Set an X-Frame-Options header
SkillSecurityA security skill for reviewing HTTP response headers for clickjacking protection on any web application with authenticated user actions. It guides an agent through checking whether a site sends X-Frame-Options or CSP frame-ancestors headers, explains the attack the headers prevent, and sug
Available today. Use it from your connected AI after setup.
No other account needed.
Have a web application with authenticated user actions whose HTTP response headers can be reviewed.
Then ask your AI: use the Set an X-Frame-Options header skill
What your AI can do with it
- Check whether responses send X-Frame-Options (DENY or SAMEORIGIN) or CSP frame-ancestors
- Explain what clickjacking is and how framing protection headers prevent it
- Recommend DENY, SAMEORIGIN, or CSP frame-ancestors based on whether framing is needed
- Review server config, headers, forms, and integration points for violations of the rule
- Flag exact responses, cookies, or browser behaviors that violate the rule and verify them
- Note that ALLOWFROM is obsolete and that CSP frame-ancestors is the modern equivalent
Getting started
- Have a web application with authenticated user actions whose HTTP response headers can be reviewed.
- Add the skill to the agent so it can be invoked when reviewing response headers.
- Ask the agent to check the site's responses for X-Frame-Options or CSP frame-ancestors headers.
- Ask the agent to apply the suggested fix, such as adding X-Frame-Options: DENY or SAMEORIGIN, or CSP frame-ancestors.
- Consult references/rule.md for implementation details and framework-specific guidance.
What this skill tells your AI
The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/x-frame-options/SKILL.md and read by ahel’s review.
Without framing protection, an attacker can embed your banking login page in a transparent iframe on a malicious site and trick users into clicking buttons they cannot see — transferring money, changing settings, or leaking credentials.
Quick Reference
- Use
X-Frame-Options: DENYto prevent all framing, orSAMEORIGINto allow framing only from your own domain ALLOWFROMis obsolete and unsupported in modern browsers — use CSPframe-ancestorsinstead- The modern equivalent is
Content-Security-Policy: frame-ancestors 'none'— prefer CSP for new sites - Both headers can coexist: X-Frame-Options for older browsers, frame-ancestors for modern ones
- Clickjacking attacks trick users into clicking invisible iframe buttons — DENY eliminates this entirely
Check
Check whether the server sends an X-Frame-Options header (DENY or SAMEORIGIN) or a Content-Security-Policy header with frame-ancestors directive to prevent clickjacking.
Fix
Add X-Frame-Options: DENY to all responses if the site does not need to be embedded anywhere. If legitimate framing is needed on the same origin, use SAMEORIGIN. For fine-grained control, use CSP frame-ancestors instead.
Explain
Explain what a clickjacking attack is, how X-Frame-Options and CSP frame-ancestors prevent it, and the difference between DENY and SAMEORIGIN values.
Code Review
Review server config, headers, forms, and integration points related to Set an X-Frame-Options header. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/x-frame-options
Signals
- GitHub stars
- 74k
- Forks
- 7k
- Last commit
- Aug 2026
Questions
- What is the difference between DENY and SAMEORIGIN?
- DENY prevents all framing of the page. SAMEORIGIN allows framing only from your own domain. Use DENY if the site does not need to be embedded anywhere, SAMEORIGIN if legitimate same-origin framing is needed.
- Should I use X-Frame-Options or CSP frame-ancestors?
- CSP frame-ancestors is the modern equivalent and is preferred for new sites. Both headers can coexist: X-Frame-Options for older browsers, frame-ancestors for modern ones.
Advanced
- Item type
- skill
- Key
x-frame-options- Source
- github.com/thedaviddias/front-end-checklist