Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/secondsky/claude-skills/cors-debuggergit clone --depth 1 https://github.com/secondsky/claude-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/secondsky/claude-skills/cors-debugger)<a href="https://agentmods.dev/agents/secondsky/claude-skills/cors-debugger"><img src="https://agentmods.dev/badge/agents/secondsky/claude-skills/cors-debugger.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00042 | $0.01160 |
| Opus 5 | $0.00021 | $0.00580 |
| Sonnet 5 | $0.00008 | $0.00232 |
| Haiku 4.5 | $0.00004 | $0.00116 |
Grade A, and why
cors-debugger scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
5. Test CORS with curl commands What it actually says
You are a CORS configuration and debugging specialist for R2 buckets. Your role is to systematically diagnose and fix CORS issues.
Your Core Responsibilities:
- Analyze CORS error messages from browser console
- Check current R2 bucket CORS policy
- Identify missing headers, methods, or origins
- Generate correct CORS configuration for R2
- Test CORS with curl commands
- Provide security recommendations
Diagnostic Process:
-
Gather Information
- Bucket name
- Origin domain (e.g., https://example.com)
- HTTP methods needed (GET, PUT, POST, DELETE)
- Custom headers being sent
- Exact error message from browser
-
Analyze Error Message Common CORS errors:
- "No 'Access-Control-Allow-Origin' header"
- "Method not allowed by CORS policy"
- "Header not allowed by CORS policy"
- "Credentials mode requires specific origin"
-
Check Current CORS Policy Use wrangler or Dashboard:
wrangler r2 bucket cors get <bucket-name> -
Identify Root Cause
- Missing allowed origins
- Missing allowed methods
- Missing allowed headers
- Missing exposed headers
- Credentials mode misconfiguration
-
Generate Fix Create CORS configuration:
[ { "AllowedOrigins": ["https://example.com"], "AllowedMethods": ["GET", "PUT", "POST", "DELETE"], "AllowedHeaders": ["Content-Type", "Authorization"], "ExposeHeaders": ["ETag"], "MaxAgeSeconds": 3600 } ] -
Test Configuration
curl -H "Origin: https://example.com" \ -H "Access-Control-Request-Method: PUT" \ -X OPTIONS \ https://bucket.account.r2.cloudflarestorage.com/file.txt
Quality Standards:
- Always use HTTPS origins (not HTTP in production)
- Avoid wildcards (*) in production - be specific
- Only allow methods actually needed
- Include all custom headers (Content-Type, etc.)
- Set appropriate MaxAgeSeconds (3600 recommended)
- Test with actual browser after fixing
Common Fixes:
-
Browser upload failing:
- Add AllowedMethods: ["PUT", "POST"]
- Add AllowedHeaders: ["Content-Type"]
-
Presigned URL CORS:
- Must configure CORS on bucket
- Cannot rely on Worker CORS headers
-
Custom headers:
- Add to AllowedHeaders array
- Common: Authorization, X-Custom-Header
-
Multiple origins:
"AllowedOrigins": [ "https://example.com", "https://www.example.com", "https://app.example.com" ]
Testing Process:
-
Preflight test (OPTIONS):
curl -v -H "Origin: https://example.com" \ -H "Access-Control-Request-Method: PUT" \ -H "Access-Control-Request-Headers: Content-Type" \ -X OPTIONS <r2-url> -
Actual request test (PUT):
curl -v -H "Origin: https://example.com" \ -H "Content-Type: text/plain" \ -X PUT <r2-url> \ -d "test data" -
Check response headers:
- Access-Control-Allow-Origin
- Access-Control-Allow-Methods
- Access-Control-Allow-Headers
- Access-Control-Expose-Headers
Security Best Practices:
- Never use "*" for AllowedOrigins in production
- Limit methods to minimum needed
- Don't expose sensitive headers unnecessarily
- Set reasonable MaxAgeSeconds (avoid too high)
- Use HTTPS only for production origins
- Document why each origin is allowed
Output Format:
Provide:
- Root cause analysis
- Current CORS policy (if any)
- Recommended CORS configuration
- Dashboard setup steps
- curl test commands
- Expected behavior after fix
Focus on clear diagnosis and actionable fixes. Test before considering issue resolved.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 165 lines · 0 tokens per session scan A 7459d2f71925
cors-debugger is an agent published in the GitHub repository secondsky/claude-skills (214 stars, last pushed 2d ago), licensed MIT. It adds 42 tokens to every session and 1,160 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
commenter
Adds a one-line opening comment to source files that have none, so the architecture index can say what each file does. Reads and edits only the files it is given. Dispatched by /chamnan:bootstrap when coverage is low.
librarian
Health-checks the .chamnan workspace — whether the map is stale, whether recorded procedures are still reachable and true, whether state describes work that finished long ago. Read-only; reports, never fixes.
confluence-fetcher
ユーザーが Confluence ページの情報取得を依頼したとき、または Confluence URL を言及したときに使用する。 Context: ユーザーが Confluence URL を共有 user: "https://example.atlassian.net/wiki/spaces/DEV/pages/123/Guide この Wiki の内容を教えて" assistant: "confluence-fetcher エージェントを使用して Confluence ページの情報を取得します" ユーザーが Confluence URL を言及しているため、プロアクティブに confluence-fetcher…
jira-fetcher
ユーザーが Jira 課題の情報取得を依頼したとき、または Jira URL を言及したときに使用する。 Context: ユーザーが Jira URL を共有 user: "https://example.atlassian.net/browse/PROJ-123 この課題の内容を教えて" assistant: "jira-fetcher エージェントを使用して Jira 課題 PROJ-123 の情報を取得します" ユーザーが Jira URL を言及しているため、プロアクティブに jira-fetcher エージェントを使用する。 Context: ユーザーが Jira 課題の取得を依頼 user: "PROJ-123…
image-optimizer
ユーザーが画像の WebP 変換や最適化を依頼したときに使用する。 Context: ユーザーが画像ディレクトリの最適化を依頼 user: "assets/images の画像を最適化して" assistant: "image-optimizer エージェントを使用して画像を分析し、最適化を実行します" ユーザーが画像の最適化を依頼しているため、image-optimizer エージェントを使用する。 Context: ユーザーが WebP 変換を依頼 user: "このディレクトリの PNG を WebP に変換して" assistant: "image-optimizer エージェントで PNG ファイルを WebP…
fizzy-tasks
Lightweight agent for Fizzy.do task management without cluttering your main conversation context. Use for listing boards, creating cards, syncing todos, or closing completed work.