
Security Headers
io.github.basitalisandhuv0.1.1更新于 Oct 5, 2026
Fetch a URL's response headers and grade CSP, HSTS, X-Frame-Options and related security headers.
概览
抓取公开网址的 HTTP 响应头并对其安全头进行评分,同时给出每个头的说明与建议。
- 功能
- 该服务器提供三个工具。check_url_headers 向公开的 http(s) 网址发送 HEAD 请求(遇到 405/501 时改用 GET),跟随重定向并对每一跳的安全头评分。grade_headers 对已有的响应头做同样的评分,不访问网络。explain_header 返回单个响应头的用途、推荐值和参考依据。评分覆盖 CSP、HSTS、X-Frame-Options、X-Content-Type-Options、Referrer-Policy、Permissions-Policy、Cross-Origin-* 系列头、Set-Cookie 属性以及信息泄露类响应头,并给出分数和等级。
- 适用场景
- 适合让助手审查自己拥有或正在评估的网站的安全头配置,对从别处取得的响应头做评分,或查询某个响应头应当如何设置。它只是配置检查,不是渗透测试。
- 运行要求
- 以 stdio 方式在本地运行,可作为 npm 包(npx @basitalisandhu/mcp-security-headers)或通过 Docker 运行 OCI 镜像;使用 npm 方式需要 Node.js。未声明任何账号、API 密钥或环境变量。check_url_headers 需要网络访问,grade_headers 和 explain_header 可离线使用。仅支持桌面客户端。
安装
在 SourceWeft 中
- 打开 控制台中的 Security Headers,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
security-headers MCP server
Fetches a public URL's response headers and grades Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, the Cross-Origin-* headers, Set-Cookie attributes and information-disclosure headers, with an explanation and a recommendation per header. The response body is never downloaded.
Part of dev-mcp-servers. Stdio transport only; the server never opens a port.
Tools
Install
Claude Code:
Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):
Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/security-headers/dist/index.js"] after npm install && npm run build at the repository root.
What it touches
- Network: One request to the URL you give plus at most
max_redirectshops, each validated. 10 s timeout per request. The host is resolved and every address checked before connecting; this does not defeat DNS rebinding between the check and the connection, so do not point the tool at hosts you do not trust to answer honestly. No telemetry. - Local files: None.
- Telemetry: none.
Notes
- Scores: CSP 25, HSTS 20, X-Frame-Options 10, X-Content-Type-Options 10, Referrer-Policy 10, Set-Cookie 10, Permissions-Policy 5, COOP 5, CORP 5. Grades: A+ (95% and no fail), A (85% and no fail), B (70%), C (55%), D (40%), otherwise F.
- A report-only CSP earns nothing: it is not enforced.
- A good grade means the headers are configured well, not that the application is secure.
Build and test
Tests use node:test and the SDK's in-memory transport; they do not reach the network.
Licence
MIT. See LICENSE.
来源:packages/security-headers/README.md,提交 58c8c95
工具
0版本历史
1- v0.1.1最新Oct 5, 2026


