Skip to content

CORS Auditor

Caution

Validates Cross-Origin Resource Sharing (CORS) and Content Security Policy (CSP) configurations to prevent data leakage and cross-origin attacks.

By WebSec Skills 1,540 v1.1.0 Updated 2026-03-10

Install

Claude Code

Copy the SKILL.md file to your project's .claude/skills/ directory

About This Skill

CORS Auditor validates your Cross-Origin Resource Sharing and Content Security Policy configurations. Misconfigured CORS is one of the most common web security vulnerabilities, often allowing attackers to steal data from authenticated users. This skill catches these misconfigurations before they become exploitable.

How It Works

  1. Configuration review — Examines server configs (Nginx, Apache, Express, Django) for CORS and CSP directives
  2. Header analysis — Parses Access-Control-Allow-Origin, Allow-Methods, Allow-Headers, and Expose-Headers
  3. Credential check — Identifies dangerous combinations like `Allow-Credentials: true` with wildcard or reflected origins
  4. CSP evaluation — Validates Content-Security-Policy for unsafe-inline, unsafe-eval, and overly broad source lists
  5. Fix generation — Produces corrected configurations with the minimum necessary permissions

Best For

  • API security reviews for SPA + backend architectures
  • Pre-deployment checks for new CORS configurations
  • CSP hardening to prevent XSS and data injection
  • Compliance with security headers best practices (SecurityHeaders.com A+ grade)

Common Findings

Reflected Origin without validation, wildcard with credentials, missing Vary: Origin header, CSP with unsafe-inline allowing XSS, and overly permissive frame-ancestors enabling clickjacking.

Use Cases

  • Audit CORS headers for overly permissive Access-Control-Allow-Origin
  • Validate Content Security Policy for XSS prevention
  • Check for misconfigured credentialed CORS with wildcard origins
  • Generate secure CORS and CSP configurations for production

Pros & Cons

Pros

  • + Catches the most dangerous CORS misconfiguration patterns
  • + Combined CORS and CSP analysis in one skill
  • + Generates corrected configurations ready to deploy

Cons

  • - Cannot test CORS behavior without sending requests to the target
  • - CSP report-uri/report-to validation requires a live endpoint

Related AI Tools

Related Skills

Stay Updated on Agent Skills

Get weekly curated skills + safety alerts

每周精选 Skills + 安全预警