AX Rush

AI readiness of mastercard.com

Measured on the home page. Overall grade: Poor.

mastercard.com

Poor · 6 passing checks, 23 warnings, 14 failures · 0.7s

ax-audit@3.6.0

LLMs.txt

  • /llms.txt not found

    Create a /llms.txt file at your site root following the llmstxt.org specification. It should be a Markdown file starting with "# Your Site Name" and include a description, sections, and links.

Robots.txt

  • /robots.txt not found

    Create a /robots.txt file at your site root. Add User-agent entries for AI crawlers (GPTBot, ClaudeBot, etc.) with Allow: / to grant access.

Agent Card (A2A)

  • /.well-known/agent.json not found

    Create a /.well-known/agent.json file following the A2A (Agent-to-Agent) protocol. It should include name, description, url, and skills fields describing your site's capabilities.

Security.txt

  • /.well-known/security.txt not found

    Create a /.well-known/security.txt file per RFC 9116. At minimum, include Contact: and Expires: fields. See https://securitytxt.org/ for a generator.

OpenAPI Spec

  • /.well-known/openapi.json not found

    Create a /.well-known/openapi.json file with your API specification following the OpenAPI 3.x standard. See https://swagger.io/specification/ for the spec.

MCP (Model Context Protocol)

  • /.well-known/mcp.json not found

    Create a /.well-known/mcp.json file describing your MCP server configuration. Include name, description, tools, and version fields. See https://modelcontextprotocol.io for the spec.

Sitemap

  • No sitemap found

    Publish an XML sitemap at /sitemap.xml and reference it from robots.txt with: Sitemap: https://your-site.com/sitemap.xml

AI Well-Known

  • 0/5 emerging AI discovery files published

  • ai.txt not found

    Publish /.well-known/ai.txt declaring opt-in/opt-out signals for AI training. See https://site.spawning.ai/spawning-ai-txt for the format.

  • genai.txt not found

    Publish /.well-known/genai.txt declaring your generative-AI usage policy.

  • ai-plugin.json not found

    Publish /ai-plugin.json (legacy ChatGPT plugin manifest). Schema: name_for_model, description_for_model, api.url. Still consumed by some agents.

  • agents.json not found

    Publish /agents.json describing your site as a callable agent (OpenAgents / Wildcard emerging spec). Includes name, description, and operations[].

  • nlweb.json not found

    Publish /.well-known/nlweb.json (Microsoft NLWeb) so agents can interact with the site through a natural-language interface.

Content NegotiationInformational

  • Homepage does not serve Markdown via content negotiation

    Serve a Markdown representation of your pages when agents request "Accept: text/markdown". Agents like Claude Code and Cursor ask for it, and Markdown cuts token usage by ~80% vs HTML. Cloudflare ("Markdown for Agents") and Vercel can enable this without code changes.

  • No <link rel="alternate" type="text/markdown"> fallback found on the homepage

    If you cannot enable content negotiation, advertise a Markdown version with <link rel="alternate" type="text/markdown" href="/index.md"> so agents can discover it.

RSL LicenseInformational

  • No RSL license discovery found

    Declare machine-readable licensing terms for your content with Really Simple Licensing. Add to robots.txt: License: https://your-site.com/license.xml — then publish the RSL document. See https://rslstandard.org.

Agent AccessInformational

  • Baseline homepage request failed — cannot compare crawler access

Structured Data

  • No JSON-LD structured data found

    Add a <script type="application/ld+json"> block in your HTML <head> with schema.org structured data describing your site, organization, or person.

Crawl EfficiencyInformational

Meta Tags

  • No AI meta tags (ai:*) found

    Add AI meta tags to your HTML <head>: <meta name="ai:summary" content="Brief description">, <meta name="ai:content_type" content="website">, <meta name="ai:author" content="Your Name">.

  • No rel="alternate" link to llms.txt in HTML

    Add to your <head>: <link rel="alternate" type="text/plain" href="/llms.txt" title="LLM-optimized content">

  • No rel="alternate" link to agent.json in HTML

    Add to your <head>: <link rel="alternate" type="application/json" href="/.well-known/agent.json" title="Agent Card">

  • No rel="me" identity links found

    Add rel="me" links to verify your identity across platforms: <link rel="me" href="https://github.com/yourname">, <link rel="me" href="https://twitter.com/yourname">.

  • No OpenGraph meta tags found

    Add at minimum og:title, og:description, og:url, og:type, and og:image. Agents and link previews depend on these.

  • No Twitter Card meta tags found

    Add twitter:card, twitter:title, twitter:description, and twitter:image so X / Threads / Bluesky / Discord agents render link previews correctly.

SEO Basics

  • <title> is too short (13 chars): "Access Denied"

    Lengthen the title to 20-70 characters with a clear topic indicator.

  • <meta name="description"> is missing

    Add <meta name="description" content="..."> in <head> with a 70-160 character summary. Agents use this as the canonical short description.

  • No <link rel="canonical"> found

    Add <link rel="canonical" href="https://your-site.com/page"> so agents have an unambiguous URL to cite even when crawled via a redirect or query-string variant.

  • <html lang="..."> is missing

    Set the document language: <html lang="en">. Multilingual agents rely on this to pick the right summarization model and avoid mixed-language ranking.

  • No UTF-8 charset declaration in HTML head

    Add <meta charset="utf-8"> as the first child of <head>. Without it, agents can mis-decode non-ASCII content.

  • Missing or incomplete viewport meta tag

    Add <meta name="viewport" content="width=device-width, initial-scale=1">. Helps mobile agents render the page correctly.

HTML Rendering

  • Sparse server-rendered content (16 words, 292 chars)

    Render at least the main page content server-side. Many AI crawlers (GPTBot, ClaudeBot, CCBot) do not execute JavaScript and will see only the static HTML.

  • Text-to-markup ratio is healthy (78.5%)

  • No semantic HTML landmarks found

    Replace generic <div> structures with semantic tags: <main>, <article>, <header>, <nav>, <footer>. Agents use these to identify the primary content region.

  • Single <h1> heading: "Access Denied"

HTTP Headers

  • Missing critical header: X-Content-Type-Options

    Add the X-Content-Type-Options response header to your server configuration. This is a critical security header.

  • Only 1/7 security headers present

    Add security headers like Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy to your server response.

  • No Link header for AI discovery (llms.txt, agent.json)

    Add a Link response header pointing to your AI discovery files: Link: </llms.txt>; rel="alternate"; type="text/plain", </.well-known/agent.json>; rel="alternate"; type="application/json"

TLS / HTTPS

  • Site is served over HTTPS

  • Could not verify HTTP→HTTPS redirect

    Test manually: a request to http://your-site.com should respond with 301 → https://your-site.com.

  • HSTS max-age=31536000

  • HSTS includes subdomains

  • HSTS preload-eligible