cors-auditorlisted
Install: claude install-skill NovaCode37/claude-security-skills
# CORS Misconfiguration Auditor
Inspects CORS response headers and reports exploitable misconfigurations with
fixes. The analysis core is pure and offline-testable; live probing uses only
stdlib `urllib` and sends a throwaway `Origin` header to detect origin
reflection.
## When to use this skill
- "Audit the CORS configuration of https://api.example.com."
- "Is it safe that my API returns Access-Control-Allow-Origin: *?"
- "Does my server reflect any Origin back?"
## What it checks
- **Wildcard + credentials** — `Allow-Origin: *` with
`Allow-Credentials: true` (`cors-wildcard-credentials`).
- **Reflected origin** — server echoes the request Origin back
(`cors-reflected-origin`); critical when combined with credentials.
- **Null origin** — `Allow-Origin: null` (`cors-null-origin`).
- **Wildcard origin** — `Allow-Origin: *` without credentials (`cors-wildcard`).
- **Credentialed CORS** — informational note when credentials are enabled
(`cors-credentials-enabled`).
- **Wildcard methods** — `Allow-Methods: *` (`cors-methods-wildcard`).
## How to run it
```bash
# Live probe (sends a throwaway Origin to test reflection)
python skills/cors-auditor/auditor.py https://api.example.com
# Probe with a specific origin
python skills/cors-auditor/auditor.py https://api.example.com --origin https://evil.example
# Offline: audit a captured header block; pass --origin to test reflection
python skills/cors-auditor/auditor.py --headers-file resp.txt --origin https://evil.example