
CSP allows unsafe-evalMEDIUMscript-src includes 'unsafe-eval'OWASP A03:2021
CSP frame-ancestors AND X-Frame-Options both missingHIGHClickjacking openCWE-1021
X-Content-Type-Options:nosniff missingMEDIUMMIME-sniff attack openOWASP A05:2021
Referrer-Policy missing or unsafe-urlMEDIUMCross-origin URL leakageOWASP A05:2021
Permissions-Policy missingLOWCamera/mic/geo permissions unrestrictedPermissions Policy spec
Server: header discloses versionLOWnginx/1.18.0 → fingerprintableCWE-200
Cache-Control public on authenticated responseHIGHShared cache may serve user A's response to user BCWE-525

Prerequisites

  • Python 3.9+
  • Authorization for non-local targets

Instructions

Step 1 — Confirm authorization
text
"Do you have authorization to perform header testing on this target?
 I need confirmation before proceeding."
Step 2 — Run the scanner
bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/checking-http-security-headers/scripts/check_headers.py \
    https://example.com \
    --authorized

Options:

Usage: check_headers.py URL [OPTIONS]

Options:
  --authorized       Attest authorization (required for non-local)
  --output FILE
  --format FMT       json | jsonl | markdown (default: markdown)
  --min-severity SEV (default: info)
  --timeout SECS     Per-probe timeout (default: 10)
  --authenticated    Treat as authenticated endpoint (stricter Cache-Control gate)
Step 3 — Interpret findings

HIGH = open exploitable class (no HSTS = MITM downgrade open; no CSP = XSS class wide open; no clickjacking guard = UI-redress attacks). MEDIUM/LOW = posture hardening.

Step 4 — Cross-skill chaining
  • After this skill, suggest auditing-cors-policy (#3) — CSP and CORS interact; certain CSP directives need matching CORS headers.
  • For HSTS preload submission, see references/PLAYBOOK.md § HSTS preload checklist.

Examples

Show full SKILL.md (189 more words)Show less
Example 1 — Mozilla Observatory grade improvement

User: "Observatory gives us a D. What's missing?"

bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/checking-http-security-headers/scripts/check_headers.py \
    https://example.com \
    --authorized \
    --format markdown

The Markdown report groups by severity; map each finding to the PLAYBOOK.md snippet for the target server type. Observatory grade typically moves D → B after addressing all HIGH findings.

Example 2 — HSTS preload eligibility pre-submission

User: "We want to submit to hstspreload.org. Is our HSTS config ready?"

bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/checking-http-security-headers/scripts/check_headers.py \
    https://example.com \
    --authorized --min-severity low

Look for "HSTS max-age below preload threshold" and "includeSubDomains missing" — both must clear before submission, OR hstspreload.org will reject.

Example 3 — Authenticated-endpoint Cache-Control sweep

User: "We had a Cache-Control bug last quarter where authenticated responses got cached publicly. Audit /api/* to make sure it's fixed."

bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/checking-http-security-headers/scripts/check_headers.py \
    https://api.example.com/me \
    --authorized --authenticated

The --authenticated flag bumps Cache-Control posture from MEDIUM to HIGH and adds a check for Cache-Control: public (forbidden on authenticated content).

Output

JSON / JSONL / Markdown. Exit codes 0 / 1 / 2 per lib/report.py.

Error Handling

  • No HTML response → INFO finding noting headers may not apply (JSON APIs use a subset of headers).
  • Redirect to login → follows once, audits the destination page.
  • Connection error → exit 2.

Resources

  • references/THEORY.md — Per-header reasoning, attack-class mapping
  • references/PLAYBOOK.md — Config snippets per server type for each required header
  • ../analyzing-tls-config/references/AUTHORIZATION.md — Active-scan authorization

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/.curated/checking-http-security-headers of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/PLAYBOOK.md
  • references/THEORY.md
  • scripts/check_headers.py

Open the folder on GitHubat commit 23ea8d4

Compare with similar skills

Checking HTTP Security Headers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Checking HTTP Security Headers compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Checking HTTP Security Headers this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Humble Header Report Analystrfc-st/humble379—~3.7kAutomated safety check: PassMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT
Defense In Depthsandgardenhq/sgai1373 repos~970Automated safety check: PassCustom licence
Kesekit Guidecdppcorp/KESE-KIT361—~1.4kAutomated safety check: PassMIT

Similar skills

  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.

    379 GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • Defense In Depth

    sandgardenhq/sgai

    A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…

    137 GitHub starsUsed in 3 repos~970 tokens
    SecurityAuto-check passed
  • Kesekit Guide

    cdppcorp/KESE-KIT

    Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

    361 GitHub stars~1.4k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Kesekit Start

    cdppcorp/KESE-KIT

    Run a security vulnerability assessment based on KISA guidelines.

    361 GitHub stars~2.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Analyzing Text With NLP

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to perform natural language processing and text analysis using the nlp-text-analyzer plugin.

    2.8k GitHub starsUsed in 1 repo~819 tokens
    Auto-check passed
  • Building Neural Networks

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill allows AI assistant to construct and configure neural network architectures using the neural-network-builder plugin.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Detecting Data Anomalies

    jeremylongshore/tons-of-skills-marketplace

    Process identify anomalies and outliers in datasets using machine learning algorithms.

    2.8k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Explaining Machine Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill enables AI assistant to provide interpretability and explainability for machine learning models.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Optimizing Prompts

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill optimizes prompts for large language models (llms) to reduce token usage, lower costs, and improve performance.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed

Categories

Questions about Checking HTTP Security Headers

What does Checking HTTP Security Headers do?

Audit a target's HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin trio (COOP, COEP, CORP). Checking HTTP Security Headers is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit a target's HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin trio (COOP, COEP, CORP).

When should I use Checking HTTP Security Headers?

Checking HTTP Security Headers fits situations like: : SOC2 / PCI auditor flagged missing security headers; A Mozilla Observatory grade is below B; you need HSTS preload eligibility for chrome://net-internals; with: audit security headers.

How do I install Checking HTTP Security Headers in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-http-security-headers -a claude-code`. Or copy the skill folder (skills/.curated/checking-http-security-headers in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/checking-http-security-headers in your project. Claude Code loads it when a task matches its description.

How do I install Checking HTTP Security Headers in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-http-security-headers -a codex`. Or copy the skill folder (skills/.curated/checking-http-security-headers in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/checking-http-security-headers in your project. Codex loads it when a task matches its description.

Can I use Checking HTTP Security Headers in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-http-security-headers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/checking-http-security-headers, .gemini/skills/checking-http-security-headers, .github/skills/checking-http-security-headers and .opencode/skills/checking-http-security-headers in your project.

What does Checking HTTP Security Headers need to run?

Going by SKILL.md and its folder, Checking HTTP Security Headers needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash(python3:*), Bash(curl:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Checking HTTP Security Headers access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Checking HTTP Security Headers safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Checking HTTP Security Headers use?

Checking HTTP Security Headers is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Checking HTTP Security Headers use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Checking HTTP Security Headers?

Skills that share tags, products or a category with Checking HTTP Security Headers: Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Humble Header Report Analyst (rfc-st/humble, 379 stars), Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars) and Defense In Depth (sandgardenhq/sgai, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Checking HTTP Security Headers?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,821 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 8, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.