Skip to main content

What we check

What a report covers today

Agent readiness has a lot of moving parts, and plenty of them are still draft specifications. So this page is split: what an assessment measures right now, and what we intend to add. Nothing is listed in the first section that a report will not actually deliver.

Assessed today

Every finding in these areas comes with the request we made and the response we received.

  • Agent discoverability

    Whether an agent can find your content at all: a valid robots.txt, a reachable sitemap, canonical URLs that do not contradict each other, and Link response headers pointing at related resources.

  • Agent guidance

    Whether you publish an llms.txt telling agents what your site is and which pages matter. A draft convention, and your report says so.

  • Machine-readable content

    Whether your content exists in the HTML the server returns, or only appears after JavaScript runs — and whether structured data describes your business in a form software can parse.

  • Bot access control

    AI-specific rules in robots.txt, Content Signals declaring how your content may be used, and a Web Bot Auth key directory for verifying which agents are genuine. Web Bot Auth is reported for information only and never counts against you.

  • Protocol discovery

    Whether an agent can find the interfaces behind your site: an API catalogue, OAuth authorisation server discovery, OAuth protected resource metadata, and an auth.md describing how to authenticate. A site with no such interfaces is marked not applicable, never failed.

  • Foundations

    HTTPS, status codes, titles and descriptions, heading structure, declared page language, image alt text, contact details, security headers, compression, caching and response time. Unglamorous, but an agent that gets a 500 or a redirect loop never reaches the interesting part.

On the roadmap — not yet assessed

These are the emerging standards we are building detection for. We list them so you know where this is heading, and so you can tell the difference between what we measure and what we merely have opinions about. What each of these is for.

  • Content negotiation

    Planned

    Whether your site can return Markdown to an agent that asks for it, instead of HTML wrapped around the content it actually wants.

  • Agent tool protocols

    Planned

    MCP server cards, A2A agent cards, Agent Skills and WebMCP tool registration — the declarations that let an agent do something on your site rather than just read it. We detect the API catalogue and OAuth side of this today; these four are not yet assessed.

    Model Context Protocol

  • DNS-level discovery

    Planned

    SVCB and HTTPS records under _agents that point an agent at your interfaces before it has fetched a single page.

  • Agentic commerce

    Planned

    Payment and checkout protocols that let an agent transact on a customer's behalf. Only relevant if you sell online, and the specifications are moving quickly.

What an assessment will not tell you

We would rather be useful than impressive. An assessment cannot promise that an AI assistant will cite or recommend your business — nobody can, and anyone saying otherwise is guessing. What it can tell you is whether an agent is able to reach and understand you, which is the part you control.

We also do not audit anything behind a login. The assessment reads public pages and well-known files only, which means it sees your site the way an agent sees it, and nothing more. How we handle your data.

See where your site stands

Enter a website and a business email. We confirm the inbox before anything is fetched.