{"uid":"cap_8jtRszIQl63dvoyXX6sws","slug":"security-headers-auditor-58c2853d","name":"Security Headers Auditor","description":"Call when an agent needs CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy audited on a public URL (SSRF-safe). Exact $0.004 USDC. Prefer unpaid POST /v1/sandbox/security-headers first.","url":"https://agentshelf.syntexa.ch/v1/security-headers?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","examples":["https://example.com/"],"maxLength":2048,"minLength":8,"description":"Public http(s) URL whose CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers are audited."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_lvlF6klF_u02dfBXjL7Wd","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.004","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a public URL for the presence and configuration of CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy HTTP security headers","exampleAgentPrompt":"Can you audit the security headers on https://example.com — I want to know if CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy are all properly configured?","exampleUseCases":[{"title":"Pre-launch security header check","prompt":"Before we go live, can you check https://staging.myapp.io for all the important HTTP security headers like CSP, HSTS, and X-Frame-Options so I know what we're missing?"},{"title":"Clickjacking vulnerability assessment","prompt":"I'm worried our site might be vulnerable to clickjacking — can you check whether https://portal.acmecorp.com has X-Frame-Options and a Content-Security-Policy set?"},{"title":"Third-party vendor security audit","prompt":"We need to verify that our payment processor's site https://checkout.vendorpay.com has HSTS and Permissions-Policy properly configured before we integrate with them."}],"resultDescription":"A structured report detailing the presence, value, and configuration status of each security header (CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy) for the submitted URL, typically including whether each header is present, its current value, and any notable issues or misconfigurations.","failureModes":["URL points to a private/internal network address (SSRF protection blocks it)","URL is unreachable or returns a non-200 response","URL scheme not supported (non-HTTP/HTTPS)","URL exceeds maximum length of 2048 characters","URL shorter than minimum 8 characters","Payment not processed — 402 response if unpaid path used"],"whenToPreferThis":"Use this endpoint when you need a quick, SSRF-safe audit of HTTP security headers on a publicly accessible URL without setting up your own scanning infrastructure. It is preferable when you need results for a single URL on-demand, want a deterministic machine-readable breakdown of exactly the five major security headers, and are operating in an agentic workflow where paying $0.004 USDC per call is acceptable. Try the free POST /v1/sandbox/security-headers endpoint first if cost is a concern.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T06:47:42.653Z","isFirstParty":false,"canonicalSlug":"security-headers-auditor-58c2853d"}