Skip to main content

cross-origin-opener-policy

Assess and implement Cross-Origin-Opener-Policy (COOP) for browsing-context isolation: same-origin, same-origin-allow-popups, unsafe-none, pairing with COEP for crossOriginIsolated / SharedArrayBuffer, and popup/OAuth breakage. Use when hardening window.opener isolation, reverse-tabnabbing residual risk, Spectre-era cross-origin isolation, missing COOP on auth shells, or verifying COOP+COEP delivery on owned apps and authorized assessments — hand framing controls to clickjacking-frame-busting, credentialed CORS to cors-credentialed-requests, and edge header lists to nginx-security-headers.

Jump to install

Source facts

Repository
tomysh1337/openstarry-code
Last source activity
August 17, 2026 at 13:35
Detected SKILL.md language
English
Stars
3
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.