Http sec audit
Skill NovaCode37/claude-security-skills/skills/http-sec-audit
Production-ready Claude Code skills for cybersecurity — secret scanning, SAST, prompt-injection testing, HTTP/JWT/dependency auditing. Zero dependencies.
npx -y skills add NovaCode37/claude-security-skills --skill http-sec-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 12 stars12 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Audit a website's HTTP security headers and cookie flags — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP/COEP, version-leaking banners, and Secure/HttpOnly/SameSite cookies. Use when the user asks to "check my site's security headers", "audit HTTP headers", "is my CSP/HSTS configured right", or "scan a URL for header misconfigs".
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
2.0 KB, as published. Nobody here has run it
HTTP Security Header Audit
Checks a site's response headers against modern web-security best practices and
returns prioritized findings with concrete fixes. The analysis core is pure and
offline-testable; live scanning uses only Python's stdlib urllib.
When to use this skill
- "Audit the security headers on https://example.com."
- "Is my CSP / HSTS / cookie config correct?"
- "Why is this site flagged for missing headers?"
What it checks
- Content-Security-Policy — presence,
unsafe-inline, wildcards. - Strict-Transport-Security — presence and
max-agelength. - X-Content-Type-Options: nosniff, X-Frame-Options /
frame-ancestors. - Referrer-Policy, Permissions-Policy.
- Information disclosure —
Server/X-Powered-Byversion banners. - Cookies —
Secure,HttpOnly,SameSite(incl.SameSite=NonewithoutSecure).
How to run it
# Live scan
python skills/http-sec-audit/audit.py https://example.com
# JSON output
python skills/http-sec-audit/audit.py https://example.com --json
# Offline: audit a saved raw header block (no network)
python skills/http-sec-audit/audit.py --headers-file response_headers.txt
Exit codes: 0 no high issues · 1 findings present · 2 fetch/usage error.
Recommended workflow for Claude
- Run the audit (live, or offline against captured headers).
- Group findings by severity and present each with its one-line fix.
- Offer ready-to-paste header snippets for the user's stack (nginx, Apache, Express, etc.) for the missing headers.
- Only scan sites the user owns or is authorized to test.