I looked into this use case before and came to the conclusion that it can't work because TLS is not non-repudiable. Once the initial public-key handshake is finished, the rest of the session uses a symmetric cipher. Because anyone with the symmetric cipher's key can encrypt their own data with it, you could encrypt your own spoofed response from the server in any transcript of the session.
https://crypto.stackexchange.com/questions/29751/are-https-w...
One solution to this is to use the site's public key to sign a Web Bundle instead of using TLS:
https://wicg.github.io/webpackage/draft-yasskin-http-origin-...
Web bundles can be served from any origin (and I'd imagine can be verified by oracles) as the data itself is signed. However, this requires the server to use web bundles in the first place, which likely isn't happening any time soon. Mozilla considers the proposal harmful: they expect Google will serve the majority of web bundles, allowing them to see what sites the user is visiting.
https://github.com/mozilla/standards-positions/issues/264
https://www.ghacks.net/2020/08/30/google-proposed-web-bundle...