memstack-security-csp-headers

memstack-security-csp-headers is a skill for Claude Code, Codex from cwinvestments/memstack. It costs 83 tokens per session (4,048 once invoked), scanned A, original, MIT.

A web security header auditor checks browser-facing HTTP headers such as Content-Security-Policy, HSTS, and X-Frame-Options. These headers tell browsers which resources are allowed and how to defend against common attacks.

In plain words
What is it for?
Use it to review a site's security headers and generate safer header settings for its framework, hosting setup, and external resources.
Why use it?
It exposes headers that are missing or too permissive, such as allowing unsafe scripts or framing that can enable clickjacking.

Skill for Claude CodeCodex

Part of the memstack plugin — 86 skills, 2 commands, 5 hooks shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/cwinvestments/memstack/csp-headers
Any agent
npx skills add cwinvestments/memstack --skill csp-headers
Clone the repo
git clone --depth 1 https://github.com/cwinvestments/memstack

Made for: Claude Code, Codex.

Or install memstack, the plugin that ships this one along with the rest of its 86 skills, 2 commands, 5 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for memstack-security-csp-headers

README.md
[![agentmods](https://agentmods.dev/badge/skills/cwinvestments/memstack/csp-headers.svg)](https://agentmods.dev/skills/cwinvestments/memstack/csp-headers)
Your own site
<a href="https://agentmods.dev/skills/cwinvestments/memstack/csp-headers"><img src="https://agentmods.dev/badge/skills/cwinvestments/memstack/csp-headers.svg" alt="Measured on agentmods" height="20"></a>
Per session 83 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,048 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00083 $0.04048
Opus 5 $0.00042 $0.02024
Sonnet 5 $0.00017 $0.00810
Haiku 4.5 $0.00008 $0.00405

Measured yesterday against content hash ccb1908b42eb, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

memstack-security-csp-headers scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/security/csp-headers/SKILL.md · 442 lines

How it starts

The opening of the file, as written. The whole thing — 442 lines — stays where its author put it; the contents beside it link to each section on GitHub.

🛡️ CSP Headers: Security Headers Auditor & Generator

Audit existing security headers, identify overly permissive directives, and generate a production-ready Content-Security-Policy with companion headers.

Activation

When this skill activates, output:

🛡️ CSP Headers: Auditing your security headers...

Context Status
User says "CSP", "security headers", "Content-Security-Policy" ACTIVE
User wants to fix unsafe-inline, unsafe-eval, or wildcard directives ACTIVE
User mentions HSTS, X-Frame-Options, or Permissions-Policy ACTIVE
User wants a full OWASP security audit (not just headers) DORMANT: see owasp-top10
User wants to scan for secrets in code DORMANT: see secrets-scanner
User wants API-level security (auth, rate limiting) DORMANT: see api-audit

Protocol

Step 1: Gather Inputs

Ask the user for:

  • Framework: Next.js, Express, Fastify, Nginx, Caddy, static hosting?
  • CDN/hosting: Vercel, Netlify, Cloudflare, self-hosted?
  • External resources: Which third-party scripts, fonts, images, or APIs are loaded? (analytics, payment widgets, CDNs)
  • Inline scripts: Does the app use inline <script> tags or inline styles?
  • Iframes: Does the app embed iframes or get embedded by others?

Step 2: Scan Existing Headers

Check for CSP and security headers in all possible locations:

Where to look:

  1. Middleware: Express/Next.js middleware setting response headers
  2. Config files: next.config.js (headers() function), nginx.conf, Caddyfile
  3. Meta tags: <meta http-equiv="Content-Security-Policy" content="..."> in HTML
  4. Hosting config: vercel.json, netlify.toml, _headers file
  5. Reverse proxy: Nginx/Caddy/Apache header directives
── EXISTING HEADERS FOUND ─────────────────

Location: [file:line or "not found"]

Content-Security-Policy:
  [current policy or "MISSING"]

Strict-Transport-Security:
  [current value or "MISSING"]

X-Content-Type-Options:
  [current value or "MISSING"]

X-Frame-Options:
  [current value or "MISSING"]

Referrer-Policy:
  [current value or "MISSING"]

Permissions-Policy:
  [current value or "MISSING"]

X-XSS-Protection:
  [current value or "MISSING, deprecated but still useful for older browsers"]

Read the full file on GitHub · 442 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday Changed ccb1908b42eb
  2. 2d ago First seen · 442 lines · 83 tokens per session scan A 5ea6d116302e

Subscribe to this mod's changes

memstack-security-csp-headers is a skill published in the GitHub repository cwinvestments/memstack (419 stars, last pushed today), licensed MIT. It adds 83 tokens to every session and 4,048 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

plan-eng-review

Eng manager-mode plan review. Lock in the execution plan — architecture, data flow, diagrams, edge cases, test coverage, performance. Walks through issues interactively with opinionated recommendations. Use when asked to "review the architecture", "engineering review", or "lock in the plan". Proactively suggest when…

GCWing/BitFun · 116 tokens

autoplan

Auto-review pipeline — reads the full CEO, design, eng, and DX review skills from disk and runs them sequentially with auto-decisions using 6 decision principles. Surfaces taste decisions (close approaches, borderline scope, codex disagreements) at a final approval gate. One command, fully reviewed plan out. Use when…

GCWing/BitFun · 152 tokens

design-review

Designer's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them. Iteratively fixes issues in source code, committing each fix atomically and re-verifying with before/after screenshots. For plan-mode design review (before implementation), use…

GCWing/BitFun · 125 tokens

retro

Weekly engineering retrospective. Analyzes commit history, work patterns, and code quality metrics with persistent history and trend tracking. Team-aware: breaks down per-person contributions with praise and growth areas. Use when asked to "weekly retro", "what did we ship", or "engineering retrospective". Proactively…

GCWing/BitFun · 76 tokens

pre-landing-review

Pre-landing PR review. Analyzes diff against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues. Use when explicitly asked for the specialized pre-landing workflow. Product /review requests are handled by BitFun's unified Review mechanism instead.…

GCWing/BitFun · 74 tokens

miniapp-dev

Develops, maintains, and generates BitFun MiniApps (Zero-Dialect Runtime). Use when (1) working on miniapp framework code under src/crates/assembly/core/src/miniapp/ or src/web-ui/src/app/scenes/miniapps/; or (2) generating / creating / designing a NEW MiniApp for the user — including any request like "做一个小应用 / 生成…

GCWing/BitFun · 143 tokens