Set an X-Frame-Options header

SkillSecurity

A security skill for reviewing HTTP response headers for clickjacking protection on any web application with authenticated user actions. It guides an agent through checking whether a site sends X-Frame-Options or CSP frame-ancestors headers, explains the attack the headers prevent, and sug

Available today. Use it from your connected AI after setup.

Have a web application with authenticated user actions whose HTTP response headers can be reviewed.

Then ask your AI: use the Set an X-Frame-Options header skill

What your AI can do with it

  • Check whether responses send X-Frame-Options (DENY or SAMEORIGIN) or CSP frame-ancestors
  • Explain what clickjacking is and how framing protection headers prevent it
  • Recommend DENY, SAMEORIGIN, or CSP frame-ancestors based on whether framing is needed
  • Review server config, headers, forms, and integration points for violations of the rule
  • Flag exact responses, cookies, or browser behaviors that violate the rule and verify them
  • Note that ALLOWFROM is obsolete and that CSP frame-ancestors is the modern equivalent

Getting started

  1. Have a web application with authenticated user actions whose HTTP response headers can be reviewed.
  2. Add the skill to the agent so it can be invoked when reviewing response headers.
  3. Ask the agent to check the site's responses for X-Frame-Options or CSP frame-ancestors headers.
  4. Ask the agent to apply the suggested fix, such as adding X-Frame-Options: DENY or SAMEORIGIN, or CSP frame-ancestors.
  5. Consult references/rule.md for implementation details and framework-specific guidance.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/x-frame-options/SKILL.md and read by ahel’s review.

Without framing protection, an attacker can embed your banking login page in a transparent iframe on a malicious site and trick users into clicking buttons they cannot see — transferring money, changing settings, or leaking credentials.

Quick Reference

  • Use X-Frame-Options: DENY to prevent all framing, or SAMEORIGIN to allow framing only from your own domain
  • ALLOWFROM is obsolete and unsupported in modern browsers — use CSP frame-ancestors instead
  • The modern equivalent is Content-Security-Policy: frame-ancestors 'none' — prefer CSP for new sites
  • Both headers can coexist: X-Frame-Options for older browsers, frame-ancestors for modern ones
  • Clickjacking attacks trick users into clicking invisible iframe buttons — DENY eliminates this entirely

Check

Check whether the server sends an X-Frame-Options header (DENY or SAMEORIGIN) or a Content-Security-Policy header with frame-ancestors directive to prevent clickjacking.

Fix

Add X-Frame-Options: DENY to all responses if the site does not need to be embedded anywhere. If legitimate framing is needed on the same origin, use SAMEORIGIN. For fine-grained control, use CSP frame-ancestors instead.

Explain

Explain what a clickjacking attack is, how X-Frame-Options and CSP frame-ancestors prevent it, and the difference between DENY and SAMEORIGIN values.

Code Review

Review server config, headers, forms, and integration points related to Set an X-Frame-Options header. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/security/x-frame-options

Signals

GitHub stars
74k
Forks
7k
Last commit
Aug 2026

Questions

What is the difference between DENY and SAMEORIGIN?
DENY prevents all framing of the page. SAMEORIGIN allows framing only from your own domain. Use DENY if the site does not need to be embedded anywhere, SAMEORIGIN if legitimate same-origin framing is needed.
Should I use X-Frame-Options or CSP frame-ancestors?
CSP frame-ancestors is the modern equivalent and is preferred for new sites. Both headers can coexist: X-Frame-Options for older browsers, frame-ancestors for modern ones.
Advanced
Item type
skill
Key
x-frame-options
Source
github.com/thedaviddias/front-end-checklist