Export Report
OVERALL SCORE
Level 4, Mostly Ready
- AI Discoverability 84 out of 100
- Agent Ease of Use 63 out of 100
- Security & Trust 45 out of 100
- GEO, AIO and AEO 55 out of 100
- SEO 92 out of 100
- Performance 99 out of 100
- Accessibility 97 out of 100
What AI sees of your website
Code Time — Coding Analytics for VS Code & JetBrains
Automatically track how long you spend coding, visualise habits by language and project, and export your raw editor data. Free plugins for VS Code, Cursor, Windsurf and every JetBrains IDE.
Next step
Turn this report into a fix workflow
3 failed checks are ready to move into MCP or CLI remediation. Generate a repair prompt, connect the scanner to your coding agent, or open the integration docs before your next rescan.
| Metric | Score | Status | Passed | Failed | Warning | Evidence |
|---|---|---|---|---|---|---|
| AI Discoverability | 84 | Mostly ready | 48 | 0 | 0 | |
| Discoverability | 100 | Strong | 10 | 0 | 0 | |
| Content Readiness | 85 | Mostly ready | 28 | 0 | 0 | |
| Bot Access Control | 71 | Needs work | 10 | 0 | 0 | |
| Agent Ease of Use | 63 | Needs work | 29 | 6 | 8 | View details |
| API | 88 | Mostly ready | 13 | 0 | 0 | |
| Auth | 50 | Needs work | 6 | 0 | 0 | |
| MCP | 40 | Priority fix | 3 | 0 | 0 | |
| Skill Discovery | 43 | Priority fix | 4 | 6 | 8 | View details |
| Google Agentic Browsing | 100 | Strong | 3 | 0 | 0 | |
| GEO, AIO and AEO | 55 | Needs work | 7 | 0 | 0 | |
| GEO Readiness | Not Applicable | Not Applicable | 2 | 0 | 0 | |
| AIO Readiness | Not Applicable | Not Applicable | 3 | 0 | 0 | |
| AEO Readiness | Not Applicable | Not Applicable | 2 | 0 | 0 | |
| SEO | 92 | Strong | 9 | 0 | 0 | |
| SEO | 92 | Strong | 9 | 0 | 0 | |
| Security & Trust | 45 | Priority fix | 7 | 0 | 0 | |
| Security & Trust | 45 | Priority fix | 7 | 0 | 0 | |
| Performance | 99 | Strong | 18 | 0 | 0 | |
| Performance | 99 | Strong | 18 | 0 | 0 |
Prioritized recommendations
Issues ranked by score impact
3 items need attention
Agent Ease of UseSkill DiscoveryEmerging recommendation
agents.json
agents.json failed at "Validate Wildcard schema shape".
25 Fail
Agent Ease of UseSkill DiscoveryEmerging recommendation
agents.json
agents.json failed at "Validate Wildcard schema shape".
Needs attention
agents.json
Issue
agents.json response is not valid JSON.
Details
Why it matters
Wildcard agents.json gives agents workflow-level context beyond plain OpenAPI, including flows, links, examples, and API action structure. It is an emerging OpenAPI-adjacent proposal, so scanners should validate the contract shape without treating it as an A2A or IETF standard.
Check name
agents.json
Score
25/100
Status
fail
Category
Skill Discovery
Maturity
Emerging recommendation
Goal
Publish a Wildcard-style agents.json file so agents can discover OpenAPI-backed workflows, links, examples, and authentication requirements.
Result
agents.json failed at "Validate Wildcard schema shape".
Validation steps
Discover agents.json
agents.json was found only at the fallback /agents.json path.
agents.json is missing or only available at a fallback path
Validate Wildcard schema shape
agents.json response is not valid JSON.
agents.json schema shape is invalid or incomplete
Validate API actions
Wildcard agents.json must include valid OpenAPI-derived action or operation definitions.
agents.json action definitions are invalid or missing
Validate flows and links
No executable flows were found.
agents.json flows or links are invalid
Review examples and LLM usability
Examples or descriptions are too thin for reliable agent argument generation.
agents.json examples or descriptions need improvement
Evidence log5 steps · 23 lines
Discover agents.json [warning]! agents.json was found only at the fallback /agents.json path.INFODiscover agents.jsonINFOTry agents.json discovery paths in priority order paths=["/.well-known/agents.json","/agents.json"]WARNagents.json candidate path did not return a usable contract path="/.well-known/agents.json" statusCode=404 contentType="text/html;charset=utf-8"PASSFound an agents.json candidate path="/agents.json" statusCode=200 contentType="text/html;charset=utf-8" bytes=54986WARNSelected fallback agents.json location path="/agents.json" requestedUrl="https://codetime.dev/agents.json"WARNagents.json was found only at the fallback /agents.json path.Validate Wildcard schema shape [fail]! agents.json response is not valid JSON.INFOValidate Wildcard schema shapeINFOParse agents.json and classify contract shape shape="unknown"FAILCompare contract shape actual="unknown" expected="wildcard"FAILCompare missing required schema fields actual="none" expected="none"FAILCompare Content-Type with JSON expectation actual=false expected=trueFAILagents.json response is not valid JSON.Validate API actions [fail]! Wildcard agents.json must include valid OpenAPI-derived action or operation definitions.INFOValidate API actionsFAILCompare API action count actual=0 expected="> 0"FAILCompare invalid action definitions actual=0 expected=0FAILWildcard agents.json must include valid OpenAPI-derived action or operation definitions.Validate flows and links [fail]! No executable flows were found.INFOValidate flows and linksFAILCompare workflow flow count actual=0 expected="> 0"FAILCompare operation link issues actual=0 expected=0FAILNo executable flows were found.Review examples and LLM usability [warning]! Examples or descriptions are too thin for reliable agent argument generation.INFOReview examples and LLM usabilityWARNCompare usable example count actual=0 expected="> 0 when actions are present"WARNExamples or descriptions are too thin for reliable agent argument generation.
Agent Ease of UseSkill DiscoveryEmerging recommendation
A2A Agent Card
A2A Agent Card failed at "Detect A2A card version".
20 Fail
Agent Ease of UseSkill DiscoveryEmerging recommendation
A2A Agent Card
A2A Agent Card failed at "Detect A2A card version".
Needs attention
A2A Agent Card
Issue
The discovered JSON document does not match a supported A2A Agent Card version family.
Details
Why it matters
A2A Agent Cards provide protocol-specific discovery for agent identity, skills, input and output modes, transport bindings, capabilities, and security requirements. Legacy A2A also used /.well-known/agent.json, so scanners must classify the card shape before reporting readiness.
Check name
A2A Agent Card
Score
39/100
Status
fail
Category
Skill Discovery
Maturity
Emerging recommendation
Goal
Publish a version-appropriate A2A Agent Card so A2A-compatible clients can discover agent skills and invoke the declared endpoint safely.
Result
A2A Agent Card failed at "Detect A2A card version".
Validation steps
Discover A2A Agent Card
The A2A Agent Card was found at a legacy or fallback path.
A2A Agent Card is missing or discovered at a non-canonical path
Detect A2A card version
The discovered JSON document does not match a supported A2A Agent Card version family.
A2A Agent Card version cannot be classified cleanly
Validate version-specific card shape
A2A Agent Card response is not valid JSON.
A2A Agent Card shape is invalid for its version
Validate HTTP delivery
The card was parseable JSON but was not served with a JSON-compatible content type.
A2A Agent Card HTTP delivery is not standards-aligned
Probe same-origin A2A endpoint
A2A endpoint probing was skipped because the endpoint was cross-origin, unavailable from the card, or uses an unsupported binding.
Advertised same-origin A2A endpoint did not answer a safe probe
Evidence log5 steps · 26 lines
Discover A2A Agent Card [warning]! The A2A Agent Card was found at a legacy or fallback path.INFODiscover A2A Agent CardINFOTry A2A discovery paths in priority order paths=["/.well-known/agent-card.json","/.well-known/agent.json","/agent-card.json","/.well-known/a2a/agent-card.json"]WARNA2A candidate path did not return a usable card path="/.well-known/agent-card.json" statusCode=404 contentType="text/html;charset=utf-8"WARNA2A candidate path did not return a usable card path="/.well-known/agent.json" statusCode=404 contentType="text/html;charset=utf-8"PASSFound an A2A candidate path="/agent-card.json" statusCode=200 contentType="text/html;charset=utf-8" bytes=55061WARNA2A candidate path did not return a usable card path="/.well-known/a2a/agent-card.json" statusCode=404 contentType="text/html;charset=utf-8"WARNSelected non-canonical A2A Agent Card path="/agent-card.json" pathClass="fallback" requestedUrl="https://codetime.dev/agent-card.json"WARNThe A2A Agent Card was found at a legacy or fallback path.Detect A2A card version [fail]! The discovered JSON document does not match a supported A2A Agent Card version family.INFODetect A2A card versionINFORead version indicators from the card detectionEvidence=[]FAILCompare detected A2A version family actual="unknown" expected="v0.1, v0.2, v0.3, or v1"FAILThe discovered JSON document does not match a supported A2A Agent Card version family.Validate version-specific card shape [fail]! A2A Agent Card response is not valid JSON.INFOValidate version-specific card shapeFAILCompare missing required card fields actual="none" expected="none"FAILCheck every declared A2A skill has required name, description, and endpoint fields actual=0 expected=0 invalidSkills=[]INFOReview declared endpoint interfaces interfaces=[]FAILA2A Agent Card response is not valid JSON.Validate HTTP delivery [warning]! The card was parseable JSON but was not served with a JSON-compatible content type.INFOValidate HTTP deliveryWARNCompare card Content-Type with JSON expectation actual="text/html;charset=utf-8" expected="application/json or +json"INFOReview selected discovery path path="/agent-card.json" pathClass="fallback"WARNHTTP delivery/path warning warning="card was found only at a non-standard fallback path"WARNThe card was parseable JSON but was not served with a JSON-compatible content type.Probe same-origin A2A endpoint [warning]! A2A endpoint probing was skipped because the endpoint was cross-origin, unavailable from the card, or uses an unsupported binding.INFOProbe same-origin A2A endpointINFOProbe same-origin A2A endpoint when scanner policy allows itSKIPSkipped endpoint probe reason="No valid A2A card was available to probe."WARNA2A endpoint probing was skipped because the endpoint was cross-origin, unavailable from the card, or uses an unsupported binding.
Agent Ease of UseSkill DiscoveryEmerging recommendation
Agent Skills index
Agent Skills index failed at "Validate discovery index schema".
14 Fail
Agent Ease of UseSkill DiscoveryEmerging recommendation
Agent Skills index
Agent Skills index failed at "Validate discovery index schema".
Needs attention
Agent Skills index
Issue
Agent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.
Details
Why it matters
An Agent Skills index lets agents discover task-specific instructions through a small trusted index, then verify and load only the skill artifacts they need.
Check name
Agent Skills index
Score
58/100
Status
fail
Category
Skill Discovery
Maturity
Emerging recommendation
Goal
Publish an Agent Skills discovery index that advertises digest-pinned SKILL.md or archive artifacts.
Result
Agent Skills index failed at "Validate discovery index schema".
Validation steps
Validate discovery index schema
Agent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.
Agent Skills discovery index schema is invalid
Top-level issues
- $schema must be https://schemas.agentskills.io/discovery/0.2.0/schema.json
Skill warnings
[ { "index": 0, "valid": true, "name": "codetime", "type": "skill-md", "description": "Query a developer's coding-time analytics from Code Time.", "url": "https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md", "digest": "sha256:e22073cabc6105c9632ab3f0557b5c5f0f1a06f836f80866ddbfdd0c6acf6786", "resolvedUrl": "https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md", "originClass": "same-origin", "missing": [], "invalid": [], "warnings": [ "description should explain when to use the skill" ] } ]Validate skill entries
One or more Agent Skills entries have quality or trust warnings.
One or more skill entries are invalid
Skill entry findings
[ { "index": 0, "valid": true, "name": "codetime", "type": "skill-md", "description": "Query a developer's coding-time analytics from Code Time.", "url": "https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md", "digest": "sha256:e22073cabc6105c9632ab3f0557b5c5f0f1a06f836f80866ddbfdd0c6acf6786", "resolvedUrl": "https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md", "originClass": "same-origin", "missing": [], "invalid": [], "warnings": [ "description should explain when to use the skill" ] } ]Validate skill content
description does not clearly state when an agent should activate the skill.
Skill artifact content is invalid
Skill content findings
- description does not clearly state when an agent should activate the skill.
- SKILL.md body lacks obvious workflow, input/output, example, or validation guidance.
Review skill artifact security
SKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask).
Skill artifacts contain security findings
Agent Skills security findings
- SKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask).
Evidence log4 steps · 20 lines
Validate discovery index schema [fail]! Agent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.INFOValidate discovery index schemaINFOParse Agent Skills index JSON validJson=true contentTypeCompatible=trueFAILCompare $schema URI actual="https://agentskills.io/schemas/index/v0.2.0.json" expected="https://schemas.agentskills.io/discovery/0.2.0/schema.json"FAILCompare top-level schema issue count actual=1 expected=0WARNCompare unknown top-level field count actual=2 expected=0FAILAgent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.Validate skill entries [warning]! One or more Agent Skills entries have quality or trust warnings.INFOValidate skill entriesWARNCompare advertised skill count actual=1 expected="> 0"WARNCompare valid skill entry count actual=1 expected="same as advertised skill count"WARNSkill entry warning skill={"index":0,"valid":true,"name":"codetime","type":"skill-md","description":"Query a developer's coding-time analytics from Code Time.","url":"https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md","digest":"sha256:e22073cabc6105c9632ab3f0557b5c5f0f1a06f836f80866ddbfdd0c6acf6786","resolvedUrl":"https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md","originClass":"same-origin","missing":[],"invalid":[],"warnings":["description should explain when to use the skill"]}WARNOne or more Agent Skills entries have quality or trust warnings.Validate skill content [warning]! description does not clearly state when an agent should activate the skill.INFOValidate skill contentWARNCompare skill artifact content failures actual=0 expected=0 name="codetime" type="skill-md" url="https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md"WARNSkill content validation warning name="codetime" warning="description does not clearly state when an agent should activate the skill."WARNSkill content validation warning name="codetime" warning="SKILL.md body lacks obvious workflow, input/output, example, or validation guidance."WARNdescription does not clearly state when an agent should activate the skill.Review skill artifact security [warning]! SKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask).INFOReview skill artifact securityFAILCompare security finding count actual=1 expected=0WARNAgent Skills artifact security warning finding="SKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask)."WARNSKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask).
Sign in to see 30 other issues and the full report
Create a free account to unlock every issue, evidence details, exports, and higher free limits.
Fix with MCP or CLI
Use this report as the handoff into remediation. Generate a coding-agent prompt with the failing checks attached, or jump to the MCP and CLI setup docs before your next rescan.
Score history