Agent skill

Validating Cors Policies

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Validate CORS policies for security issues and misconfigurations.

MITAuto-check passedDevOps & Cloud

Install Validating Cors Policies

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill validating-cors-policies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace validating-cors-policies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/validating-cors-policies .claude/skills/validating-cors-policies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validating-cors-policies
GitHub stars
2.8k
Token cost
~1.6k tokens
SKILL.md length
673 words
Files
6 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Validate CORS policies for security issues and misconfigurations.

  • Works in 10 steps: Locate all CORS configuration points by… → Check for wildcard origin… → Detect origin reflection patterns where… → …
  • Reviewing cross-origin resource sharing
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Validating Cors Policies is an agent skill from jeremylongshore/tons-of-skills-marketplace. Validate CORS policies for security issues and misconfigurations. Use when reviewing cross-origin resource sharing. Trigger with 'validate CORS', 'check CORS policy', or 'review cross-origin'.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `scripts/README.md`). Compatibility notes: Designed for Claude Code

It sits in DevOps & Cloud. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Reviewing cross-origin resource sharing
  • With validate CORS
  • Check CORS policy
  • Review cross-origin

Example prompts

  • “validate CORS”
  • “check CORS policy”
  • “review cross-origin”
  • “/validating-cors-policies”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, WebFetch, WebSearch, Grep

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Locate all CORS configuration points by scanning for Access-Control-Allow-Origin, cors() middleware, @CrossOrigin annotations, CORS policy…
  2. Check for wildcard origin (Access-Control-Allow-Origin: *) -- flag as severity high when combined with Access-Control-Allow-Credentials…
  3. Detect origin reflection patterns where the server echoes back the Origin request header without validation -- search for code that reads…
  4. Validate the origin allowlist: check that allowed origins use exact string matching rather than substring or regex patterns vulnerable to…
  5. Assess Access-Control-Allow-Methods -- flag if dangerous methods (PUT, DELETE, PATCH) are exposed without necessity. Verify that preflight…
  6. Evaluate Access-Control-Allow-Headers -- flag wildcard header allowance or exposure of sensitive headers like Authorization, Cookie, or…
  7. Check Access-Control-Expose-Headers for leakage of internal headers (e.g., X-Request-Id, X-Internal-Trace) to cross-origin consumers.
  8. Verify Access-Control-Max-Age is set to a reasonable value (600-86400 seconds) to balance security with performance -- missing or…
  9. For live endpoints, issue preflight requests via WebFetch with various Origin values (legitimate, malicious, null) and analyze the…
  10. Compile findings with severity ratings, map to OWASP Testing Guide OTG-CLIENT-007, and provide remediation with correct CORS middleware…

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • WebFetch
    • WebSearch
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cwe.mitre.org
    • developer.mozilla.org
    • owasp.org
    • fetch.spec.whatwg.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Validating Cors Policies loads about 1.6k tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 54 tokens; SKILL.md has 673 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 673 words, ~1,636 tokens.

Download SKILL.mdSave it as .claude/skills/validating-cors-policies/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
validating-cors-policies
description
Validate CORS policies for security issues and misconfigurations. Use when reviewing cross-origin resource sharing. Trigger with 'validate CORS', 'check CORS policy', or 'review cross-origin'.
allowed-tools
Read, WebFetch, WebSearch, Grep
compatibility
Designed for Claude Code
version
1.24.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
security, validating-cors

Validating CORS Policies

Overview

Validate Cross-Origin Resource Sharing configurations in web applications and APIs for security misconfigurations that enable unauthorized cross-origin access. This skill analyzes CORS headers, middleware configurations, and server response behavior to detect wildcard origins, reflected origins, credential leakage, and overly permissive header/method exposure.

Prerequisites

  • Access to the target codebase and configuration files in ${CLAUDE_SKILL_DIR}/
  • For live endpoint testing: WebFetch tool available and target URLs accessible
  • Familiarity with the web framework in use (Express, Django, Flask, Spring, ASP.NET, etc.)
  • Reference: ${CLAUDE_SKILL_DIR}/references/README.md for CORS specification details, common vulnerability patterns, and example policies

Instructions

  1. Locate all CORS configuration points by scanning for Access-Control-Allow-Origin, cors() middleware, @CrossOrigin annotations, CORS policy builders, and server config directives (nginx add_header, Apache Header set) using Grep.
  2. Check for wildcard origin (Access-Control-Allow-Origin: *) -- flag as severity high when combined with Access-Control-Allow-Credentials: true, which browsers reject but indicates a misunderstanding of the security model.
  3. Detect origin reflection patterns where the server echoes back the Origin request header without validation -- search for code that reads the Origin header and sets it directly in the response. Flag as CWE-942 (Permissive Cross-domain Policy), severity critical.
  4. Validate the origin allowlist: check that allowed origins use exact string matching rather than substring or regex patterns vulnerable to bypass (e.g., example.com.evil.com matching a check for example.com).
  5. Assess Access-Control-Allow-Methods -- flag if dangerous methods (PUT, DELETE, PATCH) are exposed without necessity. Verify that preflight (OPTIONS) responses include appropriate method restrictions.
  6. Evaluate Access-Control-Allow-Headers -- flag wildcard header allowance or exposure of sensitive headers like Authorization, Cookie, or custom auth headers to broader origins than necessary.
  7. Check Access-Control-Expose-Headers for leakage of internal headers (e.g., X-Request-Id, X-Internal-Trace) to cross-origin consumers.
  8. Verify Access-Control-Max-Age is set to a reasonable value (600-86400 seconds) to balance security with performance -- missing or excessively long max-age values deserve a low-severity note.
  9. For live endpoints, issue preflight requests via WebFetch with various Origin values (legitimate, malicious, null) and analyze the response headers to confirm server behavior matches the codebase configuration.
  10. Compile findings with severity ratings, map to OWASP Testing Guide OTG-CLIENT-007, and provide remediation with correct CORS middleware configuration examples.

Output

  • CORS configuration inventory: Table of all CORS-enabled endpoints, their allowed origins, methods, headers, and credentials settings
  • Findings report: Each finding includes severity, affected endpoint/file, CWE reference (CWE-942, CWE-346), observed behavior, and remediation code
  • Preflight test results: For live endpoints, a table of Origin values tested and the corresponding server responses
  • Remediation examples: Framework-specific CORS configuration snippets (Express cors(), Django django-cors-headers, Spring @CrossOrigin, nginx headers)
Show full SKILL.md (255 more words)Show less

Error Handling

ErrorCauseSolution
No CORS configuration foundCORS handled at infrastructure layer (CDN, API gateway)Check CDN/gateway configs (Cloudflare, AWS API Gateway, nginx) for CORS header injection
WebFetch blocked or timed outTarget endpoint unreachable or rate-limitedVerify URL accessibility; fall back to static codebase analysis of CORS middleware configuration
Inconsistent CORS behavior across endpointsMultiple CORS configurations at different layersMap each layer (application, reverse proxy, CDN) and document the effective policy per endpoint
Origin reflection false positiveDynamic origin validation with a secure allowlistVerify the allowlist logic uses exact matching; mark as informational if the implementation is secure
Preflight not triggeringRequest classified as "simple request" by the browserNote that simple GET/POST requests bypass preflight; test with custom headers to force preflight

Examples

Express.js CORS Middleware Audit

Scan ${CLAUDE_SKILL_DIR}/src/app.js and ${CLAUDE_SKILL_DIR}/src/middleware/ for cors() configuration. Flag origin: true (reflects any origin) as CWE-942, severity critical. Recommend replacing with an explicit allowlist: origin: ['https://app.example.com', 'https://admin.example.com'].

Nginx CORS Header Review

Grep ${CLAUDE_SKILL_DIR}/nginx/ for add_header Access-Control-Allow-Origin. Flag any $http_origin variable usage that reflects the origin without validation. Verify that Access-Control-Allow-Credentials is only set for origins in the allowlist using an if block or map directive.

API Gateway CORS Configuration

Review ${CLAUDE_SKILL_DIR}/infra/api-gateway.yaml or equivalent IaC definitions for CORS settings. Flag wildcard * in allowed origins when credentials are enabled. Verify that Access-Control-Allow-Methods is scoped to only the HTTP methods each endpoint actually supports.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in skills/.curated/validating-cors-policies of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/README.md
  • scripts/README.md
  • scripts/generate_test_cases.py
  • scripts/validate_cors.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Validating Cors Policies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validating Cors Policies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validating Cors Policies this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMIT
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Mirrord Operatormetalbear-co/mirrord5.4k1 repos~4.6kAutomated safety check: PassMIT
Azure PricingAzure/Copilot-Studio-and-Azure1102 repos~2.4kAutomated safety check: PassMIT
NGINX Ingress Policy CRD Guidenginx/kubernetes-ingress5.1k—~2kAutomated safety check: PassApache-2.0
Distributed Tracingwshobson/agents40k12 repos~527Automated safety check: PassMIT

Similar skills

  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Mirrord Operator

    metalbear-co/mirrord

    Help users install and configure the mirrord Operator for team/enterprise environments.

    5.4k GitHub starsUsed in 1 repo~4.6k tokens
    DevOps & CloudAuto-check passed
  • Azure Pricing

    Azure/Copilot-Studio-and-Azure

    Official

    Fetches real-time Azure retail pricing using the Azure Retail Prices API (prices.azure.com) and estimates Copilot Studio agent credit consumption.

    110 GitHub starsUsed in 2 repos~2.4k tokens
    DevOps & CloudAuto-check passed
  • NGINX Ingress Policy CRD Guide

    nginx/kubernetes-ingress

    Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.

    5.1k GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Distributed Tracing

    wshobson/agents

    Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.

    40k GitHub starsUsed in 12 repos~527 tokens
    DevOps & CloudAuto-check passed
  • ArvanCloud API Operator

    erfnzdeh/arvancloud-agent-skill

    Drives ArvanCloud's REST APIs for CDN, DNS, cloud servers, object storage and more, with helper scripts for calls, account inventory and certificates.

    134 GitHub stars~3.9k tokensUpdated 12 days ago
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Validating Cors Policies

What does Validating Cors Policies do?

Validate CORS policies for security issues and misconfigurations. Validating Cors Policies is an agent skill from jeremylongshore/tons-of-skills-marketplace. Validate CORS policies for security issues and misconfigurations.

When should I use Validating Cors Policies?

Validating Cors Policies fits situations like: reviewing cross-origin resource sharing; with validate CORS; check CORS policy; review cross-origin.

How do I install Validating Cors Policies in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill validating-cors-policies -a claude-code`. Or copy the skill folder (skills/.curated/validating-cors-policies in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/validating-cors-policies in your project. Claude Code loads it when a task matches its description.

How do I install Validating Cors Policies in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill validating-cors-policies -a codex`. Or copy the skill folder (skills/.curated/validating-cors-policies in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/validating-cors-policies in your project. Codex loads it when a task matches its description.

Can I use Validating Cors Policies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill validating-cors-policies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validating-cors-policies, .gemini/skills/validating-cors-policies, .github/skills/validating-cors-policies and .opencode/skills/validating-cors-policies in your project.

What does Validating Cors Policies need to run?

Going by SKILL.md and its folder, Validating Cors Policies needs Python for the scripts in its folder. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, WebFetch, WebSearch, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Validating Cors Policies access the network?

SKILL.md names 4 domains. As links in the text: cwe.mitre.org, developer.mozilla.org, owasp.org and fetch.spec.whatwg.org. This is read from the text; nothing was executed.

Is Validating Cors Policies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Validating Cors Policies use?

Validating Cors Policies is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validating Cors Policies use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16 tokens, read only when the agent opens those files.

What are the alternatives to Validating Cors Policies?

Skills that share tags, products or a category with Validating Cors Policies: KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Mirrord Operator (metalbear-co/mirrord, 5.4k stars), Azure Pricing (Azure/Copilot-Studio-and-Azure, 110 stars) and NGINX Ingress Policy CRD Guide (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validating Cors Policies?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.