Http Header Security Audit - Auto-activating skill for Security Fundamentals. Triggers on: http header security audit, http header security audit Part of the Security Fundamentals skill category.
36
3%
Does it follow best practices?
Impact
97%
0.98xAverage score across 3 eval scenarios
Passed
No known issues
Optimize this skill with Tessl
npx tessl skill review --optimize ./planned-skills/generated/03-security-fundamentals/http-header-security-audit/SKILL.mdnpm-based header audit script
npm package.json present
100%
100%
npm for dependencies
50%
20%
Content-Security-Policy checked
100%
100%
Strict-Transport-Security checked
100%
100%
X-Content-Type-Options checked
100%
100%
X-Frame-Options checked
100%
100%
Referrer-Policy checked
100%
100%
Report file generated
100%
100%
Present/missing/misconfigured status
100%
100%
Explanations per header
100%
100%
Standards-based evaluation
100%
100%
production-ready security header middleware
Middleware applied globally
100%
100%
Content-Security-Policy set
100%
100%
X-Content-Type-Options set
100%
100%
X-Frame-Options set
100%
100%
Strict-Transport-Security set
100%
100%
Referrer-Policy set
100%
100%
npm used for new packages
100%
100%
Production-ready values
100%
100%
Report file present
100%
100%
Rationale per header
100%
100%
Permissions-Policy or additional header
100%
100%
step-by-step audit workflow and vulnerability detection
Content-Security-Policy finding
100%
100%
X-Content-Type-Options finding
100%
100%
X-Frame-Options finding
100%
100%
Strict-Transport-Security finding
100%
100%
Severity ratings assigned
100%
100%
Remediation values provided
100%
100%
X-Powered-By flagged
100%
100%
Cookie security flagged
100%
100%
Structured JSON checklist
100%
100%
Prioritized remediation list
100%
100%
Step-by-step structure
100%
100%
c8a915c
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.