Scovant Core — https://example.com/
Profile: commerce (requested auto, confidence 85%)
Core version: 0.3.0
40 PASS, 1 WARN, 0 FAIL, 9 N/A, 0 ERROR (50 checks)
Scovant Core Static Signal Score
100 / 100
Grade: A · Scope: CANONICAL · Status: OK · Coverage: 100% · Errors: 0
Capabilities detected (descriptive, not scored): mcp: present · webmcp: absent · ucp: present · llms_txt: present · openapi: not_checked · oauth: not_checked · content_signal: present · security_txt: present
Standards: AgentReady v1.0 (descriptive, not scored): MUST 3/3 measured — 3 pass · SHOULD 5/12 measured — 5 pass · MAY none measured (0/3) — Mapping: docs/standards/agentready.md
Categories
| Category | Weight | Score | Evaluated / applicable |
|---|---|---|---|
| Access & Discovery | 25 | 100 | 25 / 25 |
| Machine Understanding | 25 | 100 | 23 / 23 |
| Agent Interfaces | 20 | 100 | 5 / 5 |
| Trust & Commerce | 15 | 100 | 15 / 15 |
| Operability & Efficiency | 15 | 100 | 16 / 16 |
Findings
| Status | ID | Title | Severity | Summary |
|---|---|---|---|---|
| PASS | CORE-ACCESS-001 | HTTPS reachability | info | HTTPS entry URL answered 200. |
| PASS | CORE-ACCESS-002 | robots.txt availability and syntax | info | robots.txt answered 200 with a well-formed policy. |
| PASS | CORE-ACCESS-003 | AI search crawler policy | info | robots.txt declares all major search and answer-engine crawlers as allowed. |
| PASS | CORE-ACCESS-004 | Training vs. search crawler separation | info | Training/content-use crawler(s) GPTBot, Google-Extended are restricted while search/retrieval crawlers remain allowed. |
| PASS | CORE-ACCESS-005 | Sitemap availability | info | A valid urlset sitemap was found at https://example.com/sitemap.xml. |
| PASS | CORE-ACCESS-006 | Sitemap freshness | info | Sitemap lastmod values look plausible. |
| PASS | CORE-ACCESS-007 | Canonical URL integrity | info | The canonical URL matches the entry URL. |
| PASS | CORE-ACCESS-008 | Indexability | info | The entry page does not declare noindex. |
| PASS | CORE-ACCESS-009 | llms.txt presence and integrity | info | llms.txt is well-formed and its 2 checked references resolve. |
| PASS | CORE-ACCESS-010 | Content-Signal declaration | info | Content-Signal is declared and internally consistent. |
| PASS | CORE-INTERFACE-001 | MCP discovery presence | info | An MCP discovery file is published and well-formed. |
| PASS | CORE-INTERFACE-002 | MCP server declaration quality | info | Every declared MCP server has a name, url, transport, and a real description. |
| PASS | CORE-MACHINE-001 | JSON-LD parseability | info | Every JSON-LD block on the sampled pages parses as valid JSON. |
| PASS | CORE-MACHINE-002 | Organization entity | info | An Organization entity declares name and url. |
| PASS | CORE-MACHINE-003 | WebSite/WebPage entity | info | A WebSite or WebPage entity was found on the sampled pages. |
| PASS | CORE-MACHINE-004 | Product structured data | info | A sampled product page exposes a Product entity with an identifier. |
| PASS | CORE-MACHINE-005 | Offer price, currency, and availability | info | The product's Offer declares price, currency, and availability. |
| PASS | CORE-MACHINE-006 | Product identifier count | info | Product entities declare two or more stable identifiers. |
| PASS | CORE-MACHINE-007 | Breadcrumbs | info | A sampled non-entry page declares a BreadcrumbList. |
| PASS | CORE-MACHINE-008 | Metadata quality | info | The entry page declares title, description, and Open Graph tags. |
| PASS | CORE-MACHINE-009 | Heading structure | info | The entry page has a single H1 and no skipped heading levels. |
| PASS | CORE-MACHINE-010 | Language declaration | info | The entry page declares a valid `lang` attribute. |
| PASS | CORE-MACHINE-011 | Image alt coverage | info | 1/1 images have an alt attribute (ratio 100%). |
| PASS | CORE-OPERABILITY-001 | Server-rendered core content | info | The entry page's static HTML carries 337 chars of visible text. |
| PASS | CORE-OPERABILITY-002 | Redirect chain complexity | info | The entry URL redirects 0 time(s) before settling. |
| PASS | CORE-OPERABILITY-003 | Cache validators | info | The entry response carries an ETag or Last-Modified validator. |
| PASS | CORE-OPERABILITY-004 | Broken machine-consumable endpoints | info | All 6 checked machine-consumable reference(s) resolve. |
| PASS | CORE-OPERABILITY-005 | Agent parse cost | info | The entry page's estimated parse cost is ~84 tokens (low). |
| PASS | CORE-OPERABILITY-008 | Unknown paths return 404 | info | Unknown paths answer with a real 404. |
| PASS | CORE-OPERABILITY-010 | Challenge pages are not served as 200 | info | No challenge page is served with HTTP 200. |
| PASS | CORE-TRUST-001 | Contact/support discoverability | info | A contact or support link was found on the entry page. |
| PASS | CORE-TRUST-002 | Shipping policy discoverability | info | A shipping policy page was found with substantive content. |
| PASS | CORE-TRUST-003 | Returns/refund policy discoverability | info | A returns/refund policy page was found with substantive content. |
| PASS | CORE-TRUST-004 | Privacy policy discoverability | info | A privacy policy page was found with substantive content. |
| PASS | CORE-TRUST-005 | Terms/conditions discoverability | info | A terms/conditions page was found with substantive content. |
| PASS | CORE-TRUST-006 | security.txt discoverability | info | A valid security.txt was found with a contact method. |
| PASS | CORE-TRUST-007 | Pricing discoverability | info | Prices are exposed as structured product data. |
| N/A | CORE-INTERFACE-003 | WebMCP static presence | info | No static WebMCP marker was found on the sampled pages. |
| N/A | CORE-INTERFACE-005 | OpenAPI discovery | info | Not applicable to the commerce profile. |
| N/A | CORE-INTERFACE-006 | OAuth authorization-server metadata | info | Not applicable to the commerce profile. |
| N/A | CORE-INTERFACE-007 | OAuth protected-resource metadata | info | Not applicable to the commerce profile. |
| N/A | CORE-OPERABILITY-006 | Form/control labels | info | No forms were found on any sampled page. |
| N/A | CORE-OPERABILITY-009 | Rate limiting is signalled | info | No 429 response was observed during this scan. |
Experimental (not scored)
CORE-ACCESS-011(PASS) — llms.txt links useful same-origin pages and carries no misplaced policy or template text.CORE-INTERFACE-008(PASS) — A UCP profile is published and valid.CORE-MACHINE-012(PASS) — The structured price matches a visible price on the page.CORE-OPERABILITY-011(WARN) — 3 of 3 machine surface(s) are not linked from anything an agent reads: llms_txt, mcp, ucp.
N/A: CORE-INTERFACE-004, CORE-INTERFACE-009, CORE-OPERABILITY-007
Evidence
CORE-ACCESS-001 — HTTPS reachability
{
"final_url": "https://example.com/",
"input_url": "https://example.com/",
"redirect_chain": [],
"redirect_count": 0,
"status": 200
}
CORE-ACCESS-002 — robots.txt availability and syntax
{
"error": null,
"resource": "https://example.com/robots.txt",
"served_as_html": false,
"sha256": "a3b24ab6056572a5c127bc7a4dba409e656da1245ef936633bab52b8b395efcf",
"sitemap_count": 1,
"status": 200,
"unknown_directives": []
}
CORE-ACCESS-003 — AI search crawler policy
{
"declared_policy": {
"Applebot": true,
"Bingbot": true,
"Claude-SearchBot": true,
"Googlebot": true,
"OAI-SearchBot": true,
"PerplexityBot": true
},
"http_status": 200,
"resource": "https://example.com/robots.txt",
"robots_present": true,
"user_fetch_policy": {
"ChatGPT-User": true,
"Claude-User": true,
"DuckAssistBot": true,
"Perplexity-User": true
}
}
CORE-ACCESS-004 — Training vs. search crawler separation
{
"explicit_separation": true,
"http_status": 200,
"resource": "https://example.com/robots.txt",
"search_blocked": [],
"training_blocked": [
"GPTBot",
"Google-Extended"
]
}
CORE-ACCESS-005 — Sitemap availability
{
"entry_count": 3,
"exists": true,
"kind": "urlset",
"parse_error": null,
"probe_error": null,
"probe_status": 200,
"served_as_html": false,
"url": "https://example.com/sitemap.xml",
"valid": true
}
CORE-ACCESS-006 — Sitemap freshness
{
"dated_entry_count": 3,
"entry_count": 3,
"newest": "2026-08-15",
"oldest": "2026-07-01",
"url": "https://example.com/sitemap.xml"
}
CORE-ACCESS-007 — Canonical URL integrity
{
"canonical_url": "https://example.com/",
"entry_url": "https://example.com/"
}
CORE-ACCESS-008 — Indexability
{
"robots_meta": null,
"x_robots_tag": null
}
CORE-ACCESS-009 — llms.txt presence and integrity
{
"errors": [],
"references_broken": [],
"references_checked": 2,
"references_unresolved": [],
"resource": "https://example.com/llms.txt",
"valid": true
}
CORE-ACCESS-010 — Content-Signal declaration
{
"declared": true,
"dimensions": {
"ai-input": "yes",
"ai-train": "no",
"search": "yes"
},
"syntax_errors": []
}
CORE-INTERFACE-001 — MCP discovery presence
{
"declared_name": "example-shop",
"endpoints": [
"https://example.com/mcp"
],
"exists": true,
"http_status": 200,
"resource": "https://example.com/.well-known/mcp.json",
"server_card": false,
"valid": true
}
CORE-INTERFACE-002 — MCP server declaration quality
{
"servers_count": 1
}
CORE-INTERFACE-003 — WebMCP static presence
{
"pages_scanned": 3,
"pages_with_marker": []
}
CORE-MACHINE-001 — JSON-LD parseability
{
"pages": [
{
"parsed": 2,
"raw": 2,
"url": "https://example.com/"
},
{
"parsed": 2,
"raw": 2,
"url": "https://example.com/products/widget"
},
{
"parsed": 0,
"raw": 0,
"url": "https://example.com/contact"
}
],
"parsed_total": 4,
"raw_total": 4
}
CORE-MACHINE-002 — Organization entity
{
"found": true,
"has_description": false,
"has_logo": true,
"has_sameAs": false,
"name": "Example Shop",
"pages_parsed": 3,
"url": "https://example.com/"
}
CORE-MACHINE-003 — WebSite/WebPage entity
{
"found": true,
"pages_parsed": 3
}
CORE-MACHINE-004 — Product structured data
{
"has_identifiers": true,
"pages_parsed": 3,
"product_pages": [
"https://example.com/products/widget"
]
}
CORE-MACHINE-005 — Offer price, currency, and availability
{
"availability": "https://schema.org/InStock",
"currency": "USD",
"missing": [],
"price": 19.99,
"url": "https://example.com/products/widget"
}
CORE-MACHINE-006 — Product identifier count
{
"count": 2,
"identifier_keys": [
"brand",
"sku"
],
"pages_parsed": 3
}
CORE-MACHINE-007 — Breadcrumbs
{
"has_breadcrumb": true,
"non_entry_pages": [
"https://example.com/products/widget",
"https://example.com/contact"
],
"non_entry_parsed": 2
}
CORE-MACHINE-008 — Metadata quality
{
"entry_url": "https://example.com/",
"issues": [],
"meta_description": "Example Shop sells widgets.",
"missing": [],
"title": "Example Shop — Widgets"
}
CORE-MACHINE-009 — Heading structure
{
"entry_url": "https://example.com/",
"h1_count": 1,
"heading_count": 2,
"issues": [],
"levels": [
"h1",
"h2"
]
}
CORE-MACHINE-010 — Language declaration
{
"entry_url": "https://example.com/",
"html_lang": "en"
}
CORE-MACHINE-011 — Image alt coverage
{
"covered": 1,
"empty_alt": 0,
"pages_parsed": 3,
"ratio": 1.0,
"total": 1,
"with_alt": 1
}
CORE-OPERABILITY-001 — Server-rendered core content
{
"entry_url": "https://example.com/",
"spa_shell_marker": false,
"visible_text_chars": 337
}
CORE-OPERABILITY-002 — Redirect chain complexity
{
"redirect_chain": [],
"redirect_count": 0
}
CORE-OPERABILITY-003 — Cache validators
{
"cache_control": null,
"etag": "\"commerce-good-v1\"",
"last_modified": null
}
CORE-OPERABILITY-004 — Broken machine-consumable endpoints
{
"broken": [],
"broken_count": 0,
"inconclusive": [
{
"source": "mcp_endpoint",
"status": 404,
"url": "https://example.com/mcp"
}
],
"refs_checked": 7,
"refs_resolved": 6,
"unresolved": []
}
CORE-OPERABILITY-005 — Agent parse cost
{
"dom_nodes": 24,
"estimated_tokens": 84,
"html_bytes": 1315,
"level": "LOW",
"link_count": 7,
"script_bytes": 247,
"script_ratio": 0.18783269961977186,
"structured_bytes": 247,
"text_chars": 337,
"token_chars_ratio": 4
}
CORE-OPERABILITY-006 — Form/control labels
{
"totals": {
"forms": 0,
"inputs": 0,
"unlabeled_inputs": 0,
"unlabeled_selects": 0,
"unnamed_buttons": 0
}
}
CORE-OPERABILITY-008 — Unknown paths return 404
{
"final_url": "https://example.com/scovant-core-probe-9b580505",
"probed_url": "https://example.com/scovant-core-probe-9b580505",
"redirected": false,
"served_html": false,
"status": 404
}
CORE-OPERABILITY-009 — Rate limiting is signalled
{
"observed": []
}
CORE-OPERABILITY-010 — Challenge pages are not served as 200
{
"honest_challenges": 0,
"pages": [],
"pages_checked": 4
}
CORE-TRUST-001 — Contact/support discoverability
{
"contact_url": "https://example.com/contact",
"kind": "page"
}
CORE-TRUST-002 — Shipping policy discoverability
{
"served_as_html": true,
"status": 200,
"text_chars": 300,
"url": "https://example.com/shipping"
}
CORE-TRUST-003 — Returns/refund policy discoverability
{
"served_as_html": true,
"status": 200,
"text_chars": 312,
"url": "https://example.com/returns"
}
CORE-TRUST-004 — Privacy policy discoverability
{
"served_as_html": true,
"status": 200,
"text_chars": 303,
"url": "https://example.com/privacy"
}
CORE-TRUST-005 — Terms/conditions discoverability
{
"served_as_html": true,
"status": 200,
"text_chars": 334,
"url": "https://example.com/terms"
}
CORE-TRUST-006 — security.txt discoverability
{
"contact": true,
"expires": "2030-01-01T00:00:00Z",
"expires_valid": true,
"found_url": "https://example.com/.well-known/security.txt",
"status": 200
}
CORE-TRUST-007 — Pricing discoverability
{
"structured_price": 19.99,
"url": "https://example.com/products/widget"
}
Remediation
- (none)
Limitations
- Scovant Core evaluates declared and static evidence only; it does not observe real agent traffic.
- Only reachability and syntax are checked; per-agent policy is evaluated by the other CORE-ACCESS checks.
- Only the declared robots.txt policy is evaluated; whether the crawler is actually served is not observed.
- Only the declared robots.txt policy is evaluated.
- Only the first-declared sitemap (or its first child, for a sitemap index) is fetched and validated.
- Only ISO 8601 date-formatted lastmod values are parsed; malformed dates are ignored, not penalised.
- Only the entry page's declared canonical is evaluated.
- Only the entry page's own robots meta tag and X-Robots-Tag header are checked.
- Absence is not penalised; the convention is emerging. Reference checks are HTTP status only.
- Absence is not penalised; the convention is emerging.
- Only `/.well-known/mcp.json` and the two candidate server-card paths are probed; a custom discovery location is not found.
- Only the `mcpServers` object at /.well-known/mcp.json is parsed; a server card is not covered by this check.
- This is a static text scan of already-fetched HTML for a marker string; the browser-side registration was not executed, so a marker's presence does not confirm the tools actually register or work.
- Only a fixed set of conventional paths, plus same-origin entry-page links naming openapi/swagger, are probed.
- Only the conventional /.well-known/oauth-authorization-server path is probed.
- Only the conventional /.well-known/oauth-protected-resource path is probed.
- Only well-formed-JSON parseability is checked; schema.org vocabulary correctness is not validated.
- Only the schema_org nodes on the sampled pages are checked; an Organization declared elsewhere on the site is not evaluated.
- Only the schema_org nodes on the sampled pages are checked.
- Only the sampled pages are checked; a product catalog not represented in the sample is not evaluated.
- Only the first sampled page that exposes a Product entity is checked.
- Only the non-entry pages in the sampled set are checked.
- Only the entry page's metadata is checked.
- Only the entry page's heading outline is checked.
- Only the entry page's `<html lang>` attribute is checked.
- Only the images on the sampled pages are counted.
- Static-HTML signal only: the raw fetched response is inspected, never rendered in a browser, so a site that hydrates real content very quickly may still be flagged here.
- Only the entry URL's own redirect chain is inspected; redirects encountered while fetching other sampled pages are not counted here.
- Only the entry response's own headers are checked; per-page-type validator strategy is not inspected.
- Only the capped set of references collected by the machine_links gatherer are checked; endpoints not linked from any declared document are not found. A declared MCP endpoint is recorded but never judged — Core does not perform the MCP handshake.
- `estimated_tokens` is a character-count estimate (chars / token_chars_ratio), never a real tokenizer count, and only the entry page is measured.
- Only forms on the sampled page set are inspected; a form behind client-side rendering that never appears in the static HTML is not seen.
- One extra request to a path that cannot exist (the URL is in evidence); a site that deliberately serves a 200 landing page for every path fails this check by design.
- Core never induces throttling; only 429 responses that happened to occur during the scan are examined, so most scans report N/A.
- Only the entry response and the sampled pages are inspected; a challenge served with an honest 403/429/503 is not a defect here (the access checks cover blocking).
- Only the entry page's anchors are scanned; a contact method reachable only from a deeper page is not found.
- Only a same-origin link discovered from the entry page's nav/footer/anchors is followed; a shipping policy reachable only from a deeper page is not found.
- Only a same-origin link discovered from the entry page's nav/footer/anchors is followed; a returns policy reachable only from a deeper page is not found.
- Only a same-origin link discovered from the entry page's nav/footer/anchors is followed; a privacy policy reachable only from a deeper page is not found.
- Only a same-origin link discovered from the entry page's nav/footer/anchors is followed; terms reachable only from a deeper page are not found.
- Only the conventional /.well-known/security.txt and legacy /security.txt paths are probed.
- Pricing-page discovery follows only a same-origin link from the entry page; the structured-price fallback checks only the sampled pages.
Not tested by Scovant Core
- Observed WAF access
- Real agent tasks
- MCP tool execution
- WebMCP state parity
- Multi-model reliability
- Regression stability
Core vs Cloud
| Capability | Core | Cloud |
|---|---|---|
| HTTP reachability | ✅ | ✅ |
| robots.txt | ✅ | ✅ |
| Sitemap | ✅ | ✅ |
| llms.txt | ✅ | ✅ |
| Structured data (JSON-LD) | ✅ | ✅ |
| Product/Offer data | ✅ | ✅ |
| Static crawler policy | ✅ | ✅ |
| Content-Signal | ✅ | ✅ |
| MCP discovery | ✅ | ✅ |
| WebMCP static presence | ✅ | ✅ |
| OpenAPI presence | ✅ | ✅ |
| OAuth authorization-server / protected-resource metadata | ✅ | ✅ |
| UCP profile validity | ✅ (experimental) | ✅ |
| Agent discovery surface (A2A cards, AI-plugin, agents.json, Agent Skills) | ✅ (experimental) | ✅ |
| Core Score | ✅ | — |
| Cloud = observed, reproducible, cross-provider, longitudinal | — | — |
| Cloud's full compatibility score | ❌ | ✅ |
| Cloud's full production ruleset | ❌ | ✅ |
| Observed WAF/bot-firewall behavior | ❌ | ✅ |
| Real crawler network access | ❌ | ✅ |
| Browser-based agent simulation | ❌ | ✅ |
| Multi-model execution | ❌ | ✅ |
| MCP tool invocation | ❌ | ✅ |
| WebMCP tool execution/state parity | ❌ | ✅ |
| Tool/UI parity checking | ❌ | ✅ |
| Checkout/task completion | ❌ | ✅ |
| CAPTCHA/challenge behavior | ❌ | ✅ |
| Verified-agent access | ❌ | ✅ |
| Failure attribution | ❌ | ✅ |
| Temporal stability / regressions | ❌ | ✅ |
| Scheduled monitoring | ❌ | ✅ |
| Alerts/webhooks | ❌ | ✅ |
| Hosted, shareable reports | ❌ | ✅ |
| Contextual fix plan | ❌ | ✅ |
Scovant Core measures passive, machine-facing signals. Scovant Cloud verifies how real agents actually behave, across providers, browser runtimes, security layers and time.
Methodology
Category weights are 25/25/20/15/15. Each check contributes PASS = 1, WARN = 0.5, FAIL = 0 to its category; ERROR lowers coverage (a document that could not be read counts against evidence), and N/A is excluded entirely. A scan scores INSUFFICIENT_EVIDENCE below a 60% coverage floor of its applicable weight. A full-selection scan that clears that floor but falls short of 85% coverage, or that hit any ERROR, is reported as DEGRADED (a score, no letter grade) rather than being silently graded on incomplete evidence. Running with checks narrowed or widened via --include/--exclude/--experimental instead reports a NOT_CANONICAL Subset Diagnostic Score over that subset, not the full Core Score. Full reference: docs/methodology.md.
Provenance
- scan_id
- local-golden
- started_at
- 2026-09-04T00:00:00Z
- completed_at
- 2026-09-04T00:00:00Z
- schema_version
- 1.0
- core_version
- 0.3.0
- profile_detector_version
- 1.0
- ruleset_version
- 2026.10
- ruleset_digest
- 994a69bc7f12
- python
- <runtime>
- platform
- <runtime>
- user_agent
- ScovantCore/0.3.0 (+https://github.com/Scovant/scovant-core)
- timeout
- 60.0
- max_pages
- 5
- network_mode
- fixture
- experimental
- False
- allow_private_networks
- False
- scan_scope
- CANONICAL
- included_checks
- []
- excluded_checks
- []
- error_count
- 0
- evidence_min_coverage
- 0.6
- canonical_min_coverage
- 0.85
- dependencies
- <runtime>
- environment_digest
- <runtime>