astro-security

SkillSecurity

Use when configuring Content Security Policy (CSP) in Astro 7 — security headers, script/style hashes, nonces, or experimentalStaticHeaders.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the astro-security skill

What this skill tells your AI

The instructions your AI receives, as published by fusengine/agents in plugins/astro-expert/skills/astro-security/SKILL.md and read by ahel’s review.

Also covers experimentalStaticHeaders for emitting CSP as adapter-based HTTP headers instead of a meta tag. States the known limitations: CSP is inactive in dev mode (test with build + preview), incompatible with <ClientRouter /> view transitions, and unsupported for Shiki's inline styles. Does not cover general deployment adapter setup beyond the CSP header wiring (astro-deployment).

Astro Security

Agent Workflow (MANDATORY)

Before ANY implementation, spawn 3 agents in parallel, one Agent call each with a name:

  1. fuse-ai-pilot:explore-codebase - Analyze existing security config, adapters, headers
  2. fuse-ai-pilot:research-expert - Verify latest Astro 7 CSP docs via Context7/Exa
  3. mcp__context7__query-docs - Check CSP compatibility with deployment adapter

After implementation, run fuse-ai-pilot:sniper for validation.


Overview

When to Use

  • Enabling CSP in an Astro project (stable in v6.0.0)
  • Configuring security.csp in astro.config.mjs
  • Adding SHA-256/384/512 hashes for external scripts or styles
  • Using nonces for dynamic script injection
  • Setting up experimentalStaticHeaders for adapter-based CSP headers

CSP in Astro

Astro 6 ships Content Security Policy as a stable feature (previously experimental). When enabled:

  • Astro automatically generates SHA hashes for all bundled scripts and styles
  • Injects a <meta http-equiv="content-security-policy"> in each page's <head>
  • Supports script-src and style-src directives by default

Limitations:

  • Not supported in dev mode — test with build + preview
  • External scripts and styles require manual hash configuration
  • Incompatible with <ClientRouter /> view transitions (use native View Transition API)
  • Shiki syntax highlighter (inline styles) not currently supported

Reference Guide

Concepts

TopicReferenceWhen to Consult
CSP overviewcsp-overview.mdUnderstanding CSP in Astro
Configurationcsp-config.mdAll config options
Script directivescript-directive.mdscript-src configuration
Style directivestyle-directive.mdstyle-src configuration
Noncesnonces.mdDynamic script injection
Static headersstatic-headers.mdAdapter-based CSP headers

Templates

TemplateWhen to Use
csp-basic.mdBasic CSP enable with algorithm
csp-advanced.mdFull config with directives + static headers

Best Practices

  1. Always test with build + preview — CSP is inactive in dev mode
  2. Start with SHA-512 — strongest hash algorithm
  3. Use 'self' explicitly — not included by default in resources
  4. Hash external scripts manually — compute SHA hashes for CDN resources
  5. Combine with adapter headers — use experimentalStaticHeaders for Vercel/Netlify

Forbidden

  • Testing CSP in dev mode (doesn't work — always use build + preview)
  • Using <ClientRouter /> with CSP enabled
  • Forgetting to add 'self' when using resources array
  • Adding unsafe-inline (defeats purpose of CSP)

Signals

GitHub stars
25
Forks
4
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
astro-security
Source
github.com/fusengine/agents