Audit security headers in a pracht app. The framework sets four defaults on
every response path; this covers the exceptions — static output served outside
first-party adapters, `headers()` exports that weaken defaults, and the choices
only you can make (HSTS, CSP).
Use for "audit security headers", "check CSP", "harden headers", "set up HSTS",
"review header policy".