security-headers
Installation
SKILL.md
Instructions
Design CSP and companion headers (HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP) for Next.js. Read csp-headers.md before changing production headers.
When to Use
- Use when rolling out CSP, HSTS, or Permissions-Policy on App Router or Pages.
- Prefer
auth-handbookfirst if OAuth popups or cookies are already broken. - Prefer
observability-handbookwhen wiring CSP report endpoints (no PII dumps).
- Inventory inline scripts and styles; decide nonce vs hash strategy for App Router (see csp-headers.md).
- Start Content-Security-Policy-Report-Only with
report-toorreport-uriif used. - Third parties: list each script domain in
script-src; avoidunsafe-inlineunless a documented exception. - Prefer
next.configheaders vs middleware based on deployment (Vercel vs self-hosted). - Document break-glass: who can widen policy for an emergency hotfix.
- After enforce: verify hydration, images/fonts, and IdP
frame-srcfor OAuth.