Install any skill in seconds. Free to start, no credit card required.
Get Started Free →HTTP security header audit (A+ to F) with fix recommendations
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 63% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -20% | 0% |
| case-18 | ✗→✓ | ▲ Improved | -16% | 0% |
| case-04 | ✓→✓ | = Same ✓ | -12% | 0% |
| case-06 | ✓→✓ | = Same ✓ | 56% | 0% |
Check any website for missing or misconfigured HTTP security headers. Returns a grade from A+ to F with a list of which headers are present, which are absent, and why each matters for protection against XSS, clickjacking, MIME sniffing, and data leakage.
No API key required. Powered by securityheaders.com.
powershell$target = "https://taracod.com" $encoded = [Uri]::EscapeDataString($target) $url = "https://securityheaders.com/?q=$encoded&followRedirects=on&hide=on" $response = Invoke-WebRequest -Uri $url -UseBasicParsing # Extract grade from HTML badge $grade = if ($response.Content -match 'class="[^"]*reportTitle[^"]*"[^>]*>[\s\S]*?label[^"]*"([^"]+)"') { $Matches[1] -replace 'label[- ]', '' -replace 'success', 'A' -replace 'warning', 'B/C' -replace 'danger', 'D/F' } else { 'check manually' } Write-Host "URL: $target" Write-Host "Grade: $grade" Write-Host "Full report: $url"
powershell$target = "https://example.com" $encoded = [Uri]::EscapeDataString($target) $response = Invoke-WebRequest -Uri "https://securityheaders.com/?q=$encoded&followRedirects=on&hide=on" -UseBasicParsing $html = $response.Content # Extract missing headers (rows marked as warnings/missing) $pattern = '<div[^>]*class="[^"]*missing[^"]*"[^>]*>([\s\S]*?)<\/div>' $missing = [regex]::Matches($html, $pattern) | ForEach-Object { $_.Groups[1].Value -replace '<[^>]+>', '' -replace '\s+', ' ' } | Where-Object { $_.Trim() } Write-Host "Missing headers:" $missing | ForEach-Object { Write-Host " ✗ $($_.Trim())" } Write-Host "" Write-Host "Report: https://securityheaders.com/?q=$encoded&followRedirects=on"
Strict-Transport-Security → Forces HTTPS; prevents downgrade attacks
Content-Security-Policy → Restricts content sources; blocks XSS
X-Frame-Options → Prevents clickjacking (deprecated by CSP)
X-Content-Type-Options → Blocks MIME-sniffing attacks
Referrer-Policy → Controls referrer data leakage
Permissions-Policy → Restricts browser feature access (camera, location, etc.)"Audit security headers for taracod.com" → Returns grade, lists present and missing headers with fix suggestions.
"Does github.com have Content-Security-Policy?" → Check the headers report — CSP row shows value if present.
"My site is getting an F — what headers am I missing?" → Audit returns the full missing-headers list with descriptions.
"Check HSTS on my production domain" → Look for Strict-Transport-Security in the report — check max-age value.
hide=on prevents results from appearing in the public "recent scans" feed — always use itfollowRedirects=on ensures the final destination URL is scanned, not just the redirectOther measured skills in the registry, with their headline benchmark lift.