security-headers

Security Headers Skill

Safety Notice

This listing is imported from skills.sh public index metadata. Review upstream SKILL.md and repository scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "security-headers" with this command: npx skills add fusengine/agents/fusengine-agents-security-headers

Security Headers Skill

Overview

Audit and configure HTTP security headers for web applications.

Required Headers

Header Purpose Severity if Missing

Content-Security-Policy Prevent XSS/injection HIGH

Strict-Transport-Security Force HTTPS HIGH

X-Content-Type-Options Prevent MIME sniffing MEDIUM

X-Frame-Options Prevent clickjacking MEDIUM

Referrer-Policy Control referrer info LOW

Permissions-Policy Control browser features LOW

X-XSS-Protection Legacy XSS filter LOW

Workflow

  • Detect framework (Next.js, Laravel, Express, etc.)

  • Check current header configuration

  • Compare against security best practices

  • Generate framework-specific configuration

  • Validate headers are properly set

Detection Points

Framework Config Location

Next.js next.config.js headers, middleware.ts

Laravel SecurityHeaders middleware

Express helmet middleware

Django SECURE_* settings

References

  • Headers Reference

  • Config Templates

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

react-effects-audit

No summary provided by upstream source.

Repository SourceNeeds Review
Security

auth-audit

No summary provided by upstream source.

Repository SourceNeeds Review
Security

dependency-audit

No summary provided by upstream source.

Repository SourceNeeds Review
Security

security-scan

No summary provided by upstream source.

Repository SourceNeeds Review