security-headers

SkillSecurity

Use when verifying or configuring HTTP security headers (CSP, HSTS, CORS, X-Frame-Options) for a web application (Next.js, Laravel, Express, Django).

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the security-headers skill

What this skill tells your AI

The instructions your AI receives, as published by fusengine/agents in plugins/security-expert/skills/security-headers/SKILL.md and read by ahel’s review.

It detects the framework (Next.js next.config.js headers/middleware.ts, Laravel SecurityHeaders middleware, Express helmet, Django SECURE_* settings), checks the current configuration against best practice, generates a framework-specific fix, and validates the headers are properly set.

Security Headers Skill

Overview

Audit and configure HTTP security headers for web applications.

Required Headers

HeaderPurposeSeverity if Missing
Content-Security-PolicyPrevent XSS/injectionHIGH
Strict-Transport-SecurityForce HTTPSHIGH
X-Content-Type-OptionsPrevent MIME sniffingMEDIUM
X-Frame-OptionsPrevent clickjackingMEDIUM
Referrer-PolicyControl referrer infoLOW
Permissions-PolicyControl browser featuresLOW
X-XSS-ProtectionLegacy XSS filterLOW

Workflow

  1. Detect framework (Next.js, Laravel, Express, etc.)
  2. Check current header configuration
  3. Compare against security best practices
  4. Generate framework-specific configuration
  5. Validate headers are properly set

Detection Points

FrameworkConfig Location
Next.jsnext.config.js headers, middleware.ts
LaravelSecurityHeaders middleware
Expresshelmet middleware
DjangoSECURE_* settings

References

Signals

GitHub stars
25
Forks
4
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
security-headers
Source
github.com/fusengine/agents