/security-headers
Use when verifying or configuring HTTP security headers (CSP, HSTS, CORS, X-Frame-Options) for a web application (Next.js, Laravel, Express, Django).
$ npx -y skills add fusengine/agents --skill security-headers --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/security-headers
Context preview
The summary Claude sees to decide when to auto-load this skill.
Use when verifying or configuring HTTP security headers (CSP, HSTS, CORS, X-Frame-Options) for a web application (Next.js, Laravel, Express, Django).
SKILL.md
security-headers.SKILL.mdname: security-headers
description: "Use when verifying or configuring HTTP security headers (CSP, HSTS, CORS, X-Frame-Options) for a web application (Next.js, Laravel, Express, Django)."
argument-hint: "[framework]"
user-invocable: true
<objective> This skill audits and configures HTTP security headers for a web application: Content-Security-Policy and Strict-Transport-Security (HIGH severity if missing), X-Content-Type-Options and X-Frame-Options (MEDIUM), and Referrer-Policy, Permissions-Policy, X-XSS-Protection (LOW).
It detects the framework (Next.js next.config.js headers/middleware.ts, Laravel SecurityHeaders middleware, Express helmet, Django SECURE_* settings), checks the current configuration against best practice, generates a framework-specific fix, and validates the headers are properly set. </objective>
Security Headers Skill
Overview
Audit and configure HTTP security headers for web applications.
Required Headers
| Header | Purpose | Severity if Missing | |--------|---------|-------------------| | Content-Security-Policy | Prevent XSS/injection | HIGH | | Strict-Transport-Security | Force HTTPS | HIGH | | X-Content-Type-Options | Prevent MIME sniffing | MEDIUM | | X-Frame-Options | Prevent clickjacking | MEDIUM | | Referrer-Policy | Control referrer info | LOW | | Permissions-Policy | Control browser features | LOW | | X-XSS-Protection | Legacy XSS filter | LOW |
Workflow
1. **Detect** framework (Next.js, Laravel, Express, etc.) 2. **Check** current header configuration 3. **Compare** against security best practices 4. **Generate** framework-specific configuration 5. **Validate** headers are properly set
Detection Points
| Framework | Config Location | |-----------|----------------| | Next.js | `next.config.js` headers, `middleware.ts` | | Laravel | `SecurityHeaders` middleware | | Express | `helmet` middleware | | Django | `SECURE_*` settings |
References
- [Headers Reference](references/headers-reference.md)
- [Config Templates](references/templates/headers-config.md)
Read more
name: security-headers description: "Use when verifying or configuring HTTP security headers (CSP, HSTS, CORS, X-Frame-Options) for a web application (Next.js, Laravel, Express, Django)." argument-hint: "[framework]" user-invocable: true
<objective> This skill audits and configures HTTP security headers for a web application: Content-Security-Policy and Strict-Transport-Security (HIGH severity if missing), X-Content-Type-Options and X-Frame-Options (MEDIUM), and Referrer-Policy, Permissions-Policy, X-XSS-Protection (LOW).
It detects the framework (Next.js next.config.js headers/middleware.ts, Laravel SecurityHeaders middleware, Express helmet, Django SECURE_* settings), checks the current configuration against best practice, generates a framework-specific fix, and validates the headers are properly set. </objective>
Security Headers Skill
Overview
Audit and configure HTTP security headers for web applications.
Required Headers
| Header | Purpose | Severity if Missing | |--------|---------|-------------------| | Content-Security-Policy | Prevent XSS/injection | HIGH | | Strict-Transport-Security | Force HTTPS | HIGH | | X-Content-Type-Options | Prevent MIME sniffing | MEDIUM | | X-Frame-Options | Prevent clickjacking | MEDIUM | | Referrer-Policy | Control referrer info | LOW | | Permissions-Policy | Control browser features | LOW | | X-XSS-Protection | Legacy XSS filter | LOW |
Workflow
1. **Detect** framework (Next.js, Laravel, Express, etc.) 2. **Check** current header configuration 3. **Compare** against security best practices 4. **Generate** framework-specific configuration 5. **Validate** headers are properly set
Detection Points
| Framework | Config Location | |-----------|----------------| | Next.js | `next.config.js` headers, `middleware.ts` | | Laravel | `SecurityHeaders` middleware | | Express | `helmet` middleware | | Django | `SECURE_*` settings |
References
- [Headers Reference](references/headers-reference.md)
- [Config Templates](references/templates/headers-config.md)
A plugin ecosystem that turns Claude Code into a supervised, multi-agent development environment.
Repo: fusengine/agents
Other skills on fusengine-agents.
- /agent-creator
Use when creating expert agents. Generates agent.md with frontmatter, hooks, required sections, and skill references.
Open skill - /apex-methodology
Use when starting ANY development task -- feature, bug fix, refactor, hotfix (triggers: implement, create, build, fix, add feature, refactor, develop).
Open skill - /brainstorming
Use when creating a feature/component or adding functionality. Fires BEFORE APEX Analyze to refine requirements via structured questioning.
Open skill - /challenge
Use before a root-cause, done/verified claim, irreversible action, or 2nd-time fix reaches the owner (APEX or plain conversation); also fires at every eLicit/Verify gate. Not for code correctness (use sniper).
Open skill - /code-quality
Use when validating code quality after modifications -- SOLID compliance, DRY duplication, linter errors, architecture violations. Do NOT use for functional verification (run verification FIRST, then code-quality).
Open skill - /elicitation
Use when an expert agent self-reviews and self-corrects code after the Execute phase, before sniper validation (BMAD-METHOD elicitation techniques).
Open skill

