Security Headers Hardener

Audit and harden a web app's or API's HTTP security headers — Content-Security-Policy, HSTS, X-Content-Type-Options, frame-ancestors, Referrer-Policy, Permissions-Policy, and CORS — and produce a staged rollout that won't break the site. Use before a launch, during a security pass, or when a scanner (Mozilla Observatory, securityheaders.com, a pentest) flags missing or weak headers. Audits and edits header config; rolls CSP out Report-Only first.

imtiazrayhan 6172436 10.5 KB Updated

File contents

imtiazrayhan/agentscamp-library/tree/main/skills/security-headers-hardener commit 6172436923

Frequently asked questions

npx skillmds@latest add imtiazrayhan/security-headers-hardener