Install
$ agentstack add skill-shieldnet-360-secure-vibe-cors-security ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
CORS Security
Strict CORS configuration: no wildcard with credentials, allowlist-based origins, sensible preflight cache, minimal exposed headers
ALWAYS
- Use an allowlist of origins, not
*. Reflect the incomingOriginheader only when it matches a known entry from configuration (or matches a precompiled regex of operator-controlled hostnames). - If responses include credentials (cookies,
Authorization), setAccess-Control-Allow-Credentials: trueand ensureAccess-Control-Allow-Originis a single specific origin string — never*. - Include
Vary: Originon responses whose body depends on the requestOrigin, so caches don't serve one origin's response to another. - Restrict preflight
Access-Control-Allow-Methodsto the actual methods the endpoint accepts; restrictAccess-Control-Allow-Headersto the actual headers consumed. - Set
Access-Control-Max-Ageto a sensible value (≤ 86400 in production) to amortize preflight latency without locking in a bad allowlist. - Maintain the allowlist in code (or in a config file checked into source), not derived from a database — so attackers can't add their origin by inserting a row.
NEVER
- Set
Access-Control-Allow-Origin: *together withAccess-Control-Allow-Credentials: true. The Fetch spec forbids it for a reason — browsers will refuse the response, but the bigger problem is that an upstream proxy / cache may already have leaked it. - Reflect the
Originheader without an allowlist check (Access-Control- Allow-Origin:for every incoming origin). That's the same as*for credentials but with worse caching behavior. - Allow
nullas an Origin.nullis what Chrome sends from sandboxed iframes,data:URIs, andfile://— none of which should have credentialed access to your API. - Allow arbitrary subdomains with a regex like
.*\.example\.com$without considering subdomain takeover. Pin specific subdomains; treat*.example.comas a deliberate decision tied to subdomain ownership controls. - Expose internal headers via
Access-Control-Expose-Headers. Limit to the minimal set the frontend genuinely needs. - Use CORS as authorization. CORS is a browser policy; it does not stop server-to-server, curl, or non-browser clients. Authenticate the request properly.
KNOWN FALSE POSITIVES
- Truly public, unauthenticated APIs (e.g., open data, marketing CDN endpoints) can legitimately use
Access-Control-Allow-Origin: *without credentials. - Internal admin tools restricted to a private network can use a single fixed origin; the wildcard concern doesn't apply because there are no cross-origin callers.
- A handful of integrations (Stripe.js, Plaid, Auth0) expect specific CORS headers — read each provider's CORS section before relaxing the baseline.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ShieldNet-360
- Source: ShieldNet-360/secure-vibe
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.