site-server-audit

Audit websites for DNS, TLS, headers, paths, cookies, and software signatures.

15|Updated May 12, 2026
One-click install
npx skills add https://github.com/GoldenWing-360/claude-security-skills --skill site-server-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: site-server-audit
Source: https://github.com/GoldenWing-360/claude-security-skills/tree/main/site-server-audit
Command: npx skills add https://github.com/GoldenWing-360/claude-security-skills --skill site-server-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and assets (resource) components.

What problem does it solve?

This Skill enables security professionals and developers to perform comprehensive, passive security audits of websites without intrusive actions, helping identify vulnerabilities and misconfigurations.

Core Features & Use Cases

  • Passive Security Checks: Verify DNS configurations, TLS protocols, security headers, exposed paths, cookies, and software fingerprinting.
  • Pre-Deployment Assessment: Conduct audits before launching or after infrastructure updates to ensure security compliance.
  • Use Case: An auditor reviews a client’s website to identify misconfigurations such as missing security headers or exposed sensitive paths, enabling targeted remediation.

Quick Start

Provide the target hostname and optional document root path to perform a passive security assessment of the website.

Frequently Asked Questions about site-server-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a passive website security audit to identify vulnerabilities and misconfigurations?

You can perform a passive website security audit by providing a target hostname and optional document root path. The assessment checks DNS configurations, TLS protocols, security headers, exposed paths, cookies, and software signatures to identify vulnerabilities without intrusive actions.

What does a passive security assessment check for to ensure website compliance?

A passive security assessment checks for website compliance by verifying DNS configurations, TLS protocols, security headers, exposed sensitive paths, cookies, and software fingerprinting. It identifies misconfigurations and vulnerabilities to ensure targeted remediation.

Can I use passive security checks to review a website before deployment or after infrastructure updates?

Yes, you can use passive security checks to review a website before deployment or after infrastructure updates. This verifies DNS, TLS, security headers, exposed paths, cookies, and software signatures to ensure security compliance without intrusive actions.

What is the best way to find missing security headers and exposed paths on a target website?

The best way to find missing security headers and exposed paths is through a passive security audit. This process assesses the target hostname to identify vulnerabilities and misconfigurations like missing headers or exposed sensitive paths, enabling targeted remediation.

Do I need a document root path to assess website TLS and DNS configurations?

No, you only need the target hostname to assess website TLS and DNS configurations. Providing an optional document root path enhances the passive security assessment by allowing deeper checks of exposed paths and software signatures.