AX Rush

Preparación para AI de beardbrand.com

Informe del sitio: 1 página medida. Valoración general: Aceptable.

Puntuación del sitio · beardbrand.com

Combina el origen y 1 página medida. El reporte de abajo detalla solamente la página de origen.

beardbrand.com

Aceptable · 42 comprobaciones correctas, 34 advertencias, 9 fallos · 9,6 s

Comparte este informe con tu equipo técnico

Lleva los hallazgos a quienes pueden resolverlos. Copia un resumen listo para enviar por Slack, Teams o revisar en la próxima reunión.

Correo

Este informe es público. Tu equipo puede abrirlo sin una cuenta.

Contenido

49/100

¿Hay algo que un agente pueda leer?

  • Homepage does not serve Markdown via content negotiation

    Serve a Markdown representation of your pages when agents request "Accept: text/markdown". Agents like Claude Code and Cursor ask for it, and Markdown cuts token usage by roughly 80% against HTML. Cloudflare ("Markdown for Agents") and Vercel can enable this without code changes.

  • No <link rel="alternate" type="text/markdown"> fallback found on the homepage

    If you cannot enable content negotiation, advertise a Markdown version with <link rel="alternate" type="text/markdown" href="/index.md"> so agents can discover it.

  • No JSON-LD structured data found

    Add a <script type="application/ld+json"> block in your HTML <head> with schema.org structured data describing your site, organization, or person.

  • Sparse server-rendered content (13 words, 88 chars)

    Render at least the main page content server-side. Many AI crawlers (GPTBot, ClaudeBot, CCBot) do not execute JavaScript and will see only the static HTML.

  • Text-to-markup ratio is healthy (17.0% of structural markup)

  • No semantic HTML landmarks found

    Replace generic <div> structures with semantic tags: <main>, <article>, <header>, <nav>, <footer>. Agents use these to identify the primary content region.

  • Single <h1> heading: "Your connection needs to be verified before you can proceed"

  • <title> length 28 chars: "Verifying your connection..."

  • <meta name="description"> is missing

    Add <meta name="description" content="..."> in <head> with a 70-160 character summary. Agents use this as the canonical short description.

  • No <link rel="canonical"> found

    Add <link rel="canonical" href="https://your-site.com/page"> so agents have an unambiguous URL to cite even when crawled via a redirect or query-string variant.

  • <html lang="en">

  • UTF-8 charset declared

  • Viewport meta present: "width=device-width, initial-scale=1.0"

  • 1 obstacle(s) on the entry page

    A CAPTCHA or a meta refresh on the landing page stops an agent before it reaches any content. If bot protection is needed, apply it to the actions that need it, not to reading a page.

  • Method note: this reads markup, not a rendered accessibility tree

Acceso

86/100

¿Un agente puede siquiera llegar al sitio?

  • A missing page redirects (301) instead of returning 404

    A redirect on a nonexistent path hides the error. Return 404 or 410 so a client can tell the difference.

  • Homepage answers after 1 redirect

  • HEAD requests are supported

  • Content-Type: text/html with charset

  • Site is served over HTTPS

  • HTTP requests redirect to HTTPS

  • HSTS max-age is short (7889238s = ~91 days)

    Use at least max-age=15768000 (~6 months); preload list submission requires max-age=31536000 (1 year).

  • HSTS does not include subdomains

    Add includeSubDomains to apply HSTS across api., docs., etc. Required for preload list submission.

  • HSTS lacks the preload directive

    Add preload (and ensure max-age >= 31536000 + includeSubDomains) and submit the domain at https://hstspreload.org for browser-built-in HTTPS enforcement.

  • ChatGPT-User receives a Cloudflare challenge instead of the page

    Challenge pages require running JavaScript. Crawlers that only fetch HTML — which is most of them — never get past one, so the page is effectively unavailable to them even though nothing is "blocked". Add a bot-management exception for verified AI crawlers. ax-audit sends this user agent from its own network without a Web Bot Auth signature, so an edge that verifies crawlers by IP range or signature will reject the probe while admitting the real crawler. Confirm against your WAF logs before changing any rule.

  • 1 crawler probe(s) could not be settled from outside

    ax-audit sends this user agent from its own network without a Web Bot Auth signature, so an edge that verifies crawlers by IP range or signature will reject the probe while admitting the real crawler. Confirm against your WAF logs before changing any rule.

  • Homepage is indexable

  • No directive restricts how AI assistants may use this page

Descubrimiento

79/100

¿Un agente encuentra lo que publicas?

  • No AI meta tags (ai:*) found

    Add AI meta tags to your HTML <head>: <meta name="ai:summary" content="Brief description">, <meta name="ai:content_type" content="website">, <meta name="ai:author" content="Your Name">.

  • No rel="alternate" link to llms.txt in HTML

    Add to your <head>: <link rel="alternate" type="text/plain" href="/llms.txt" title="LLM-optimized content">

  • No rel="alternate" link to the Agent Card in HTML

    Add to your <head>: <link rel="alternate" type="application/json" href="/.well-known/agent-card.json" title="Agent Card">

  • No rel="me" identity links found

    Add rel="me" links to verify your identity across platforms: <link rel="me" href="https://github.com/yourname">, <link rel="me" href="https://twitter.com/yourname">.

  • No OpenGraph meta tags found

    Add at minimum og:title, og:description, og:url, og:type, and og:image. Agents and link previews depend on these.

  • No Twitter Card meta tags found

    Add twitter:card, twitter:title, twitter:description, and twitter:image so X / Threads / Bluesky / Discord agents render link previews correctly.

  • /robots.txt exists

  • 1/12 core AI crawlers configured

    Add explicit User-agent entries for the missing crawlers with Allow: / for each one.

  • 1 AI crawler(s) explicitly blocked

    These crawlers have "Disallow: /" rules. If you want AI agents to access your site, change to "Allow: /" for each blocked crawler.

  • 1 training crawler(s) blocked — recorded as a deliberate policy choice

  • Sitemap directive present

  • No Content-Signal directive found (optional)

    Declare how crawlers may use your content after access with the Content Signals Policy, e.g.: Content-Signal: search=yes, ai-train=no. Known signals: search, ai-input, ai-train, plus the optional use=immediate|reference|full. Generate yours at contentsignals.org.

  • 1/57 known AI crawlers have explicit rules

    Add explicit User-agent entries for more AI crawlers to maximize discoverability.

  • Missing critical header: Strict-Transport-Security

    Add the Strict-Transport-Security response header to your server configuration. This is a critical security header.

  • 5/7 security headers present

  • No Link header for AI discovery (llms.txt, Agent Card)

    Add a Link response header pointing to your AI discovery files: Link: </llms.txt>; rel="alternate"; type="text/plain", </.well-known/agent-card.json>; rel="alternate"; type="application/json"

  • No machine-readable discovery relations beyond llms.txt and the Agent Card

    Advertise what you publish with Link relations so agents stop guessing paths. Add the ones that apply, for example: Link: </llms.txt>; rel="describedby", </.well-known/api-catalog>; rel="api-catalog". Informational in 3.x: this does not affect your score.

  • /llms.txt exists

  • /llms.txt Content-Type OK (text/markdown)

  • H1 heading: "Agent Instructions — Beardbrand"

  • No blockquote description found ("> ...")

    Add a blockquote description after the H1 heading, e.g.: > A brief summary of your site for AI agents.

  • 5 section heading(s) found

  • 5 link(s) found

  • /llms-full.txt also available (bonus)

  • No rel="describedby" link to llms.txt

    llms.txt v2 uses this relation so a page can name the file that covers it. Add <link rel="describedby" href="/llms.txt"> or the equivalent Link header, so an agent that landed on a deep page does not have to guess that an index exists.

  • 2 duplicate link(s) in llms.txt

    Each URL should appear once. Duplicates spend an agent’s budget re-reading what it already has.

  • 3 sampled link(s) resolve

  • 1 sampled link(s) redirect

    Point llms.txt at the final URL. Each redirect is a round trip the agent pays for on every visit.

  • No per-page Markdown mirror found

    llms.txt v2 documents appending .md to a URL for its Markdown version. The index tells an agent which pages exist; the mirrors are what make reading them cheap.

  • Consumer note: llms.txt is read by coding agents, not by search

  • Sitemap located: https://www.beardbrand.com/sitemap.xml

  • Content-Type is XML (application/xml)

  • Sitemap-index references 5 child sitemap(s)

  • 3/3 sample child sitemap(s) reachable

  • Sample yielded 111 URL(s) across 3 child(ren)

  • Newest <lastmod> is recent (0 day(s) ago)

Protocolos

9/100

¿Qué puede invocar un agente?

  • /.well-known/agent-card.json not found

    This site offers something an agent could call, but nothing tells an agent what. Publish an A2A Agent Card at /.well-known/agent-card.json. A minimal 1.0 card needs name, description, version, capabilities, supportedInterfaces, defaultInputModes, defaultOutputModes and skills. Spec: https://a2a-protocol.org/latest/specification/

  • API surface present but no machine-readable description found

    The API exists; nothing describes it in a form an agent can read, so using it requires a human to read your documentation first. Serve an OpenAPI description at /openapi.json and advertise it with Link: </openapi.json>; rel="service-desc". For several APIs, publish an RFC 9727 catalog.

  • No agent resource catalog found

    A catalog is one document listing everything an agent can call here — agent cards, MCP servers, APIs, skills — so a client stops probing four conventions to find out. Worth publishing once you have more than one of those. Informational: both ai-catalog.json and ard.json are still drafts, so this never affects your score.

  • No Agent Skills published

    This site has documentation, so it has procedures worth teaching. A skill is a SKILL.md an agent installs and follows: setup steps, argument shapes, the mistakes to avoid. Publish one per task at /.well-known/agent-skills/{name}/SKILL.md and list them in /.well-known/agent-skills/index.json.

  • UCP profile published at /.well-known/ucp

  • UCP version 2026-08-25

  • 1 commerce service(s) declared: dev.ucp.shopping

  • 2 declared schema URL(s) resolve

  • UCP profile declares no payment handlers

    Without a payment handler an agent can read your catalog but cannot complete a purchase. Declare the handlers you accept.

  • UCP profile declares no signing keys

    Publish the public keys an agent uses to verify your responses. Money is moving; identity should not rest on DNS alone.

  • Protected-resource metadata published (RFC 9728)

  • 2 authorization server(s) named

  • Authorization server https://account.beardbrand.com publishes discovery metadata

  • PKCE with S256 supported

  • No automated client registration

    Without dynamic registration or Client ID Metadata Documents, every new agent needs a human to register it first. That is a queue, not an integration.

  • No MCP server — MCP discovery does not apply to this site

  • No forms and no WebMCP code — nothing here for an agent to invoke as a tool

Política

18/100

¿Qué derechos de uso están declarados?

  • /.well-known/security.txt not found

    Create a /.well-known/security.txt file per RFC 9116. At minimum, include Contact: and Expires: fields. See https://securitytxt.org/ for a generator.

  • No RSL license discovery found

    Declare machine-readable licensing terms for your content with Really Simple Licensing. Add to robots.txt: License: https://your-site.com/license.xml — then publish the RSL document. See https://rslstandard.org.

  • No machine-readable usage policy declared

    State your terms where they can be read without a lawyer. The lowest-effort option is a Content-Signal line in robots.txt: Content-Signal: search=yes, ai-input=yes, ai-train=no. Absence is neutral, not permission — but it also gives you nothing to point at.

Detalles técnicos

Motor
axrush-engine@6.0.0
Escaneado
10 sept 2026, 19:01:53 UTC
Duración
9625 ms
Checks ejecutados
26

Convierte este informe en mejoras continuas

Dale a tu equipo informes completos, correcciones priorizadas y seguimiento para mantener las mejoras después de cada lanzamiento.

Leer este reporte por la API o el servidor MCP