csp-skill is a public Codex skill repository for auditing and implementing Content Security Policy across web applications.
This repository packages a ready-to-use CSP skill together with reference material that explains the browser rules, implementation patterns, and security tradeoffs behind strong policies.
It is designed for:
- Codex agents that need to audit or implement CSP
- engineers who want a practical, teachable CSP reference
- projects that need a repeatable report-only to enforcement workflow
csp/- installable Codex skillcsp/SKILL.md- agent-facing workflow and triggerscsp/references/- CSP theory, implementation guidance, and security patternscsp/assets/- visual assets used by the skill
- Clone the repository.
- Copy
csp/into your Codex skills directory, or point Codex at this repo if you keep skills versioned in place. - Invoke the skill with
/csp auditor/csp implement. - Use the reference files when you need the reasoning behind a policy choice.
- detect the stack and rendering model
- audit inline code and external resources
- classify each finding as refactor, nonce, hash, allowlist, or remove
- draft the smallest policy that fits the app
- roll out in
Content-Security-Policy-Report-Onlyfirst when risk is unclear - verify browser behavior and tighten the policy over time
- The skill is intentionally written in a didactic style so it can serve as both an agent tool and a learning resource.
- The reference material is paraphrased knowledge, not copied prose.
MIT. See LICENSE.