CORS Audit

Installation
SKILL.md

CORS Audit

Access to fetch at 'https://api.myapp.com' from origin 'https://evil.com' has been set with CORS policy: No 'Access-Control-Allow-Origin'

Then you add Access-Control-Allow-Origin: * and it works. Except now your API accepts requests from every site on the internet, with every user's credentials, if you forgot to check the credentials flag.

This skill probes your CORS configuration with crafted Origin headers, finds the misconfigurations that let attackers run authenticated cross-origin requests against your users, and generates the correct allow-list config for your stack.

Works against any live URL via curl. Scans Express/FastAPI/Go/Rails/Django source. Zero external API.


Trigger Phrases

Installs
4
First Seen
Apr 22, 2026
CORS Audit from skills.volces.com