This source did not publish a separate summary. Review SKILL.md before using the skill.
SKILL.md
Checking HTTP Security Headers
Overview
HTTP response headers are the cheapest defense-in-depth layer most web
apps ship. Each header closes one specific attack class — HSTS forces
HTTPS, CSP blocks script injection, X-Frame-Options blocks clickjacking,
etc. Missing headers don't break the app; they just leave the attack
class open. This skill probes for the presence + value correctness of
the canonical security-relevant headers.
When the skill produces findings
Finding
Severity
Threshold
Affected control
HSTS header missing
HIGH
No Strict-Transport-Security on HTTPS response
OWASP A05:2021
HSTS max-age below preload threshold
MEDIUM
max-age under 31536000s (1y)
hstspreload.org
HSTS includeSubDomains missing for preload
LOW
preload directive without includeSubDomains
hstspreload.org
CSP header missing
HIGH
No Content-Security-Policy header
OWASP A03:2021
CSP allows unsafe-inline
MEDIUM
script-src or style-src includes 'unsafe-inline'
OWASP A03:2021
CSP allows unsafe-eval
MEDIUM
script-src includes 'unsafe-eval'
OWASP A03:2021
CSP frame-ancestors AND X-Frame-Options both missing
HIGH
Clickjacking open
CWE-1021
X-Content-Type-Options:nosniff missing
MEDIUM
MIME-sniff attack open
OWASP A05:2021
Referrer-Policy missing or unsafe-url
MEDIUM
Cross-origin URL leakage
OWASP A05:2021
Permissions-Policy missing
LOW
Camera/mic/geo permissions unrestricted
Permissions Policy spec
Server: header discloses version
LOW
nginx/1.18.0 → fingerprintable
CWE-200
Cache-Control public on authenticated response
HIGH
Shared cache may serve user A's response to user B
CWE-525
Prerequisites
Python 3.9+
Authorization for non-local targets
Instructions
Step 1 — Confirm authorization
"Do you have authorization to perform header testing on this target?
I need confirmation before proceeding."
HIGH = open exploitable class (no HSTS = MITM downgrade open; no CSP =
XSS class wide open; no clickjacking guard = UI-redress attacks).
MEDIUM/LOW = posture hardening.
Step 4 — Cross-skill chaining
After this skill, suggest auditing-cors-policy (#3) — CSP and CORS
interact; certain CSP directives need matching CORS headers.
For HSTS preload submission, see references/PLAYBOOK.md § HSTS
preload checklist.
The Markdown report groups by severity; map each finding to the
PLAYBOOK.md snippet for the target server type. Observatory grade
typically moves D → B after addressing all HIGH findings.
Example 2 — HSTS preload eligibility pre-submission
User: "We want to submit to hstspreload.org. Is our HSTS config ready?"
The --authenticated flag bumps Cache-Control posture from MEDIUM to
HIGH and adds a check for Cache-Control: public (forbidden on
authenticated content).