Set Secure, HttpOnly, and SameSite flags on session cookies
SkillSecuritysession-cookie-flags is a skill that gives an AI agent a checklist for reviewing session cookies and authentication setup. It is used when reviewing server-side session management, setting up authentication middleware, or auditing cookie configuration in HTTP response headers.
Use Set Secure, HttpOnly, and SameSite flags on session cookies in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Set Secure, HttpOnly, and SameSite flags on session cookies and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Set Secure, HttpOnly, and SameSite flags on session cookies skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Have an AI agent that can load skills.
What your AI can do with it
- Review server-side session management
- Set up authentication middleware
- Audit cookie configuration in HTTP response headers
- Check session cookies against a checklist
Getting started
- Have an AI agent that can load skills.
- Add the session-cookie-flags skill to the agent's available skills.
- Ask the agent to review session management, authentication middleware, or cookie configuration in HTTP response headers.
What this skill tells your AI
The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/session-cookie-flags/SKILL.md and read by ahel’s review.
Missing cookie flags are one of the most common and easily fixed authentication weaknesses. Without Secure, session tokens are transmitted in plain text over HTTP and can be captured by network eavesdroppers. Without HttpOnly, any XSS payload can exfiltrate the session token in one line. Without SameSite, any website can trigger authenticated actions on behalf of the victim without their knowledge.
Quick Reference
- Secure — cookie is only sent over HTTPS, never plain HTTP
- HttpOnly — cookie is invisible to JavaScript (blocks XSS theft)
- SameSite=Strict or Lax — prevents the cookie from being sent on cross-site requests (blocks CSRF)
- Never use SameSite=None without also setting Secure and understanding the CSRF implications
Check
Check whether session and authentication cookies are set with the Secure, HttpOnly, and SameSite flags.
Fix
Update the server's cookie configuration to include Secure, HttpOnly, and SameSite=Strict (or Lax) on all session and auth cookies.
Explain
Explain what each cookie security flag does and the specific attack each one prevents.
Code Review
Review all Set-Cookie headers and cookie creation code. Flag any cookies missing the HttpOnly flag, absent Secure flag, or an unspecified or overly permissive SameSite setting.
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/session-cookie-flags
Signals
- GitHub stars
- 74k
- Forks
- 7k
- Last commit
- Oct 2026
Questions
- When should this skill be used?
- When reviewing server-side session management, setting up authentication middleware, or auditing cookie configuration in HTTP response headers.
- What does the skill provide?
- A checklist the agent can follow when reviewing session cookies and authentication setup.
Advanced
- Item type
- skill
- Key
session-cookie-flags- Source
- github.com/thedaviddias/front-end-checklist
github.com/thedaviddias/front-end-checklist
Related picks
Skill · davila7
The pick for Web (OWASP)security-and-hardening
Skill · addyosmani
The pick for Web (OWASP)gws-shared
Skill · googleworkspace
More in Securitybrandkit
Skill · leonxlnx
More in Securitydefi-amm-security
Skill · affaan-m
More in Securityfastapi-patterns
Skill · affaan-m
More in Security