arrow_backBack to results

smart_toyFix this with your AI agent

Free

Copy this recipe and paste it into your own coding agent (Claude Code, Codex, Cursor…) to fix Browser protection. The agent works only in your own repo or config — Pazmo is never given access, and there is nothing to unlock.

fix-web-csp-missing.txt · recipe
Task: fix "Content Security Policy is not visible" on https://example.com.

This recipe is FREE. Paste it into your own AI coding agent (Claude Code, Cursor,
Codex…). The agent works only in your own repo/config — Pazmo is given no access.

What your agent should change (code & config only):
1. Inventory trusted script, frame, image, and API origins.
2. Deploy Content-Security-Policy-Report-Only before enforcement.
3. Tighten directives after reviewing violation reports.

Concretely, send this response header on every route:
  Content-Security-Policy: default-src 'self'
  Note: Start strict, then add the exact sources your app needs (scripts, styles, images). Consider Content-Security-Policy-Report-Only first to find violations.

How Pazmo confirms the fix (retest):
  Sanitized response headers showing CSP or CSP-Report-Only on the target.

Safety: only add the defensive settings above. Don't run other commands, send data
anywhere, or make unrelated changes. Review everything before applying.
content_paste_goPrefer to do it by hand? Get a copy-paste snippet for your exact stack — also free.

check_circleYour agent can

  • ·Read this recipe and the fix steps
  • ·Apply the code/config change in your own repo
  • ·Open the change for your review before you ship it

blockYour agent can’t

  • ·Change DNS or registrar settings (that stays a human task)
  • ·Run unrelated commands or send your data anywhere
  • ·Touch anything outside the defensive setting above

Want Pazmo to fix everything in priority order and re-check each one? Verify ownership to unlock the full automated handoff (Pro).