Skip to main content
Glama
shakiltousif

http-security-headers-mcp

by shakiltousif

http-security-headers-mcp

Analyze and score HTTP security headers (CSP, HSTS, CORS, cookies) with actionable fix recommendations for web applications.

Available on MCPize

Tools

Tool

Description

scan_headers

Fetch a URL and analyze all security headers. Returns A+ to F grade with findings.

score_headers

Score a set of headers you provide. Returns grade and per-header breakdown.

analyze_csp

Deep analysis of a Content-Security-Policy header. Detects unsafe sources and bypass risks.

generate_headers

Generate recommended security headers config for Express, Next.js, nginx, Apache, Cloudflare, or Vercel.

Related MCP server: web-doctor

Quick Start

npx -y mcpize connect @shakiltousif/http-security-headers-mcp --client claude

Or visit: mcpize.com/mcp/http-security-headers-mcp

Per-client install

Claude:    claude mcp add --transport http http-security-headers-mcp https://http-security-headers-mcp.mcpize.run/mcp
Cursor:    cursor mcp add http-security-headers-mcp https://http-security-headers-mcp.mcpize.run/mcp
Windsurf:  windsurf mcp add http-security-headers-mcp https://http-security-headers-mcp.mcpize.run/mcp

JSON Config (manual setup)

{
  "mcpServers": {
    "http-security-headers-mcp": {
      "url": "https://http-security-headers-mcp.mcpize.run/mcp"
    }
  }
}

Run Locally

npm install
mcpize dev              # Start dev server with hot reload
mcpize dev --playground # Interactive testing in your browser

Server runs at http://localhost:3000/mcp

Development

mcpize dev         # Development mode (port 3000, hot reload, loads .env)
npm run build      # Compile TypeScript
npm test           # Run unit tests (26 tests)
bash test-mcp.sh   # MCP protocol smoke test (14 checks)
npm start          # Run compiled server (port 8080)

Deploy

mcpize login                # Authenticate (opens browser)
mcpize deploy               # Ship it!

Project Structure

src/
  index.ts          # Express + MCP server setup, tool registration
  tools.ts          # Pure business logic (header analysis, scoring, CSP parsing)
tests/
  tools.test.ts     # Unit tests (vitest)
test-mcp.sh         # MCP protocol smoke test
mcpize.yaml         # MCPize deployment config
Dockerfile          # Production container build

License

MIT

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Audit any website for privacy, security, accessibility, and performance issues — with scores, grades, and actionable fix instructions. No account required.
    3
    4 npm
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables live website health checks including TLS, HTTPS, and security headers, returning an A-F grade with specific fixes.
    2
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Offline, dependency-free transport-layer hardening auditor for MCP Streamable HTTP endpoints, probing for DNS rebinding, CORS, session-ID, cleartext, and protocol conformance defects with a severity-weighted score and CI gate.
    MIT