Security Headers Analyzer

Network REST API MCP

Grade a set of HTTP response headers for security: returns a 0-100 score, a letter grade (A+ to F), a pass/fail/warning summary, and a per-header finding with a recommendation for CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin-* headers. Pass the headers you already have; this tool does not fetch the URL.

This page documents the MCP tool findutils:security_headers_analyzer. See the REST reference →

Call it over MCP

Tool name findutils:security_headers_analyzer · no API keys · 120 requests/min per IP

Claude Code

claude mcp add findutils --transport http https://mcp.findutils.com/

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "findutils": {
      "url": "https://mcp.findutils.com/"
    }
  }
}

Raw JSON-RPC (any MCP client) — verified example

curl -X POST https://mcp.findutils.com/ \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "security_headers_analyzer",
      "arguments": {
        "headers": {
          "content-security-policy": "default-src '\''self'\''",
          "strict-transport-security": "max-age=31536000",
          "x-content-type-options": "nosniff",
          "x-frame-options": "DENY"
        },
        "url": "https://example.com"
      }
    }
  }'

Input schema

Argument Type Required Description
headers object yes Response headers as an object of header name → value (case-insensitive), e.g. {"content-security-policy": "default-src 'self'"}. A raw "Name: value" block string (one header per line, as copied from curl -I) is also accepted.
url string no Optional URL the headers came from. Echoed in the result only.

Example arguments (verified)

{
  "headers": {
    "content-security-policy": "default-src 'self'",
    "strict-transport-security": "max-age=31536000",
    "x-content-type-options": "nosniff",
    "x-frame-options": "DENY"
  },
  "url": "https://example.com"
}

Also a REST endpoint

The same tool answers plain HTTP at POST /api/tools/security-headers-analyzer/execute — no key, 60 requests/min.

Open the REST reference for Security Headers Analyzer →

More Network tools