Wardn Hub
MCP ServersSkillsCategoriesAPI docsSubmit server
Submit server
Wardn HubTrusted MCP server directory.

Registry

  • MCP Servers
  • Skills
  • Categories

Resources

  • API docs
  • Score method

Contribute

  • Submit server
  • Advertise
© 2026 Wardn Hub
Wardn Hub
MCP ServersSkillsCategoriesAPI docsSubmit server
Submit server
skills/jeremylongshore/claude-code-plugins-plus-skills/curated-checking-http-security-headers

curated-checking-http-security-headers

1
jeremylongshore/claude-code-plugins-plus-skills·Security·Audit pending·Snapshot 7271d6a72b71

Summary

This source did not publish a separate summary. Review SKILL.md before using the skill.

SKILL.md

Checking HTTP Security Headers

Overview

HTTP response headers are the cheapest defense-in-depth layer most web apps ship. Each header closes one specific attack class — HSTS forces HTTPS, CSP blocks script injection, X-Frame-Options blocks clickjacking, etc. Missing headers don't break the app; they just leave the attack class open. This skill probes for the presence + value correctness of the canonical security-relevant headers.

When the skill produces findings

FindingSeverityThresholdAffected control
HSTS header missingHIGHNo Strict-Transport-Security on HTTPS responseOWASP A05:2021
HSTS max-age below preload thresholdMEDIUMmax-age under 31536000s (1y)hstspreload.org
HSTS includeSubDomains missing for preloadLOWpreload directive without includeSubDomainshstspreload.org
CSP header missingHIGHNo Content-Security-Policy headerOWASP A03:2021
CSP allows unsafe-inlineMEDIUMscript-src or style-src includes 'unsafe-inline'OWASP A03:2021
CSP allows unsafe-evalMEDIUMscript-src includes 'unsafe-eval'OWASP A03:2021
CSP frame-ancestors AND X-Frame-Options both missingHIGHClickjacking openCWE-1021
X-Content-Type-Options:nosniff missingMEDIUMMIME-sniff attack openOWASP A05:2021
Referrer-Policy missing or unsafe-urlMEDIUMCross-origin URL leakageOWASP A05:2021
Permissions-Policy missingLOWCamera/mic/geo permissions unrestrictedPermissions Policy spec
Server: header discloses versionLOWnginx/1.18.0 → fingerprintableCWE-200
Cache-Control public on authenticated responseHIGHShared cache may serve user A's response to user BCWE-525

Prerequisites

  • Python 3.9+
  • Authorization for non-local targets

Instructions

Step 1 — Confirm authorization

"Do you have authorization to perform header testing on this target?
 I need confirmation before proceeding."

Step 2 — Run the scanner

python3 ${CLAUDE_PLUGIN_ROOT}/skills/checking-http-security-headers/scripts/check_headers.py \
    https://example.com \
    --authorized

Options:

Usage: check_headers.py URL [OPTIONS]

Options:
  --authorized       Attest authorization (required for non-local)
  --output FILE
  --format FMT       json | jsonl | markdown (default: markdown)
  --min-severity SEV (default: info)
  --timeout SECS     Per-probe timeout (default: 10)
  --authenticated    Treat as authenticated endpoint (stricter Cache-Control gate)

Step 3 — Interpret findings

HIGH = open exploitable class (no HSTS = MITM downgrade open; no CSP = XSS class wide open; no clickjacking guard = UI-redress attacks). MEDIUM/LOW = posture hardening.

Step 4 — Cross-skill chaining

  • After this skill, suggest auditing-cors-policy (#3) — CSP and CORS interact; certain CSP directives need matching CORS headers.
  • For HSTS preload submission, see references/PLAYBOOK.md § HSTS preload checklist.

Examples

Example 1 — Mozilla Observatory grade improvement

User: "Observatory gives us a D. What's missing?"

python3 ${CLAUDE_PLUGIN_ROOT}/skills/checking-http-security-headers/scripts/check_headers.py \
    https://example.com \
    --authorized \
    --format markdown

The Markdown report groups by severity; map each finding to the PLAYBOOK.md snippet for the target server type. Observatory grade typically moves D → B after addressing all HIGH findings.

Example 2 — HSTS preload eligibility pre-submission

User: "We want to submit to hstspreload.org. Is our HSTS config ready?"

python3 ${CLAUDE_PLUGIN_ROOT}/skills/checking-http-security-headers/scripts/check_headers.py \
    https://example.com \
    --authorized --min-severity low

Look for "HSTS max-age below preload threshold" and "includeSubDomains missing" — both must clear before submission, OR hstspreload.org will reject.

Example 3 — Authenticated-endpoint Cache-Control sweep

User: "We had a Cache-Control bug last quarter where authenticated responses got cached publicly. Audit /api/* to make sure it's fixed."

python3 ${CLAUDE_PLUGIN_ROOT}/skills/checking-http-security-headers/scripts/check_headers.py \
    https://api.example.com/me \
    --authorized --authenticated

The --authenticated flag bumps Cache-Control posture from MEDIUM to HIGH and adds a check for Cache-Control: public (forbidden on authenticated content).

Output

JSON / JSONL / Markdown. Exit codes 0 / 1 / 2 per lib/report.py.

Error Handling

  • No HTML response → INFO finding noting headers may not apply (JSON APIs use a subset of headers).
  • Redirect to login → follows once, audits the destination page.
  • Connection error → exit 2.

Resources

  • references/THEORY.md — Per-header reasoning, attack-class mapping
  • references/PLAYBOOK.md — Config snippets per server type for each required header
  • ../analyzing-tls-config/references/AUTHORIZATION.md — Active-scan authorization

Related skills

implementing-backup-strategieskubernetes-secrets-managerbuilding-gitops-workflowsmanaging-api-cachemanaging-network-policies