Skip to main content
Glama
1nc0gn30

web-security-guard

by 1nc0gn30

πŸ›‘οΈ Web Security Guard


🌟 Overview

Web Security Guard (web-security-guard) is a zero-dependency, high-performance security automation suite and interactive Google Material 3 Security Studio. Built for developers, DevOps engineers, and autonomous AI coding agents, it eliminates the complexity of securing modern web applications against Cross-Site Scripting (XSS), Clickjacking, MIME confusion, and supply chain tampering.

                  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                  β”‚          Google Security Studio UI            β”‚
                  β”‚   Material 3 Light Mode  β€’  0-100 Grade Gauge β”‚
                  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                          β”‚
        β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
        β–Ό                   β–Ό                     β–Ό                   β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Live Auditor  β”‚   β”‚ CSP Level 3   β”‚     β”‚  SRI Engine   β”‚   β”‚   WCAG 2.2    β”‚
β”‚ Headers & SSR β”‚   β”‚ Nonces & Next β”‚     β”‚ Hashes & Tag  β”‚   β”‚ Color Contrastβ”‚
β”‚ 10+ Vectors   β”‚   β”‚ Multi-Platformβ”‚     β”‚ Auto-Inject   β”‚   β”‚ CB Simulation β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜     β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
        β”‚                   β”‚                     β”‚                   β”‚
        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                            β–Ό                     β–Ό
                  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                  β”‚        Model Context Protocol (MCP) Hub       β”‚
                  β”‚  Claude Desktop β€’ Cursor β€’ Cline β€’ Zed β€’ CLI  β”‚
                  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Related MCP server: Sekrd Security Scanner

πŸš€ Key Features

1. πŸ›‘οΈ Multi-Vector Security Header Auditor

  • Audits live websites or response headers against OWASP Top 10 and Google Web Security guidelines.

  • Computes an animated 0–100 Security Grade Gauge ($A+, A, B, C, D, F$).

  • Evaluates:

    • Strict-Transport-Security (HSTS duration, subdomains, preloading).

    • Content-Security-Policy Level 3.

    • X-Frame-Options & CSP frame-ancestors.

    • X-Content-Type-Options: nosniff.

    • Referrer-Policy, Permissions-Policy, COOP, COEP, CORP.

    • RFC 6265bis Cookie Hardening (Secure, HttpOnly, SameSite, __Host- prefixes).

    • Information Leakage detection (Server, X-Powered-By).

2. πŸ”’ CSP Level 3 Policy Builder & Framework Exporter

  • Interactive synthesis of modern 'strict-dynamic' policies with per-request cryptographic nonces.

  • Eliminates vulnerable domain allowlists.

  • Generates 1-click drop-in configurations for:

    • Next.js 14/15 App Router (middleware.ts)

    • Nginx (nginx.conf)

    • Vercel (vercel.json)

    • Netlify (_headers and netlify.toml)

    • Cloudflare Workers

    • Apache (.htaccess)

    • Express.js (helmet)

3. 🧬 Subresource Integrity (SRI) Hasher & HTML Injector

  • Computes SHA-256, SHA-384, and SHA-512 base64 digests for local files or remote CDN bundles.

  • Automated HTML Batch Injector parses raw HTML and inserts integrity and crossorigin="anonymous" tags to protect against supply-chain attacks.

4. 🎨 WCAG 2.2 Color Contrast & Color Blindness Simulator

  • Exact relative luminance ($L = 0.2126 R + 0.7152 G + 0.0722 B$) calculation.

  • Live compliance validation for WCAG AA Normal (4.5:1), AA Large (3:1), UI Components (3:1), and AAA Normal (7:1).

  • Integrated matrix transformation simulation for Protanopia, Deuteranopia, Tritanopia, and Achromatopsia.

5. πŸ€– AI Agent Model Context Protocol (MCP) Hub

  • Out-of-the-box MCP server compatible with Claude Desktop, Cursor AI, Cline, Roo Code, and Zed Editor.

  • Equips LLM agents with tools: audit_url, generate_csp, calculate_sri, calculate_contrast, and remediate_headers.

6. ⚑ Multi-Platform Hardening Exporter

  • 1-click .zip bundle export containing pre-configured security files for your entire infrastructure stack.


πŸ“¦ Installation & Quickstart

Option A: Run via uvx (Zero Install)

# Start the Google Security Studio UI
uvx web-security-guard serve --port 8080 --open

# Audit a live URL directly from CLI
uvx web-security-guard audit https://example.com

Option B: Install via pip

pip install web-security-guard

πŸ’» CLI Usage

# 1. Audit a live website with interactive report
web-sec-guard audit https://google.com

# 2. Audit and output machine-readable JSON
web-sec-guard audit https://example.com --format json

# 3. Generate Level 3 CSP for Next.js App Router
web-sec-guard csp --preset strict_nonce --export nextjs

# 4. Compute Subresource Integrity for CDN script
web-sec-guard sri https://cdn.jsdelivr.net/npm/bootstrap@5.3.3/dist/js/bootstrap.bundle.min.js

# 5. Check WCAG 2.2 Color Contrast
web-sec-guard contrast --fg "#1a73e8" --bg "#ffffff"

# 6. Launch Google Security Studio Web UI
web-sec-guard serve --host 127.0.0.1 --port 8080 --open

🐍 Python SDK

from web_security_guard import (
    SecurityAuditEngine,
    CSPBuilderEngine,
    SRIEngine,
    WCAGContrastEngine,
)

# 1. Run live audit
audit = SecurityAuditEngine.fetch_and_audit("https://example.com")
print(f"Grade: {audit['grade']} (Score: {audit['score']}/100)")

# 2. Build CSP Level 3 policy
csp_data = CSPBuilderEngine.generate({"preset": "strict_nonce"})
print("Next.js Middleware:\n", csp_data["frameworks"]["nextjs"])

# 3. Compute SRI hash
sri = SRIEngine.hash_content_or_url(url="https://cdn.example.com/app.js")
print("SRI Tag:", sri["script_tag"])

# 4. Evaluate WCAG 2.2 Contrast
contrast = WCAGContrastEngine.evaluate("#1a73e8", "#ffffff")
print(f"Ratio: {contrast['ratio_formatted']} | AA: {contrast['wcag_aa_normal']}")

πŸ€– MCP Client Configuration for AI Agents

Add web-security-guard to your AI editor or Claude Desktop config:

{
  "mcpServers": {
    "web-security-guard": {
      "command": "uvx",
      "args": ["web-security-guard", "mcp"]
    }
  }
}

Detailed guides for Cursor, Cline, Zed, and Claude Desktop are available in docs/MCP_GUIDE.md.


πŸ“š Documentation & Reference Examples


πŸ§ͺ Testing & CI

# Run unit tests with pytest
PYTHONPATH=src pytest tests/ -v

All 15 GitHub Actions test matrix jobs run on Python 3.9 through 3.13 on Ubuntu, macOS, and Windows.


πŸ“„ License

Licensed under the Apache License, Version 2.0. See LICENSE for details.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    A comprehensive suite of HTTP and API testing tools that enables AI agents to perform requests, check endpoint health, and decode JWTs. It also provides utilities for URL parsing and detailed security analysis of HTTP response headers.
    5
    30 npm
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Enables deep security auditing of web applications directly from AI IDEs including Cursor and Claude Code. Scans URLs for vulnerabilities, returns security scores with SHIP/BLOCK verdicts, and provides specific fix prompts for remediation.
    3
    -