Product Kit · 1.0.0
HTTP Security Remediation Kit
Turn submitted HTTP headers and optional local HTML metadata into sanitized security findings, reviewable header candidates, assertions, and a remediation report.
Web developers reviewing caller-exported HTTP evidence offline without giving Utilito a target to contact.
Build-time verified sample
This static sample is separate from the live result below. Status: blocked; sanitized findings: 5.
Offline boundary
There is no target URL field, no fetch, no DNS, no TLS inspection, no crawl, and no endpoint scan. This is not a penetration test or security certification.
Scoped evidence
Cookie, CORS, CSP, cache, HSTS, framing, referrer, permissions, and content type stay separate. Findings expose safe header names and ordinals, never submitted values.
Manual remediation
Corrected candidates require manual review. They are not deployed configuration and not a compliance guarantee. Assertions are inert and never execute submitted content.
Limits and review notes
- Only caller-submitted header lines and optional browser-local HTML metadata are inspected. There is no target URL field, fetch, DNS, TLS, crawl, endpoint scan, or penetration test.
- Authorization material, credentials, secret-shaped content, request Cookie values, and non-redacted Set-Cookie values fail closed before findings, reports, assertions, or artifacts are created.
- Findings expose only stable codes, severities, domains, safe header names, and ordinals. Cookie, CORS, CSP, cache, HSTS, framing, referrer, permissions, and content-type policy remain separately scoped.
- Corrected header candidates are illustrative manual-review examples. They are not deployed configuration, security certification, or compliance guarantees. Generated assertions inspect caller-provided header names only and never execute submitted content.
Free runnable capability
Build and download one bounded browser-local HTTP remediation packet with no signup.
Builder capability
The existing Builder Pilot can coordinate higher bounded review volume; it does not add fetching, scanning, deployment, compliance certification, credentials, storage, or monitoring.
See the existing Builder PilotPrivacy boundary
Browser generation runs locally. API and MCP are response-only; credentials and cookie values fail closed before findings or artifacts, and no target, fetch, DNS, TLS, crawl, scan, storage, telemetry, or model is used.