Agent skill

Securityheaders

by taracodlabs in taracodlabs/aiden

HTTP security header audit (A+ to F) with fix recommendations

Apache-2.0Auto-check passedSecurity

Install Securityheaders

skills CLI
$ npx skills add taracodlabs/aiden --skill securityheaders -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install taracodlabs/aiden securityheaders --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/taracodlabs/aiden.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/securityheaders .claude/skills/securityheaders && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
securityheaders
GitHub stars
849
Token cost
~956 tokens
SKILL.md length
263 words
Files
3
Skills in repo
63
Repo updated
First seen
Licence
Apache-2.0

At a glance

HTTP security header audit (A+ to F) with fix recommendations

  • Tasks that involve Secure coding
  • SKILL.md covers When to Use, How to Use, Examples and Cautions, plus 1 more section
  • Runs TypeScript scripts from its folder; reaches securityheaders.com and taracod.com

What it does

Securityheaders is an agent skill from taracodlabs/aiden. HTTP security header audit (A+ to F) with fix recommendations

Its SKILL.md is about 960 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `index.ts` and `skill.json`).

It sits in Security, covering Secure coding. The repository describes itself as: Aiden — an autonomous AI agent and work engine built solo. It can operate your browser, terminal, files, apps, APIs, skills and tools, remember context, recover from failures… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Secure coding

Example prompts

  • “/securityheaders”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 3704204. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • securityheaders.com
    • taracod.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Securityheaders loads about 956 tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 263 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~956

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from taracodlabs/aiden at commit 3704204, republished under its Apache-2.0 licence (© taracodlabs). 263 words, ~956 tokens.

Download SKILL.mdSave it as .claude/skills/securityheaders/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
securityheaders
description
HTTP security header audit (A+ to F) with fix recommendations
category
security
version
1.0.0
license
Apache-2.0
origin
aiden
tags
security, http, headers, csp, hsts, xframe, audit, web, hardening, compliance

Security Headers — HTTP Header Audit

Check any website for missing or misconfigured HTTP security headers. Returns a grade from A+ to F with a list of which headers are present, which are absent, and why each matters for protection against XSS, clickjacking, MIME sniffing, and data leakage.

No API key required. Powered by securityheaders.com.

When to Use

  • Audit a website before a security review or penetration test
  • Verify that a newly deployed application has the correct security headers
  • Check compliance with security baselines (OWASP, NIST, CIS)
  • User asks "check security headers for X", "is example.com missing HSTS?", "grade the headers on my site"

How to Use

Check security headers for a URL
powershell
$target  = "https://taracod.com"
$encoded = [Uri]::EscapeDataString($target)
$url     = "https://securityheaders.com/?q=$encoded&followRedirects=on&hide=on"

$response = Invoke-WebRequest -Uri $url -UseBasicParsing
# Extract grade from HTML badge
$grade = if ($response.Content -match 'class="[^"]*reportTitle[^"]*"[^>]*>[\s\S]*?label[^"]*"([^"]+)"') {
    $Matches[1] -replace 'label[- ]', '' -replace 'success', 'A' -replace 'warning', 'B/C' -replace 'danger', 'D/F'
} else { 'check manually' }

Write-Host "URL:   $target"
Write-Host "Grade: $grade"
Write-Host "Full report: $url"
Audit headers and list missing ones
powershell
$target   = "https://example.com"
$encoded  = [Uri]::EscapeDataString($target)
$response = Invoke-WebRequest -Uri "https://securityheaders.com/?q=$encoded&followRedirects=on&hide=on" -UseBasicParsing
$html     = $response.Content

# Extract missing headers (rows marked as warnings/missing)
$pattern  = '<div[^>]*class="[^"]*missing[^"]*"[^>]*>([\s\S]*?)<\/div>'
$missing  = [regex]::Matches($html, $pattern) | ForEach-Object {
    $_.Groups[1].Value -replace '<[^>]+>', '' -replace '\s+', ' '
} | Where-Object { $_.Trim() }

Write-Host "Missing headers:"
$missing | ForEach-Object { Write-Host "  ✗ $($_.Trim())" }
Write-Host ""
Write-Host "Report: https://securityheaders.com/?q=$encoded&followRedirects=on"
Key security headers and what they do
Strict-Transport-Security  → Forces HTTPS; prevents downgrade attacks
Content-Security-Policy    → Restricts content sources; blocks XSS
X-Frame-Options            → Prevents clickjacking (deprecated by CSP)
X-Content-Type-Options     → Blocks MIME-sniffing attacks
Referrer-Policy            → Controls referrer data leakage
Permissions-Policy         → Restricts browser feature access (camera, location, etc.)

Examples

"Audit security headers for taracod.com" → Returns grade, lists present and missing headers with fix suggestions.

"Does github.com have Content-Security-Policy?" → Check the headers report — CSP row shows value if present.

"My site is getting an F — what headers am I missing?" → Audit returns the full missing-headers list with descriptions.

"Check HSTS on my production domain" → Look for Strict-Transport-Security in the report — check max-age value.

Cautions

  • hide=on prevents results from appearing in the public "recent scans" feed — always use it
  • followRedirects=on ensures the final destination URL is scanned, not just the redirect
  • The tool scans what headers are sent — not what your server config says it should send
  • Rate-limit: do not hammer the free service; add delays when scanning multiple URLs
  • Grade is based on header presence, not perfect configuration — review values manually

Requirements

  • None — no API key needed

© taracodlabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/securityheaders of taracodlabs/aiden.

  • SKILL.md
  • index.ts
  • skill.json

Open the folder on GitHubat commit 3704204

Compare with similar skills

Securityheaders next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Securityheaders compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Securityheaders this skilltaracodlabs/aiden849—~956Automated safety check: PassApache-2.0
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Humble Header Report Analystrfc-st/humble378—~3.7kAutomated safety check: PassMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT
Defense In Depthsandgardenhq/sgai1373 repos~970Automated safety check: PassCustom licence
Kesekit Guidecdppcorp/KESE-KIT359—~1.4kAutomated safety check: PassMIT

Similar skills

  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.

    378 GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • Defense In Depth

    sandgardenhq/sgai

    A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…

    137 GitHub starsUsed in 3 repos~970 tokens
    SecurityAuto-check passed
  • Kesekit Guide

    cdppcorp/KESE-KIT

    Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

    359 GitHub stars~1.4k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Kesekit Start

    cdppcorp/KESE-KIT

    Run a security vulnerability assessment based on KISA guidelines.

    359 GitHub stars~2.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed

More from taracodlabs/aiden

All 63 skills in this repo
  • Google Flights Search

    taracodlabs/aiden

    Searches Google Flights for prices, schedules and availability through browser automation with URL-based queries, and stops short of booking.

    849 GitHub stars~1.5k tokensUpdated 24 days ago
    Auto-check passed
  • OpenAI Codex CLI Bridge

    taracodlabs/aiden

    Delegates code generation, editing and explanation tasks to the OpenAI Codex CLI, with commands for interactive, auto-edit, question-only and model-specific runs.

    849 GitHub starsUsed in 1 repo~826 tokens
    Auto-check passed
  • Google Hotels Search

    taracodlabs/aiden

    Searches Google Hotels through the agent-browser tool for prices, ratings, amenities and availability, building a search URL from the location and dates and reporting a results table.

    849 GitHub stars~1.5k tokensUpdated 24 days ago
    Auto-check passed
  • Generates dark-themed architecture, component, data-flow and network diagrams as self-contained HTML and SVG files that open in any browser.

    849 GitHub stars~1.3k tokensUpdated 24 days ago
    Auto-check passed
  • Aggregates holdings across Zerodha, Upstox and Angel One and normalizes order parameters into one format, with confirmation required before any routing.

    849 GitHub stars~1.1k tokensUpdated 24 days ago
    Auto-check passed
  • arXiv Paper Search

    taracodlabs/aiden

    Searches arXiv by keyword, category, author or paper ID through its public API and downloads PDFs, with no API key needed.

    849 GitHub stars~1k tokensUpdated 24 days ago
    Auto-check passed

Categories

Questions about Securityheaders

What does Securityheaders do?

HTTP security header audit (A+ to F) with fix recommendations. Securityheaders is an agent skill from taracodlabs/aiden.

When should I use Securityheaders?

Securityheaders fits situations like: tasks that involve Secure coding.

How do I install Securityheaders in Claude Code?

Run `npx skills add taracodlabs/aiden --skill securityheaders -a claude-code`. Or copy the skill folder (skills/securityheaders in taracodlabs/aiden) into .claude/skills/securityheaders in your project. Claude Code loads it when a task matches its description.

How do I install Securityheaders in Codex?

Run `npx skills add taracodlabs/aiden --skill securityheaders -a codex`. Or copy the skill folder (skills/securityheaders in taracodlabs/aiden) into .agents/skills/securityheaders in your project. Codex loads it when a task matches its description.

Can I use Securityheaders in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add taracodlabs/aiden --skill securityheaders -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/securityheaders, .gemini/skills/securityheaders, .github/skills/securityheaders and .opencode/skills/securityheaders in your project.

What does Securityheaders need to run?

Going by SKILL.md and its folder, Securityheaders needs TypeScript for the scripts in its folder. Our summary lists: Node.js.

Does Securityheaders access the network?

SKILL.md names 2 domains. In commands or code: securityheaders.com and taracod.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Securityheaders safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Securityheaders use?

Securityheaders is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Securityheaders use?

About 956 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Securityheaders?

Skills that share tags, products or a category with Securityheaders: Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Humble Header Report Analyst (rfc-st/humble, 378 stars), Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars) and Defense In Depth (sandgardenhq/sgai, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Securityheaders?

taracodlabs (a GitHub organization) maintains it in taracodlabs/aiden, which has 849 GitHub stars. The repository holds 63 skills in this directory. The repository was last updated on September 13, 2026.

Source: taracodlabs/aiden on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.