http-security-headersAnalyze HTTP security headers for any URL. Check for HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, CORS, and more....
Install via ClawdBot CLI:
clawdbot install charlie-morrison/http-security-headersGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://example.comAI Analysis
The skill's core function is to analyze publicly accessible HTTP headers from user-provided URLs, which is consistent with its stated purpose. The primary risk is the potential for the script to send requests to arbitrary external servers, but this is an inherent part of the security scanning functionality and not hidden credential harvesting. The 'UNSAFE_SHELL' signal appears to be a false positive from a code example (`eval()` is not present in the provided definition).
Audited Apr 17, 2026 · audit v1.0
Generated May 6, 2026
An online store needs to meet PCI DSS and OWASP security header requirements. The agent scans the checkout and login pages, identifies missing HSTS and CSP headers, and provides Nginx configuration snippets to fix them, ensuring customer data protection and regulatory compliance.
A SaaS startup preparing for launch uses the agent to scan all subdomains for missing security headers. The agent reveals a missing X-Frame-Options on the dashboard, preventing clickjacking attacks, and provides Apache directives to implement it, enhancing trust before going live.
A bank's security team runs a batch scan on multiple customer-facing URLs. The agent grades them C due to missing Referrer-Policy and Permissions-Policy headers, then gives prioritized fixes with OWASP references, helping the team meet security benchmarks for financial regulations.
A healthcare provider's patient portal is scanned for security headers. The agent identifies missing Content-Security-Policy and Strict-Transport-Security, critical for HIPAA compliance. It outputs a markdown report with specific header values and deployment instructions for the web server team.
Offer a free tier for single URL scans with basic grades, and a premium tier for batch scans, JSON reports, and CI integration. Revenue comes from monthly subscriptions for security teams needing ongoing audits.
Integrate the agent as a plugin in CI/CD pipelines (GitHub Actions, Jenkins) to automatically scan header security on every deployment. Charge per pipeline or per scan with enterprise licensing.
Security consultants use the agent to quickly audit client websites and generate branded reports. They resell the scans as part of larger security assessments, and the company charges a per-project license fee or usage-based pricing.
💬 Integration Tip
Integrate the scanner into your CI/CD pipeline using the exit codes to fail builds when security grades drop below your threshold. For example, add a step in GitHub Actions that runs `python3 scripts/scan_headers.py https://your-site.com --min-grade A`.
Scored May 6, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...