Your agent reads the project on your machine, points out what is exposed, makes a backup, simulates the fix and only applies what you approve.

blinda-site is a method for your AI agent (Claude Code or Codex) to protect a website without touching the site that is live. It reads the project's code and settings on your machine, finds what is exposed and builds a plan of fixes. Each fix comes with two levels of risk: how serious the problem is and how likely the change is to break something. Before changing anything, the method requires a backup and a local simulation. To use it, all you need is the site project on your computer and an agent open in its folder.
An external scanner reads a page and, on someone else's site, can look like an attack. Looking from the inside, you see far more and you don't need anyone's permission.
The diagnosis reads code, config, lockfile and git history. No requests to the live site, no changes to the project.
No fix without a backup branch and without a build, a local server and a browser checking first.
The severity of the problem and the risk of the fix are measured separately. Anything risky always asks first.
The first three only read. Nothing changes in the project until the plan is approved and the backup exists.
CSP, X-Frame-Options, nosniff, Referrer-Policy and HSTS in next.config, vercel.json, _headers.
npm audit on the lockfile, the framework version and whether its line still receives fixes.
.env in git or in the history, a key in the code, a secret exposed to the browser.
Supabase: a table without RLS, service_role on the front end, an API route that doesn't check the session. Without local migrations, the report says "not verified".
The agent reads and comments: injected HTML, open redirect, upload without a limit.
A safe fix for a medium problem comes before a risky fix for a serious problem, which waits for your go-ahead.
| Safe fix | Moderate | Risky | |
|---|---|---|---|
| Critical | do first | do, testing | ask first |
| High / medium | do | do, testing | ask first |
| Low | do if cheap | note it | note it |
| Real finding | Severity | Fix | Fix risk |
|---|---|---|---|
| Checkout with no security headers at all | high | headers + minimal CSP | safe |
| Next.js 16.1.6 in the range of published advisories | medium | patch to 16.3.8 | safe |
| Next.js 14 with no new fixes | high | migrate to 16 | risky |
| No script CSP | medium | script-src with nonce | risky (removes caching) |
| Secret key committed | critical | rotate the key | moderate |
No paid account or external service.
The site folder on your computer, preferably with git.
cd ~/projetos/meu-site git status
Claude Code or Codex open in the site folder.
claude # or: codex
For the build, npm audit and the local simulation.
node -v && npm -v
Until the v1 scripts are ready, the agent follows the script in METODO.md.
Clone the kit next to your project.
git clone https://github.com/inematds/blinda-site ~/projetos/blinda-site
Open the agent in your site's folder and paste the request (the method file is in Portuguese; the agent reads it fine).
# inside Claude Code / Codex, in the site folder Follow ~/projetos/blinda-site/METODO.md, steps 1 to 3. Read-only: do not change anything outside the blindagem/ folder. Write blindagem/relatorio.md and blindagem/plano.md.
Each finding has evidence and severity; each fix has a risk and "how to test". Mark what you approve.
cat blindagem/relatorio.md blindagem/plano.md
The agent creates the backup branch, applies the fixes on the branch, runs the build, starts it on a free port and checks the headers and the browser console.
I approve items 1, 2 and 4 of the plan. Do steps 4 and 5 of METODO.md
and show me the simulation result before applying.
One commit per fix. At the end, the agent repeats the diagnosis and writes the before ร after table.
You can apply (step 6) and verify (step 7). Push only after I take a look.
After publishing, look at your own site's headers.
curl -sI https://seusite.com | grep -iE "content-security|x-frame|nosniff|referrer"
On 10/10/2026 an external scanner gave inema.club a D grade (46/100). We fixed the INEMA sites by hand, and the experience became this script.
Next 16.1.6 โ 16.3.8, minimal CSP, X-Frame-Options, nosniff, Referrer-Policy and x-powered-by turned off. Build, 12 tests and browser without errors.
The checkout sent no security headers at all and wasn't even in the scan. It got all of them, tested with the checkout links.
They already had almost everything; they got the minimal CSP. inema.pro was left with the Next 14 migration noted as a risky fix.
Pilot on the INEMA sites, in this order: pay.inema.pro, inema.club, inema.vip, eventos.inema.pro.