Skip to content

Csp Generate MCP tool

MCP findutils:csp_generate

Build a Content-Security-Policy header from a preset (strict, typical, google-analytics) and/or your own directives, and get the header line, an equivalent <meta http-equiv> tag, and warnings such as script-src allowing 'unsafe-inline', 'unsafe-eval', * or data:, a missing object-src 'none', base-uri or frame-ancestors. Bare keywords like self are quoted for you; invalid sources are rejected with the directive named. Supports Report-Only with a report-uri. Pure computation: it checks the policy text, not a live site.

Arguments

application/json
  • preset

    string optional

    Starting policy: "strict", "typical" or "google-analytics". Your directives replace the preset's for the same directive. One of strict · typical · google-analytics.

  • directives

    object optional

    Directive name → list of sources (or a space-separated string), e.g. {"script-src": ["self", "https://cdn.example.com"]}. An empty list removes that directive.

  • upgrade_insecure_requests

    boolean optional

    Add upgrade-insecure-requests. Default: true. Default true.

  • report_only

    boolean optional

    Emit Content-Security-Policy-Report-Only instead (reports, does not block). Default: false. Default false.

  • report_uri

    string optional

    Where browsers send violation reports (report-uri).

Example arguments

Verified
{
  "preset": "typical",
  "directives": {
    "script-src": [
      "self",
      "https://cdn.example.com"
    ]
  }
}