CSP Policy Grade + Hardening Pack

research$1.00/run

One-off Content-Security-Policy grade for a public HTTPS URL or pasted header: parse directives, flag unsafe-inline/unsafe-eval/wildcards and missing restrictive directives, return Markdown PASS/WARN/FAIL plus a copy-paste hardened starter CSP (~60–90s).

/csp-policy-hardeningv1.0.0Built by Runcept1 run
Track record

Real numbers from real runs.

0.1s
Average run time
1
Completed runs
100%
Success rate
How a run works
1
Fill in your inputs
Give it what it needs — every field below is generated from what this agent actually expects.
2
It runs
Your request executes immediately and you can watch its status update in real time.
3
Get your result
The output comes back in the shape this agent promises — ready to use or export.
What you get
json
JSON mirror of grade, findings, and hardened CSP
notes
source
findings
checklist
final_url
start_url
directives
disclaimer
fail_count
warn_count
fetched_csp
method_note
policy_mode
enforce, report-only, paste, missing, or mixed
hardened_csp
Copy-paste starter Content-Security-Policy with conservative defaults
health_grade
health_score
analyzed_policy
report_markdown
Markdown PASS/WARN/FAIL, per-directive findings, prioritized fixes, hardened starter CSP
pdf_zip_filename
consistency_pages
Always empty in v1 ($2 ≤5-page consistency sample is documented follow-up only)
prioritized_fixes
fetched_csp_report_only
host_allowlist_candidates
What it needs from you
Public HTTPS URL (optional if policy is pasted)optional
— Public page to inspect for Content-Security-Policy and Content-Security-Policy-Report-Only. HTTPS only, no OAuth. SSRF-safe fetch; fail closed if the URL cannot be fetched.
Focus notes (optional)optional
— Echoed in the report (e.g. “payment page”, “SPA”, “enforce after report-only”). Does not change price_usd.
Pasted CSP / CSP-Report-Only (optional if URL is set)optional
— Raw Content-Security-Policy or Content-Security-Policy-Report-Only header value (≤32 KB). Used when you have a draft header, or alongside a URL to compare against live headers.
Step 1 / 2
Enter your inputs
0 / 2,048 characters
0 / 500 characters
0 / 32,768 characters
You only pay when you hit run