Set Secure, HttpOnly, and SameSite flags on session cookies
SkillSecuritysession-cookie-flags is a skill for AI agents that checks whether session and authentication cookies use the Secure, HttpOnly, and SameSite flags. It reviews Set-Cookie headers and cookie creation code, flags missing or permissive settings, and explains what each flag does and which attack it prevents. It is used when reviewing server-side session management, setting up authentication middleware, or auditing cookie configuration in HTTP response hea
Available today. Use it from your connected AI after setup.
No other account needed.
Have the skill file available to the agent, including its name and description metadata.
Then ask your AI: use the Set Secure, HttpOnly, and SameSite flags on session cookies skill
What your AI can do with it
- Check whether session and authentication cookies set Secure, HttpOnly, and SameSite flags
- Review all Set-Cookie headers and cookie creation code for missing flags
- Flag cookies missing HttpOnly, absent Secure, or with unspecified or overly permissive Sam
- Explain what each cookie security flag does and the specific attack it prevents
- Guide updates to server cookie configuration to include Secure, HttpOnly, and SameSite=Str
Getting started
- Have the skill file available to the agent, including its name and description metadata.
- Ask the agent to review session management, authentication middleware, or cookie configuration in HTTP response headers.
- Provide the Set-Cookie headers or cookie creation code the agent should inspect.
- Ask for the fix: add Secure, HttpOnly, and SameSite=Strict (or Lax) to all session and auth cookies.
- Consult references/rule.md for full implementation details, code examples, and framework-specific guidance.
What this skill tells your AI
The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/session-cookie-flags/SKILL.md and read by ahel’s review.
Missing cookie flags are one of the most common and easily fixed authentication weaknesses. Without Secure, session tokens are transmitted in plain text over HTTP and can be captured by network eavesdroppers. Without HttpOnly, any XSS payload can exfiltrate the session token in one line. Without SameSite, any website can trigger authenticated actions on behalf of the victim without their knowledge.
Quick Reference
- Secure — cookie is only sent over HTTPS, never plain HTTP
- HttpOnly — cookie is invisible to JavaScript (blocks XSS theft)
- SameSite=Strict or Lax — prevents the cookie from being sent on cross-site requests (blocks CSRF)
- Never use SameSite=None without also setting Secure and understanding the CSRF implications
Check
Check whether session and authentication cookies are set with the Secure, HttpOnly, and SameSite flags.
Fix
Update the server's cookie configuration to include Secure, HttpOnly, and SameSite=Strict (or Lax) on all session and auth cookies.
Explain
Explain what each cookie security flag does and the specific attack each one prevents.
Code Review
Review all Set-Cookie headers and cookie creation code. Flag any cookies missing the HttpOnly flag, absent Secure flag, or an unspecified or overly permissive SameSite setting.
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/session-cookie-flags
Signals
- GitHub stars
- 74k
- Forks
- 7k
- Last commit
- Aug 2026
Questions
- What does each cookie flag do?
- Secure sends the cookie only over HTTPS. HttpOnly makes it invisible to JavaScript, blocking XSS theft. SameSite=Strict or Lax prevents it being sent on cross-site requests, blocking CSRF.
- When should this skill be used?
- When reviewing server-side session management, setting up authentication middleware, or auditing cookie configuration in HTTP response headers.
Advanced
- Item type
- skill
- Key
session-cookie-flags- Source
- github.com/thedaviddias/front-end-checklist