Atlas / Skills / leoyeai / Phy Security Headers

Phy Security HeadersCAUTION

skills/leoyeai/phy-security-headers

๐Ÿง  Curated collection of 1209+ best OpenClaw skills โ€” weekly updated by MyClaw.ai

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
1.0.0
Hosts
1 documented
License
MIT
Stars
2,160
01

Overview

๐Ÿง  Curated collection of 1209+ best OpenClaw skills โ€” weekly updated by MyClaw.ai

Read from source at commit 4f3b4a2a472eOBSERVED ยท 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit โ€” this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: phy-security-headers
description: HTTP security header auditor that fetches response headers from any URL and grades them against OWASP, Mozilla Observatory, and Google standards. Checks Content-Security-Policy (detects unsafe-inline, wildcard sources, missing directives), HSTS (max-age, includeSubDomains, preload), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, CORP/COEP/COOP isolation headers. Assigns A/B/C/F grade per header, generates a one-command nginx/Apache/Next.js fix for every gap. Works against any live URL or local dev server via curl. Zero external cloud account. Triggers on "security headers", "CSP audit", "HSTS missing", "clickjacking", "content security policy", "mozilla observatory", "/sec-headers".
license: Apache-2.0
metadata:
  author: PHY041
  version: "1.0.0"
  tags:
    - security
    - http-headers
    - csp
    - hsts
    - owasp
    - web-security
    - developer-tools
    - frontend
    - devops
    - compliance
---

# Security Headers Auditor

Your site passes all the security scanners until someone iframes it, injects a script through an open CDN source in your CSP, or steals credentials from a page with no HSTS preload.

This skill fetches your response headers, grades each security header against OWASP and Mozilla Observatory standards, and gives you the exact config line to add to nginx, Apache, Next.js, or Cloudflare Workers.

**Works against any URL via curl. Zero external API.**

---

## Trigger Phrases

- "security headers", "check my headers", "http headers audit"
- "CSP audit", "content security policy"
- "HSTS missing", "HSTS preload"
- "clickjacking protection", "X-Frame-Options"
- "mozilla observatory", "OWASP headers"
- "Permissions-Policy", "CORP COEP COOP"
- "/sec-headers"

---

## How to Provide Input

```bash
# Option 1: Audit a live URL
/sec-headers https://myapp.com

# Option 2: Audit local dev server
/sec-headers http://localhost:3000

# Option 3: Audit specific path
/sec-headers https://myapp.com/dashboard

# Option 4: Audit with custom port
/sec-headers https://staging.myapp.com:8443

# Option 5: Grade only (no fix suggestions)
/sec-headers https://myapp.com --grade-only

# Option 6: Generate nginx config snippet
/sec-headers https://myapp.com --output nginx

# Option 7: Generate Next.js headers config
/sec-headers https://myapp.com --output nextjs
```

---

## Step 1: Fetch Headers

```bash
# Fetch all response headers
URL="https://myapp.com"

curl -sI "$URL" \
  --max-time 10 \
  --user-agent "SecurityHeaderAuditor/1.0" \
  -L  # follow redirects

# Also check www redirect behavior
curl -sI "http://$URL" 2>/dev/null | head -5

# Save raw headers for parsing
HEADERS=$(curl -sI "$URL" --max-time 10 -L 2>/dev/null)
echo "$HEADERS"
```

---

## Step 2: Grade Each Header

```python
import re
import subprocess
import sys
from dataclasses import dataclass, field
from typing import Optional


@dataclass
class HeaderCheck:
    name: str
    present: bool
    value: Optional[str]
    grade: str       # A / B / C / F / MISSING
    issues: list[str]
    fixes: list[str]
    severity: str    # CRITICAL / HIGH / MEDIUM / LOW / INFO


def fetch_headers(url: str) -> dict[str, str]:
    """Fetch HTTP response headers from URL."""
    result = subprocess.run(
        ['curl', '-sI', url, '--max-time', '10', '-L',
         '--user-agent', 'SecurityHeaderAuditor/1.0'],
        capture_output=True, text=True
    )
    headers = {}
    for line in result.stdout.splitlines():
        if ':' in line and not line.startswith('HTTP/'):
            key, _, value = line.partition(':')
            headers[key.strip().lower()] = value.strip()
    return headers


# โ”€โ”€ Content-Security-Policy โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

def check_csp(value: Optional[str]) -> HeaderCheck:
    issues = []
    fixes = []
    grade = 'A'

    if not value:
        return HeaderCheck(
            name='Content-Security-Policy',
            present=False, value=None, grade='F',
            issues=['CSP header is missing โ€” XSS attacks have no browser-level mitigation'],
            fixes=[
                "Add to nginx: add_header Content-Security-Policy "
                "\"default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self';\" always;",
                "Next.js (next.config.js headers): { key: 'Content-Security-Policy', value: \"default-src 'self'...\" }",
            ],
            severity='CRITICAL',
        )

    directives = {d.split()[0].lower(): d for d in value.split(';') if d.strip()}

    # unsafe-inline in script-src โ€” CRITICAL
    script_src = directives.get('script-src', directives.get('default-src', ''))
    if "'unsafe-inline'" in script_src:
        grade = 'F'
        issues.append("'unsafe-inline' in script-src โ€” negates XSS protection entirely")
        fixes.append("Replace 'unsafe-inline' with a nonce: script-src 'nonce-{random}' 'strict-dynamic'")

    # unsafe-eval
    if "'unsafe-eval'" in script_src:
        grade = 'C' if grade == 'A' else grade
        issues.append("'unsafe-eval' allows eval() โ€” enables second-order XSS")
        fixes.append("Remove 'unsafe-eval'; refactor code using eval() to use Function() alternatives")

    # Wildcard source
    for directive_name, directive_val in directives.items():
        if re.search(r'\bhttps?://\*\b|^\*$', directive_val):
            grade = 'C' if grade == 'A' else grade
            issues.append(f"Wildcard source (*) in {directive_name} โ€” allows loading from any domain")
            fixes.append(f"Replace * in {directive_name} with explicit trusted domains")

    # Missing object-src
    if 'object-src' not in directives and 'default-src' not in directives:
        grade = 'B' if grade == 'A' else grade
        issues.append("Missing object-src โ€” allows Flash/plugin injection if default-src not set")
        fixes.append("Add: object-src 'none'")

    # Missing base-uri
    if 'base-uri' not in directives:
        issues.append
04

Trust audit

CAUTIONgrade B ยท trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

HIGHPrompt injection ยท prompt.credential_read ยท CWE-94, CWE-1427
SKILL.md:23
Your site passes all the security scanners until someone iframes it, injects a script through an open CDN source in your CSP, or steals credentials from a page with no HSTS preload.
Why it matters. asks the agent to read credentials
MEDIUMObfuscation / stealth ยท obf.base64_blob ยท CWE-506, CWE-94
skills/compdf-conversion-cli/scripts/license.xml:9
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s

Gates applied: no_behavioural_pass.

Audited 2026-10-08 ยท audit v0.4.1 ยท source sha 4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__phy-security-headers.json ยท Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f3b4a2a472eCAUTIONB89first audit
06

Questions

What does the Phy Security Headers skill do?

๐Ÿง  Curated collection of 1209+ best OpenClaw skills โ€” weekly updated by MyClaw.ai

Is Phy Security Headers safe to install?

With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Phy Security Headers access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Phy Security Headers work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes โ€” this is the first audit.

Advertisement