ToolypetMCP
intermediate5 minutessecurity

Web Security Header Audit

Audit your website's security headers, generate a CSP policy, evaluate it, and configure CORS.

security-headerscspcorsaudit

이 레시피 활용 시점

Run this audit before launching any web application. Security headers protect against XSS, clickjacking, and other common attacks. Many compliance standards require proper header configuration.

단계

1

Security Header Checker

이 도구 사용해보기

Audit existing security headers

프롬프트:Check these security headers: X-Frame-Options: DENY, Strict-Transport-Security: max-age=31536000
2

Create a proper CSP policy

프롬프트:Generate a Content Security Policy allowing scripts from self and Google Analytics
3

Verify the CSP is secure

프롬프트:Evaluate the generated CSP policy for weaknesses
4

CORS Header Generator

이 도구 사용해보기

Configure CORS properly

프롬프트:Generate CORS headers allowing requests from https://app.example.com

자주 묻는 질문

What's the most important security header?

Content-Security-Policy (CSP) is the most impactful as it prevents XSS attacks. Strict-Transport-Security (HSTS) is also critical for HTTPS enforcement.

How often should I audit security headers?

Audit after every deployment and at least monthly. New third-party scripts or CDN changes may require CSP updates.

관련 레시피