security-headers
SkillSecurityUse when verifying or configuring HTTP security headers (CSP, HSTS, CORS, X-Frame-Options) for a web application (Next.js, Laravel, Express, Django).
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the security-headers skill
What this skill tells your AI
The instructions your AI receives, as published by fusengine/agents in plugins/security-expert/skills/security-headers/SKILL.md and read by ahel’s review.
It detects the framework (Next.js next.config.js headers/middleware.ts, Laravel SecurityHeaders middleware, Express helmet, Django SECURE_* settings), checks the current configuration against best practice, generates a framework-specific fix, and validates the headers are properly set.
Security Headers Skill
Overview
Audit and configure HTTP security headers for web applications.
Required Headers
| Header | Purpose | Severity if Missing |
|---|---|---|
| Content-Security-Policy | Prevent XSS/injection | HIGH |
| Strict-Transport-Security | Force HTTPS | HIGH |
| X-Content-Type-Options | Prevent MIME sniffing | MEDIUM |
| X-Frame-Options | Prevent clickjacking | MEDIUM |
| Referrer-Policy | Control referrer info | LOW |
| Permissions-Policy | Control browser features | LOW |
| X-XSS-Protection | Legacy XSS filter | LOW |
Workflow
- Detect framework (Next.js, Laravel, Express, etc.)
- Check current header configuration
- Compare against security best practices
- Generate framework-specific configuration
- Validate headers are properly set
Detection Points
| Framework | Config Location |
|---|---|
| Next.js | next.config.js headers, middleware.ts |
| Laravel | SecurityHeaders middleware |
| Express | helmet middleware |
| Django | SECURE_* settings |
References
Signals
- GitHub stars
- 25
- Forks
- 4
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
security-headers- Source
- github.com/fusengine/agents