Analyze HTTP security headers of web domains to identify vulnerabilities and misconfigurations. Use when you need to audit website security headers, assess header compliance, or get security recommendations for web applications. Trigger with phrases like "analyze security headers", "check HTTP headers", "audit website security headers", or "evaluate CSP and HSTS configuration".
Fetches and evaluates HTTP security headers for web domains to identify vulnerabilities and misconfigurations. Used when auditing website security, checking header compliance, or assessing CSP and HSTS configurations.
/plugin marketplace add jeremylongshore/claude-code-plugins-plus-skills/plugin install security-headers-analyzer@claude-code-plugins-plusThis skill is limited to using the following tools:
assets/README.mdreferences/README.mdreferences/errors.mdreferences/examples.mdreferences/implementation.mdscripts/README.mdscripts/analyze_headers.pyscripts/generate_report.pyThis skill provides automated assistance for the described functionality.
Before using this skill, ensure:
See {baseDir}/references/implementation.md for detailed implementation guide.
The skill produces:
Primary Output: Security headers analysis report
Report Structure:
# Security Headers Analysis - example.com
## Error Handling
See `{baseDir}/references/errors.md` for comprehensive error handling.
## Examples
See `{baseDir}/references/examples.md` for detailed examples.
## Resources
- OWASP Secure Headers Project: https://owasp.org/www-project-secure-headers/
- MDN Security Headers Guide: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers#security
- Security Headers Scanner: https://securityheaders.com/
- CSP Reference: https://content-security-policy.com/
- HSTS Preload: https://hstspreload.org/