GrowthOS

← Directory / Latest completed evaluation

Evaluation completed

Public evaluation · completed

Agentic Infrastructure - Vercel

vercel.com

The autonomous stack for every app and agent.

Website: https://vercel.com/
Journey entry: https://vercel.com/

Readiness score

55.3–91.2/ 100

Provisional range · incomplete checks

64% coverage

Unknown or unavailable checks widen this range. This is not a final score.

Public response and metadata checks with a static browser sample. Even 100 does not establish complete website usability or task success.

readiness-v2 · website-v1
Thu, 10 Sep 2026 19:29:28 GMT

74 checks in this report

46 evaluated · 28 unresolved · 0 not applicable

The percentage above weights applicable checks by importance. Unavailable observations remain unresolved; they do not count as passes.

discovery76.7–83.393% covered
access65–9075% covered
understanding64.7–94.171% covered
interaction25–95.829% covered

Start here

Priority findings

Create a fix brief

Choose findings to include. No selection includes all actionable findings.

Findings

Content links have descriptive accessible names.partial

4 of 5 sampled content links have descriptive names.

Recommended fix

Replace ambiguous link names with clear destination descriptions.

Verify: Repeat the documented observation on the public homepage.

web.link-purpose · check 1.0.0 · applicability: applicable

ARD catalog entries identify typed, usable resources.fail

ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 200.

Recommended fix

Publish an ARD catalog with specVersion, host and complete entries.

Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

discovery.ard · check 2.0.0 · applicability: applicable

  • ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 200.
    Source evidence ↗
Agent Skills index has typed entries and SHA-256 digests.partial

Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 200.

Recommended fix

Publish the v0.2.0 skills index with name, description, type, URL and digest per skill.

Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

discovery.skills · check 2.0.0 · applicability: applicable

  • Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 200.
    Source evidence ↗
Published Markdown frontmatter includes useful metadata.partial

Markdown frontmatter title and description checked.

Recommended fix

Provide YAML title and description metadata in published Markdown documents.

Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

content.markdown-frontmatter · check 2.0.0 · applicability: applicable

Protected-resource metadata identifies its resource and authorization servers.fail

RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.

Recommended fix

Publish RFC 9728 resource metadata and authorization_servers.

Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

auth.protected-resource · check 2.0.0 · applicability: applicable

  • RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.
    Source evidence ↗
auth.md includes substantive authentication walkthrough sections.fail

auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 200.

Recommended fix

Publish auth.md covering discovery, registration, exchange, use, errors and revocation.

Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

auth.instructions · check 2.0.0 · applicability: applicable

  • auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 200.
    Source evidence ↗

Separate observation

Observed agent journey

unresolved

One attempt at the selected task. This does not measure overall completion rate and does not change the core score.

Understand the product

No evidence meeting the task completion criteria was observed.

Observed
Thu, 10 Sep 2026 19:29:35 GMT
Actions
9
Evaluator / configuration
deterministic-v1 / public-static-v1
Browser
Chromium 151.0.7922.34
  1. navigate and inspect visible text

    Visible text did not meet task completion criteria.

  2. navigate and inspect visible text

    Visible text did not meet task completion criteria.

  3. navigate and inspect visible text

    Visible text did not meet task completion criteria.

  4. navigate and inspect visible text

    Visible text did not meet task completion criteria.

  5. navigate and inspect visible text

    Visible text did not meet task completion criteria.

  6. navigate and inspect visible text

    Visible text did not meet task completion criteria.

  7. navigate and inspect visible text

    Visible text did not meet task completion criteria.

  8. navigate and inspect visible text

    Visible text did not meet task completion criteria.

  9. navigate and inspect visible text

    Visible text did not meet task completion criteria.

    Navigator v1 uses deterministic, read-only browsing with page JavaScript disabled. Finding API documentation does not mean an API request was executed.

    Observed capabilities

    Protocol evidence

    Discovery, declaration validation, and protocol validation describe different levels of evidence. Applicable API, authentication and protocol checks contribute to readiness. Supplemental commerce and emerging declarations are shown separately.

    Structured content 1.0.0

    pass

    4 structured-content observations; JSON-LD syntax and only advertised text representations checked. Claims and remote contexts were not verified.

    Depth: declaration validated

    structured.declarationpass

    13 of 13 advertised JSON-LD blocks parse as objects or arrays. Factual claims and remote contexts are not verified.

    structured.declaration · check 1.0.0 · applicability: applicable

    structured.llmsunknown

    Advertised text representation could not be verified.

    structured.llms · check 1.0.0 · applicability: unknown

    structured.llmsunknown

    Advertised text representation could not be verified.

    structured.llms · check 1.0.0 · applicability: unknown

    structured.markdownunknown

    Advertised text representation could not be verified.

    structured.markdown · check 1.0.0 · applicability: unknown

    OpenAPI 1.0.0

    unknown

    Advertised endpoint could not be acquired.

    Depth: discovered

    openapi.declarationunknown

    Advertised endpoint could not be acquired.

    openapi.declaration · check 1.0.0 · applicability: unknown

    OAuth / OIDC 1.0.0

    partial

    Issuer and HTTPS endpoint declarations are consistent. Complete OIDC conformance, authentication and token exchange were not tested.

    Depth: declaration validated

    oauth.declarationpartial

    Issuer and HTTPS endpoint declarations are consistent. Complete OIDC conformance, authentication and token exchange were not tested.

    oauth.declaration · check 1.0.0 · applicability: applicable

    • Issuer and HTTPS endpoint declarations are consistent. Complete OIDC conformance, authentication and token exchange were not tested.
      Source evidence ↗

    Model Context Protocol 1.0.0

    unknown

    No advertised or explicitly supplied MCP endpoint was discovered.

    Depth: discovered

    mcp.declarationunknown

    No advertised or explicitly supplied MCP endpoint was discovered.

    mcp.declaration · check 1.0.0 · applicability: unknown

      Agent2Agent 1.0.0

      unknown

      No advertised Agent2Agent endpoint was discovered in the sampled pages.

      Depth: discovered

      a2a.declarationunknown

      No advertised Agent2Agent endpoint was discovered in the sampled pages.

      a2a.declaration · check 1.0.0 · applicability: unknown

        Agent Skills 1.0.0

        unknown

        No advertised Agent Skills endpoint was discovered in the sampled pages.

        Depth: discovered

        skills.declarationunknown

        No advertised Agent Skills endpoint was discovered in the sampled pages.

        skills.declaration · check 1.0.0 · applicability: unknown

          WebMCP 1.0.0

          unknown

          No WebMCP declaration evidence found in sampled HTML.

          Depth: discovered

          webmcp.declarationunknown

          No WebMCP declaration evidence found in sampled HTML.

          webmcp.declaration · check 1.0.0 · applicability: unknown

            All readiness checks

            web · 9/12 evaluated

            A title and description identify the page.pass

            Title present; description present.

            web.identity · check 1.0.0 · applicability: applicable

            Public same-origin content has crawlable links.pass

            4 sampled crawlable same-origin content links.

            web.navigation · check 1.0.0 · applicability: applicable

            Robots policy permits this public observation.pass

            Robots policy permits the homepage.

            web.discovery-policy · check 1.0.0 · applicability: applicable

            The homepage returns a usable successful response.pass

            Homepage returned HTTP 200.

            web.http-access · check 1.0.0 · applicability: applicable

            Transport uses verified HTTPS without downgrade or loops.pass

            HTTPS certificate verified for all fetched hops.

            web.transport · check 1.0.0 · applicability: applicable

            An absent page has an explicit not-found response.pass

            Nonexistent-path probe returned HTTP 404.

            web.error-semantics · check 1.0.0 · applicability: applicable

            The raw document exposes meaningful main content.pass

            930 normalized main-text characters in the raw HTML.

            web.raw-content · check 1.0.0 · applicability: applicable

            Language and headings describe document structure.pass

            Document language declared; 5 meaningful headings.

            web.structure · check 1.0.0 · applicability: applicable

            Content links have descriptive accessible names.partial

            4 of 5 sampled content links have descriptive names.

            Recommended fix

            Replace ambiguous link names with clear destination descriptions.

            Verify: Repeat the documented observation on the public homepage.

            web.link-purpose · check 1.0.0 · applicability: applicable

            Rendered actionable controls have accessible names.unknown

            Rendered browser observation unavailable; no interaction evidence was inferred from source HTML.

            web.control-names · check 1.0.0 · applicability: unknown

            • Rendered browser observation unavailable; no interaction evidence was inferred from source HTML.
              Source evidence ↗
            Sampled public controls accept keyboard focus.unknown

            Rendered browser observation unavailable; no interaction evidence was inferred from source HTML.

            web.keyboard · check 1.0.0 · applicability: unknown

            • Rendered browser observation unavailable; no interaction evidence was inferred from source HTML.
              Source evidence ↗
            A public link reaches its declared destination.unknown

            Rendered browser observation unavailable; no interaction evidence was inferred from source HTML.

            web.navigation-result · check 1.0.0 · applicability: unknown

            • Rendered browser observation unavailable; no interaction evidence was inferred from source HTML.
              Source evidence ↗

            discovery · 7/9 evaluated

            A syntactically recognizable robots.txt is published.pass

            Published robots.txt format and User-agent directives checked.

            discovery.robots · check 2.0.0 · applicability: applicable

            A bounded XML sitemap contains absolute public locations.pass

            14156 public locations in sampled sitemap files. HTTP 200.

            discovery.sitemap · check 2.0.0 · applicability: applicable

            Sampled sitemap lastmod values are valid, nonfuture dates.pass

            14156 valid nonfuture lastmod values for 14156 sampled locations; update truth and recency not inferred. HTTP 200.

            discovery.sitemap-freshness · check 2.0.0 · applicability: applicable

            • 14156 valid nonfuture lastmod values for 14156 sampled locations; update truth and recency not inferred. HTTP 200.
              Source evidence ↗
            HTTP Link headers advertise agent-useful resources.pass

            1 agent-useful HTTP Link relations parsed.

            discovery.link-headers · check 2.0.0 · applicability: applicable

            DNS-AID entrypoints publish SVCB/HTTPS or TXT index records.unknown

            0 DNS-AID service/index answers across 0/7 answered DNS queries. DNSSEC trust and service execution are not validated.

            discovery.dns-aid · check 2.0.0 · applicability: unknown

            • 0 DNS-AID service/index answers across 0/7 answered DNS queries. DNSSEC trust and service execution are not validated.
              Source evidence ↗
            RFC 9727 catalog contains valid API Linkset entries.pass

            RFC 9727 Linkset anchors, public target links and content type checked; HEAD/profile and nested catalog conformance untested. HTTP 200.

            discovery.api-catalog · check 2.0.0 · applicability: applicable

            • RFC 9727 Linkset anchors, public target links and content type checked; HEAD/profile and nested catalog conformance untested. HTTP 200.
              Source evidence ↗
            ARD catalog entries identify typed, usable resources.fail

            ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 200.

            Recommended fix

            Publish an ARD catalog with specVersion, host and complete entries.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            discovery.ard · check 2.0.0 · applicability: applicable

            • ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 200.
              Source evidence ↗
            Agent Skills index has typed entries and SHA-256 digests.partial

            Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 200.

            Recommended fix

            Publish the v0.2.0 skills index with name, description, type, URL and digest per skill.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            discovery.skills · check 2.0.0 · applicability: applicable

            • Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 200.
              Source evidence ↗
            A usable public machine interface is advertised.unknown

            A declared machine interface is required for complete agent readiness; homepage richness alone does not meet this rule.

            discovery.agent-interface · check 2.0.0 · applicability: unknown

            • A declared machine interface is required for complete agent readiness; homepage richness alone does not meet this rule.
              Source evidence ↗

            content · 14/15 evaluated

            llms.txt is available as non-HTML text.pass

            llms.txt non-HTML text representation checked. HTTP 200.

            content.llms · check 2.0.0 · applicability: applicable

            llms.txt has a title, summary and categorized links.pass

            llms.txt title, blockquote summary, sections and resource links checked. HTTP 200.

            content.llms-structure · check 2.0.0 · applicability: applicable

            • llms.txt title, blockquote summary, sections and resource links checked. HTTP 200.
              Source evidence ↗
            Sampled llms.txt resource links resolve.unknown

            1/3 sampled llms.txt links acquired.

            content.llms-links · check 2.0.0 · applicability: unknown

            Accept: text/markdown returns useful Markdown.pass

            Accept: text/markdown response media type and non-HTML body checked.

            content.markdown · check 2.0.0 · applicability: applicable

            Negotiated Markdown declares Vary: Accept.pass

            Negotiated Markdown must declare Vary: Accept to avoid representation cache collisions.

            content.markdown-vary · check 2.0.0 · applicability: applicable

            • Negotiated Markdown must declare Vary: Accept to avoid representation cache collisions.
              Source evidence ↗
            A Markdown alternate is advertised or resolves.pass

            Advertised Markdown alternates and fetched Markdown URLs checked.

            content.markdown-alternate · check 2.0.0 · applicability: applicable

            Sampled Markdown has bounded length, balanced fences and descriptive links.pass

            Sampled Markdown: 2281 characters, 0 fence boundaries, 26 public links.

            content.markdown-quality · check 2.0.0 · applicability: applicable

            Published Markdown frontmatter includes useful metadata.partial

            Markdown frontmatter title and description checked.

            Recommended fix

            Provide YAML title and description metadata in published Markdown documents.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            content.markdown-frontmatter · check 2.0.0 · applicability: applicable

            Advertised developer documentation is publicly readable.pass

            3/9 advertised documentation pages publicly acquired.

            content.docs · check 2.0.0 · applicability: applicable

            Pricing or a documented free/enterprise pricing policy is readable.pass

            Sampled content checked for monetary prices, free tiers or explicit sales/pricing policy.

            content.pricing · check 2.0.0 · applicability: applicable

            • Sampled content checked for monetary prices, free tiers or explicit sales/pricing policy.
              Source evidence ↗
            Privacy, terms or security information is linked.pass

            Homepage and sampled-page privacy, terms and security links checked; legal adequacy not assessed.

            content.trust · check 2.0.0 · applicability: applicable

            • Homepage and sampled-page privacy, terms and security links checked; legal adequacy not assessed.
              Source evidence ↗
            Public quickstart text includes request, credential and response guidance.pass

            First-request command, credential setup and expected response guidance inspected; onboarding was not executed.

            content.onboarding · check 2.0.0 · applicability: applicable

            • First-request command, credential setup and expected response guidance inspected; onboarding was not executed.
              Source evidence ↗
            Public documentation links or describes SDK installation.pass

            SDK installation commands and package links checked; packages were not installed.

            content.sdk · check 2.0.0 · applicability: applicable

            • SDK installation commands and package links checked; packages were not installed.
              Source evidence ↗
            Public documentation describes CLI installation and usage.pass

            CLI availability and installation guidance checked; commands were not run.

            content.cli · check 2.0.0 · applicability: applicable

            Public docs describe a sandbox or test mode.pass

            Sandbox/test-mode declarations checked; environment behavior untested.

            content.sandbox · check 2.0.0 · applicability: applicable

            access · 3/4 evaluated

            Robots policy permits sampled AI crawlers and user agents.pass

            6/6 sampled training and user-agent robots policies allow the homepage.

            access.ai-policy · check 2.0.0 · applicability: applicable

            Content-Signal directives declare recognized yes/no policies.pass

            Content-Signal recognized directive/value syntax checked; a declared restriction is not silently treated as permission.

            access.content-signals · check 2.0.0 · applicability: applicable

            • Content-Signal recognized directive/value syntax checked; a declared restriction is not silently treated as permission.
              Source evidence ↗
            An explicit agent User-Agent can acquire useful public content.unknown

            Explicit ChatGPT-User/1.0 public acquisition and challenge/representation check; robots restrictions honored.

            access.agent-reachability · check 2.0.0 · applicability: unknown

            • Explicit ChatGPT-User/1.0 public acquisition and challenge/representation check; robots restrictions honored.
              Source evidence ↗
            An explicit agent User-Agent receives Markdown when requested.pass

            Explicit ChatGPT-User/1.0 public acquisition and challenge/representation check; robots restrictions honored.

            access.agent-markdown · check 2.0.0 · applicability: applicable

            • Explicit ChatGPT-User/1.0 public acquisition and challenge/representation check; robots restrictions honored.
              Source evidence ↗

            entity · 5/5 evaluated

            Title, description, canonical URL and social metadata identify the product.pass

            Title, description, canonical link and Open Graph identity fields checked.

            entity.metadata · check 2.0.0 · applicability: applicable

            JSON-LD contains meaningful schema.org typed entities.pass

            11 meaningful schema.org entities; 0 malformed JSON-LD blocks.

            entity.jsonld · check 2.0.0 · applicability: applicable

            Organization JSON-LD includes name, URL and identity details.pass

            2 Organization entities checked for name, URL, logo, description and contact/address details.

            entity.organization · check 2.0.0 · applicability: applicable

            • 2 Organization entities checked for name, URL, logo, description and contact/address details.
              Source evidence ↗
            Entity sameAs links identify public external profiles.pass

            JSON-LD sameAs public external identity links checked; profile ownership not verified.

            entity.linking · check 2.0.0 · applicability: applicable

            • JSON-LD sameAs public external identity links checked; profile ownership not verified.
              Source evidence ↗
            Structured data covers organization and product/content entities.pass

            6 distinct JSON-LD types found.

            entity.breadth · check 2.0.0 · applicability: applicable

            api · 0/13 evaluated

            An advertised OpenAPI 3.x document declares title, version and paths.unknown

            OpenAPI 3.0–3.2 root title/version/paths structure checked; full specification conformance not implied.

            api.description · check 2.0.0 · applicability: unknown

            • OpenAPI 3.0–3.2 root title/version/paths structure checked; full specification conformance not implied.
              Source evidence ↗
            OpenAPI defines nonempty, described operations with unique operationId values.unknown

            0/0 operations meet description and unique operationId requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

            api.operations · check 2.0.0 · applicability: unknown

            • 0/0 operations meet description and unique operationId requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
              Source evidence ↗
            Operation parameters and request bodies contain usable schemas.unknown

            0/0 operations meet typed parameter and request body requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

            api.parameters · check 2.0.0 · applicability: unknown

            • 0/0 operations meet typed parameter and request body requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
              Source evidence ↗
            Operations declare response schemas and descriptions.unknown

            0/0 operations meet described success response schema requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

            api.responses · check 2.0.0 · applicability: unknown

            • 0/0 operations meet described success response schema requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
              Source evidence ↗
            Operations document structured client/server error responses.unknown

            0/0 operations meet typed error response requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

            api.errors · check 2.0.0 · applicability: unknown

            • 0/0 operations meet typed error response requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
              Source evidence ↗
            OpenAPI declares usable security schemes and operation requirements.unknown

            OpenAPI security schemes and referenced security requirements inspected.

            api.authentication · check 2.0.0 · applicability: unknown

            List operations describe pagination parameters or continuation fields.unknown

            Pagination parameters/continuation fields inspected Declaration-only; no endpoint execution.

            api.pagination · check 2.0.0 · applicability: unknown

            • Pagination parameters/continuation fields inspected Declaration-only; no endpoint execution.
              Source evidence ↗
            API documents version or deprecation policy.unknown

            Version and deprecation declarations inspected Declaration-only; no endpoint execution.

            api.versioning · check 2.0.0 · applicability: unknown

            • Version and deprecation declarations inspected Declaration-only; no endpoint execution.
              Source evidence ↗
            Mutation operations declare idempotency support.unknown

            Idempotency request support inspected Declaration-only; no endpoint execution.

            api.idempotency · check 2.0.0 · applicability: unknown

            • Idempotency request support inspected Declaration-only; no endpoint execution.
              Source evidence ↗
            API responses or docs expose rate limits and retry guidance.unknown

            Observed rate-limit headers and documented retry policy checked.

            api.rate-limits · check 2.0.0 · applicability: unknown

            Long-running operation behavior is declared.unknown

            Asynchronous operation declarations inspected Declaration-only; no endpoint execution.

            api.async · check 2.0.0 · applicability: unknown

            • Asynchronous operation declarations inspected Declaration-only; no endpoint execution.
              Source evidence ↗
            Batch or bulk operation declarations are published.unknown

            Batch/bulk operation declarations inspected Declaration-only; no endpoint execution.

            api.batch · check 2.0.0 · applicability: unknown

            • Batch/bulk operation declarations inspected Declaration-only; no endpoint execution.
              Source evidence ↗
            Operation identifiers and input schemas can describe bounded function inputs.unknown

            0/0 operations meet bounded function naming and input schema requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

            api.function-calling · check 2.0.0 · applicability: unknown

            • 0/0 operations meet bounded function naming and input schema requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
              Source evidence ↗

            auth · 7/7 evaluated

            OAuth/OIDC metadata has a consistent issuer and HTTPS endpoint declarations.pass

            OAuth issuer/HTTPS endpoint and authorization-code response declarations checked; login and token exchange untested. HTTP 200.

            auth.discovery · check 2.0.0 · applicability: applicable

            • OAuth issuer/HTTPS endpoint and authorization-code response declarations checked; login and token exchange untested. HTTP 200.
              Source evidence ↗
            Protected-resource metadata identifies its resource and authorization servers.fail

            RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.

            Recommended fix

            Publish RFC 9728 resource metadata and authorization_servers.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            auth.protected-resource · check 2.0.0 · applicability: applicable

            • RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.
              Source evidence ↗
            API or OAuth metadata declares nonempty permission scopes.pass

            4 declared permission scopes; actual enforcement not tested.

            auth.scopes · check 2.0.0 · applicability: applicable

            OAuth discovery declares PKCE S256.pass

            PKCE S256 discovery declaration checked; no authorization exchange performed. HTTP 200.

            auth.pkce · check 2.0.0 · applicability: applicable

            • PKCE S256 discovery declaration checked; no authorization exchange performed. HTTP 200.
              Source evidence ↗
            auth.md includes substantive authentication walkthrough sections.fail

            auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 200.

            Recommended fix

            Publish auth.md covering discovery, registration, exchange, use, errors and revocation.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            auth.instructions · check 2.0.0 · applicability: applicable

            • auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 200.
              Source evidence ↗
            agent_auth metadata links instructions and declared registration mechanisms.fail

            agent_auth declaration and auth.md linkage inspected; full draft request-shape conformance untested.

            Recommended fix

            Publish machine-readable agent_auth methods and auth.md instruction URLs.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            auth.agent-metadata · check 2.0.0 · applicability: applicable

            • agent_auth declaration and auth.md linkage inspected; full draft request-shape conformance untested.
              Source evidence ↗
            Observed authentication challenges advertise resource metadata.pass

            Observed public authentication challenges checked for RFC 9728 resource_metadata; no artificial protected request or login was sent.

            auth.challenge · check 2.0.0 · applicability: applicable

            • Observed public authentication challenges checked for RFC 9728 resource_metadata; no artificial protected request or login was sent.
              Source evidence ↗

            mcp · 1/8 evaluated

            MCP Server Card identifies the server and transport.fail

            MCP Server Card identity, capabilities and explicit transport endpoint checked; draft schema subset. HTTP 404.

            Recommended fix

            Publish a server card with serverInfo, capabilities and a transport endpoint.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            mcp.card · check 2.0.0 · applicability: applicable

            • MCP Server Card identity, capabilities and explicit transport endpoint checked; draft schema subset. HTTP 404.
              Source evidence ↗
            An advertised MCP endpoint initializes and lists capabilities read-only.unknown

            No advertised or explicitly supplied MCP endpoint was discovered.

            mcp.handshake · check 2.0.0 · applicability: unknown

            MCP initialization declares meaningful server identity.unknown

            MCP initialization serverInfo name/version and instructions checked.

            mcp.identity · check 2.0.0 · applicability: unknown

            MCP exposes nonempty tools with unique stable names.unknown

            0/0 MCP tools have unique stable names.

            mcp.tools · check 2.0.0 · applicability: unknown

            MCP tools have substantive descriptions.unknown

            0/0 MCP tools have substantive descriptions.

            mcp.descriptions · check 2.0.0 · applicability: unknown

            MCP inputs contain typed property descriptions and valid required references.unknown

            0/0 MCP inputs have typed described properties and valid required references.

            mcp.schemas · check 2.0.0 · applicability: unknown

            • 0/0 MCP inputs have typed described properties and valid required references.
              Source evidence ↗
            MCP tool annotations declare safety and idempotency hints.unknown

            0/0 MCP tools declare all four safety/idempotency annotations. Hints are not verified effects.

            mcp.annotations · check 2.0.0 · applicability: unknown

            • 0/0 MCP tools declare all four safety/idempotency annotations. Hints are not verified effects.
              Source evidence ↗
            MCP resource listings expose valid named URI resources.unknown

            0/0 MCP resources have name, URI, description and MIME type. Resource contents not read.

            mcp.resources · check 2.0.0 · applicability: unknown

            • 0/0 MCP resources have name, URI, description and MIME type. Resource contents not read.
              Source evidence ↗

            protocol · 0/1 evaluated

            A2A card declares identity, interfaces, capabilities and useful skills.unknown

            A2A identity, declared interfaces, capabilities and skill descriptions checked; tasks are not invoked. HTTP 404.

            protocol.a2a · check 2.0.0 · applicability: unknown

            • A2A identity, declared interfaces, capabilities and skill descriptions checked; tasks are not invoked. HTTP 404.
              Source evidence ↗

            Reference check families

            GrowthOS observations grouped against Cloudflare’s public checklist. These reuse the evidence above; they are not extra points.

            Inspect 22 check families
            A syntactically recognizable robots.txt is published.pass

            Published robots.txt format and User-agent directives checked.

            discovery.robots · check 2.0.0 · applicability: applicable

            A bounded XML sitemap contains absolute public locations.pass

            14156 public locations in sampled sitemap files. HTTP 200.

            discovery.sitemap · check 2.0.0 · applicability: applicable

            HTTP Link headers advertise agent-useful resources.pass

            1 agent-useful HTTP Link relations parsed.

            discovery.link-headers · check 2.0.0 · applicability: applicable

            DNS-AID entrypoints publish SVCB/HTTPS or TXT index records.unknown

            0 DNS-AID service/index answers across 0/7 answered DNS queries. DNSSEC trust and service execution are not validated.

            discovery.dns-aid · check 2.0.0 · applicability: unknown

            • 0 DNS-AID service/index answers across 0/7 answered DNS queries. DNSSEC trust and service execution are not validated.
              Source evidence ↗
            Accept: text/markdown returns useful Markdown.pass

            Accept: text/markdown response media type and non-HTML body checked.

            content.markdown · check 2.0.0 · applicability: applicable

            Robots policy permits sampled AI crawlers and user agents.pass

            6/6 sampled training and user-agent robots policies allow the homepage.

            access.ai-policy · check 2.0.0 · applicability: applicable

            Content-Signal directives declare recognized yes/no policies.pass

            Content-Signal recognized directive/value syntax checked; a declared restriction is not silently treated as permission.

            access.content-signals · check 2.0.0 · applicability: applicable

            • Content-Signal recognized directive/value syntax checked; a declared restriction is not silently treated as permission.
              Source evidence ↗
            supplemental.web bot authnot applicable

            Web Bot Auth public JWKS identity/key fields checked. Signing, key possession, rotation and receiver verification not tested. HTTP 404.

            supplemental.web-bot-auth · check 2.0.0 · applicability: not applicable

            • Web Bot Auth public JWKS identity/key fields checked. Signing, key possession, rotation and receiver verification not tested. HTTP 404.
              Source evidence ↗
            RFC 9727 catalog contains valid API Linkset entries.pass

            RFC 9727 Linkset anchors, public target links and content type checked; HEAD/profile and nested catalog conformance untested. HTTP 200.

            discovery.api-catalog · check 2.0.0 · applicability: applicable

            • RFC 9727 Linkset anchors, public target links and content type checked; HEAD/profile and nested catalog conformance untested. HTTP 200.
              Source evidence ↗
            OAuth/OIDC metadata has a consistent issuer and HTTPS endpoint declarations.pass

            OAuth issuer/HTTPS endpoint and authorization-code response declarations checked; login and token exchange untested. HTTP 200.

            auth.discovery · check 2.0.0 · applicability: applicable

            • OAuth issuer/HTTPS endpoint and authorization-code response declarations checked; login and token exchange untested. HTTP 200.
              Source evidence ↗
            Protected-resource metadata identifies its resource and authorization servers.fail

            RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.

            Recommended fix

            Publish RFC 9728 resource metadata and authorization_servers.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            auth.protected-resource · check 2.0.0 · applicability: applicable

            • RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.
              Source evidence ↗
            auth.md includes substantive authentication walkthrough sections.fail

            auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 200.

            Recommended fix

            Publish auth.md covering discovery, registration, exchange, use, errors and revocation.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            auth.instructions · check 2.0.0 · applicability: applicable

            • auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 200.
              Source evidence ↗
            MCP Server Card identifies the server and transport.fail

            MCP Server Card identity, capabilities and explicit transport endpoint checked; draft schema subset. HTTP 404.

            Recommended fix

            Publish a server card with serverInfo, capabilities and a transport endpoint.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            mcp.card · check 2.0.0 · applicability: applicable

            • MCP Server Card identity, capabilities and explicit transport endpoint checked; draft schema subset. HTTP 404.
              Source evidence ↗
            A2A card declares identity, interfaces, capabilities and useful skills.unknown

            A2A identity, declared interfaces, capabilities and skill descriptions checked; tasks are not invoked. HTTP 404.

            protocol.a2a · check 2.0.0 · applicability: unknown

            • A2A identity, declared interfaces, capabilities and skill descriptions checked; tasks are not invoked. HTTP 404.
              Source evidence ↗
            Agent Skills index has typed entries and SHA-256 digests.partial

            Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 200.

            Recommended fix

            Publish the v0.2.0 skills index with name, description, type, URL and digest per skill.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            discovery.skills · check 2.0.0 · applicability: applicable

            • Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 200.
              Source evidence ↗
            supplemental.webmcpfail

            Static WebMCP API/declarative-form indicators inspected. Runtime tool discovery and invocation require a supporting browser and were not performed.

            Recommended fix

            Publish accurate, public machine-readable declarations and verify their behavior independently.

            Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

            supplemental.webmcp · check 2.0.0 · applicability: applicable

            • Static WebMCP API/declarative-form indicators inspected. Runtime tool discovery and invocation require a supporting browser and were not performed.
              Source evidence ↗
            ARD catalog entries identify typed, usable resources.fail

            ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 200.

            Recommended fix

            Publish an ARD catalog with specVersion, host and complete entries.

            Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

            discovery.ard · check 2.0.0 · applicability: applicable

            • ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 200.
              Source evidence ↗
            supplemental.x402fail

            Observed 402/payment-required x402 requirements checked for version, network, asset, recipient and amount. No payment sent.

            Recommended fix

            Publish accurate, public machine-readable declarations and verify their behavior independently.

            Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

            supplemental.x402 · check 2.0.0 · applicability: applicable

            • Observed 402/payment-required x402 requirements checked for version, network, asset, recipient and amount. No payment sent.
              Source evidence ↗
            supplemental.mppunknown

            OpenAPI x-payment-info intent/method/amount/currency declarations inspected. Payment challenge fulfillment and session behavior not tested.

            supplemental.mpp · check 2.0.0 · applicability: unknown

            • OpenAPI x-payment-info intent/method/amount/currency declarations inspected. Payment challenge fulfillment and session behavior not tested.
              Source evidence ↗
            supplemental.ucpfail

            UCP profile version, services and capabilities declaration subset checked; endpoints, checkout and signatures untested. HTTP 404.

            Recommended fix

            Publish accurate, public machine-readable declarations and verify their behavior independently.

            Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

            supplemental.ucp · check 2.0.0 · applicability: applicable

            • UCP profile version, services and capabilities declaration subset checked; endpoints, checkout and signatures untested. HTTP 404.
              Source evidence ↗
            supplemental.acpfail

            ACP discovery protocol/version, API base URL, transports and services checked; checkout sessions never created. HTTP 404.

            Recommended fix

            Publish accurate, public machine-readable declarations and verify their behavior independently.

            Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

            supplemental.acp · check 2.0.0 · applicability: applicable

            • ACP discovery protocol/version, API base URL, transports and services checked; checkout sessions never created. HTTP 404.
              Source evidence ↗
            supplemental.ap2unknown

            A2A card AP2 extension URI inspected. Signed mandates, authorization and payments untested; no guessed AP2 endpoint implies conformance.

            supplemental.ap2 · check 2.0.0 · applicability: unknown

            • A2A card AP2 extension URI inspected. Signed mandates, authorization and payments untested; no guessed AP2 endpoint implies conformance.
              Source evidence ↗

            Additional observations

            Supplemental declaration observations and explicitly unperformed external/runtime assessments. These have no score weight.

            Inspect declarations and unperformed assessments
            public.agent instructionsunknown

            Public when-to-use/agent instruction guidance or explicit instruction-file links inspected; instructions not followed.

            public.agent-instructions · check 2.0.0 · applicability: unknown

            • Public when-to-use/agent instruction guidance or explicit instruction-file links inspected; instructions not followed.
              Source evidence ↗
            public.agent configsunknown

            Public links to agent platform configuration files inspected; repository contents not recursively searched.

            public.agent-configs · check 2.0.0 · applicability: unknown

            • Public links to agent platform configuration files inspected; repository contents not recursively searched.
              Source evidence ↗
            public.agent pluginsunknown

            Explicit agent-plugin manifest links inspected; full package schema and installation not tested.

            public.agent-plugins · check 2.0.0 · applicability: unknown

            • Explicit agent-plugin manifest links inspected; full package schema and installation not tested.
              Source evidence ↗
            public.agent viewpass

            Public agent-view/mode declarations inspected; alternate UI not executed.

            public.agent-view · check 2.0.0 · applicability: applicable

            public.markdown fallbackunknown

            A bounded .md URL fallback sample returns non-HTML Markdown; unrelated URLs are not enumerated.

            public.markdown-fallback · check 2.0.0 · applicability: unknown

            • A bounded .md URL fallback sample returns non-HTML Markdown; unrelated URLs are not enumerated.
              Source evidence ↗
            public.modular llmsunknown

            Advertised product-area llms.txt resources acquired; unadvertised areas not guessed.

            public.modular-llms · check 2.0.0 · applicability: unknown

            • Advertised product-area llms.txt resources acquired; unadvertised areas not guessed.
              Source evidence ↗
            public.nlwebunknown

            NLWeb/feed declarations inspected; /ask requests and streaming responses not executed.

            public.nlweb · check 2.0.0 · applicability: unknown

            • NLWeb/feed declarations inspected; /ask requests and streaming responses not executed.
              Source evidence ↗
            public.a2uiunknown

            A2UI declaration indicators inspected; generated UI quality is not evaluated.

            public.a2ui · check 2.0.0 · applicability: unknown

            • A2UI declaration indicators inspected; generated UI quality is not evaluated.
              Source evidence ↗
            public.native controlspass

            181 native controls and 0 custom ARIA control declarations observed. Focus/keyboard evidence remains in browser checks.

            public.native-controls · check 2.0.0 · applicability: applicable

            • 181 native controls and 0 custom ARIA control declarations observed. Focus/keyboard evidence remains in browser checks.
              Source evidence ↗
            public.form labelspass

            3/3 source form controls have label associations; runtime accessible names independently sampled by browser.

            public.form-labels · check 2.0.0 · applicability: applicable

            • 3/3 source form controls have label associations; runtime accessible names independently sampled by browser.
              Source evidence ↗
            public.injection indicatorsunknown

            No bounded source-label injection indicator detected. This is not an injection-safety guarantee or pass.

            public.injection-indicators · check 2.0.0 · applicability: unknown

            • No bounded source-label injection indicator detected. This is not an injection-safety guarantee or pass.
              Source evidence ↗
            public.graphql errorsnot applicable

            Public GraphQL errors declaration patterns inspected; schema introspection, coverage and operations are not executed.

            public.graphql-errors · check 2.0.0 · applicability: not applicable

            • Public GraphQL errors declaration patterns inspected; schema introspection, coverage and operations are not executed.
              Source evidence ↗
            public.graphql paginationnot applicable

            Public GraphQL pagination declaration patterns inspected; schema introspection, coverage and operations are not executed.

            public.graphql-pagination · check 2.0.0 · applicability: not applicable

            • Public GraphQL pagination declaration patterns inspected; schema introspection, coverage and operations are not executed.
              Source evidence ↗
            public.graphql versioningnot applicable

            Public GraphQL versioning declaration patterns inspected; schema introspection, coverage and operations are not executed.

            public.graphql-versioning · check 2.0.0 · applicability: not applicable

            • Public GraphQL versioning declaration patterns inspected; schema introspection, coverage and operations are not executed.
              Source evidence ↗
            public.graphql asyncnot applicable

            Public GraphQL async declaration patterns inspected; schema introspection, coverage and operations are not executed.

            public.graphql-async · check 2.0.0 · applicability: not applicable

            • Public GraphQL async declaration patterns inspected; schema introspection, coverage and operations are not executed.
              Source evidence ↗
            public.graphql batchnot applicable

            Public GraphQL batch declaration patterns inspected; schema introspection, coverage and operations are not executed.

            public.graphql-batch · check 2.0.0 · applicability: not applicable

            • Public GraphQL batch declaration patterns inspected; schema introspection, coverage and operations are not executed.
              Source evidence ↗
            public.graphql schemanot applicable

            Public GraphQL schema declaration patterns inspected; schema introspection, coverage and operations are not executed.

            public.graphql-schema · check 2.0.0 · applicability: not applicable

            • Public GraphQL schema declaration patterns inspected; schema introspection, coverage and operations are not executed.
              Source evidence ↗
            public.schema complexityunknown

            OpenAPI traversal bounded to depth24,20000 nodes per schema and200000 total nodes; 0 external and 0 unresolved references. No LLM comprehension or actual tool generation evaluated.

            public.schema-complexity · check 2.0.0 · applicability: unknown

            • OpenAPI traversal bounded to depth24,20000 nodes per schema and200000 total nodes; 0 external and 0 unresolved references. No LLM comprehension or actual tool generation evaluated.
              Source evidence ↗
            public.json errorspass

            Actual acquired 4xx responses inspected for JSON objects. No fabricated malformed API calls sent; unobserved error behavior stays unknown.

            public.json-errors · check 2.0.0 · applicability: applicable

            • Actual acquired 4xx responses inspected for JSON objects. No fabricated malformed API calls sent; unobserved error behavior stays unknown.
              Source evidence ↗
            public.ard trustfail

            ARD trust/signature/attestation declaration presence inspected; signatures, compliance and identity claims not verified.

            Recommended fix

            Publish accurate, public machine-readable declarations and verify their behavior independently.

            Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

            public.ard-trust · check 2.0.0 · applicability: applicable

            • ARD trust/signature/attestation declaration presence inspected; signatures, compliance and identity claims not verified.
              Source evidence ↗
            public.mcp surfacesfail

            1 distinct public MCP advertisements; product-vs-docs capability coverage and additional handshakes untested.

            Recommended fix

            Publish accurate, public machine-readable declarations and verify their behavior independently.

            Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

            public.mcp-surfaces · check 2.0.0 · applicability: applicable

            • 1 distinct public MCP advertisements; product-vs-docs capability coverage and additional handshakes untested.
              Source evidence ↗
            public.search assessmentunsupported

            Category share-of-voice, search ranking, brand accuracy and developer-resource retrieval require an external search/LLM assessment; not performed.

            public.search-assessment · check 2.0.0 · applicability: unknown

            • Category share-of-voice, search ranking, brand accuracy and developer-resource retrieval require an external search/LLM assessment; not performed.
              Source evidence ↗
            public.registry assessmentunsupported

            MCP registry, npm/PyPI, skills.sh, ChatGPT app and Wikipedia/Wikidata membership/branding not independently queried in this deterministic scan; public links alone do not prove membership.

            public.registry-assessment · check 2.0.0 · applicability: unknown

            • MCP registry, npm/PyPI, skills.sh, ChatGPT app and Wikipedia/Wikidata membership/branding not independently queried in this deterministic scan; public links alone do not prove membership.
              Source evidence ↗
            public.auth walkthroughunsupported

            Authentication walkthrough simulation and registration/claim/token transactions not performed; only documentation and discovery metadata inspected.

            public.auth-walkthrough · check 2.0.0 · applicability: unknown

            • Authentication walkthrough simulation and registration/claim/token transactions not performed; only documentation and discovery metadata inspected.
              Source evidence ↗
            public.mcp app runtimeunsupported

            MCP Apps HTML view loading/CSP, UI quality and interactive app behavior not tested; no resource reads or UI tool executions performed.

            public.mcp-app-runtime · check 2.0.0 · applicability: unknown

            • MCP Apps HTML view loading/CSP, UI quality and interactive app behavior not tested; no resource reads or UI tool executions performed.
              Source evidence ↗
            public.mcp error behaviorunsupported

            MCP error-response semantics not proactively exercised: only permitted initialize/list operations are sent.

            public.mcp-error-behavior · check 2.0.0 · applicability: unknown

            • MCP error-response semantics not proactively exercised: only permitted initialize/list operations are sent.
              Source evidence ↗

            Keep the evidence

            Exports contain public findings from this observation. Private contacts and raw browser artifacts are excluded.

            Scan 061fe71a-abf7-485f-9e81-923d0e50774a · Created Thu, 10 Sep 2026 19:29:12 GMT

            Saved observations

            Evaluation history

            Each report preserves the evidence collected at that time. Compare scores only within the same methodology and coverage; a failed refresh does not replace the published evaluation.

            1 completed evaluation · Showing 1

            1. readiness-v2 · website-v1
              55.3–91.2Provisional range · 64% coverage
              UnresolvedObserved journey
              View report

            A fresh observation

            Observe this website again

            Submit another evaluation or choose a different journey. A matching recent scan may be reused; availability and cooldowns apply.

            Core baseline: https://vercel.com/ · Journey entry: homepage

            Share your email if you would like us to follow up about this scan. It stays private; we will not send an automatic report or subscribe you.

            Advanced: protocol hints

            Public, unauthenticated URLs only. Never include credentials, access tokens, or private customer data.

            Completed reports are public. Completed readiness evaluations are automatically listed in the directory, regardless of score or journey outcome.