CSP enforced by the host, if any.
CSP declared by the resource before host policy is applied.
HTML document rendered in the sandbox.
MIME type reported by the resource.
Whether the MIME type is the MCP App resource media type.
MIME validation warning, or null for a valid resource.
Browser permissions requested by the resource.
Whether the app prefers a visible host border.
Normalized HTML, CSP, permissions, and MIME metadata for a rendered view.