GrowthOS
Evaluation completed

Public evaluation · completed

Example Domain

example.org

Website: https://example.org/
Journey entry: https://example.org/

Readiness score

28.7/ 100

Complete applicable checks

100% coverage

Evaluated discovery, access, content and interaction checks, including applicable API and authentication evidence.

Public response and metadata checks with a static browser sample. Even 100 does not establish complete website usability or task success.

readiness-v2 · website-v1
Thu, 10 Sep 2026 19:09:06 GMT

74 checks in this report

44 evaluated · 0 unresolved · 30 not applicable

The percentage above weights applicable checks by importance. Unavailable observations remain unresolved; they do not count as passes.

discovery10.7100% covered
access46.2100% covered
understanding20.8100% covered
interaction28.6100% covered

Start here

Priority findings

Create a fix brief

Choose findings to include. No selection includes all actionable findings.

Findings

The raw document exposes meaningful main content.partial

125 normalized main-text characters in the raw HTML.

Recommended fix

Render useful main content in the initial HTML response.

Verify: Repeat the documented observation on the public homepage.

web.raw-content · check 1.0.0 · applicability: applicable

A title and description identify the page.partial

Title present; description absent.

Recommended fix

Provide a meaningful title and meta description.

Verify: Repeat the documented observation on the public homepage.

web.identity · check 1.0.0 · applicability: applicable

Public same-origin content has crawlable links.fail

0 sampled crawlable same-origin content links.

Recommended fix

Use descriptive anchor elements with public href destinations.

Verify: Repeat the documented observation on the public homepage.

web.navigation · check 1.0.0 · applicability: applicable

Content links have descriptive accessible names.fail

0 of 1 sampled content links have descriptive names.

Recommended fix

Replace ambiguous link names with clear destination descriptions.

Verify: Repeat the documented observation on the public homepage.

web.link-purpose · check 1.0.0 · applicability: applicable

A syntactically recognizable robots.txt is published.fail

Published robots.txt format and User-agent directives checked.

Recommended fix

Publish robots.txt with User-agent and Allow/Disallow directives.

Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

discovery.robots · check 2.0.0 · applicability: applicable

A bounded XML sitemap contains absolute public locations.fail

0 public locations in sampled sitemap files. HTTP 404.

Recommended fix

Publish a valid sitemap and advertise it in robots.txt.

Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

discovery.sitemap · check 2.0.0 · applicability: applicable

Separate observation

Observed agent journey

unresolved

One attempt at the selected task. This does not measure overall completion rate and does not change the core score.

Understand the product

No evidence meeting the task completion criteria was observed.

Observed
Thu, 10 Sep 2026 19:09:16 GMT
Actions
1
Evaluator / configuration
deterministic-v1 / public-static-v1
Browser
Chromium 151.0.7922.34
  1. navigate and inspect visible text

    Visible text did not meet task completion criteria.

    Navigator v1 uses deterministic, read-only browsing with page JavaScript disabled. Finding API documentation does not mean an API request was executed.

    Observed capabilities

    Protocol evidence

    Discovery, declaration validation, and protocol validation describe different levels of evidence. Applicable API, authentication and protocol checks contribute to readiness. Supplemental commerce and emerging declarations are shown separately.

    Structured content 1.0.0

    unknown

    No JSON-LD declaration was discovered in sampled pages.

    Depth: discovered

    structured.declarationunknown

    No JSON-LD declaration was discovered in sampled pages.

    structured.declaration · check 1.0.0 · applicability: unknown

      OpenAPI 1.0.0

      unknown

      No advertised OpenAPI endpoint was discovered in the sampled pages.

      Depth: discovered

      openapi.declarationunknown

      No advertised OpenAPI endpoint was discovered in the sampled pages.

      openapi.declaration · check 1.0.0 · applicability: unknown

        OAuth / OIDC 1.0.0

        unknown

        No advertised OAuth / OIDC endpoint was discovered in the sampled pages.

        Depth: discovered

        oauth.declarationunknown

        No advertised OAuth / OIDC endpoint was discovered in the sampled pages.

        oauth.declaration · check 1.0.0 · applicability: unknown

          Model Context Protocol 1.0.0

          unknown

          No advertised or explicitly supplied MCP endpoint was discovered.

          Depth: discovered

          mcp.declarationunknown

          No advertised or explicitly supplied MCP endpoint was discovered.

          mcp.declaration · check 1.0.0 · applicability: unknown

            Agent2Agent 1.0.0

            unknown

            No advertised Agent2Agent endpoint was discovered in the sampled pages.

            Depth: discovered

            a2a.declarationunknown

            No advertised Agent2Agent endpoint was discovered in the sampled pages.

            a2a.declaration · check 1.0.0 · applicability: unknown

              Agent Skills 1.0.0

              unknown

              No advertised Agent Skills endpoint was discovered in the sampled pages.

              Depth: discovered

              skills.declarationunknown

              No advertised Agent Skills endpoint was discovered in the sampled pages.

              skills.declaration · check 1.0.0 · applicability: unknown

                WebMCP 1.0.0

                unknown

                No WebMCP declaration evidence found in sampled HTML.

                Depth: discovered

                webmcp.declarationunknown

                No WebMCP declaration evidence found in sampled HTML.

                webmcp.declaration · check 1.0.0 · applicability: unknown

                  All readiness checks

                  web · 11/11 evaluated

                  A title and description identify the page.partial

                  Title present; description absent.

                  Recommended fix

                  Provide a meaningful title and meta description.

                  Verify: Repeat the documented observation on the public homepage.

                  web.identity · check 1.0.0 · applicability: applicable

                  Public same-origin content has crawlable links.fail

                  0 sampled crawlable same-origin content links.

                  Recommended fix

                  Use descriptive anchor elements with public href destinations.

                  Verify: Repeat the documented observation on the public homepage.

                  web.navigation · check 1.0.0 · applicability: applicable

                  Robots policy permits this public observation.pass

                  No robots.txt policy is published (HTTP 404).

                  web.discovery-policy · check 1.0.0 · applicability: applicable

                  The homepage returns a usable successful response.pass

                  Homepage returned HTTP 200.

                  web.http-access · check 1.0.0 · applicability: applicable

                  Transport uses verified HTTPS without downgrade or loops.pass

                  HTTPS certificate verified for all fetched hops.

                  web.transport · check 1.0.0 · applicability: applicable

                  An absent page has an explicit not-found response.pass

                  Nonexistent-path probe returned HTTP 404.

                  web.error-semantics · check 1.0.0 · applicability: applicable

                  The raw document exposes meaningful main content.partial

                  125 normalized main-text characters in the raw HTML.

                  Recommended fix

                  Render useful main content in the initial HTML response.

                  Verify: Repeat the documented observation on the public homepage.

                  web.raw-content · check 1.0.0 · applicability: applicable

                  Language and headings describe document structure.pass

                  Document language declared; 1 meaningful headings.

                  web.structure · check 1.0.0 · applicability: applicable

                  Content links have descriptive accessible names.fail

                  0 of 1 sampled content links have descriptive names.

                  Recommended fix

                  Replace ambiguous link names with clear destination descriptions.

                  Verify: Repeat the documented observation on the public homepage.

                  web.link-purpose · check 1.0.0 · applicability: applicable

                  Rendered actionable controls have accessible names.pass

                  1 of 1 rendered sampled controls have accessible names. Static Chromium profile: target JavaScript, forms, images and embedded frames disabled; actual DOM and Tab focus observed.

                  web.control-names · check 1.0.0 · applicability: applicable

                  • 1 of 1 rendered sampled controls have accessible names. Static Chromium profile: target JavaScript, forms, images and embedded frames disabled; actual DOM and Tab focus observed.
                    Source evidence ↗
                  Sampled public controls accept keyboard focus.pass

                  1 of 1 sampled controls reached by Tab with detectable focus.

                  web.keyboard · check 1.0.0 · applicability: applicable

                  A public link reaches its declared destination.not applicable

                  Public navigation observation: none.

                  web.navigation-result · check 1.0.0 · applicability: not applicable

                  discovery · 9/9 evaluated

                  A syntactically recognizable robots.txt is published.fail

                  Published robots.txt format and User-agent directives checked.

                  Recommended fix

                  Publish robots.txt with User-agent and Allow/Disallow directives.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.robots · check 2.0.0 · applicability: applicable

                  A bounded XML sitemap contains absolute public locations.fail

                  0 public locations in sampled sitemap files. HTTP 404.

                  Recommended fix

                  Publish a valid sitemap and advertise it in robots.txt.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.sitemap · check 2.0.0 · applicability: applicable

                  Sampled sitemap lastmod values are valid, nonfuture dates.fail

                  0 valid nonfuture lastmod values for 0 sampled locations; update truth and recency not inferred. HTTP 404.

                  Recommended fix

                  Add accurate lastmod values to sitemap entries when content changes.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.sitemap-freshness · check 2.0.0 · applicability: applicable

                  • 0 valid nonfuture lastmod values for 0 sampled locations; update truth and recency not inferred. HTTP 404.
                    Source evidence ↗
                  HTTP Link headers advertise agent-useful resources.fail

                  0 agent-useful HTTP Link relations parsed.

                  Recommended fix

                  Add service-desc, service-doc, api-catalog, describedby or alternate Link relations.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.link-headers · check 2.0.0 · applicability: applicable

                  DNS-AID entrypoints publish SVCB/HTTPS or TXT index records.fail

                  0 DNS-AID service/index answers across 7/7 answered DNS queries. DNSSEC trust and service execution are not validated.

                  Recommended fix

                  Publish DNS-AID service bindings at _index, _mcp or _a2a._agents.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.dns-aid · check 2.0.0 · applicability: applicable

                  • 0 DNS-AID service/index answers across 7/7 answered DNS queries. DNSSEC trust and service execution are not validated.
                    Source evidence ↗
                  RFC 9727 catalog contains valid API Linkset entries.fail

                  RFC 9727 Linkset anchors, public target links and content type checked; HEAD/profile and nested catalog conformance untested. HTTP 404.

                  Recommended fix

                  Publish /.well-known/api-catalog as application/linkset+json with public service links.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.api-catalog · check 2.0.0 · applicability: applicable

                  • RFC 9727 Linkset anchors, public target links and content type checked; HEAD/profile and nested catalog conformance untested. HTTP 404.
                    Source evidence ↗
                  ARD catalog entries identify typed, usable resources.fail

                  ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 404.

                  Recommended fix

                  Publish an ARD catalog with specVersion, host and complete entries.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.ard · check 2.0.0 · applicability: applicable

                  • ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 404.
                    Source evidence ↗
                  Agent Skills index has typed entries and SHA-256 digests.fail

                  Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 404.

                  Recommended fix

                  Publish the v0.2.0 skills index with name, description, type, URL and digest per skill.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.skills · check 2.0.0 · applicability: applicable

                  • Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 404.
                    Source evidence ↗
                  A usable public machine interface is advertised.fail

                  A declared machine interface is required for complete agent readiness; homepage richness alone does not meet this rule.

                  Recommended fix

                  Advertise an OpenAPI description, MCP endpoint or Agent Card for your product.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.agent-interface · check 2.0.0 · applicability: applicable

                  • A declared machine interface is required for complete agent readiness; homepage richness alone does not meet this rule.
                    Source evidence ↗

                  content · 15/15 evaluated

                  llms.txt is available as non-HTML text.fail

                  llms.txt non-HTML text representation checked. HTTP 404.

                  Recommended fix

                  Publish concise /llms.txt with a product summary and documentation links.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.llms · check 2.0.0 · applicability: applicable

                  llms.txt has a title, summary and categorized links.fail

                  llms.txt title, blockquote summary, sections and resource links checked. HTTP 404.

                  Recommended fix

                  Use a single H1, blockquote summary, H2 sections and descriptive Markdown links.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.llms-structure · check 2.0.0 · applicability: applicable

                  • llms.txt title, blockquote summary, sections and resource links checked. HTTP 404.
                    Source evidence ↗
                  Sampled llms.txt resource links resolve.fail

                  0/0 sampled llms.txt links acquired.

                  Recommended fix

                  Repair broken llms.txt links and make linked documentation public.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.llms-links · check 2.0.0 · applicability: applicable

                  Accept: text/markdown returns useful Markdown.fail

                  Accept: text/markdown response media type and non-HTML body checked.

                  Recommended fix

                  Serve an actual Markdown representation with Content-Type: text/markdown.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.markdown · check 2.0.0 · applicability: applicable

                  Negotiated Markdown declares Vary: Accept.fail

                  Negotiated Markdown must declare Vary: Accept to avoid representation cache collisions.

                  Recommended fix

                  Add Vary: Accept when content changes with the Accept request header.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.markdown-vary · check 2.0.0 · applicability: applicable

                  • Negotiated Markdown must declare Vary: Accept to avoid representation cache collisions.
                    Source evidence ↗
                  A Markdown alternate is advertised or resolves.fail

                  Advertised Markdown alternates and fetched Markdown URLs checked.

                  Recommended fix

                  Advertise text/markdown alternates in HTML or HTTP Link headers.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.markdown-alternate · check 2.0.0 · applicability: applicable

                  Sampled Markdown has bounded length, balanced fences and descriptive links.fail

                  Sampled Markdown: 0 characters, 0 fence boundaries, 0 public links.

                  Recommended fix

                  Keep Markdown concise, balance code fences and name linked resources.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.markdown-quality · check 2.0.0 · applicability: applicable

                  Published Markdown frontmatter includes useful metadata.fail

                  Markdown frontmatter title and description checked.

                  Recommended fix

                  Provide YAML title and description metadata in published Markdown documents.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.markdown-frontmatter · check 2.0.0 · applicability: applicable

                  Advertised developer documentation is publicly readable.fail

                  0/0 advertised documentation pages publicly acquired.

                  Recommended fix

                  Link public API documentation from your homepage and permit unauthenticated reading.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.docs · check 2.0.0 · applicability: applicable

                  Pricing or a documented free/enterprise pricing policy is readable.fail

                  Sampled content checked for monetary prices, free tiers or explicit sales/pricing policy.

                  Recommended fix

                  Publish accessible pricing amounts, free-tier terms or a clear contact-sales policy.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.pricing · check 2.0.0 · applicability: applicable

                  • Sampled content checked for monetary prices, free tiers or explicit sales/pricing policy.
                    Source evidence ↗
                  Privacy, terms or security information is linked.fail

                  Homepage and sampled-page privacy, terms and security links checked; legal adequacy not assessed.

                  Recommended fix

                  Link public privacy, terms and security pages.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.trust · check 2.0.0 · applicability: applicable

                  • Homepage and sampled-page privacy, terms and security links checked; legal adequacy not assessed.
                    Source evidence ↗
                  Public quickstart text includes request, credential and response guidance.fail

                  First-request command, credential setup and expected response guidance inspected; onboarding was not executed.

                  Recommended fix

                  Document a first request with credential setup, example command and expected result.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.onboarding · check 2.0.0 · applicability: applicable

                  • First-request command, credential setup and expected response guidance inspected; onboarding was not executed.
                    Source evidence ↗
                  Public documentation links or describes SDK installation.fail

                  SDK installation commands and package links checked; packages were not installed.

                  Recommended fix

                  Publish SDK package links with installation and usage examples.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.sdk · check 2.0.0 · applicability: applicable

                  • SDK installation commands and package links checked; packages were not installed.
                    Source evidence ↗
                  Public documentation describes CLI installation and usage.fail

                  CLI availability and installation guidance checked; commands were not run.

                  Recommended fix

                  Provide documented CLI installation and a first command.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.cli · check 2.0.0 · applicability: applicable

                  Public docs describe a sandbox or test mode.fail

                  Sandbox/test-mode declarations checked; environment behavior untested.

                  Recommended fix

                  Document a safe sandbox, test credentials or dry-run environment.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.sandbox · check 2.0.0 · applicability: applicable

                  access · 4/4 evaluated

                  Robots policy permits sampled AI crawlers and user agents.pass

                  6/6 sampled training and user-agent robots policies allow the homepage.

                  access.ai-policy · check 2.0.0 · applicability: applicable

                  Content-Signal directives declare recognized yes/no policies.fail

                  Content-Signal recognized directive/value syntax checked; a declared restriction is not silently treated as permission.

                  Recommended fix

                  Publish explicit search, ai-input and ai-train Content-Signal values.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  access.content-signals · check 2.0.0 · applicability: applicable

                  • Content-Signal recognized directive/value syntax checked; a declared restriction is not silently treated as permission.
                    Source evidence ↗
                  An explicit agent User-Agent can acquire useful public content.pass

                  Explicit ChatGPT-User/1.0 public acquisition and challenge/representation check; robots restrictions honored.

                  access.agent-reachability · check 2.0.0 · applicability: applicable

                  • Explicit ChatGPT-User/1.0 public acquisition and challenge/representation check; robots restrictions honored.
                    Source evidence ↗
                  An explicit agent User-Agent receives Markdown when requested.fail

                  Explicit ChatGPT-User/1.0 public acquisition and challenge/representation check; robots restrictions honored.

                  Recommended fix

                  Make Markdown negotiation work for agent User-Agents as well as ordinary clients.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  access.agent-markdown · check 2.0.0 · applicability: applicable

                  • Explicit ChatGPT-User/1.0 public acquisition and challenge/representation check; robots restrictions honored.
                    Source evidence ↗

                  entity · 5/5 evaluated

                  Title, description, canonical URL and social metadata identify the product.partial

                  Title, description, canonical link and Open Graph identity fields checked.

                  Recommended fix

                  Provide a title, description, canonical URL and Open Graph title/description.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  entity.metadata · check 2.0.0 · applicability: applicable

                  JSON-LD contains meaningful schema.org typed entities.fail

                  0 meaningful schema.org entities; 0 malformed JSON-LD blocks.

                  Recommended fix

                  Publish valid JSON-LD with a schema.org context and meaningful entity fields.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  entity.jsonld · check 2.0.0 · applicability: applicable

                  Organization JSON-LD includes name, URL and identity details.fail

                  0 Organization entities checked for name, URL, logo, description and contact/address details.

                  Recommended fix

                  Add Organization name, URL, logo, description and address/contactPoint details to your structured data.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  entity.organization · check 2.0.0 · applicability: applicable

                  • 0 Organization entities checked for name, URL, logo, description and contact/address details.
                    Source evidence ↗
                  Entity sameAs links identify public external profiles.fail

                  JSON-LD sameAs public external identity links checked; profile ownership not verified.

                  Recommended fix

                  Connect your entity to authoritative external profiles through sameAs.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  entity.linking · check 2.0.0 · applicability: applicable

                  • JSON-LD sameAs public external identity links checked; profile ownership not verified.
                    Source evidence ↗
                  Structured data covers organization and product/content entities.fail

                  0 distinct JSON-LD types found.

                  Recommended fix

                  Describe the organization and relevant product, software, service or article types.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  entity.breadth · check 2.0.0 · applicability: applicable

                  api · 0/0 evaluated

                  An advertised OpenAPI 3.x document declares title, version and paths.not applicable

                  OpenAPI 3.0–3.2 root title/version/paths structure checked; full specification conformance not implied.

                  api.description · check 2.0.0 · applicability: not applicable

                  • OpenAPI 3.0–3.2 root title/version/paths structure checked; full specification conformance not implied.
                    Source evidence ↗
                  OpenAPI defines nonempty, described operations with unique operationId values.not applicable

                  0/0 operations meet description and unique operationId requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

                  api.operations · check 2.0.0 · applicability: not applicable

                  • 0/0 operations meet description and unique operationId requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
                    Source evidence ↗
                  Operation parameters and request bodies contain usable schemas.not applicable

                  0/0 operations meet typed parameter and request body requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

                  api.parameters · check 2.0.0 · applicability: not applicable

                  • 0/0 operations meet typed parameter and request body requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
                    Source evidence ↗
                  Operations declare response schemas and descriptions.not applicable

                  0/0 operations meet described success response schema requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

                  api.responses · check 2.0.0 · applicability: not applicable

                  • 0/0 operations meet described success response schema requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
                    Source evidence ↗
                  Operations document structured client/server error responses.not applicable

                  0/0 operations meet typed error response requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

                  api.errors · check 2.0.0 · applicability: not applicable

                  • 0/0 operations meet typed error response requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
                    Source evidence ↗
                  OpenAPI declares usable security schemes and operation requirements.not applicable

                  OpenAPI security schemes and referenced security requirements inspected.

                  api.authentication · check 2.0.0 · applicability: not applicable

                  List operations describe pagination parameters or continuation fields.not applicable

                  Pagination parameters/continuation fields inspected Declaration-only; no endpoint execution.

                  api.pagination · check 2.0.0 · applicability: not applicable

                  • Pagination parameters/continuation fields inspected Declaration-only; no endpoint execution.
                    Source evidence ↗
                  API documents version or deprecation policy.not applicable

                  Version and deprecation declarations inspected Declaration-only; no endpoint execution.

                  api.versioning · check 2.0.0 · applicability: not applicable

                  • Version and deprecation declarations inspected Declaration-only; no endpoint execution.
                    Source evidence ↗
                  Mutation operations declare idempotency support.not applicable

                  Idempotency request support inspected Declaration-only; no endpoint execution.

                  api.idempotency · check 2.0.0 · applicability: not applicable

                  • Idempotency request support inspected Declaration-only; no endpoint execution.
                    Source evidence ↗
                  API responses or docs expose rate limits and retry guidance.not applicable

                  Observed rate-limit headers and documented retry policy checked.

                  api.rate-limits · check 2.0.0 · applicability: not applicable

                  Long-running operation behavior is declared.not applicable

                  Asynchronous operation declarations inspected Declaration-only; no endpoint execution.

                  api.async · check 2.0.0 · applicability: not applicable

                  • Asynchronous operation declarations inspected Declaration-only; no endpoint execution.
                    Source evidence ↗
                  Batch or bulk operation declarations are published.not applicable

                  Batch/bulk operation declarations inspected Declaration-only; no endpoint execution.

                  api.batch · check 2.0.0 · applicability: not applicable

                  • Batch/bulk operation declarations inspected Declaration-only; no endpoint execution.
                    Source evidence ↗
                  Operation identifiers and input schemas can describe bounded function inputs.not applicable

                  0/0 operations meet bounded function naming and input schema requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.

                  api.function-calling · check 2.0.0 · applicability: not applicable

                  • 0/0 operations meet bounded function naming and input schema requirements. 0 external and 0 unresolved local references; reference-limited observations stay unknown.
                    Source evidence ↗

                  auth · 0/0 evaluated

                  OAuth/OIDC metadata has a consistent issuer and HTTPS endpoint declarations.not applicable

                  OAuth issuer/HTTPS endpoint and authorization-code response declarations checked; login and token exchange untested. HTTP 404.

                  auth.discovery · check 2.0.0 · applicability: not applicable

                  • OAuth issuer/HTTPS endpoint and authorization-code response declarations checked; login and token exchange untested. HTTP 404.
                    Source evidence ↗
                  Protected-resource metadata identifies its resource and authorization servers.not applicable

                  RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.

                  auth.protected-resource · check 2.0.0 · applicability: not applicable

                  • RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.
                    Source evidence ↗
                  API or OAuth metadata declares nonempty permission scopes.not applicable

                  0 declared permission scopes; actual enforcement not tested.

                  auth.scopes · check 2.0.0 · applicability: not applicable

                  OAuth discovery declares PKCE S256.not applicable

                  PKCE S256 discovery declaration checked; no authorization exchange performed. HTTP 404.

                  auth.pkce · check 2.0.0 · applicability: not applicable

                  • PKCE S256 discovery declaration checked; no authorization exchange performed. HTTP 404.
                    Source evidence ↗
                  auth.md includes substantive authentication walkthrough sections.not applicable

                  auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 404.

                  auth.instructions · check 2.0.0 · applicability: not applicable

                  • auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 404.
                    Source evidence ↗
                  agent_auth metadata links instructions and declared registration mechanisms.not applicable

                  agent_auth declaration and auth.md linkage inspected; full draft request-shape conformance untested.

                  auth.agent-metadata · check 2.0.0 · applicability: not applicable

                  • agent_auth declaration and auth.md linkage inspected; full draft request-shape conformance untested.
                    Source evidence ↗
                  Observed authentication challenges advertise resource metadata.not applicable

                  Observed public authentication challenges checked for RFC 9728 resource_metadata; no artificial protected request or login was sent.

                  auth.challenge · check 2.0.0 · applicability: not applicable

                  • Observed public authentication challenges checked for RFC 9728 resource_metadata; no artificial protected request or login was sent.
                    Source evidence ↗

                  mcp · 0/0 evaluated

                  MCP Server Card identifies the server and transport.not applicable

                  MCP Server Card identity, capabilities and explicit transport endpoint checked; draft schema subset. HTTP 404.

                  mcp.card · check 2.0.0 · applicability: not applicable

                  • MCP Server Card identity, capabilities and explicit transport endpoint checked; draft schema subset. HTTP 404.
                    Source evidence ↗
                  An advertised MCP endpoint initializes and lists capabilities read-only.not applicable

                  No advertised or explicitly supplied MCP endpoint was discovered.

                  mcp.handshake · check 2.0.0 · applicability: not applicable

                  MCP initialization declares meaningful server identity.not applicable

                  MCP initialization serverInfo name/version and instructions checked.

                  mcp.identity · check 2.0.0 · applicability: not applicable

                  MCP exposes nonempty tools with unique stable names.not applicable

                  0/0 MCP tools have unique stable names.

                  mcp.tools · check 2.0.0 · applicability: not applicable

                  MCP tools have substantive descriptions.not applicable

                  0/0 MCP tools have substantive descriptions.

                  mcp.descriptions · check 2.0.0 · applicability: not applicable

                  MCP inputs contain typed property descriptions and valid required references.not applicable

                  0/0 MCP inputs have typed described properties and valid required references.

                  mcp.schemas · check 2.0.0 · applicability: not applicable

                  • 0/0 MCP inputs have typed described properties and valid required references.
                    Source evidence ↗
                  MCP tool annotations declare safety and idempotency hints.not applicable

                  0/0 MCP tools declare all four safety/idempotency annotations. Hints are not verified effects.

                  mcp.annotations · check 2.0.0 · applicability: not applicable

                  • 0/0 MCP tools declare all four safety/idempotency annotations. Hints are not verified effects.
                    Source evidence ↗
                  MCP resource listings expose valid named URI resources.not applicable

                  0/0 MCP resources have name, URI, description and MIME type. Resource contents not read.

                  mcp.resources · check 2.0.0 · applicability: not applicable

                  • 0/0 MCP resources have name, URI, description and MIME type. Resource contents not read.
                    Source evidence ↗

                  protocol · 0/0 evaluated

                  A2A card declares identity, interfaces, capabilities and useful skills.not applicable

                  A2A identity, declared interfaces, capabilities and skill descriptions checked; tasks are not invoked. HTTP 404.

                  protocol.a2a · check 2.0.0 · applicability: not applicable

                  • A2A identity, declared interfaces, capabilities and skill descriptions checked; tasks are not invoked. HTTP 404.
                    Source evidence ↗

                  Reference check families

                  GrowthOS observations grouped against Cloudflare’s public checklist. These reuse the evidence above; they are not extra points.

                  Inspect 22 check families
                  A syntactically recognizable robots.txt is published.fail

                  Published robots.txt format and User-agent directives checked.

                  Recommended fix

                  Publish robots.txt with User-agent and Allow/Disallow directives.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.robots · check 2.0.0 · applicability: applicable

                  A bounded XML sitemap contains absolute public locations.fail

                  0 public locations in sampled sitemap files. HTTP 404.

                  Recommended fix

                  Publish a valid sitemap and advertise it in robots.txt.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.sitemap · check 2.0.0 · applicability: applicable

                  HTTP Link headers advertise agent-useful resources.fail

                  0 agent-useful HTTP Link relations parsed.

                  Recommended fix

                  Add service-desc, service-doc, api-catalog, describedby or alternate Link relations.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.link-headers · check 2.0.0 · applicability: applicable

                  DNS-AID entrypoints publish SVCB/HTTPS or TXT index records.fail

                  0 DNS-AID service/index answers across 7/7 answered DNS queries. DNSSEC trust and service execution are not validated.

                  Recommended fix

                  Publish DNS-AID service bindings at _index, _mcp or _a2a._agents.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.dns-aid · check 2.0.0 · applicability: applicable

                  • 0 DNS-AID service/index answers across 7/7 answered DNS queries. DNSSEC trust and service execution are not validated.
                    Source evidence ↗
                  Accept: text/markdown returns useful Markdown.fail

                  Accept: text/markdown response media type and non-HTML body checked.

                  Recommended fix

                  Serve an actual Markdown representation with Content-Type: text/markdown.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  content.markdown · check 2.0.0 · applicability: applicable

                  Robots policy permits sampled AI crawlers and user agents.pass

                  6/6 sampled training and user-agent robots policies allow the homepage.

                  access.ai-policy · check 2.0.0 · applicability: applicable

                  Content-Signal directives declare recognized yes/no policies.fail

                  Content-Signal recognized directive/value syntax checked; a declared restriction is not silently treated as permission.

                  Recommended fix

                  Publish explicit search, ai-input and ai-train Content-Signal values.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  access.content-signals · check 2.0.0 · applicability: applicable

                  • Content-Signal recognized directive/value syntax checked; a declared restriction is not silently treated as permission.
                    Source evidence ↗
                  supplemental.web bot authnot applicable

                  Web Bot Auth public JWKS identity/key fields checked. Signing, key possession, rotation and receiver verification not tested. HTTP 404.

                  supplemental.web-bot-auth · check 2.0.0 · applicability: not applicable

                  • Web Bot Auth public JWKS identity/key fields checked. Signing, key possession, rotation and receiver verification not tested. HTTP 404.
                    Source evidence ↗
                  RFC 9727 catalog contains valid API Linkset entries.fail

                  RFC 9727 Linkset anchors, public target links and content type checked; HEAD/profile and nested catalog conformance untested. HTTP 404.

                  Recommended fix

                  Publish /.well-known/api-catalog as application/linkset+json with public service links.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.api-catalog · check 2.0.0 · applicability: applicable

                  • RFC 9727 Linkset anchors, public target links and content type checked; HEAD/profile and nested catalog conformance untested. HTTP 404.
                    Source evidence ↗
                  OAuth/OIDC metadata has a consistent issuer and HTTPS endpoint declarations.not applicable

                  OAuth issuer/HTTPS endpoint and authorization-code response declarations checked; login and token exchange untested. HTTP 404.

                  auth.discovery · check 2.0.0 · applicability: not applicable

                  • OAuth issuer/HTTPS endpoint and authorization-code response declarations checked; login and token exchange untested. HTTP 404.
                    Source evidence ↗
                  Protected-resource metadata identifies its resource and authorization servers.not applicable

                  RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.

                  auth.protected-resource · check 2.0.0 · applicability: not applicable

                  • RFC 9728 resource identifier and public authorization server declarations checked. HTTP 404.
                    Source evidence ↗
                  auth.md includes substantive authentication walkthrough sections.not applicable

                  auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 404.

                  auth.instructions · check 2.0.0 · applicability: not applicable

                  • auth.md walkthrough sections and substantive section bodies checked; registration/claim/exchange are never performed. HTTP 404.
                    Source evidence ↗
                  MCP Server Card identifies the server and transport.not applicable

                  MCP Server Card identity, capabilities and explicit transport endpoint checked; draft schema subset. HTTP 404.

                  mcp.card · check 2.0.0 · applicability: not applicable

                  • MCP Server Card identity, capabilities and explicit transport endpoint checked; draft schema subset. HTTP 404.
                    Source evidence ↗
                  A2A card declares identity, interfaces, capabilities and useful skills.not applicable

                  A2A identity, declared interfaces, capabilities and skill descriptions checked; tasks are not invoked. HTTP 404.

                  protocol.a2a · check 2.0.0 · applicability: not applicable

                  • A2A identity, declared interfaces, capabilities and skill descriptions checked; tasks are not invoked. HTTP 404.
                    Source evidence ↗
                  Agent Skills index has typed entries and SHA-256 digests.fail

                  Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 404.

                  Recommended fix

                  Publish the v0.2.0 skills index with name, description, type, URL and digest per skill.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.skills · check 2.0.0 · applicability: applicable

                  • Skills index revision undeclared: typed entries and SHA-256 digest format checked for v0.2.0; legacy v0.1.0 is partial adoption. Package integrity/installation untested. HTTP 404.
                    Source evidence ↗
                  supplemental.webmcpfail

                  Static WebMCP API/declarative-form indicators inspected. Runtime tool discovery and invocation require a supporting browser and were not performed.

                  Recommended fix

                  Publish accurate, public machine-readable declarations and verify their behavior independently.

                  Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

                  supplemental.webmcp · check 2.0.0 · applicability: applicable

                  • Static WebMCP API/declarative-form indicators inspected. Runtime tool discovery and invocation require a supporting browser and were not performed.
                    Source evidence ↗
                  ARD catalog entries identify typed, usable resources.fail

                  ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 404.

                  Recommended fix

                  Publish an ARD catalog with specVersion, host and complete entries.

                  Verify: Repeat the bounded public acquisition and semantic checks documented in readiness-v2. Runtime transactions are not performed.

                  discovery.ard · check 2.0.0 · applicability: applicable

                  • ARD host/version and bounded entry identity, media type and exclusive URL/data fields checked; signatures and trust assertions unverified. HTTP 404.
                    Source evidence ↗
                  supplemental.x402not applicable

                  Observed 402/payment-required x402 requirements checked for version, network, asset, recipient and amount. No payment sent.

                  supplemental.x402 · check 2.0.0 · applicability: not applicable

                  • Observed 402/payment-required x402 requirements checked for version, network, asset, recipient and amount. No payment sent.
                    Source evidence ↗
                  supplemental.mppnot applicable

                  OpenAPI x-payment-info intent/method/amount/currency declarations inspected. Payment challenge fulfillment and session behavior not tested.

                  supplemental.mpp · check 2.0.0 · applicability: not applicable

                  • OpenAPI x-payment-info intent/method/amount/currency declarations inspected. Payment challenge fulfillment and session behavior not tested.
                    Source evidence ↗
                  supplemental.ucpnot applicable

                  UCP profile version, services and capabilities declaration subset checked; endpoints, checkout and signatures untested. HTTP 404.

                  supplemental.ucp · check 2.0.0 · applicability: not applicable

                  • UCP profile version, services and capabilities declaration subset checked; endpoints, checkout and signatures untested. HTTP 404.
                    Source evidence ↗
                  supplemental.acpnot applicable

                  ACP discovery protocol/version, API base URL, transports and services checked; checkout sessions never created. HTTP 404.

                  supplemental.acp · check 2.0.0 · applicability: not applicable

                  • ACP discovery protocol/version, API base URL, transports and services checked; checkout sessions never created. HTTP 404.
                    Source evidence ↗
                  supplemental.ap2not applicable

                  A2A card AP2 extension URI inspected. Signed mandates, authorization and payments untested; no guessed AP2 endpoint implies conformance.

                  supplemental.ap2 · check 2.0.0 · applicability: not applicable

                  • A2A card AP2 extension URI inspected. Signed mandates, authorization and payments untested; no guessed AP2 endpoint implies conformance.
                    Source evidence ↗

                  Additional observations

                  Supplemental declaration observations and explicitly unperformed external/runtime assessments. These have no score weight.

                  Inspect declarations and unperformed assessments
                  public.agent instructionsfail

                  Public when-to-use/agent instruction guidance or explicit instruction-file links inspected; instructions not followed.

                  Recommended fix

                  Publish accurate, public machine-readable declarations and verify their behavior independently.

                  Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

                  public.agent-instructions · check 2.0.0 · applicability: applicable

                  • Public when-to-use/agent instruction guidance or explicit instruction-file links inspected; instructions not followed.
                    Source evidence ↗
                  public.agent configsfail

                  Public links to agent platform configuration files inspected; repository contents not recursively searched.

                  Recommended fix

                  Publish accurate, public machine-readable declarations and verify their behavior independently.

                  Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

                  public.agent-configs · check 2.0.0 · applicability: applicable

                  • Public links to agent platform configuration files inspected; repository contents not recursively searched.
                    Source evidence ↗
                  public.agent pluginsfail

                  Explicit agent-plugin manifest links inspected; full package schema and installation not tested.

                  Recommended fix

                  Publish accurate, public machine-readable declarations and verify their behavior independently.

                  Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

                  public.agent-plugins · check 2.0.0 · applicability: applicable

                  • Explicit agent-plugin manifest links inspected; full package schema and installation not tested.
                    Source evidence ↗
                  public.agent viewfail

                  Public agent-view/mode declarations inspected; alternate UI not executed.

                  Recommended fix

                  Publish accurate, public machine-readable declarations and verify their behavior independently.

                  Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

                  public.agent-view · check 2.0.0 · applicability: applicable

                  public.markdown fallbackfail

                  A bounded .md URL fallback sample returns non-HTML Markdown; unrelated URLs are not enumerated.

                  Recommended fix

                  Publish accurate, public machine-readable declarations and verify their behavior independently.

                  Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

                  public.markdown-fallback · check 2.0.0 · applicability: applicable

                  • A bounded .md URL fallback sample returns non-HTML Markdown; unrelated URLs are not enumerated.
                    Source evidence ↗
                  public.modular llmsfail

                  Advertised product-area llms.txt resources acquired; unadvertised areas not guessed.

                  Recommended fix

                  Publish accurate, public machine-readable declarations and verify their behavior independently.

                  Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

                  public.modular-llms · check 2.0.0 · applicability: applicable

                  • Advertised product-area llms.txt resources acquired; unadvertised areas not guessed.
                    Source evidence ↗
                  public.nlwebfail

                  NLWeb/feed declarations inspected; /ask requests and streaming responses not executed.

                  Recommended fix

                  Publish accurate, public machine-readable declarations and verify their behavior independently.

                  Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

                  public.nlweb · check 2.0.0 · applicability: applicable

                  • NLWeb/feed declarations inspected; /ask requests and streaming responses not executed.
                    Source evidence ↗
                  public.a2uifail

                  A2UI declaration indicators inspected; generated UI quality is not evaluated.

                  Recommended fix

                  Publish accurate, public machine-readable declarations and verify their behavior independently.

                  Verify: Repeat the documented public declaration inspection; this supplemental observation has no score weight.

                  public.a2ui · check 2.0.0 · applicability: applicable

                  • A2UI declaration indicators inspected; generated UI quality is not evaluated.
                    Source evidence ↗
                  public.native controlspass

                  1 native controls and 0 custom ARIA control declarations observed. Focus/keyboard evidence remains in browser checks.

                  public.native-controls · check 2.0.0 · applicability: applicable

                  • 1 native controls and 0 custom ARIA control declarations observed. Focus/keyboard evidence remains in browser checks.
                    Source evidence ↗
                  public.form labelsnot applicable

                  0/0 source form controls have label associations; runtime accessible names independently sampled by browser.

                  public.form-labels · check 2.0.0 · applicability: not applicable

                  • 0/0 source form controls have label associations; runtime accessible names independently sampled by browser.
                    Source evidence ↗
                  public.injection indicatorsunknown

                  No bounded source-label injection indicator detected. This is not an injection-safety guarantee or pass.

                  public.injection-indicators · check 2.0.0 · applicability: unknown

                  • No bounded source-label injection indicator detected. This is not an injection-safety guarantee or pass.
                    Source evidence ↗
                  public.graphql errorsnot applicable

                  Public GraphQL errors declaration patterns inspected; schema introspection, coverage and operations are not executed.

                  public.graphql-errors · check 2.0.0 · applicability: not applicable

                  • Public GraphQL errors declaration patterns inspected; schema introspection, coverage and operations are not executed.
                    Source evidence ↗
                  public.graphql paginationnot applicable

                  Public GraphQL pagination declaration patterns inspected; schema introspection, coverage and operations are not executed.

                  public.graphql-pagination · check 2.0.0 · applicability: not applicable

                  • Public GraphQL pagination declaration patterns inspected; schema introspection, coverage and operations are not executed.
                    Source evidence ↗
                  public.graphql versioningnot applicable

                  Public GraphQL versioning declaration patterns inspected; schema introspection, coverage and operations are not executed.

                  public.graphql-versioning · check 2.0.0 · applicability: not applicable

                  • Public GraphQL versioning declaration patterns inspected; schema introspection, coverage and operations are not executed.
                    Source evidence ↗
                  public.graphql asyncnot applicable

                  Public GraphQL async declaration patterns inspected; schema introspection, coverage and operations are not executed.

                  public.graphql-async · check 2.0.0 · applicability: not applicable

                  • Public GraphQL async declaration patterns inspected; schema introspection, coverage and operations are not executed.
                    Source evidence ↗
                  public.graphql batchnot applicable

                  Public GraphQL batch declaration patterns inspected; schema introspection, coverage and operations are not executed.

                  public.graphql-batch · check 2.0.0 · applicability: not applicable

                  • Public GraphQL batch declaration patterns inspected; schema introspection, coverage and operations are not executed.
                    Source evidence ↗
                  public.graphql schemanot applicable

                  Public GraphQL schema declaration patterns inspected; schema introspection, coverage and operations are not executed.

                  public.graphql-schema · check 2.0.0 · applicability: not applicable

                  • Public GraphQL schema declaration patterns inspected; schema introspection, coverage and operations are not executed.
                    Source evidence ↗
                  public.schema complexitynot applicable

                  OpenAPI traversal bounded to depth24,20000 nodes per schema and200000 total nodes; 0 external and 0 unresolved references. No LLM comprehension or actual tool generation evaluated.

                  public.schema-complexity · check 2.0.0 · applicability: not applicable

                  • OpenAPI traversal bounded to depth24,20000 nodes per schema and200000 total nodes; 0 external and 0 unresolved references. No LLM comprehension or actual tool generation evaluated.
                    Source evidence ↗
                  public.json errorsunknown

                  Actual acquired 4xx responses inspected for JSON objects. No fabricated malformed API calls sent; unobserved error behavior stays unknown.

                  public.json-errors · check 2.0.0 · applicability: unknown

                  • Actual acquired 4xx responses inspected for JSON objects. No fabricated malformed API calls sent; unobserved error behavior stays unknown.
                    Source evidence ↗
                  public.ard trustnot applicable

                  ARD trust/signature/attestation declaration presence inspected; signatures, compliance and identity claims not verified.

                  public.ard-trust · check 2.0.0 · applicability: not applicable

                  • ARD trust/signature/attestation declaration presence inspected; signatures, compliance and identity claims not verified.
                    Source evidence ↗
                  public.mcp surfacesnot applicable

                  0 distinct public MCP advertisements; product-vs-docs capability coverage and additional handshakes untested.

                  public.mcp-surfaces · check 2.0.0 · applicability: not applicable

                  • 0 distinct public MCP advertisements; product-vs-docs capability coverage and additional handshakes untested.
                    Source evidence ↗
                  public.search assessmentunsupported

                  Category share-of-voice, search ranking, brand accuracy and developer-resource retrieval require an external search/LLM assessment; not performed.

                  public.search-assessment · check 2.0.0 · applicability: unknown

                  • Category share-of-voice, search ranking, brand accuracy and developer-resource retrieval require an external search/LLM assessment; not performed.
                    Source evidence ↗
                  public.registry assessmentunsupported

                  MCP registry, npm/PyPI, skills.sh, ChatGPT app and Wikipedia/Wikidata membership/branding not independently queried in this deterministic scan; public links alone do not prove membership.

                  public.registry-assessment · check 2.0.0 · applicability: unknown

                  • MCP registry, npm/PyPI, skills.sh, ChatGPT app and Wikipedia/Wikidata membership/branding not independently queried in this deterministic scan; public links alone do not prove membership.
                    Source evidence ↗
                  public.auth walkthroughunsupported

                  Authentication walkthrough simulation and registration/claim/token transactions not performed; only documentation and discovery metadata inspected.

                  public.auth-walkthrough · check 2.0.0 · applicability: unknown

                  • Authentication walkthrough simulation and registration/claim/token transactions not performed; only documentation and discovery metadata inspected.
                    Source evidence ↗
                  public.mcp app runtimeunsupported

                  MCP Apps HTML view loading/CSP, UI quality and interactive app behavior not tested; no resource reads or UI tool executions performed.

                  public.mcp-app-runtime · check 2.0.0 · applicability: unknown

                  • MCP Apps HTML view loading/CSP, UI quality and interactive app behavior not tested; no resource reads or UI tool executions performed.
                    Source evidence ↗
                  public.mcp error behaviorunsupported

                  MCP error-response semantics not proactively exercised: only permitted initialize/list operations are sent.

                  public.mcp-error-behavior · check 2.0.0 · applicability: unknown

                  • MCP error-response semantics not proactively exercised: only permitted initialize/list operations are sent.
                    Source evidence ↗

                  Keep the evidence

                  Exports contain public findings from this observation. Private contacts and raw browser artifacts are excluded.

                  Scan 5c15d8cb-cf34-4d4a-af8d-4682525e57fa · Created Thu, 10 Sep 2026 19:08:59 GMT