Token导航 LogoToken导航TokenDH.com
待分类操作浏览器github未标认证来源可访问许可证需确认审计通过

cors-security-headerscors 安全标头

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

742

周安装

30

GitHub Stars

12

下载量

233
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:cors-security-headers(cors 安全标头)
来源仓库:https://github.com/claude-dev-suite/claude-dev-suite
仓库路径:skills/cors-security-headers
安装命令:
npx skills add https://github.com/claude-dev-suite/claude-dev-suite --skill cors-security-headers
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/claude-dev-suite/claude-dev-suite --skill cors-security-headers

简介

cors-security-headers 提供 Express 框架下的 CORS 与安全标头配置示例,强化传输安全。

  • 适用于 Web 应用部署前的安全加固,支持动态源验证与预检缓存优化。
  • 包含 credentials 处理、方法限制与头部白名单等关键安全参数设置建议。
  • 配置时应严格限定 origin 范围,避免使用通配符暴露敏感接口给任意来源。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

CORS & Security Headers

CORS (Express)

import cors from 'cors';

// Restrictive (recommended)
app.use(cors({
  origin: ['https://myapp.com', 'https://admin.myapp.com'],
  methods: ['GET', 'POST', 'PUT', 'DELETE'],
  allowedHeaders: ['Content-Type', 'Authorization'],
  credentials: true,
  maxAge: 86400, // Preflight cache: 24h
}));

// Dynamic origin
app.use(cors({
  origin: (origin, callback) => {
    const allowed = ALLOWED_ORIGINS.includes(origin!) || !origin; // !origin = same-origin
    callback(null, allowed ? origin : false);
  },
  credentials: true,
}));

Security Headers (Helmet.js)

import helmet from 'helmet';

app.use(helmet({
  contentSecurityPolicy: {
    directives: {
      defaultSrc: ["'self'"],
      scriptSrc: ["'self'", "'unsafe-inline'", 'https://cdn.example.com'],
      styleSrc: ["'self'", "'unsafe-inline'"],
      imgSrc: ["'self'", 'data:', 'https:'],
      connectSrc: ["'self'", 'https://api.example.com'],
      frameSrc: ["'none'"],
      objectSrc: ["'none'"],
    },
  },
  hsts: { maxAge: 31536000, includeSubDomains: true, preload: true },
  referrerPolicy: { policy: 'strict-origin-when-cross-origin' },
}));

CSRF Protection

import csrf from 'csurf';

// For server-rendered forms (session-based apps)
app.use(csrf({ cookie: true }));
app.get('/form', (req, res) => {
  res.render('form', { csrfToken: req.csrfToken() });
});

// For SPAs: use SameSite cookies + custom header
// No csrf library needed — rely on:
// 1. SameSite=Strict/Lax cookies
// 2. Check Origin/Referer header matches
// 3. Custom header requirement (X-Requested-With)

Secure Cookies

app.use(session({
  cookie: {
    httpOnly: true,        // No JS access
    secure: true,          // HTTPS only
    sameSite: 'lax',       // CSRF protection
    maxAge: 24 * 60 * 60 * 1000,
    domain: '.myapp.com',  // Shared across subdomains
  },
}));

Spring Boot Security Headers

@Bean
SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    return http
        .cors(cors -> cors.configurationSource(corsConfig()))
        .headers(headers -> headers
            .contentSecurityPolicy(csp -> csp.policyDirectives("default-src 'self'"))
            .referrerPolicy(ref -> ref.policy(ReferrerPolicyHeaderWriter.ReferrerPolicy.STRICT_ORIGIN))
            .frameOptions(frame -> frame.deny())
        )
        .csrf(csrf -> csrf.csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse()))
        .build();
}

@Bean
CorsConfigurationSource corsConfig() {
    var config = new CorsConfiguration();
    config.setAllowedOrigins(List.of("https://myapp.com"));
    config.setAllowedMethods(List.of("GET", "POST", "PUT", "DELETE"));
    config.setAllowCredentials(true);
    var source = new UrlBasedCorsConfigurationSource();
    source.registerCorsConfiguration("/**", config);
    return source;
}

Key Headers Reference

HeaderPurposeRecommended Value
Strict-Transport-SecurityForce HTTPSmax-age=31536000; includeSubDomains
Content-Security-PolicyRestrict resource loadingdefault-src 'self' + specifics
X-Content-Type-OptionsPrevent MIME sniffingnosniff
X-Frame-OptionsPrevent clickjackingDENY
Referrer-PolicyControl referrer infostrict-origin-when-cross-origin
Permissions-PolicyRestrict browser featurescamera=(), microphone=()

Anti-Patterns

Anti-PatternFix
Access-Control-Allow-Origin: * with credentialsSpecify exact origins
No CSP headerAdd Content-Security-Policy
CSRF token in URL query paramsUse header or hidden form field
SameSite=None without SecureAlways pair SameSite=None with Secure
Missing HSTSEnable with long max-age and preload

Production Checklist

  • CORS: specific origins, no wildcard with credentials
  • Helmet.js (or equivalent) for all security headers
  • CSP configured and tested
  • HSTS with preload
  • Secure, HttpOnly, SameSite cookies
  • CSRF protection for state-changing requests

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.92%
按下载量换算84

Claude

26.01%
按下载量换算61

Cursor

18.45%
按下载量换算43

Gemini CLI

9.95%
按下载量换算23

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

操作浏览器

该 Skill 可能涉及浏览器控制能力,使用时可能读取或操作网页内容,需要在受控环境中确认权限边界。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills