check @community/check-content-security-policy

Content Security Policy

CSP header must be present on HTML responses, must not contain 'unsafe-inline' or 'unsafe-eval' in script-src, and must not use wildcard (*) as the sole source in script-src or default-src.

Skill
@community
Domain
security
Version
1.0.0
Quality
0.0
Edges
0 out · 0 in
Tokens
62/484/940
$ aoe install @community/check-content-security-policy

Projection

Always in _index.xml · the agent never has to ask for this.

ContentSecurityPolicy [check] v1.0.0

CSP header must be present on HTML responses, must not contain 'unsafe-inline' or 'unsafe-eval' in script-src, and must not use wildcard (*) as the sole source in script-src or default-src.

Source

aoe-engine/examples/frontend-design/primes/compiled/@community/check-content-security-policy/atom.yaml