Set a Referrer-Policy header

SkillWeb & browsing

referrer-policy is a skill that guides an AI agent through reviewing the Referrer-Policy HTTP header on a website. It is used when checking response headers for privacy hardening on sites that handle authentication, session state, or sensitive URL parameters, so that URLs containing sensitive data are not leaked through referrer information.

Available today. Use it from your connected AI after setup.

Have an AI agent that can load and use skills.

Then ask your AI: use the Set a Referrer-Policy header skill

What your AI can do with it

  • Reviews Referrer-Policy HTTP response headers on a website
  • Checks privacy hardening of headers on sites with authentication
  • Covers sites that use session state or sensitive URL parameters
  • Identifies when URLs with sensitive data could be leaked via referrers

Getting started

  1. Have an AI agent that can load and use skills.
  2. Add the referrer-policy skill to the agent's available skills.
  3. Ask the agent to review the HTTP response headers of the website in question.
  4. The agent applies the skill to check the Referrer-Policy header for privacy hardening.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/referrer-policy/SKILL.md and read by ahel’s review.

Without a Referrer-Policy, a password reset link like https://example.com/reset?token=abc123 is included in the Referer header when the user clicks an external link on that page — leaking the token to third parties.

Quick Reference

  • Use Referrer-Policy: strict-origin-when-cross-origin — the recommended modern default
  • strict-origin-when-cross-origin sends the full URL for same-origin requests, only the origin for cross-origin HTTPS, and nothing for HTTPS→HTTP
  • Never use unsafe-url — it sends the full URL including path and query string to every external site
  • Can be set via HTTP header, <meta> tag, or the referrerpolicy attribute on individual <a> and <img> elements
  • Sensitive URLs (reset tokens, private IDs) in query strings can be exposed via the Referer header if policy is too permissive

Check

Check whether the server sends a Referrer-Policy header and verify the value is appropriate. The recommended value is strict-origin-when-cross-origin. Check for any pages with sensitive URL parameters that could be leaked via the Referer header.

Fix

Add Referrer-Policy: strict-origin-when-cross-origin to all HTTP responses. Configure it in your web server, CDN, or application framework. For pages with particularly sensitive URLs, consider no-referrer or same-origin.

Explain

Explain what the Referer header contains, how a permissive Referrer-Policy can leak sensitive URL parameters to third parties, and what the difference is between the various Referrer-Policy values.

Code Review

Review server config, headers, forms, and integration points related to Set a Referrer-Policy header. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/security/referrer-policy

Signals

GitHub stars
74k
Forks
7k
Last commit
Aug 2026

Questions

When should this skill be used?
Use it when reviewing HTTP response headers for privacy hardening on any website that handles authentication, session state, or sensitive URL parameters.
What does the skill actually do?
It guides the agent to review the Referrer-Policy HTTP header so that websites do not leak URLs containing sensitive data through referrer information.
Does it apply to any website?
It is intended for websites that handle authentication, session state, or sensitive URL parameters, where referrer leakage could expose sensitive data.
Advanced
Item type
skill
Key
referrer-policy
Source
github.com/thedaviddias/front-end-checklist