security-headers

Installation
SKILL.md

Instructions

Design CSP and companion headers (HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP) for Next.js. Read csp-headers.md before changing production headers.

When to Use

  • Use when rolling out CSP, HSTS, or Permissions-Policy on App Router or Pages.
  • Prefer auth-handbook first if OAuth popups or cookies are already broken.
  • Prefer observability-handbook when wiring CSP report endpoints (no PII dumps).
  1. Inventory inline scripts and styles; decide nonce vs hash strategy for App Router (see csp-headers.md).
  2. Start Content-Security-Policy-Report-Only with report-to or report-uri if used.
  3. Third parties: list each script domain in script-src; avoid unsafe-inline unless a documented exception.
  4. Prefer next.config headers vs middleware based on deployment (Vercel vs self-hosted).
  5. Document break-glass: who can widen policy for an emergency hotfix.
  6. After enforce: verify hydration, images/fonts, and IdP frame-src for OAuth.

Outcomes

Installs
7
First Seen
May 30, 2026
security-headers — bh611627/skillcodex