auditing-cors-policy

Installation
SKILL.md

Auditing CORS Policy

Overview

CORS misconfiguration is one of the most common middle-severity findings in web bug bounties. The browser-enforced rules are subtle, the failure modes are silent (the wrong cors response just works until an attacker weaponizes it), and the "fix" engineers reach for — Access-Control-Allow-Origin: * — opens the very class of attacks CORS was meant to prevent when paired with credentials.

This skill probes each common CORS misconfiguration with synthetic Origin headers and grades the response.

When the skill produces findings

Installs
1
GitHub Stars
2.8K
First Seen
12 days ago
auditing-cors-policy — jeremylongshore/tons-of-skills-marketplace