Skill file
---
name: security-headers-review
description: "Reviews HTTP security headers and cookie settings for a site and gives the exact configuration. Use for web hardening."
---
# Security headers review
A few headers block many common attacks.
## How to work
1. Fetch the headers or read the server config.
2. Check CSP, HSTS, X-Content-Type-Options, frame protection, referrer policy and permissions policy.
3. Check cookie flags: Secure, HttpOnly, SameSite.
4. Explain the risk of each gap.
5. Provide the config for the server in use.
## Rules
- Test a strict policy in report-only mode first.
- Do not break the site: list what to check.
## Output
A table of headers with status and recommended values.
How to use it
- Download the skill.
- Put its folder (with SKILL.md inside) in .claude/skills/security-headers-review/ for just this project, or in ~/.claude/skills/ for every project.
- Restart your tool and ask for what the skill does. It loads on its own when it fits.
Try it
Review the security headers of https://example.com.
Reviews HTTP security headers and cookie settings for a site and gives the exact configuration. Use for web hardening.