cors-scannerScan web endpoints for CORS misconfigurations. Detect origin reflection, wildcard policies, null origin acceptance, credential leaks, subdomain trust, HTTP o...
Install via ClawdBot CLI:
clawdbot install charlie-morrison/cors-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://api.example.comAudited Apr 16, 2026 · audit v1.0
Generated May 21, 2026
Before deploying a new API endpoint, run a CORS scan to ensure no misconfigurations exist that could expose sensitive data. The scanner checks for origin reflection, wildcard policies, and other common issues, assigning a security grade to streamline review.
When integrating with a partner API, verify that your CORS policy does not inadvertently trust malicious origins. Use the scanner to detect HTTP origin trust on HTTPS or subdomain wildcards that could be exploited.
As part of a security assessment, scan a client's web endpoints for CORS misconfigurations. The 13 checks cover critical issues like null origin acceptance and credential leaks, enabling comprehensive reporting with A-F grades.
Integrate the CORS scanner into CI/CD pipelines to automatically reject builds that introduce dangerous CORS policies. The --min-grade flag allows failing any deployment that scores below a C grade, ensuring security gates.
Scan internal web applications to verify they block cross-origin requests from external sites. The private network access check helps prevent attackers from using CORS to access internal resources via browser-based attacks.
Offer free access to basic scans (single URL, text output) and charge for batch scanning, JSON/markdown reports, and CI/CD integration features. Revenue comes from monthly subscriptions for advanced capabilities.
Security consultants bundle the scanner into their penetration testing services, providing automated CORS checks as a value-add. Charges are per-engagement or included in a retainer.
License the scanner to enterprises for use in their internal security toolchain. Offer site-wide or organization-wide licenses with priority support and custom integrations.
💬 Integration Tip
Run the scanner from the command line or incorporate into scripts; for CI/CD, use --min-grade to enforce policy automatically.
Scored May 21, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...