CORS Misconfiguration Auditor
Inspects CORS response headers and reports exploitable misconfigurations with
fixes. The analysis core is pure and offline-testable; live probing uses only
stdlib urllib and sends a throwaway Origin header to detect origin
reflection.
When to use this skill
- "Audit the CORS configuration of https://api.example.com."
- "Is it safe that my API returns Access-Control-Allow-Origin: *?"
- "Does my server reflect any Origin back?"
What it checks
- Wildcard + credentials —
Allow-Origin: *withAllow-Credentials: true(cors-wildcard-credentials). - Reflected origin — server echoes the request Origin back
(
cors-reflected-origin); critical when combined with credentials. - Null origin —
Allow-Origin: null(cors-null-origin). - Wildcard origin —
Allow-Origin: *without credentials (cors-wildcard). - Credentialed CORS — informational note when credentials are enabled
(
cors-credentials-enabled). - Wildcard methods —
Allow-Methods: *(cors-methods-wildcard).
How to run it
# Live probe (sends a throwaway Origin to test reflection)
python skills/cors-auditor/auditor.py https://api.example.com
# Probe with a specific origin
python skills/cors-auditor/auditor.py https://api.example.com --origin https://evil.example
# Offline: audit a captured header block; pass --origin to test reflection
python skills/cors-auditor/auditor.py --headers-file resp.txt --origin https://evil.example
# Only fail CI on high/critical (hides the medium wildcard + info notes)
python skills/cors-auditor/auditor.py https://api.example.com --min-severity high
Exit codes: 0 clean · 1 findings reported · 2 fetch/usage error.
Every reported finding fails the build. The default reports everything down to
info (including cors-credentials-enabled); raise --min-severity to
low/medium/high to filter advisory notes out of both the report and the
exit code.
Recommended workflow for Claude
- Probe the endpoint (live) or audit captured headers (offline).
- Explain each finding and why it is exploitable (e.g. reflected origin + credentials = cross-origin data theft).
- Recommend an explicit origin allowlist and dropping credentials where not needed.
- Only test APIs the user owns or is authorized to test.