用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/taracodlabs/aiden --skill securityheaders命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | securityheaders |
| description | HTTP security header audit (A+ to F) with fix recommendations |
| category | security |
| version | 1.0.0 |
| license | Apache-2.0 |
| origin | aiden |
| tags | security, http, headers, csp, hsts, xframe, audit, web, hardening, compliance |
Check any website for missing or misconfigured HTTP security headers. Returns a grade from A+ to F with a list of which headers are present, which are absent, and why each matters for protection against XSS, clickjacking, MIME sniffing, and data leakage.
No API key required. Powered by securityheaders.com.
$target = "https://taracod.com"
$encoded = [Uri]::EscapeDataString($target)
$url = "https://securityheaders.com/?q=$encoded&followRedirects=on&hide=on"
$response = Invoke-WebRequest -Uri $url -UseBasicParsing
# Extract grade from HTML badge
$grade = if ($response.Content -match 'class="[^"]*reportTitle[^"]*"[^>]*>[\s\S]*?label[^"]*"([^"]+)"') {
$Matches[1] -replace 'label[- ]', '' -replace 'success', 'A' -replace 'warning', 'B/C' -replace 'danger', 'D/F'
} else { 'check manually' }
Write-Host "URL: $target"
Write-Host "Grade: $grade"
Write-Host "Full report: $url"
$target = "https://example.com"
$encoded = [Uri]::EscapeDataString($target)
$response = Invoke-WebRequest -Uri "https://securityheaders.com/?q=$encoded&followRedirects=on&hide=on" -UseBasicParsing
$html = $response.Content
# Extract missing headers (rows marked as warnings/missing)
$pattern = '<div[^>]*class="[^"]*missing[^"]*"[^>]*>([\s\S]*?)<\/div>'
$missing = [regex]::Matches($html, $pattern) | ForEach-Object {
$_.Groups[1].Value -replace '<[^>]+>', '' -replace '\s+', ' '
} | Where-Object { $_.Trim() }
Write-Host "Missing headers:"
$missing | ForEach-Object { Write-Host " ✗ $($_.Trim())" }
Write-Host ""
Write-Host "Report: https://securityheaders.com/?q=$encoded&followRedirects=on"
Strict-Transport-Security → Forces HTTPS; prevents downgrade attacks
Content-Security-Policy → Restricts content sources; blocks XSS
X-Frame-Options → Prevents clickjacking (deprecated by CSP)
X-Content-Type-Options → Blocks MIME-sniffing attacks
Referrer-Policy → Controls referrer data leakage
Permissions-Policy → Restricts browser feature access (camera, location, etc.)
"Audit security headers for taracod.com" → Returns grade, lists present and missing headers with fix suggestions.
"Does github.com have Content-Security-Policy?" → Check the headers report — CSP row shows value if present.
"My site is getting an F — what headers am I missing?" → Audit returns the full missing-headers list with descriptions.
"Check HSTS on my production domain" → Look for Strict-Transport-Security in the report — check max-age value.
hide=on prevents results from appearing in the public "recent scans" feed — always use itfollowRedirects=on ensures the final destination URL is scanned, not just the redirect