Security Headers

io.github.basitalisandhuv0.1.1更新於 Oct 5, 2026

Fetch a URL's response headers and grade CSP, HSTS, X-Frame-Options and related security headers.

概覽

AI 產生的概覽

抓取公開網址的 HTTP 回應標頭並為其安全標頭評分,同時提供每個標頭的說明與建議。

功能
此伺服器提供三個工具。check_url_headers 對公開的 http(s) 網址送出 HEAD 請求(遇到 405/501 時改用 GET),跟隨重新導向並對每一跳的安全標頭評分。grade_headers 對你手上既有的標頭做相同評分,不存取網路。explain_header 回傳單一標頭的用途、建議值與參考依據。評分涵蓋 CSP、HSTS、X-Frame-Options、X-Content-Type-Options、Referrer-Policy、Permissions-Policy、Cross-Origin-* 系列標頭、Set-Cookie 屬性以及資訊揭露類標頭,並給出分數與等級。
適用情境
適合讓助理稽核你自己擁有或正在評估的網站的安全標頭設定、為從其他地方取得的標頭評分,或查詢某個標頭應該如何設定。它只是設定檢查,並非滲透測試。
執行需求
以 stdio 方式在本機執行,可作為 npm 套件(npx @basitalisandhu/mcp-security-headers)或透過 Docker 執行 OCI 映像;使用 npm 方式需要 Node.js。未宣告任何帳號、API 金鑰或環境變數。check_url_headers 需要網路存取,grade_headers 與 explain_header 可離線使用。僅支援桌面用戶端。
安裝前請注意
check_url_headers 會對你提供的網址發出外部請求並跟隨重新導向,因此只應指向你信任的主機;README 指出主機驗證無法阻止驗證與連線之間的 DNS 重綁定。不會下載回應內容,也不傳送遙測資料。評分良好只代表標頭設定妥當,並不代表應用程式整體安全。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Security Headers,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

security-headers MCP server

Fetches a public URL's response headers and grades Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, the Cross-Origin-* headers, Set-Cookie attributes and information-disclosure headers, with an explanation and a recommendation per header. The response body is never downloaded.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
check_url_headersurl, method? (HEAD or GET), max_redirects? (0 to 10, default 5)HEAD request (GET on 405/501) to a public http(s) URL, redirects followed with the same checks on every hop, then a graded report. Refuses localhost, .local, .internal, private, loopback, link-local, CGNAT and cloud-metadata addresses, including names that resolve to them.
grade_headersheaders (object), https?The same grading for headers you already have, for example from curl -I. No network.
explain_headerheaderPurpose, recommended value and reference for one header.

Install

Claude Code:

bash
claude mcp add security-headers -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "security-headers": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/security-headers/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: One request to the URL you give plus at most max_redirects hops, each validated. 10 s timeout per request. The host is resolved and every address checked before connecting; this does not defeat DNS rebinding between the check and the connection, so do not point the tool at hosts you do not trust to answer honestly. No telemetry.
  • Local files: None.
  • Telemetry: none.

Notes

  • Scores: CSP 25, HSTS 20, X-Frame-Options 10, X-Content-Type-Options 10, Referrer-Policy 10, Set-Cookie 10, Permissions-Policy 5, COOP 5, CORP 5. Grades: A+ (95% and no fail), A (85% and no fail), B (70%), C (55%), D (40%), otherwise F.
  • A report-only CSP earns nothing: it is not enforced.
  • A good grade means the headers are configured well, not that the application is secure.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-security-headersnpm test -w @basitalisandhu/mcp-security-headers

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

來源:packages/security-headers/README.md,提交 58c8c95

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.1最新Oct 5, 2026