← ClaudeAtlas

cors-auditorlisted

Audit a site's Cross-Origin Resource Sharing (CORS) configuration for misconfigurations — wildcard origin with credentials, reflected arbitrary Origin, the 'null' origin, overly broad allowed methods, and risky credentialed CORS. Use when the user asks to "check my CORS config", "is my API's CORS safe", "test for CORS misconfiguration", or "why can any site call my API".
NovaCode37/claude-security-skills · ★ 11 · AI & Automation · score 75
Install: claude install-skill NovaCode37/claude-security-skills
# CORS Misconfiguration Auditor Inspects CORS response headers and reports exploitable misconfigurations with fixes. The analysis core is pure and offline-testable; live probing uses only stdlib `urllib` and sends a throwaway `Origin` header to detect origin reflection. ## When to use this skill - "Audit the CORS configuration of https://api.example.com." - "Is it safe that my API returns Access-Control-Allow-Origin: *?" - "Does my server reflect any Origin back?" ## What it checks - **Wildcard + credentials** — `Allow-Origin: *` with `Allow-Credentials: true` (`cors-wildcard-credentials`). - **Reflected origin** — server echoes the request Origin back (`cors-reflected-origin`); critical when combined with credentials. - **Null origin** — `Allow-Origin: null` (`cors-null-origin`). - **Wildcard origin** — `Allow-Origin: *` without credentials (`cors-wildcard`). - **Credentialed CORS** — informational note when credentials are enabled (`cors-credentials-enabled`). - **Wildcard methods** — `Allow-Methods: *` (`cors-methods-wildcard`). ## How to run it ```bash # Live probe (sends a throwaway Origin to test reflection) python skills/cors-auditor/auditor.py https://api.example.com # Probe with a specific origin python skills/cors-auditor/auditor.py https://api.example.com --origin https://evil.example # Offline: audit a captured header block; pass --origin to test reflection python skills/cors-auditor/auditor.py --headers-file resp.txt --origin https://evil.example