{"uid":"cap_g6gxZ6V1Ui8t2QUmu2uFL","slug":"khipu-security-headers-auditor-aafd2944","name":"Khipu Security Headers Auditor","description":"Security headers audit for a URL — HSTS, CSP, clickjacking, cookie flags, info leaks. Returns score 0-100, findings with severity and fixes.","url":"https://khipu-x402.khipu-agency.workers.dev/v1/security-headers","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","queryParams"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["url"],"properties":{"url":{"type":"string","format":"uri"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_dceNKB0KItHxAT_cTXIPQ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a URL's HTTP security headers and returns a 0-100 score with severity-ranked findings and remediation advice covering HSTS, CSP, clickjacking, cookie flags, and info leaks.","exampleAgentPrompt":"Can you run a security headers audit on https://example.com and tell me the score, what's missing or misconfigured — like HSTS, CSP, clickjacking protection, cookie flags — and how to fix each issue?","exampleUseCases":[{"title":"Pre-launch security checklist for web app","prompt":"Before we go live, can you audit the security headers on https://app.mycompany.com and give me a score plus a list of everything that needs to be fixed, like missing HSTS, weak CSP, or insecure cookies?"},{"title":"Third-party vendor security due diligence","prompt":"I need to evaluate the security posture of a vendor's site — can you check the HTTP security headers on https://vendor-portal.example.com and flag anything concerning like missing clickjacking protection or info leaks?"},{"title":"CI/CD pipeline security regression check","prompt":"Can you scan https://staging.myapp.io for security header issues and tell me if the score dropped or if there are new findings compared to a healthy baseline — specifically HSTS, CSP, and cookie flags?"}],"resultDescription":"Returns a numeric security score from 0 to 100, a list of security findings each tagged with severity level (e.g. critical, high, medium, low) and category (HSTS, CSP, clickjacking, cookie flags, information leaks), plus actionable remediation recommendations for each finding.","failureModes":["Invalid or unreachable URL returns an error — target must be accessible from the auditor's network","Non-HTTP/HTTPS URLs may be rejected by the URI format validator","Servers behind auth walls or bot-blocking may return incomplete header sets, reducing audit accuracy","Rate limiting or network timeouts on the target URL can cause partial or failed audits","Malformed URL input fails schema validation before the request is made"],"whenToPreferThis":"Choose this endpoint when you need a quick, structured security-header audit with a numeric score and actionable fixes for a specific URL — especially useful in CI/CD pipelines, vendor assessments, or pre-launch reviews. Prefer it over manual header inspection tools when you need machine-readable severity ratings and remediation steps. It is best suited for single-URL audits rather than broad crawls or full penetration testing.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:31:20.493Z","isFirstParty":false}