ToolypetMCP
intermediate5 minutessecurity

Web Security Header Audit

Audit your website's security headers, generate a CSP policy, evaluate it, and configure CORS.

security-headerscspcorsaudit

このレシピの使いどころ

Run this audit before launching any web application. Security headers protect against XSS, clickjacking, and other common attacks. Many compliance standards require proper header configuration.

ステップ

1

Security Header Checker

このツールを試す

Audit existing security headers

プロンプト:Check these security headers: X-Frame-Options: DENY, Strict-Transport-Security: max-age=31536000
2

Create a proper CSP policy

プロンプト:Generate a Content Security Policy allowing scripts from self and Google Analytics
3

Verify the CSP is secure

プロンプト:Evaluate the generated CSP policy for weaknesses
4

CORS Header Generator

このツールを試す

Configure CORS properly

プロンプト:Generate CORS headers allowing requests from https://app.example.com

よくある質問

What's the most important security header?

Content-Security-Policy (CSP) is the most impactful as it prevents XSS attacks. Strict-Transport-Security (HSTS) is also critical for HTTPS enforcement.

How often should I audit security headers?

Audit after every deployment and at least monthly. New third-party scripts or CDN changes may require CSP updates.

関連レシピ