Skip to content
Back to skills

Security Headers

ASecurity

Verify and configure HTTP security headers (CSP, HSTS, CORS, X-Frame-Options, etc). Checks current configuration and generates framework-specific fixes.

  • 29 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 28, 2026
ai-agentsgonextjsexpressdjangosecurity

Works with

  • cli

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned May 28, 2026

npx -y skills add fusengine/agents --skill security-headers --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Headers?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Headers
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/fusengine-security-headers/badge)](https://www.skillsdirectory.com/skills/fusengine-security-headers)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-headers
description: Verify and configure HTTP security headers (CSP, HSTS, CORS, X-Frame-Options, etc). Checks current configuration and generates framework-specific fixes.
argument-hint: "[framework]"
user-invocable: true
---

# Security Headers Skill

## Overview

Audit and configure HTTP security headers for web applications.

## Required Headers

| Header | Purpose | Severity if Missing |
|--------|---------|-------------------|
| Content-Security-Policy | Prevent XSS/injection | HIGH |
| Strict-Transport-Security | Force HTTPS | HIGH |
| X-Content-Type-Options | Prevent MIME sniffing | MEDIUM |
| X-Frame-Options | Prevent clickjacking | MEDIUM |
| Referrer-Policy | Control referrer info | LOW |
| Permissions-Policy | Control browser features | LOW |
| X-XSS-Protection | Legacy XSS filter | LOW |

## Workflow

1. **Detect** framework (Next.js, Laravel, Express, etc.)
2. **Check** current header configuration
3. **Compare** against security best practices
4. **Generate** framework-specific configuration
5. **Validate** headers are properly set

## Detection Points

| Framework | Config Location |
|-----------|----------------|
| Next.js | `next.config.js` headers, `middleware.ts` |
| Laravel | `SecurityHeaders` middleware |
| Express | `helmet` middleware |
| Django | `SECURE_*` settings |

## References

- [Headers Reference](references/headers-reference.md)
- [Config Templates](references/templates/headers-config.md)

Files in this skill

  • SKILL.md1.4 KB
  • references/headers-reference.md1.8 KB
  • references/templates/headers-config.md1.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…