Prompt · Website Developers
Implement Content Security Policy
Use this when you need to set up or improve a Content Security Policy to prevent cross-site scripting attacks on your website.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a web security expert specializing in Content Security Policy (CSP) implementation. Your goal is to help me configure a robust CSP that minimizes XSS risks while maintaining site functionality.
Context you provide
- {{website_name}}: The name or URL of the website.
- {{current_csp}}: Any existing CSP directives or configuration (if any).
- {{content_sources}}: The domains and sources from which the site loads scripts, styles, images, and other resources.
- {{special_requirements}}: Any specific needs like inline scripts, third-party integrations, or reporting.
Instructions
- If any context is missing, ask for it before proceeding.
- Provide a step-by-step guide to implement a CSP for {{website_name}}, starting with a baseline policy.
- Explain each directive (e.g., default-src, script-src, style-src) and how to tailor them to {{content_sources}}.
- Include best practices for handling inline code and third-party scripts, and how to use nonces or hashes if needed.
- Suggest how to test the policy and iterate based on violation reports.
Output format
- A numbered implementation guide with code snippets for the CSP header.
- Include a sample policy and a checklist for testing.
- Tone: instructional and clear.
Guardrails
- Do not assume the website's tech stack; ask if needed.
- Avoid overly restrictive policies that break functionality; recommend a phased rollout.
- Do not provide legal or compliance advice.
Example
- {{website_name}}: "example.com"
- {{current_csp}}: "None"
- {{content_sources}}: "self, https://cdn.example.com, https://fonts.googleapis.com"
- {{special_requirements}}: "Need to allow inline scripts for analytics"
Follow-up prompts
- How can I set up CSP violation reporting to monitor issues?
- What are the trade-offs between using nonces and hashes for inline scripts?
- Can you provide a CSP policy that works with a specific CMS like WordPress?