product image

Security headers skill for Claude Code — dead headers and broken CSP

$12

18 header findings in one _headers file, each with file:line and the reason

On the bundled sample: 18 findings (11 errors, 4 warnings, 3 info) in 1 file from 28 rules, including ALLOW-FROM, X-XSS-Protection, an unquoted CSP self and a hard-coded nonce.

What you get
• SKILL.md, an offline Node scanner (scripts/scan.js) and the 28-rule table
• file:line, severity and why the browser ignores or weakens each header
• Replacement lines, applied only after you agree
• CI: node scripts/scan.js . exits 1 on any error

Install in 30 seconds
Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: “Review the security headers in this repo. Is anything obsolete or not actually enforced? Don’t edit anything yet.”. Needs Node 16+.

What it does not do
It does not fetch your live site or see headers set by a CDN or app code; no network calls, no edits without your OK.

FAQ
Q: How is this different from asking Claude without the skill?
A: The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of guessing from memory.
Q: How do I get the files?
A: After paying, open it in your Whop library: in “Download — security-headers-review” the lesson “security-headers-review.zip” has the zip attached.