Method + roadmap ยท v1 scripts under construction

Shield your site by looking from the inside

Your agent reads the project on your machine, points out what is exposed, makes a backup, simulates the fix and only applies what you approve.

Banner: Shield your site โ€” security from the inside
In short

blinda-site is a method for your AI agent (Claude Code or Codex) to protect a website without touching the site that is live. It reads the project's code and settings on your machine, finds what is exposed and builds a plan of fixes. Each fix comes with two levels of risk: how serious the problem is and how likely the change is to break something. Before changing anything, the method requires a backup and a local simulation. To use it, all you need is the site project on your computer and an agent open in its folder.

What it is

Security without scanning anyone's site

An external scanner reads a page and, on someone else's site, can look like an attack. Looking from the inside, you see far more and you don't need anyone's permission.

The steps: diagnosis, plan, backup, simulation, apply and verify

๐Ÿ” Local only

The diagnosis reads code, config, lockfile and git history. No requests to the live site, no changes to the project.

๐Ÿ’พ Backup and simulation

No fix without a backup branch and without a build, a local server and a browser checking first.

โš–๏ธ Two risk axes

The severity of the problem and the risk of the fix are measured separately. Anything risky always asks first.

How it works

7 steps, in this order

The first three only read. Nothing changes in the project until the plan is approved and the backup exists.

1 Diagnoseโ†’ 2 Reportโ†’ 3 Planโ†’ 4 Backupโ†’ 5 Simulateโ†’ 6 Applyโ†’ 7 Verify

1. Headers and config

CSP, X-Frame-Options, nosniff, Referrer-Policy and HSTS in next.config, vercel.json, _headers.

2. Dependencies

npm audit on the lockfile, the framework version and whether its line still receives fixes.

3. Secrets

.env in git or in the history, a key in the code, a secret exposed to the browser.

4. Database and login

Supabase: a table without RLS, service_role on the front end, an API route that doesn't check the session. Without local migrations, the report says "not verified".

5. Code (v2)

The agent reads and comments: injected HTML, open redirect, upload without a limit.

Risk matrix

Serious doesn't always mean urgent to change

A safe fix for a medium problem comes before a risky fix for a serious problem, which waits for your go-ahead.

Safe fixModerateRisky
Criticaldo firstdo, testingask first
High / mediumdodo, testingask first
Lowdo if cheapnote itnote it
Real findingSeverityFixFix risk
Checkout with no security headers at allhighheaders + minimal CSPsafe
Next.js 16.1.6 in the range of published advisoriesmediumpatch to 16.3.8safe
Next.js 14 with no new fixeshighmigrate to 16risky
No script CSPmediumscript-src with noncerisky (removes caching)
Secret key committedcriticalrotate the keymoderate
Prerequisites

What you need

No paid account or external service.

The local project

The site folder on your computer, preferably with git.

cd ~/projetos/meu-site
git status

An agent

Claude Code or Codex open in the site folder.

claude   # or: codex

Node and npm

For the build, npm audit and the local simulation.

node -v && npm -v
User guide ยท step by step

How to use it today

Until the v1 scripts are ready, the agent follows the script in METODO.md.

โš ๏ธ Status on 10/10/2026: method and roadmap published; the automatic scripts for layers 1โ€“4 are still under construction. The script already works with the agent doing the checks.
1

Download the method

Clone the kit next to your project.

git clone https://github.com/inematds/blinda-site ~/projetos/blinda-site
2

Ask for the diagnosis (read-only)

Open the agent in your site's folder and paste the request (the method file is in Portuguese; the agent reads it fine).

# inside Claude Code / Codex, in the site folder
Follow ~/projetos/blinda-site/METODO.md, steps 1 to 3.
Read-only: do not change anything outside the blindagem/ folder.
Write blindagem/relatorio.md and blindagem/plano.md.
3

Read the report and the plan

Each finding has evidence and severity; each fix has a risk and "how to test". Mark what you approve.

cat blindagem/relatorio.md blindagem/plano.md
4

Backup and simulation

The agent creates the backup branch, applies the fixes on the branch, runs the build, starts it on a free port and checks the headers and the browser console.

I approve items 1, 2 and 4 of the plan. Do steps 4 and 5 of METODO.md
and show me the simulation result before applying.
5

Apply and verify

One commit per fix. At the end, the agent repeats the diagnosis and writes the before ร— after table.

You can apply (step 6) and verify (step 7). Push only after I take a look.
6

Check it yourself

After publishing, look at your own site's headers.

curl -sI https://seusite.com | grep -iE "content-security|x-frame|nosniff|referrer"
Real case

Where the method came from

On 10/10/2026 an external scanner gave inema.club a D grade (46/100). We fixed the INEMA sites by hand, and the experience became this script.

inema.club

Next 16.1.6 โ†’ 16.3.8, minimal CSP, X-Frame-Options, nosniff, Referrer-Policy and x-powered-by turned off. Build, 12 tests and browser without errors.

pay.inema.pro

The checkout sent no security headers at all and wasn't even in the scan. It got all of them, tested with the checkout links.

inema.vip and inema.pro

They already had almost everything; they got the minimal CSP. inema.pro was left with the Next 14 migration noted as a risky fix.

Roadmap

Next steps

Pilot on the INEMA sites, in this order: pay.inema.pro, inema.club, inema.vip, eventos.inema.pro.

v0 โœ“
Method and roadmapMETODO.md, risk matrix, report and plan templates. Published.
v1
Layer 1โ€“4 scripts + skillAutomatic read-only checks, generated report, skill for Claude Code and Codex, pilot on the 4 sites.
v2
Code layer + CI modeThe agent reads the code and points out risks; diagnosis on every push in GitHub Actions.
v3
DashboardHistory of each site's grades over time.