Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Use when reviewing HTTP response headers for privacy hardening on any website that handles authentication, session state, or sensitive URL parameters.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-12 | ✗→✓ | ▲ Improved | 44% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 11% | 0% |
| case-03 | ✓→✓ | = Same ✓ | -2% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 5% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 47% | 0% |
Without a Referrer-Policy, a password reset link like https://example.com/reset?token=abc123 is included in the Referer header when the user clicks an external link on that page — leaking the token to third parties.
Referrer-Policy: strict-origin-when-cross-origin — the recommended modern defaultstrict-origin-when-cross-origin sends the full URL for same-origin requests, only the origin for cross-origin HTTPS, and nothing for HTTPS→HTTPunsafe-url — it sends the full URL including path and query string to every external site<meta> tag, or the referrerpolicy attribute on individual <a> and <img> elementsCheck whether the server sends a Referrer-Policy header and verify the value is appropriate. The recommended value is strict-origin-when-cross-origin. Check for any pages with sensitive URL parameters that could be leaked via the Referer header.
Add Referrer-Policy: strict-origin-when-cross-origin to all HTTP responses. Configure it in your web server, CDN, or application framework. For pages with particularly sensitive URLs, consider no-referrer or same-origin.
Explain what the Referer header contains, how a permissive Referrer-Policy can leak sensitive URL parameters to third parties, and what the difference is between the various Referrer-Policy values.
Review server config, headers, forms, and integration points related to Set a Referrer-Policy header. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.
For full implementation details, code examples, and framework-specific guidance, see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/referrer-policy
Other measured skills in the registry, with their headline benchmark lift.