Export Report
OVERALL SCORE
Level 3, Bot-Aware
- AI Discoverability 55 out of 100
- Agent Ease of Use 62 out of 100
- Security & Trust 45 out of 100
- GEO, AIO and AEO 32 out of 100
- SEO 100 out of 100
- Performance 47 out of 100
- Accessibility 58 out of 100
What AI sees of your website
Backstage Software Catalog and Developer Platform
Backstage is an open source developer portal framework that centralizes your software catalog, unifies infrastructure tools, and helps teams ship high-quality code faster.
Next step
Turn this report into a fix workflow
3 failed checks are ready to move into MCP or CLI remediation. Generate a repair prompt, connect the scanner to your coding agent, or open the integration docs before your next rescan.
| Metric | Score | Status | Passed | Failed | Warning | Evidence |
|---|---|---|---|---|---|---|
| AI Discoverability | 55 | Needs work | 23 | 1 | 0 | View details |
| Discoverability | 67 | Needs work | 8 | 0 | 0 | |
| Content Readiness | 55 | Needs work | 14 | 0 | 0 | |
| Bot Access Control | 45 | Priority fix | 1 | 1 | 0 | View details |
| Agent Ease of Use | 62 | Needs work | 4 | 2 | 4 | View details |
| API | 67 | Needs work | 2 | 0 | 0 | |
| Skill Discovery | 46 | Priority fix | 0 | 2 | 4 | View details |
| Google Agentic Browsing | 100 | Strong | 2 | 0 | 0 | |
| GEO, AIO and AEO | 32 | Priority fix | 3 | 0 | 0 | |
| GEO Readiness | Not Applicable | Not Applicable | 1 | 0 | 0 | |
| AIO Readiness | Not Applicable | Not Applicable | 1 | 0 | 0 | |
| AEO Readiness | Not Applicable | Not Applicable | 1 | 0 | 0 | |
| SEO | 100 | Strong | 10 | 0 | 0 | |
| SEO | 100 | Strong | 10 | 0 | 0 | |
| Security & Trust | 45 | Priority fix | 7 | 1 | 0 | View details |
| Security & Trust | 45 | Priority fix | 7 | 1 | 0 | View details |
| Performance | 47 | Priority fix | 12 | 0 | 0 | |
| Performance | 47 | Priority fix | 12 | 0 | 0 |
Prioritized recommendations
Issues ranked by score impact
3 items need attention
AI DiscoverabilityBot Access ControlEstablished
AI bot rules in robots.txt
AI bot rules in robots.txt failed at "Classify AI crawler rules".
69 Fail
AI DiscoverabilityBot Access ControlEstablished
AI bot rules in robots.txt
AI bot rules in robots.txt failed at "Classify AI crawler rules".
Needs attention
AI bot rules in robots.txt
Issue
No explicit User-agent rules were found for major AI crawler tokens.
Details
Why it matters
AI crawler product tokens have different meanings. Explicit robots.txt groups make training, search, and retrieval access policy auditable for compliant crawler operators.
Check name
AI bot rules in robots.txt
Score
31/100
Status
fail
Category
Bot Access Control
Maturity
Established
Goal
Declare deliberate robots.txt rules for major AI training, AI search, user-triggered, and dataset crawlers.
Result
AI bot rules in robots.txt failed at "Classify AI crawler rules".
Validation steps
Classify AI crawler rules
No explicit User-agent rules were found for major AI crawler tokens.
robots.txt lacks explicit AI crawler rules
Evidence log1 step · 6 lines
Classify AI crawler rules [fail]! No explicit User-agent rules were found for major AI crawler tokens.INFOClassify AI crawler rulesINFOParsing User-agent groups and Allow/Disallow records for known AI crawler tokens evaluatedPath="/"INFOEvaluating exact User-agent matches before wildcard fallback exactAiPolicyCount=0 totalCrawlerTokens=18FAILNo explicit AI crawler User-agent groups were found examplesExpected=["GPTBot","OAI-SearchBot","ClaudeBot","Google-Extended","CCBot"]FAILCompare explicit AI crawler coverage actual=0 expected="> 0 explicit non-search AI crawler policies" missingTokens=["GPTBot","OAI-SearchBot","ChatGPT-User","ClaudeBot","Claude-SearchBot","Claude-User","Google-Extended","Applebot-Extended","Amazonbot","Amzn-SearchBot","Amzn-User","PerplexityBot"]INFOResolved effective root-path policy for crawler tokens blocked=0 allowed=21 unspecified=0Agent Ease of UseSkill DiscoveryEmerging recommendation
Agent Skills index
Agent Skills index failed at "Validate discovery index schema".
67 Fail
Agent Ease of UseSkill DiscoveryEmerging recommendation
Agent Skills index
Agent Skills index failed at "Validate discovery index schema".
Needs attention
Agent Skills index
Issue
Agent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.
Details
Why it matters
An Agent Skills index lets agents discover task-specific instructions through a small trusted index, then verify and load only the skill artifacts they need.
Check name
Agent Skills index
Score
33/100
Status
fail
Category
Skill Discovery
Maturity
Emerging recommendation
Goal
Publish an Agent Skills discovery index that advertises digest-pinned SKILL.md or archive artifacts.
Result
Agent Skills index failed at "Validate discovery index schema".
Validation steps
Discover Agent Skills index
Agent Skills index was found only at the legacy /.well-known/skills/index.json path.
Agent Skills index is only available at the legacy path
Validate discovery index schema
Agent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.
Agent Skills discovery index schema is invalid
Top-level issues
- $schema must be https://schemas.agentskills.io/discovery/0.2.0/schema.json
Invalid skills
[ { "index": 0, "valid": false, "name": "mui-to-bui-migration", "type": "", "description": "Migrate Backstage plugins from Material-UI (MUI) to Backstage UI (BUI). Use this skill when migrating components, updating imports, replacing styling patterns, or converting MUI components to their BUI equivalents.", "url": "", "digest": "", "resolvedUrl": "https://backstage.io/.well-known/skills/index.json", "originClass": "same-origin", "missing": [ "type", "url", "digest" ], "invalid": [], "warnings": [] }, { "index": 1, "valid": false, "name": "app-frontend-system-migration", "type": "", "description": "Migrate a Backstage app from the old frontend system to the new one. Use this skill when converting an app to use the new extension-based frontend system, including the hybrid migration phase and the full migration of routes, sidebar, plugins, APIs, themes, and other app-level concerns.", "url": "", "digest": "", "resolvedUrl": "https://backstage.io/.well-known/skills/index.json", "originClass": "same-origin", "missing": [ "type", "url", "digest" ], "invalid": [], "warnings": [] }, { "index": 2, "valid": false, "name": "plugin-new-frontend-system-support", "type": "", "description": "Add new frontend system support to an existing Backstage plugin while keeping the old system working. Use this skill for published or shared plugins that need to work in both old and new frontend system apps.", "url": "", "digest": "", "resolvedUrl": "https://backstage.io/.well-known/skills/index.json", "originClass": "same-origin", "missing": [ "type", "url", "digest" ], "invalid": [], "warnings": [] }, { "index": 3, "valid": false, "name": "plugin-full-frontend-system-migration", "type": "", "description": "Fully migrate a Backstage plugin to the new frontend system, dropping all old system support. Use this skill for internal plugins that only need to run in a single app, or when you are ready to remove backward compatibility entirely.", "url": "", "digest": "", "resolvedUrl": "https://backstage.io/.well-known/skills/index.json", "originClass": "same-origin", "missing": [ "type", "url", "digest" ], "invalid": [], "warnings": [] }, { "truncated": true, "omittedCount": 2, "originalCount": 6 } ]Validate skill entries
One or more Agent Skills entries have invalid required fields.
One or more skill entries are invalid
Skill entry findings
[ { "index": 0, "valid": false, "name": "mui-to-bui-migration", "type": "", "description": "Migrate Backstage plugins from Material-UI (MUI) to Backstage UI (BUI). Use this skill when migrating components, updating imports, replacing styling patterns, or converting MUI components to their BUI equivalents.", "url": "", "digest": "", "resolvedUrl": "https://backstage.io/.well-known/skills/index.json", "originClass": "same-origin", "missing": [ "type", "url", "digest" ], "invalid": [], "warnings": [] }, { "index": 1, "valid": false, "name": "app-frontend-system-migration", "type": "", "description": "Migrate a Backstage app from the old frontend system to the new one. Use this skill when converting an app to use the new extension-based frontend system, including the hybrid migration phase and the full migration of routes, sidebar, plugins, APIs, themes, and other app-level concerns.", "url": "", "digest": "", "resolvedUrl": "https://backstage.io/.well-known/skills/index.json", "originClass": "same-origin", "missing": [ "type", "url", "digest" ], "invalid": [], "warnings": [] }, { "index": 2, "valid": false, "name": "plugin-new-frontend-system-support", "type": "", "description": "Add new frontend system support to an existing Backstage plugin while keeping the old system working. Use this skill for published or shared plugins that need to work in both old and new frontend system apps.", "url": "", "digest": "", "resolvedUrl": "https://backstage.io/.well-known/skills/index.json", "originClass": "same-origin", "missing": [ "type", "url", "digest" ], "invalid": [], "warnings": [] }, { "index": 3, "valid": false, "name": "plugin-full-frontend-system-migration", "type": "", "description": "Fully migrate a Backstage plugin to the new frontend system, dropping all old system support. Use this skill for internal plugins that only need to run in a single app, or when you are ready to remove backward compatibility entirely.", "url": "", "digest": "", "resolvedUrl": "https://backstage.io/.well-known/skills/index.json", "originClass": "same-origin", "missing": [ "type", "url", "digest" ], "invalid": [], "warnings": [] }, { "truncated": true, "omittedCount": 2, "originalCount": 6 } ]Verify advertised artifacts
No valid skill artifacts were available to verify.
Validate skill content
For skill-md artifacts, include valid YAML frontmatter with name and description followed by Markdown. For archives, include a safe root SKILL.md and no unsafe paths.
Review skill artifact security
Do not publish secrets or prompt-injection instructions in skill artifacts. Treat scripts, archives, and cross-origin artifacts as software supply-chain surfaces.
Evidence log6 steps · 29 lines
Discover Agent Skills index [warning]! Agent Skills index was found only at the legacy /.well-known/skills/index.json path.INFODiscover Agent Skills indexINFOTry Agent Skills index paths in priority order paths=["/.well-known/agent-skills/index.json","/.well-known/skills/index.json"]WARNAgent Skills index candidate was not usable path="/.well-known/agent-skills/index.json" url="https://backstage.io/.well-known/agent-skills/index.json" statusCode=404PASSFetched Agent Skills index candidate path="/.well-known/skills/index.json" url="https://backstage.io/.well-known/skills/index.json" statusCode=200 contentType="application/json; charset=utf-8" bytes=2197 selected="selected"WARNAgent Skills index was found only at the legacy /.well-known/skills/index.json path.Validate discovery index schema [fail]! Agent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.INFOValidate discovery index schemaINFOParse Agent Skills index JSON validJson=true contentTypeCompatible=trueFAILCompare $schema URI expected="https://schemas.agentskills.io/discovery/0.2.0/schema.json"FAILCompare top-level schema issue count actual=1 expected=0FAILCompare unknown top-level field count actual=0 expected=0FAILAgent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.Validate skill entries [fail]! One or more Agent Skills entries have invalid required fields.INFOValidate skill entriesFAILCompare advertised skill count actual=6 expected="> 0"FAILCompare valid skill entry count actual=0 expected="same as advertised skill count"FAILInvalid skill entry skill={"index":0,"valid":false,"name":"mui-to-bui-migration","type":"","description":"Migrate Backstage plugins from Material-UI (MUI) to Backstage UI (BUI). Use this skill when migrating components, updating imports, replacing styling patterns, or converting MUI components to their BUI equivalents.","url":"","digest":"","resolvedUrl":"https://backstage.io/.well-known/skills/index.json","originClass":"same-origin","missing":["type","url","digest"],"invalid":[],"warnings":[]}FAILInvalid skill entry skill={"index":1,"valid":false,"name":"app-frontend-system-migration","type":"","description":"Migrate a Backstage app from the old frontend system to the new one. Use this skill when converting an app to use the new extension-based frontend system, including the hybrid migration phase and the full migration of routes, sidebar, plugins, APIs, themes, and other app-level concerns.","url":"","digest":"","resolvedUrl":"https://backstage.io/.well-known/skills/index.json","originClass":"same-origin","missing":["type","url","digest"],"invalid":[],"warnings":[]}FAILInvalid skill entry skill={"index":2,"valid":false,"name":"plugin-new-frontend-system-support","type":"","description":"Add new frontend system support to an existing Backstage plugin while keeping the old system working. Use this skill for published or shared plugins that need to work in both old and new frontend system apps.","url":"","digest":"","resolvedUrl":"https://backstage.io/.well-known/skills/index.json","originClass":"same-origin","missing":["type","url","digest"],"invalid":[],"warnings":[]}FAILInvalid skill entry skill={"index":3,"valid":false,"name":"plugin-full-frontend-system-migration","type":"","description":"Fully migrate a Backstage plugin to the new frontend system, dropping all old system support. Use this skill for internal plugins that only need to run in a single app, or when you are ready to remove backward compatibility entirely.","url":"","digest":"","resolvedUrl":"https://backstage.io/.well-known/skills/index.json","originClass":"same-origin","missing":["type","url","digest"],"invalid":[],"warnings":[]}FAILInvalid skill entry skill={"index":4,"valid":false,"name":"plugin-analytics-instrumentation","type":"","description":"Instrument a Backstage frontend plugin with analytics events using the Backstage Analytics API. Use this skill when adding, reviewing, or extending event capture (captureEvent, AnalyticsContext) in plugin components, deciding whether an interaction warrants an event, or writing tests for analytics behavior.","url":"","digest":"","resolvedUrl":"https://backstage.io/.well-known/skills/index.json","originClass":"same-origin","missing":["type","url","digest"],"invalid":[],"warnings":[]}FAILInvalid skill entry skill={"index":5,"valid":false,"name":"onboard-to-openapi-server","type":"","description":"Use this skill when the user wants to migrate an existing Backstage backend plugin's hand-written Express router to the typed OpenAPI tooling. Optionally, can also add typed client generation and migrate router tests to the OpenAPI test wrapper.","url":"","digest":"","resolvedUrl":"https://backstage.io/.well-known/skills/index.json","originClass":"same-origin","missing":["type","url","digest"],"invalid":[],"warnings":[]}FAILOne or more Agent Skills entries have invalid required fields.Verify advertised artifacts [warning]! No valid skill artifacts were available to verify.INFOVerify advertised artifactsWARNCompare artifact fetch count actual=0 expected="> 0"WARNNo valid skill artifacts were available to verify.Validate skill content [warning]INFOValidate skill contentWARNAgent Skills step completed with warningsReview skill artifact security [warning]INFOReview skill artifact securityWARNCompare security finding count actual=0 expected=0WARNAgent Skills step completed with warnings
Security & TrustSecurity & TrustEstablished
Content-Security-Policy
Content-Security-Policy failed at "Find enforcing CSP delivery".
60 Fail
Security & TrustSecurity & TrustEstablished
Content-Security-Policy
Content-Security-Policy failed at "Find enforcing CSP delivery".
Needs attention
Content-Security-Policy
Issue
Applicable HTML response is missing an enforcing Content-Security-Policy header.
Details
Why it matters
Content Security Policy reduces the impact of injection bugs by limiting where scripts, styles, frames, forms, and other browser resources can load or execute.
Check name
Content-Security-Policy
Score
40/100
Status
fail
Category
Security & Trust
Maturity
Established
Goal
Constrain browser resource loading and script execution with an enforcing Content-Security-Policy header.
Result
Content-Security-Policy failed at "Find enforcing CSP delivery".
Validation steps
Find enforcing CSP delivery
Applicable HTML response is missing an enforcing Content-Security-Policy header.
Enforcing Content-Security-Policy header is missing
Evidence log1 step · 4 lines
Find enforcing CSP delivery [fail]! Applicable HTML response is missing an enforcing Content-Security-Policy header.INFOFind enforcing CSP deliveryINFORead CSP delivery headers enforcingHeader="missing" reportOnlyHeader="missing" metaPolicyCount=0 legacyHeadersPresent=[]FAILRequire enforcing Content-Security-Policy header actual="missing" expected="present" issue="Applicable HTML response is missing an enforcing Content-Security-Policy header."FAILApplicable HTML response is missing an enforcing Content-Security-Policy header.Sign in to see 39 other issues and the full report
Create a free account to unlock every issue, evidence details, exports, and higher free limits.
Fix with MCP or CLI
Use this report as the handoff into remediation. Generate a coding-agent prompt with the failing checks attached, or jump to the MCP and CLI setup docs before your next rescan.
Score history