phy-security-headersHTTP security header auditor that fetches response headers from any URL and grades them against OWASP, Mozilla Observatory, and Google standards. Checks Cont...
Install via ClawdBot CLI:
clawdbot install phy041/phy-security-headersGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
report → https://yoursite.com/csp-reportPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://canlah.aiAudited Sep 7, 2026 · audit v1.0
Generated Sep 7, 2026
A development team integrates this skill into their continuous integration pipeline to automatically audit staging and production URLs after each deployment. The skill flags missing or misconfigured security headers before code goes live, ensuring compliance with security standards.
An e-commerce platform uses the skill to perform a comprehensive security header audit on their public-facing website and payment pages. It identifies gaps in CSP, HSTS, and clickjacking protection to protect customer data and maintain trust.
A healthcare startup conducts regular security header audits on their patient portal to meet HIPAA and OWASP requirements. The skill provides a clear grade and actionable fixes, helping them demonstrate compliance to regulators.
Following a security incident, a company uses the skill to rapidly inspect their web server headers and identify vulnerabilities such as missing HSTS preload or permissive CSP that could be exploited. The generated fixes are applied immediately to mitigate further risks.
A security engineer uses the skill to audit headers before and after adjusting WAF rules, ensuring that security headers are correctly configured to work alongside the WAF, providing layered defense against web attacks.
Offer a free online tool that lets website owners quickly scan their security headers and get a grade. Sell premium reports with in-depth analysis, fix implementation assistance, and continuous monitoring as a subscription.
Cybersecurity consulting firms integrate this skill into their service offerings to perform detailed security header audits for clients. They charge clients for the audit report and for implementing the recommended fixes.
Integrate this skill into a broader developer tools platform (e.g., CI/CD plugins, security dashboards) and charge developers or teams for headless audits as part of their development workflow.
💬 Integration Tip
To integrate this skill, parse the CLI outputs or Python functions to obtain structured grades and fixes, then automate posting results to your internal dashboard or issue tracker via webhooks.
Scored Sep 7, 2026
Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and pos...
When the user wants to plan a product launch, feature announcement, or release strategy. Also use when the user mentions 'launch,' 'Product Hunt,' 'feature r...
When the user wants to build a free tool for marketing — lead generation, SEO value, or brand awareness. Use when they mention 'engineering as marketing,' 'f...
管理多类型项目看板,支持新增项目、变更状态与版本、分类管理及查看项目总览和变更日志。
Competitor Analysis — SEO/GEO Intelligence & Market Positioning. Analyze competitor SEO rankings, AI search citations, content strategy, and market posi...
Conduct structured PHQ-9 depression symptom screening and submit the completed assessment for evaluation.