security_csp_generator
Generate and analyze Content-Security-Policy headers, catching unsafe-inline, unsafe-eval, and missing directives per W3C CSP Level 3.
Instructions
Menu ID: csp_generator. CSP Generator. Build, parse, and analyze Content-Security-Policy (CSP) headers. Catches unsafe-inline, unsafe-eval, missing default-src/frame-ancestors/base-uri, wildcard sources, and strict-dynamic misconfiguration per W3C CSP Level 3. Use describe_tool with tool_id "csp_generator" for full page guidance.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| operation | Yes | ||
| policy | Yes |