AX Rush

Préparation de marriott.com à l'IA

Rapport du site : 1 page mesurée. Note globale : Faible.

Score du site · marriott.com

Combine l'origine et 1 page mesurée. Le rapport ci-dessous détaille uniquement la page d'origine.

marriott.com

Faible · 14 vérifications réussies, 25 avertissements, 12 échecs · 0,6 s

Partagez ce rapport avec votre équipe technique

Transmettez les constats à ceux qui peuvent les résoudre. Copiez un résumé prêt pour Slack, Teams ou votre prochaine réunion.

E-mail

Ce rapport est public. Votre équipe peut l’ouvrir sans compte.

Contenu

46/100

Y a-t-il de la substance qu'un agent puisse lire ?

  • Homepage does not serve Markdown via content negotiation

    Serve a Markdown representation of your pages when agents request "Accept: text/markdown". Agents like Claude Code and Cursor ask for it, and Markdown cuts token usage by roughly 80% against HTML. Cloudflare ("Markdown for Agents") and Vercel can enable this without code changes.

  • No <link rel="alternate" type="text/markdown"> fallback found on the homepage

    If you cannot enable content negotiation, advertise a Markdown version with <link rel="alternate" type="text/markdown" href="/index.md"> so agents can discover it.

  • No JSON-LD structured data found

    Add a <script type="application/ld+json"> block in your HTML <head> with schema.org structured data describing your site, organization, or person.

  • <title> is too short (13 chars): "Access Denied"

    Lengthen the title to 20-70 characters with a clear topic indicator.

  • <meta name="description"> is missing

    Add <meta name="description" content="..."> in <head> with a 70-160 character summary. Agents use this as the canonical short description.

  • No <link rel="canonical"> found

    Add <link rel="canonical" href="https://your-site.com/page"> so agents have an unambiguous URL to cite even when crawled via a redirect or query-string variant.

  • <html lang="..."> is missing

    Set the document language: <html lang="en">. Multilingual agents rely on this to pick the right summarization model and avoid mixed-language ranking.

  • No UTF-8 charset declaration in HTML head

    Add <meta charset="utf-8"> as the first child of <head>. Without it, agents can mis-decode non-ASCII content.

  • Missing or incomplete viewport meta tag

    Add <meta name="viewport" content="width=device-width, initial-scale=1">. Helps mobile agents render the page correctly.

  • Sparse server-rendered content (16 words, 282 chars)

    Render at least the main page content server-side. Many AI crawlers (GPTBot, ClaudeBot, CCBot) do not execute JavaScript and will see only the static HTML.

  • Text-to-markup ratio is healthy (77.9%)

  • No semantic HTML landmarks found

    Replace generic <div> structures with semantic tags: <main>, <article>, <header>, <nav>, <footer>. Agents use these to identify the primary content region.

  • Single <h1> heading: "Access Denied"

  • No lang attribute on <html>

    Agents route, translate and pick a voice from this. Add lang="en" or whichever applies.

  • Method note: this reads markup, not a rendered accessibility tree

Accès

50/100

Un agent peut-il seulement la récupérer ?

  • A nonexistent path returns 403 rather than 404

    Answering unknown paths with 403 is a defensible hardening choice, but it stops a client distinguishing "missing" from "forbidden".

  • Homepage answers without a redirect

  • No character encoding declared in the header or the document

    Without a charset, non-ASCII text is decoded by guesswork and quoted back with replacement characters. Add charset=utf-8.

  • Site is served over HTTPS

  • Could not verify HTTP→HTTPS redirect

    Test manually: a request to http://your-site.com should respond with 301 → https://your-site.com.

  • HSTS max-age is short (86400s = ~1 days)

    Use at least max-age=15768000 (~6 months); preload list submission requires max-age=31536000 (1 year).

  • HSTS includes subdomains

  • HSTS lacks the preload directive

    Add preload (and ensure max-age >= 31536000 + includeSubDomains) and submit the domain at https://hstspreload.org for browser-built-in HTTPS enforcement.

  • Homepage is indexable

  • No directive restricts how AI assistants may use this page

Découverte

15/100

Un agent trouve-t-il ce que vous publiez ?

  • /llms.txt not found

    Create a /llms.txt file at your site root following the llmstxt.org specification. It should be a Markdown file starting with "# Your Site Name" and include a description, sections, and links.

  • /robots.txt not found

    Create a /robots.txt file at your site root. Add User-agent entries for AI crawlers (GPTBot, ClaudeBot, etc.) with Allow: / to grant access.

  • No sitemap found

    Publish an XML sitemap at /sitemap.xml and reference it from robots.txt with: Sitemap: https://your-site.com/sitemap.xml

  • No AI meta tags (ai:*) found

    Add AI meta tags to your HTML <head>: <meta name="ai:summary" content="Brief description">, <meta name="ai:content_type" content="website">, <meta name="ai:author" content="Your Name">.

  • No rel="alternate" link to llms.txt in HTML

    Add to your <head>: <link rel="alternate" type="text/plain" href="/llms.txt" title="LLM-optimized content">

  • No rel="alternate" link to the Agent Card in HTML

    Add to your <head>: <link rel="alternate" type="application/json" href="/.well-known/agent-card.json" title="Agent Card">

  • No rel="me" identity links found

    Add rel="me" links to verify your identity across platforms: <link rel="me" href="https://github.com/yourname">, <link rel="me" href="https://twitter.com/yourname">.

  • No OpenGraph meta tags found

    Add at minimum og:title, og:description, og:url, og:type, and og:image. Agents and link previews depend on these.

  • No Twitter Card meta tags found

    Add twitter:card, twitter:title, twitter:description, and twitter:image so X / Threads / Bluesky / Discord agents render link previews correctly.

  • Missing critical header: X-Content-Type-Options

    Add the X-Content-Type-Options response header to your server configuration. This is a critical security header.

  • Only 1/7 security headers present

    Add security headers like Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy to your server response.

  • No Link header for AI discovery (llms.txt, Agent Card)

    Add a Link response header pointing to your AI discovery files: Link: </llms.txt>; rel="alternate"; type="text/plain", </.well-known/agent-card.json>; rel="alternate"; type="application/json"

  • No machine-readable discovery relations beyond llms.txt and the Agent Card

    Advertise what you publish with Link relations so agents stop guessing paths. Add the ones that apply, for example: Link: </llms.txt>; rel="describedby", </.well-known/api-catalog>; rel="api-catalog". Informational in 3.x: this does not affect your score.

Protocoles

0/100

Qu'un agent peut-il appeler ?

  • No agent resource catalog found

    A catalog is one document listing everything an agent can call here — agent cards, MCP servers, APIs, skills — so a client stops probing four conventions to find out. Worth publishing once you have more than one of those. Informational: both ai-catalog.json and ard.json are still drafts, so this never affects your score.

  • /.well-known/ucp requires authentication

    The UCP profile must be publicly accessible with no authentication. An agent reads it before it has any credentials.

  • No agent-facing surface — an Agent Card does not apply to this site

  • No API surface — API discovery does not apply to this site

  • No MCP server — MCP discovery does not apply to this site

  • No developer-facing surface — skills do not apply to this site

  • No forms and no WebMCP code — nothing here for an agent to invoke as a tool

  • Nothing on this site requires authorization — auth discovery does not apply

Politique

18/100

Quels droits d'usage sont déclarés ?

  • /.well-known/security.txt not found

    Create a /.well-known/security.txt file per RFC 9116. At minimum, include Contact: and Expires: fields. See https://securitytxt.org/ for a generator.

  • No RSL license discovery found

    Declare machine-readable licensing terms for your content with Really Simple Licensing. Add to robots.txt: License: https://your-site.com/license.xml — then publish the RSL document. See https://rslstandard.org.

  • No machine-readable usage policy declared

    State your terms where they can be read without a lawyer. The lowest-effort option is a Content-Signal line in robots.txt: Content-Signal: search=yes, ai-input=yes, ai-train=no. Absence is neutral, not permission — but it also gives you nothing to point at.

Détails techniques

Moteur
ax-audit@4.1.0
Analysé
4 sept. 2026, 22:30:36 UTC
Durée
637 ms
Checks exécutés
26

Transformez ce rapport en améliorations continues

Offrez à votre équipe des rapports complets, des corrections prioritaires et un suivi pour préserver les progrès après chaque livraison.

Lire ce rapport via l'API ou le serveur MCP