Set an X-Frame-Options header

SkillSecurity

x-frame-options is a skill for AI agents that reviews HTTP response headers for clickjacking protection. It checks whether a website's security settings block attackers from tricking users into clicking hidden buttons, and is used when reviewing any web application with authenticated user actions.

Use Set an X-Frame-Options header in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Set an X-Frame-Options header and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Set an X-Frame-Options header skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Have a web application with authenticated user actions that you want to review.

Set an X-Frame-Options headerStart free

What your AI can do with it

  • Review HTTP response headers for clickjacking protection
  • Check whether security settings block attackers from tricking users into clicking hidden
  • Apply to any web application with authenticated user actions

Getting started

  1. Have a web application with authenticated user actions that you want to review.
  2. Add the x-frame-options skill to your agent's available skills.
  3. Ask the agent to review the application's HTTP response headers for clickjacking protection.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/x-frame-options/SKILL.md and read by ahel’s review.

Without framing protection, an attacker can embed your banking login page in a transparent iframe on a malicious site and trick users into clicking buttons they cannot see — transferring money, changing settings, or leaking credentials.

Quick Reference

  • Use X-Frame-Options: DENY to prevent all framing, or SAMEORIGIN to allow framing only from your own domain
  • ALLOWFROM is obsolete and unsupported in modern browsers — use CSP frame-ancestors instead
  • The modern equivalent is Content-Security-Policy: frame-ancestors 'none' — prefer CSP for new sites
  • Both headers can coexist: X-Frame-Options for older browsers, frame-ancestors for modern ones
  • Clickjacking attacks trick users into clicking invisible iframe buttons — DENY eliminates this entirely

Check

Check whether the server sends an X-Frame-Options header (DENY or SAMEORIGIN) or a Content-Security-Policy header with frame-ancestors directive to prevent clickjacking.

Fix

Add X-Frame-Options: DENY to all responses if the site does not need to be embedded anywhere. If legitimate framing is needed on the same origin, use SAMEORIGIN. For fine-grained control, use CSP frame-ancestors instead.

Explain

Explain what a clickjacking attack is, how X-Frame-Options and CSP frame-ancestors prevent it, and the difference between DENY and SAMEORIGIN values.

Code Review

Review server config, headers, forms, and integration points related to Set an X-Frame-Options header. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/security/x-frame-options

Signals

GitHub stars
74k
Forks
7k
Last commit
Oct 2026

Questions

When should this skill be used?
Use it when reviewing HTTP response headers for clickjacking protection on any web application with authenticated user actions.
What does the skill check?
It checks whether a website's security settings block attackers from tricking users into clicking hidden buttons.
Advanced
Item type
skill
Key
x-frame-options
Source
github.com/thedaviddias/front-end-checklist