# Cors Security

> Strict CORS configuration: no wildcard with credentials, allowlist-based origins, sensible preflight cache, minimal exposed headers — Applies to: when generating CORS middleware or framework config; when wiring API Gateway / Cloud Front / Nginx CORS headers; when reviewing a cross-origin browser-facing endpoint

- **Type:** Skill
- **Install:** `agentstack add skill-shieldnet-360-secure-vibe-cors-security`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [ShieldNet-360](https://agentstack.voostack.com/s/shieldnet-360)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [ShieldNet-360](https://github.com/ShieldNet-360)
- **Source:** https://github.com/ShieldNet-360/secure-vibe/tree/main/dist/claude-skills/.claude/skills/cors-security

## Install

```sh
agentstack add skill-shieldnet-360-secure-vibe-cors-security
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# CORS Security

Strict CORS configuration: no wildcard with credentials, allowlist-based origins, sensible preflight cache, minimal exposed headers

## ALWAYS

- Use an **allowlist** of origins, not `*`. Reflect the incoming `Origin` header only when it matches a known entry from configuration (or matches a precompiled regex of operator-controlled hostnames).
- If responses include credentials (cookies, `Authorization`), set `Access-Control-Allow-Credentials: true` **and** ensure `Access-Control-Allow-Origin` is a single specific origin string — never `*`.
- Include `Vary: Origin` on responses whose body depends on the request `Origin`, so caches don't serve one origin's response to another.
- Restrict preflight `Access-Control-Allow-Methods` to the actual methods the endpoint accepts; restrict `Access-Control-Allow-Headers` to the actual headers consumed.
- Set `Access-Control-Max-Age` to a sensible value (≤ 86400 in production) to amortize preflight latency without locking in a bad allowlist.
- Maintain the allowlist in code (or in a config file checked into source), not derived from a database — so attackers can't add their origin by inserting a row.

## NEVER

- Set `Access-Control-Allow-Origin: *` together with `Access-Control-Allow-Credentials: true`. The Fetch spec forbids it for a reason — browsers will refuse the response, but the bigger problem is that an upstream proxy / cache may already have leaked it.
- Reflect the `Origin` header without an allowlist check (`Access-Control- Allow-Origin: ` for every incoming origin). That's the same as `*` for credentials but with worse caching behavior.
- Allow `null` as an Origin. `null` is what Chrome sends from sandboxed iframes, `data:` URIs, and `file://` — none of which should have credentialed access to your API.
- Allow arbitrary subdomains with a regex like `.*\.example\.com$` without considering subdomain takeover. Pin specific subdomains; treat `*.example.com` as a deliberate decision tied to subdomain ownership controls.
- Expose internal headers via `Access-Control-Expose-Headers`. Limit to the minimal set the frontend genuinely needs.
- Use CORS as authorization. CORS is a *browser* policy; it does not stop server-to-server, curl, or non-browser clients. Authenticate the request properly.

## KNOWN FALSE POSITIVES

- Truly public, unauthenticated APIs (e.g., open data, marketing CDN endpoints) can legitimately use `Access-Control-Allow-Origin: *` *without* credentials.
- Internal admin tools restricted to a private network can use a single fixed origin; the wildcard concern doesn't apply because there are no cross-origin callers.
- A handful of integrations (Stripe.js, Plaid, Auth0) expect specific CORS headers — read each provider's CORS section before relaxing the baseline.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [ShieldNet-360](https://github.com/ShieldNet-360)
- **Source:** [ShieldNet-360/secure-vibe](https://github.com/ShieldNet-360/secure-vibe)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** yes
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-shieldnet-360-secure-vibe-cors-security
- Seller: https://agentstack.voostack.com/s/shieldnet-360
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
