{"slug":"jeremylongshore-auditing-cors-policy","source_name":"jeremylongshore/auditing-cors-policy","name":"Jeremylongshore/Auditing CORS Policy","description":"Audit a target's CORS posture — Access-Control-Allow-Origin handling,\nreflected-origin bypass, credentials+wildcard mismatch, preflight\nOPTIONS behavior, Vary header correctness.\nUse when: a third-party integration is failing CORS preflight and\nsomeone proposes \"just set Allow-Origin to *\" as the fix, OR your\nbug-bounty inbox has a credential-reuse exploit chain.\nThreshold: any reflection of arbitrary Origin into Allow-Origin,\nAllow-Credentials:true with wildcard origin (browser-rejected combo\nb","version":1,"lift":{"pass_rate_delta_pts":45.45,"pass_rate_pct":86.4,"total_cases":22,"passed_cases":19,"tokens_delta_pct":30.9,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-08-13T03:04:49.903138+00:00"},"skill_score":null,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":45.45,"with_pass_pct":86.4,"without_pass_pct":40.9,"tokens_delta_pct":30.9,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":21,"verdict":"mixed","never_hurt":true,"completed_at":"2026-08-13T03:04:49.903138+00:00","run_id":"56da03d3-ef46-4c9e-abb9-a1dbe5cd2a85","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":"safe","content_status":"clean","indexable":true},"license":"MIT","install_count":0,"manifest_hash":"09769a8dc8273af5fc8e2fcc35d5bd168318c161128d26607f83f5c5ef08c8b0","raw_url":"https://app.decimal.ai/s/jeremylongshore-auditing-cors-policy/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/jeremylongshore-auditing-cors-policy"}