Grade a set of HTTP response headers for security: returns a 0-100 score, a letter grade (A+ to F), a pass/fail/warning summary, and a per-header finding with a recommendation for CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin-* headers. Pass the headers you already have; this tool does not fetch the URL.
This page documents the MCP tool findutils:security_headers_analyzer. See the REST reference →
Call it over MCP
Tool name findutils:security_headers_analyzer
· no API keys · 120 requests/min per IP
Claude Code
claude mcp add findutils --transport http https://mcp.findutils.com/ Claude Desktop — claude_desktop_config.json
{
"mcpServers": {
"findutils": {
"url": "https://mcp.findutils.com/"
}
}
} Raw JSON-RPC (any MCP client) — verified example
curl -X POST https://mcp.findutils.com/ \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "security_headers_analyzer",
"arguments": {
"headers": {
"content-security-policy": "default-src '\''self'\''",
"strict-transport-security": "max-age=31536000",
"x-content-type-options": "nosniff",
"x-frame-options": "DENY"
},
"url": "https://example.com"
}
}
}' Input schema
| Argument | Type | Required | Description |
|---|---|---|---|
| headers | object | yes | Response headers as an object of header name → value (case-insensitive), e.g. {"content-security-policy": "default-src 'self'"}. A raw "Name: value" block string (one header per line, as copied from curl -I) is also accepted. |
| url | string | no | Optional URL the headers came from. Echoed in the result only. |
Example arguments (verified)
{
"headers": {
"content-security-policy": "default-src 'self'",
"strict-transport-security": "max-age=31536000",
"x-content-type-options": "nosniff",
"x-frame-options": "DENY"
},
"url": "https://example.com"
} Also a REST endpoint
The same tool answers plain HTTP at
POST /api/tools/security-headers-analyzer/execute — no key, 60 requests/min.
More Network tools
Cidr Calculate
Compute network / broadcast / first-last host / subnet mask / hosts count for a CIDR (e.g.
Cookie Analyzer
Analyze Set-Cookie header strings and return a per-cookie list of security issues, an overall 0-100 score, and recommendations.
Curl To Code
Returns source code that performs the same HTTP request as a cURL command, in JavaScript (fetch), Python (requests), PHP (cURL), Go (net/htt
Dns Lookup
Return the DNS records of a domain for one record type (A, AAAA, CNAME, MX, TXT, NS or SOA).
Dns Security Scanner
Return a DNS security report for a domain: SPF, DMARC, MX and CAA records with issues, a 0-100 score, a letter grade and recommendations.
Email Security Checker
Return an email-security report for the domain of an email address: MX, SPF, DKIM (common selectors), DMARC, MTA-STS, TLS-RPT and BIMI check
Har To Curl
Convert a HAR (HTTP Archive) file into curl commands, one per recorded request, and return them as a script plus a per-request list.
Http Status Code Lookup
Return the meaning, typical use case and fix for HTTP status codes.