Agent skill

Security Headers Configuration

by secondsky in secondsky/claude-skills

Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks.

MITAuto-check passedSecurity

Install Security Headers Configuration

skills CLI
$ npx skills add secondsky/claude-skills --skill security-headers-configuration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/claude-skills security-headers-configuration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/security-headers-configuration/skills/security-headers-configuration .claude/skills/security-headers-configuration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-headers-configuration
GitHub stars
227
Token cost
~638 tokens
SKILL.md length
116 words
Files
2 (incl. references)
Skills in repo
169
Repo updated
First seen
Licence
MIT

At a glance

Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks.

  • Hardening web applications
  • SKILL.md covers Essential Headers, Express Implementation, Nginx Configuration and Verification Tools, plus 3 more sections
  • Reaches fonts.gstatic.com
  • Passing security audits

What it does

Security Headers Configuration is an agent skill from secondsky/claude-skills. Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks. Use when hardening web applications, passing security audits, or implementing Content Security Policy.

Its SKILL.md is about 640 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/python-apache.md`).

It sits in Security, covering Secure coding, Security review and Web application vulnerabilities. It works with Python. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.

When your agent uses it

  • Hardening web applications
  • Passing security audits
  • Implementing Content Security Policy

Example prompts

  • “Use the security-headers-configuration skill to configure HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks”
  • “/security-headers-configuration”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript and nginx).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • fonts.gstatic.com

    Also links to:

    • securityheaders.com
    • observatory.mozilla.org
    • csp-evaluator.withgoogle.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Headers Configuration loads about 638 tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 58 tokens; SKILL.md has 116 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~638
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 116 words, ~638 tokens.

Download SKILL.mdSave it as .claude/skills/security-headers-configuration/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-headers-configuration
description
Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks. Use when hardening web applications, passing security audits, or implementing Content Security Policy.
license
MIT

Security Headers Configuration

Implement HTTP security headers to defend against common browser-based attacks.

Essential Headers

HeaderPurposeValue
HSTSForce HTTPSmax-age=31536000; includeSubDomains
CSPRestrict resourcesdefault-src 'self'
X-Frame-OptionsPrevent clickjackingDENY
X-Content-Type-OptionsPrevent MIME sniffingnosniff

Express Implementation

javascript
const helmet = require('helmet');

app.use(helmet());

// Custom CSP
app.use(helmet.contentSecurityPolicy({
  directives: {
    defaultSrc: ["'self'"],
    scriptSrc: ["'self'", "'unsafe-inline'"],
    styleSrc: ["'self'", "'unsafe-inline'"],
    imgSrc: ["'self'", "data:", "https:"],
    connectSrc: ["'self'", "https://api.example.com"],
    fontSrc: ["'self'", "https://fonts.gstatic.com"],
    frameAncestors: ["'none'"]
  }
}));

Nginx Configuration

nginx
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
add_header X-Frame-Options "DENY" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self'" always;

Verification Tools

Security Headers Checklist

  • HSTS enabled with long max-age
  • CSP configured and tested
  • X-Frame-Options set to DENY
  • X-Content-Type-Options set to nosniff
  • Referrer-Policy configured
  • Permissions-Policy disables unused features

Additional Implementations

See references/python-apache.md for:

  • Python Flask security headers middleware
  • Flask-Talisman library configuration
  • Apache .htaccess configuration
  • Header testing script

Common Mistakes

  • Setting CSP to report-only permanently
  • Using overly permissive policies
  • Forgetting to test after changes
  • Not including all subdomains in HSTS

© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/security-headers-configuration/skills/security-headers-configuration of secondsky/claude-skills.

  • SKILL.md
  • references/python-apache.md

Open the folder on GitHubat commit 8837836

Compare with similar skills

Security Headers Configuration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Headers Configuration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Headers Configuration this skillsecondsky/claude-skills227—~638Automated safety check: PassMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check: notes
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Python kwargs setattr Allowlist

    microsoft/onnxruntime

    Official

    Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects.

    22k GitHub stars~737 tokensUpdated today
    SecurityAuto-check passed

More from secondsky/claude-skills

All 169 skills in this repo
  • Tanstack AI

    secondsky/claude-skills

    TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.

    227 GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check: notes
  • Auto Animate

    secondsky/claude-skills

    AutoAnimate (@formkit/auto-animate) zero-config animations for React.

    227 GitHub stars~2.9k tokensUpdated 9 days ago
    Auto-check passed
  • Base UI React

    secondsky/claude-skills

    MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.

    227 GitHub stars~1.9k tokensUpdated 9 days ago
    Auto-check passed
  • Cloudflare Images

    secondsky/claude-skills

    This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…

    227 GitHub stars~3.6k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Nextjs

    secondsky/claude-skills

    Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).

    227 GitHub stars~5.3k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Sandbox

    secondsky/claude-skills

    Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.

    227 GitHub stars~4.5k tokensUpdated 9 days ago
    Auto-check passed

Works with

Categories

Questions about Security Headers Configuration

What does Security Headers Configuration do?

Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks. Security Headers Configuration is an agent skill from secondsky/claude-skills. Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks.

When should I use Security Headers Configuration?

Security Headers Configuration fits situations like: hardening web applications; passing security audits; implementing Content Security Policy.

How do I install Security Headers Configuration in Claude Code?

Run `npx skills add secondsky/claude-skills --skill security-headers-configuration -a claude-code`. Or copy the skill folder (plugins/security-headers-configuration/skills/security-headers-configuration in secondsky/claude-skills) into .claude/skills/security-headers-configuration in your project. Claude Code loads it when a task matches its description.

How do I install Security Headers Configuration in Codex?

Run `npx skills add secondsky/claude-skills --skill security-headers-configuration -a codex`. Or copy the skill folder (plugins/security-headers-configuration/skills/security-headers-configuration in secondsky/claude-skills) into .agents/skills/security-headers-configuration in your project. Codex loads it when a task matches its description.

Can I use Security Headers Configuration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill security-headers-configuration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-headers-configuration, .gemini/skills/security-headers-configuration, .github/skills/security-headers-configuration and .opencode/skills/security-headers-configuration in your project.

What does Security Headers Configuration need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Headers Configuration is instructions for the agent only. Our summary lists: Python 3.

Does Security Headers Configuration access the network?

SKILL.md names 4 domains. In commands or code: fonts.gstatic.com; the agent is likely to contact it when it follows the instructions. As links in the text: securityheaders.com, observatory.mozilla.org and csp-evaluator.withgoogle.com. This is read from the text; nothing was executed.

Is Security Headers Configuration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Headers Configuration use?

Security Headers Configuration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Headers Configuration use?

About 638 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Security Headers Configuration?

Skills that share tags, products or a category with Security Headers Configuration: Security Auditor (eigent-ai/eigent, 15k stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Headers Configuration?

secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.

Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.