Product Kit · 1.0.0

Browser-local · offline evidence only

HTTP Security Remediation Kit

Turn submitted HTTP headers and optional local HTML metadata into sanitized security findings, reviewable header candidates, assertions, and a remediation report.

Web developers reviewing caller-exported HTTP evidence offline without giving Utilito a target to contact.

Build-time verified sample

This static sample is separate from the live result below. Status: blocked; sanitized findings: 5.

Remove authorization, credentials, tokens, Cookie values, and secret-shaped content. Use [REDACTED] for Set-Cookie values.

Runnable browser-local sample input is ready.

Live result

Not generated. Build a new browser-local remediation packet.

Offline boundary

There is no target URL field, no fetch, no DNS, no TLS inspection, no crawl, and no endpoint scan. This is not a penetration test or security certification.

Scoped evidence

Cookie, CORS, CSP, cache, HSTS, framing, referrer, permissions, and content type stay separate. Findings expose safe header names and ordinals, never submitted values.

Manual remediation

Corrected candidates require manual review. They are not deployed configuration and not a compliance guarantee. Assertions are inert and never execute submitted content.

Limits and review notes

  • Only caller-submitted header lines and optional browser-local HTML metadata are inspected. There is no target URL field, fetch, DNS, TLS, crawl, endpoint scan, or penetration test.
  • Authorization material, credentials, secret-shaped content, request Cookie values, and non-redacted Set-Cookie values fail closed before findings, reports, assertions, or artifacts are created.
  • Findings expose only stable codes, severities, domains, safe header names, and ordinals. Cookie, CORS, CSP, cache, HSTS, framing, referrer, permissions, and content-type policy remain separately scoped.
  • Corrected header candidates are illustrative manual-review examples. They are not deployed configuration, security certification, or compliance guarantees. Generated assertions inspect caller-provided header names only and never execute submitted content.

Free runnable capability

Build and download one bounded browser-local HTTP remediation packet with no signup.

Builder capability

The existing Builder Pilot can coordinate higher bounded review volume; it does not add fetching, scanning, deployment, compliance certification, credentials, storage, or monitoring.

See the existing Builder Pilot

Privacy boundary

Browser generation runs locally. API and MCP are response-only; credentials and cookie values fail closed before findings or artifacts, and no target, fetch, DNS, TLS, crawl, scan, storage, telemetry, or model is used.