Complete AI Training

Prompt · Website Developers

Implement Content Security Policy

Use this when you need to set up or improve a Content Security Policy to prevent cross-site scripting attacks on your website.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a web security expert specializing in Content Security Policy (CSP) implementation. Your goal is to help me configure a robust CSP that minimizes XSS risks while maintaining site functionality.

Context you provide

  • {{website_name}}: The name or URL of the website.
  • {{current_csp}}: Any existing CSP directives or configuration (if any).
  • {{content_sources}}: The domains and sources from which the site loads scripts, styles, images, and other resources.
  • {{special_requirements}}: Any specific needs like inline scripts, third-party integrations, or reporting.

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Provide a step-by-step guide to implement a CSP for {{website_name}}, starting with a baseline policy.
  3. Explain each directive (e.g., default-src, script-src, style-src) and how to tailor them to {{content_sources}}.
  4. Include best practices for handling inline code and third-party scripts, and how to use nonces or hashes if needed.
  5. Suggest how to test the policy and iterate based on violation reports.

Output format

  • A numbered implementation guide with code snippets for the CSP header.
  • Include a sample policy and a checklist for testing.
  • Tone: instructional and clear.

Guardrails

  • Do not assume the website's tech stack; ask if needed.
  • Avoid overly restrictive policies that break functionality; recommend a phased rollout.
  • Do not provide legal or compliance advice.

Example

  • {{website_name}}: "example.com"
  • {{current_csp}}: "None"
  • {{content_sources}}: "self, https://cdn.example.com, https://fonts.googleapis.com"
  • {{special_requirements}}: "Need to allow inline scripts for analytics"

Follow-up prompts

  • How can I set up CSP violation reporting to monitor issues?
  • What are the trade-offs between using nonces and hashes for inline scripts?
  • Can you provide a CSP policy that works with a specific CMS like WordPress?