Parse one Content-Security-Policy and report its structure, with the fallback rules applied. A fetch directive absent while default-src is present is reported as covered; base-uri and frame-ancestors do not fall back, so absence there is a finding. unsafe-inline alongside a nonce is reported differently from unsafe-inline alone, since supporting browsers ignore it. A repeated directive is reported because only the first takes effect. Structure only, not an assessment of adequacy.
Coinbase Agentic Market feed · snapshot May 2026 (not live on-chain)
| From | Amount | When |
|---|---|---|
| 0x7e6b65…2b1c | $0.0010 | 2026-09-09T21:47:47 |