check @community/check-cookie-secure-flags

Cookie Secure Flags

Session and auth cookies must carry Secure, HttpOnly, and SameSite=Strict (or Lax for OAuth flows).…

Skill
@community
Domain
security
Version
1.0.0
Quality
0.0
Edges
0 out · 0 in
Tokens
83/559/1074
$ aoe install @community/check-cookie-secure-flags

Projection

Always in _index.xml · the agent never has to ask for this.

CookieSecureFlags [check] v1.0.0

Session and auth cookies must carry Secure, HttpOnly, and SameSite=Strict (or Lax for OAuth flows). Missing any flag opens specific attack vectors: Secure omission allows plain-HTTP cookie theft, HttpOnly omission allows XSS cookie exfiltration, SameSite omission allows CSRF.

Source

aoe-engine/examples/frontend-design/primes/compiled/@community/check-cookie-secure-flags/atom.yaml