GrowthOS

Versioned protocol adapters

Inspect the capability.
Verify the evidence.

The scanner records the supported revision and the depth reached. Applicable API and authentication findings contribute to the current readiness method; supplemental declarations are labeled separately.

Read the evidence depth

Discovered: a public declaration or endpoint was found. Declaration validated: the documented structural subset was inspected. Protocol validated: a bounded supported exchange completed. None establishes unrestricted task execution.

Discovery

robots.txt, sitemap, HTTP Link, DNS-AID, API catalog

Public response parsing, sitemap locations and dates, discovery links and actual DNS records. DNSSEC trust and service execution are separate, untested claims.

Machine-readable content

llms.txt, Markdown, JSON-LD

Negotiated content type and Vary, linked Markdown, document structure, structured entity fields and identity links. Public claims are not independently verified.

OpenAPI

3.0–3.2

Declared operations, unique identifiers, parameter and response schemas, structured error models, security declarations and function-input compatibility. References and schema traversal are bounded. Authenticated API execution is not performed.

MCP

2025-11-25

Server-card discovery, initialization and bounded tools/resources/prompts listings. Tool descriptions, schemas, annotations and resource metadata are inspected. No tools/call, resources/read or prompts/get. Unsupported negotiated revisions are labeled.

Authentication

OAuth / OIDC, RFC 9728, auth.md

Issuer and HTTPS endpoint declarations, protected-resource metadata, scopes, PKCE and agent registration instructions. No registration, login, credential exchange or revocation requests are sent.

Agent discovery

A2A, Agent Skills, ARD

Agent identity/interfaces/skills, typed skills indexes and digest format, and capability catalog entries. Package installation, integrity verification and task execution are not implied by a valid declaration.

Bot access

AI crawler policies, Content Signals, Web Bot Auth

Declared crawler policy, an explicit agent User-Agent observation, recognized content signals and public key directory fields. Key possession, request signing and bot identity are not verified.

Commerce

x402, MPP, UCP, ACP, AP2

Supplemental payment requirements and discovery declarations where relevant. No purchase, checkout, payment credential transfer or signed mandate is executed. These checks do not increase the readiness score.

Browser and other interfaces

WebMCP, GraphQL, NLWeb, agent configurations

Static declarations and publicly readable documentation can be observed. Dynamic browser tool execution, authenticated GraphQL behavior, marketplace ownership and external search rankings remain distinct assessments.

How discovery works

The scanner combines canonical discovery paths, HTTP Link headers, advertised page links, llms.txt resources and explicit OpenAPI/MCP hints. Publicly advertised documentation and authorization surfaces may be on other origins. Every fetch still passes network validation, robots policy and scan budgets.

A missing or invalid declaration, an unavailable observation and a surface outside the product’s applicable scope receive different outcomes. Reports expose the checks, reasons, evidence and unperformed operations.

Extending protocol support

Protocol adapters have versioned rules and source references. A new revision adds its own evidence and compatibility tests. Changes to scored coverage require a new measurement method so earlier reports remain interpretable.