Phy Security HeadersCAUTION
๐ง Curated collection of 1209+ best OpenClaw skills โ weekly updated by MyClaw.ai
Overview
๐ง Curated collection of 1209+ best OpenClaw skills โ weekly updated by MyClaw.ai
4f3b4a2a472eOBSERVED ยท 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit โ this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: phy-security-headers
description: HTTP security header auditor that fetches response headers from any URL and grades them against OWASP, Mozilla Observatory, and Google standards. Checks Content-Security-Policy (detects unsafe-inline, wildcard sources, missing directives), HSTS (max-age, includeSubDomains, preload), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, CORP/COEP/COOP isolation headers. Assigns A/B/C/F grade per header, generates a one-command nginx/Apache/Next.js fix for every gap. Works against any live URL or local dev server via curl. Zero external cloud account. Triggers on "security headers", "CSP audit", "HSTS missing", "clickjacking", "content security policy", "mozilla observatory", "/sec-headers".
license: Apache-2.0
metadata:
author: PHY041
version: "1.0.0"
tags:
- security
- http-headers
- csp
- hsts
- owasp
- web-security
- developer-tools
- frontend
- devops
- compliance
---
# Security Headers Auditor
Your site passes all the security scanners until someone iframes it, injects a script through an open CDN source in your CSP, or steals credentials from a page with no HSTS preload.
This skill fetches your response headers, grades each security header against OWASP and Mozilla Observatory standards, and gives you the exact config line to add to nginx, Apache, Next.js, or Cloudflare Workers.
**Works against any URL via curl. Zero external API.**
---
## Trigger Phrases
- "security headers", "check my headers", "http headers audit"
- "CSP audit", "content security policy"
- "HSTS missing", "HSTS preload"
- "clickjacking protection", "X-Frame-Options"
- "mozilla observatory", "OWASP headers"
- "Permissions-Policy", "CORP COEP COOP"
- "/sec-headers"
---
## How to Provide Input
```bash
# Option 1: Audit a live URL
/sec-headers https://myapp.com
# Option 2: Audit local dev server
/sec-headers http://localhost:3000
# Option 3: Audit specific path
/sec-headers https://myapp.com/dashboard
# Option 4: Audit with custom port
/sec-headers https://staging.myapp.com:8443
# Option 5: Grade only (no fix suggestions)
/sec-headers https://myapp.com --grade-only
# Option 6: Generate nginx config snippet
/sec-headers https://myapp.com --output nginx
# Option 7: Generate Next.js headers config
/sec-headers https://myapp.com --output nextjs
```
---
## Step 1: Fetch Headers
```bash
# Fetch all response headers
URL="https://myapp.com"
curl -sI "$URL" \
--max-time 10 \
--user-agent "SecurityHeaderAuditor/1.0" \
-L # follow redirects
# Also check www redirect behavior
curl -sI "http://$URL" 2>/dev/null | head -5
# Save raw headers for parsing
HEADERS=$(curl -sI "$URL" --max-time 10 -L 2>/dev/null)
echo "$HEADERS"
```
---
## Step 2: Grade Each Header
```python
import re
import subprocess
import sys
from dataclasses import dataclass, field
from typing import Optional
@dataclass
class HeaderCheck:
name: str
present: bool
value: Optional[str]
grade: str # A / B / C / F / MISSING
issues: list[str]
fixes: list[str]
severity: str # CRITICAL / HIGH / MEDIUM / LOW / INFO
def fetch_headers(url: str) -> dict[str, str]:
"""Fetch HTTP response headers from URL."""
result = subprocess.run(
['curl', '-sI', url, '--max-time', '10', '-L',
'--user-agent', 'SecurityHeaderAuditor/1.0'],
capture_output=True, text=True
)
headers = {}
for line in result.stdout.splitlines():
if ':' in line and not line.startswith('HTTP/'):
key, _, value = line.partition(':')
headers[key.strip().lower()] = value.strip()
return headers
# โโ Content-Security-Policy โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
def check_csp(value: Optional[str]) -> HeaderCheck:
issues = []
fixes = []
grade = 'A'
if not value:
return HeaderCheck(
name='Content-Security-Policy',
present=False, value=None, grade='F',
issues=['CSP header is missing โ XSS attacks have no browser-level mitigation'],
fixes=[
"Add to nginx: add_header Content-Security-Policy "
"\"default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self';\" always;",
"Next.js (next.config.js headers): { key: 'Content-Security-Policy', value: \"default-src 'self'...\" }",
],
severity='CRITICAL',
)
directives = {d.split()[0].lower(): d for d in value.split(';') if d.strip()}
# unsafe-inline in script-src โ CRITICAL
script_src = directives.get('script-src', directives.get('default-src', ''))
if "'unsafe-inline'" in script_src:
grade = 'F'
issues.append("'unsafe-inline' in script-src โ negates XSS protection entirely")
fixes.append("Replace 'unsafe-inline' with a nonce: script-src 'nonce-{random}' 'strict-dynamic'")
# unsafe-eval
if "'unsafe-eval'" in script_src:
grade = 'C' if grade == 'A' else grade
issues.append("'unsafe-eval' allows eval() โ enables second-order XSS")
fixes.append("Remove 'unsafe-eval'; refactor code using eval() to use Function() alternatives")
# Wildcard source
for directive_name, directive_val in directives.items():
if re.search(r'\bhttps?://\*\b|^\*$', directive_val):
grade = 'C' if grade == 'A' else grade
issues.append(f"Wildcard source (*) in {directive_name} โ allows loading from any domain")
fixes.append(f"Replace * in {directive_name} with explicit trusted domains")
# Missing object-src
if 'object-src' not in directives and 'default-src' not in directives:
grade = 'B' if grade == 'A' else grade
issues.append("Missing object-src โ allows Flash/plugin injection if default-src not set")
fixes.append("Add: object-src 'none'")
# Missing base-uri
if 'base-uri' not in directives:
issues.appendTrust audit
CAUTIONgrade B ยท trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
Your site passes all the security scanners until someone iframes it, injects a script through an open CDN source in your CSP, or steals credentials from a page with no HSTS preload.
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s
Gates applied: no_behavioural_pass.
4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__phy-security-headers.json ยท Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f3b4a2a472e | CAUTION | B | 89 | first audit |
Questions
What does the Phy Security Headers skill do?
๐ง Curated collection of 1209+ best OpenClaw skills โ weekly updated by MyClaw.ai
Is Phy Security Headers safe to install?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Phy Security Headers access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Phy Security Headers work with?
Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes โ this is the first audit.