CanAgentUse tools

UCP Suite

Validate Universal Commerce Protocol discovery, then test product search, carts, checkout links, and merchant handoff flows.

MCP Playground

Connect to remote MCP servers, inspect tools and resources, test prompts, auth, headers, notifications, and JSON-RPC responses.

A2A Playground

Inspect Agent Cards, validate advertised endpoints, and prepare safe requests for agent-to-agent workflows.

Agent Website Viewer

Enter a public URL and see the roles, names, landmarks, controls, and blockers that shape how AI agents understand the page.

SCANNED
Jul 26, 2026, 8:06 PM
VISIBILITY
Public
Rescan Report
Share Report
Copy Report Link
Export Report
75/100

OVERALL SCORE

Level 4, Mostly Ready

Good readiness for AI agents
AIDiscoverability84%Agent Easeof Use63%Security& Trust45%GEO, AIO, AEO55%SEO92%Performance99%Accessibility97%
  • AI Discoverability 84 out of 100
  • Agent Ease of Use 63 out of 100
  • Security & Trust 45 out of 100
  • GEO, AIO and AEO 55 out of 100
  • SEO 92 out of 100
  • Performance 99 out of 100
  • Accessibility 97 out of 100

CAPTURED SCREENSHOT

Captured website desktop screenshot

What AI sees of your website

Code Time — Coding Analytics for VS Code & JetBrains favicon

Code Time — Coding Analytics for VS Code & JetBrains

Automatically track how long you spend coding, visualise habits by language and project, and export your raw editor data. Free plugins for VS Code, Cursor, Windsurf and every JetBrains IDE.

Open Agent View

Next step

Turn this report into a fix workflow

3 failed checks are ready to move into MCP or CLI remediation. Generate a repair prompt, connect the scanner to your coding agent, or open the integration docs before your next rescan.

Fix with MCP / CLI
Detailed report scores grouped by capability area
MetricScoreStatusPassedFailedWarningEvidence
AI Discoverability
84
Mostly ready4800
Discoverability
100
Strong1000
Content Readiness
85
Mostly ready2800
Bot Access Control
71
Needs work1000
Agent Ease of Use
63
Needs work2968View details
API
88
Mostly ready1300
Auth
50
Needs work600
MCP
40
Priority fix300
Skill Discovery
43
Priority fix468View details
Google Agentic Browsing
100
Strong300
GEO, AIO and AEO
55
Needs work700
GEO Readiness
Not Applicable
Not Applicable200
AIO Readiness
Not Applicable
Not Applicable300
AEO Readiness
Not Applicable
Not Applicable200
SEO
92
Strong900
SEO
92
Strong900
Security & Trust
45
Priority fix700
Security & Trust
45
Priority fix700
Performance
99
Strong1800
Performance
99
Strong1800

Prioritized recommendations

Issues ranked by score impact

3 items need attention

Agent Ease of UseSkill DiscoveryEmerging recommendation

agents.json

agents.json failed at "Validate Wildcard schema shape".

25 Fail

Needs attention

agents.json

Failed check
01

Issue

agents.json response is not valid JSON.

Details

02

Why it matters

Wildcard agents.json gives agents workflow-level context beyond plain OpenAPI, including flows, links, examples, and API action structure. It is an emerging OpenAPI-adjacent proposal, so scanners should validate the contract shape without treating it as an A2A or IETF standard.

Check name

agents.json

Score

25/100

Status

fail

Category

Skill Discovery

Maturity

Emerging recommendation

Goal

Publish a Wildcard-style agents.json file so agents can discover OpenAPI-backed workflows, links, examples, and authentication requirements.

Result

agents.json failed at "Validate Wildcard schema shape".

Validation steps

  1. Discover agents.json

    agents.json was found only at the fallback /agents.json path.

    agents.json is missing or only available at a fallback path
  2. Validate Wildcard schema shape

    agents.json response is not valid JSON.

    agents.json schema shape is invalid or incomplete
  3. Validate API actions

    Wildcard agents.json must include valid OpenAPI-derived action or operation definitions.

    agents.json action definitions are invalid or missing
  4. Validate flows and links

    No executable flows were found.

    agents.json flows or links are invalid
  5. Review examples and LLM usability

    Examples or descriptions are too thin for reliable agent argument generation.

    agents.json examples or descriptions need improvement
Evidence log5 steps · 23 lines
Discover agents.json [warning]! agents.json was found only at the fallback /agents.json path.INFODiscover agents.jsonINFOTry agents.json discovery paths in priority order paths=["/.well-known/agents.json","/agents.json"]WARNagents.json candidate path did not return a usable contract path="/.well-known/agents.json" statusCode=404 contentType="text/html;charset=utf-8"PASSFound an agents.json candidate path="/agents.json" statusCode=200 contentType="text/html;charset=utf-8" bytes=54986WARNSelected fallback agents.json location path="/agents.json" requestedUrl="https://codetime.dev/agents.json"WARNagents.json was found only at the fallback /agents.json path.Validate Wildcard schema shape [fail]! agents.json response is not valid JSON.INFOValidate Wildcard schema shapeINFOParse agents.json and classify contract shape shape="unknown"FAILCompare contract shape actual="unknown" expected="wildcard"FAILCompare missing required schema fields actual="none" expected="none"FAILCompare Content-Type with JSON expectation actual=false expected=trueFAILagents.json response is not valid JSON.Validate API actions [fail]! Wildcard agents.json must include valid OpenAPI-derived action or operation definitions.INFOValidate API actionsFAILCompare API action count actual=0 expected="> 0"FAILCompare invalid action definitions actual=0 expected=0FAILWildcard agents.json must include valid OpenAPI-derived action or operation definitions.Validate flows and links [fail]! No executable flows were found.INFOValidate flows and linksFAILCompare workflow flow count actual=0 expected="> 0"FAILCompare operation link issues actual=0 expected=0FAILNo executable flows were found.Review examples and LLM usability [warning]! Examples or descriptions are too thin for reliable agent argument generation.INFOReview examples and LLM usabilityWARNCompare usable example count actual=0 expected="> 0 when actions are present"WARNExamples or descriptions are too thin for reliable agent argument generation.

Agent Ease of UseSkill DiscoveryEmerging recommendation

A2A Agent Card

A2A Agent Card failed at "Detect A2A card version".

20 Fail

Needs attention

A2A Agent Card

Failed check
01

Issue

The discovered JSON document does not match a supported A2A Agent Card version family.

Details

02

Why it matters

A2A Agent Cards provide protocol-specific discovery for agent identity, skills, input and output modes, transport bindings, capabilities, and security requirements. Legacy A2A also used /.well-known/agent.json, so scanners must classify the card shape before reporting readiness.

Check name

A2A Agent Card

Score

39/100

Status

fail

Category

Skill Discovery

Maturity

Emerging recommendation

Goal

Publish a version-appropriate A2A Agent Card so A2A-compatible clients can discover agent skills and invoke the declared endpoint safely.

Result

A2A Agent Card failed at "Detect A2A card version".

Validation steps

  1. Discover A2A Agent Card

    The A2A Agent Card was found at a legacy or fallback path.

    A2A Agent Card is missing or discovered at a non-canonical path
  2. Detect A2A card version

    The discovered JSON document does not match a supported A2A Agent Card version family.

    A2A Agent Card version cannot be classified cleanly
  3. Validate version-specific card shape

    A2A Agent Card response is not valid JSON.

    A2A Agent Card shape is invalid for its version
  4. Validate HTTP delivery

    The card was parseable JSON but was not served with a JSON-compatible content type.

    A2A Agent Card HTTP delivery is not standards-aligned
  5. Probe same-origin A2A endpoint

    A2A endpoint probing was skipped because the endpoint was cross-origin, unavailable from the card, or uses an unsupported binding.

    Advertised same-origin A2A endpoint did not answer a safe probe
Evidence log5 steps · 26 lines
Discover A2A Agent Card [warning]! The A2A Agent Card was found at a legacy or fallback path.INFODiscover A2A Agent CardINFOTry A2A discovery paths in priority order paths=["/.well-known/agent-card.json","/.well-known/agent.json","/agent-card.json","/.well-known/a2a/agent-card.json"]WARNA2A candidate path did not return a usable card path="/.well-known/agent-card.json" statusCode=404 contentType="text/html;charset=utf-8"WARNA2A candidate path did not return a usable card path="/.well-known/agent.json" statusCode=404 contentType="text/html;charset=utf-8"PASSFound an A2A candidate path="/agent-card.json" statusCode=200 contentType="text/html;charset=utf-8" bytes=55061WARNA2A candidate path did not return a usable card path="/.well-known/a2a/agent-card.json" statusCode=404 contentType="text/html;charset=utf-8"WARNSelected non-canonical A2A Agent Card path="/agent-card.json" pathClass="fallback" requestedUrl="https://codetime.dev/agent-card.json"WARNThe A2A Agent Card was found at a legacy or fallback path.Detect A2A card version [fail]! The discovered JSON document does not match a supported A2A Agent Card version family.INFODetect A2A card versionINFORead version indicators from the card detectionEvidence=[]FAILCompare detected A2A version family actual="unknown" expected="v0.1, v0.2, v0.3, or v1"FAILThe discovered JSON document does not match a supported A2A Agent Card version family.Validate version-specific card shape [fail]! A2A Agent Card response is not valid JSON.INFOValidate version-specific card shapeFAILCompare missing required card fields actual="none" expected="none"FAILCheck every declared A2A skill has required name, description, and endpoint fields actual=0 expected=0 invalidSkills=[]INFOReview declared endpoint interfaces interfaces=[]FAILA2A Agent Card response is not valid JSON.Validate HTTP delivery [warning]! The card was parseable JSON but was not served with a JSON-compatible content type.INFOValidate HTTP deliveryWARNCompare card Content-Type with JSON expectation actual="text/html;charset=utf-8" expected="application/json or +json"INFOReview selected discovery path path="/agent-card.json" pathClass="fallback"WARNHTTP delivery/path warning warning="card was found only at a non-standard fallback path"WARNThe card was parseable JSON but was not served with a JSON-compatible content type.Probe same-origin A2A endpoint [warning]! A2A endpoint probing was skipped because the endpoint was cross-origin, unavailable from the card, or uses an unsupported binding.INFOProbe same-origin A2A endpointINFOProbe same-origin A2A endpoint when scanner policy allows itSKIPSkipped endpoint probe reason="No valid A2A card was available to probe."WARNA2A endpoint probing was skipped because the endpoint was cross-origin, unavailable from the card, or uses an unsupported binding.

Agent Ease of UseSkill DiscoveryEmerging recommendation

Agent Skills index

Agent Skills index failed at "Validate discovery index schema".

14 Fail

Needs attention

Agent Skills index

Failed check
01

Issue

Agent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.

Details

02

Why it matters

An Agent Skills index lets agents discover task-specific instructions through a small trusted index, then verify and load only the skill artifacts they need.

Check name

Agent Skills index

Score

58/100

Status

fail

Category

Skill Discovery

Maturity

Emerging recommendation

Goal

Publish an Agent Skills discovery index that advertises digest-pinned SKILL.md or archive artifacts.

Result

Agent Skills index failed at "Validate discovery index schema".

Validation steps

  1. Validate discovery index schema

    Agent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.

    Agent Skills discovery index schema is invalid
    Top-level issues
    • $schema must be https://schemas.agentskills.io/discovery/0.2.0/schema.json
    Skill warnings
    [
      {
        "index": 0,
        "valid": true,
        "name": "codetime",
        "type": "skill-md",
        "description": "Query a developer's coding-time analytics from Code Time.",
        "url": "https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md",
        "digest": "sha256:e22073cabc6105c9632ab3f0557b5c5f0f1a06f836f80866ddbfdd0c6acf6786",
        "resolvedUrl": "https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md",
        "originClass": "same-origin",
        "missing": [],
        "invalid": [],
        "warnings": [
          "description should explain when to use the skill"
        ]
      }
    ]
  2. Validate skill entries

    One or more Agent Skills entries have quality or trust warnings.

    One or more skill entries are invalid
    Skill entry findings
    [
      {
        "index": 0,
        "valid": true,
        "name": "codetime",
        "type": "skill-md",
        "description": "Query a developer's coding-time analytics from Code Time.",
        "url": "https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md",
        "digest": "sha256:e22073cabc6105c9632ab3f0557b5c5f0f1a06f836f80866ddbfdd0c6acf6786",
        "resolvedUrl": "https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md",
        "originClass": "same-origin",
        "missing": [],
        "invalid": [],
        "warnings": [
          "description should explain when to use the skill"
        ]
      }
    ]
  3. Validate skill content

    description does not clearly state when an agent should activate the skill.

    Skill artifact content is invalid
    Skill content findings
    • description does not clearly state when an agent should activate the skill.
    • SKILL.md body lacks obvious workflow, input/output, example, or validation guidance.
  4. Review skill artifact security

    SKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask).

    Skill artifacts contain security findings
    Agent Skills security findings
    • SKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask).
Evidence log4 steps · 20 lines
Validate discovery index schema [fail]! Agent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.INFOValidate discovery index schemaINFOParse Agent Skills index JSON validJson=true contentTypeCompatible=trueFAILCompare $schema URI actual="https://agentskills.io/schemas/index/v0.2.0.json" expected="https://schemas.agentskills.io/discovery/0.2.0/schema.json"FAILCompare top-level schema issue count actual=1 expected=0WARNCompare unknown top-level field count actual=2 expected=0FAILAgent Skills index must use $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json.Validate skill entries [warning]! One or more Agent Skills entries have quality or trust warnings.INFOValidate skill entriesWARNCompare advertised skill count actual=1 expected="> 0"WARNCompare valid skill entry count actual=1 expected="same as advertised skill count"WARNSkill entry warning skill={"index":0,"valid":true,"name":"codetime","type":"skill-md","description":"Query a developer's coding-time analytics from Code Time.","url":"https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md","digest":"sha256:e22073cabc6105c9632ab3f0557b5c5f0f1a06f836f80866ddbfdd0c6acf6786","resolvedUrl":"https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md","originClass":"same-origin","missing":[],"invalid":[],"warnings":["description should explain when to use the skill"]}WARNOne or more Agent Skills entries have quality or trust warnings.Validate skill content [warning]! description does not clearly state when an agent should activate the skill.INFOValidate skill contentWARNCompare skill artifact content failures actual=0 expected=0 name="codetime" type="skill-md" url="https://codetime.dev/.well-known/agent-skills/codetime/SKILL.md"WARNSkill content validation warning name="codetime" warning="description does not clearly state when an agent should activate the skill."WARNSkill content validation warning name="codetime" warning="SKILL.md body lacks obvious workflow, input/output, example, or validation guidance."WARNdescription does not clearly state when an agent should activate the skill.Review skill artifact security [warning]! SKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask).INFOReview skill artifact securityFAILCompare security finding count actual=1 expected=0WARNAgent Skills artifact security warning finding="SKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask)."WARNSKILL.md references external URLs; fetched content is an additional trust boundary (https://codetime.dev, https://codetime.dev/en/user/profile., https://api.codetime.dev/v3, https://api.codetime.dev/v3/docs/openapi.json, https://codetime.dev/ask).

Sign in to see 30 other issues and the full report

Create a free account to unlock every issue, evidence details, exports, and higher free limits.

Fix with MCP or CLI

Use this report as the handoff into remediation. Generate a coding-agent prompt with the failing checks attached, or jump to the MCP and CLI setup docs before your next rescan.

Fix with MCP / CLI

Score history