{"id":23888,"plugin_id":"plugins_6ab3634387ec81919729f26fb2a8e67b","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:17:49.208Z","digest":"54f1b435b4f07f4ae025fe0ddbe16ab8d4b46e5346b5ba7e0dad75b78ec61cd4","against":null,"payload":{"name":"headers-cors-cache-security","description":"Review HTTP security headers, CORS, cookies, redirects, and cache isolation for sensitive responses.","included_files":[],"skill_md_contents":"---\nname: headers-cors-cache-security\ndescription: Review HTTP security headers, CORS, cookies, redirects, and cache isolation for sensitive responses.\n---\n\n# Headers, CORS, and Cache Security\n\nInspect response headers on static, Worker-generated, SSR, API, and error responses. Consider CSP, frame protections, `X-Content-Type-Options`, Referrer-Policy, Permissions-Policy, and HSTS only with deployment-specific compatibility analysis. Cloudflare Pages `_headers` rules do not automatically affect responses generated by Worker code; verify both paths. Avoid blindly copying CSP/HSTS examples that could break scripts, subdomains, or preload behavior.\n\nTreat CORS as a browser access policy, never as authentication. Avoid wildcard origins with credentials; allow only necessary origins, methods, and headers. Review cookie attributes and redirect destinations. For caching, verify cache keys and bypass/private behavior for authenticated or personalized content; test cross-user cache isolation. Do not cache sensitive responses publicly without explicit safe design evidence. Report actual response observations separately from repository configuration.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}