Scovant Core — https://example.com/

Profile: commerce (requested auto, confidence 85%)

Core version: 0.5.0

42 PASS, 11 WARN, 3 FAIL, 10 N/A, 0 ERROR (66 checks)

Scovant Core Static Signal Score

99 / 100

Grade: A · Scope: CANONICAL · Status: OK · Coverage: 100% · Errors: 0

Capabilities detected (descriptive, not scored): mcp: present · webmcp: absent · ucp: present · llms_txt: present · openapi: not_checked · oauth: not_checked · content_signal: present · security_txt: invalid

Standards: AgentReady v1.0 (descriptive, not scored): MUST 3/3 measured — 3 pass · SHOULD 5/12 measured — 5 pass · MAY none measured (0/3) — Mapping: docs/standards/agentready.md

Categories

CategoryWeightScoreEvaluated / applicable
Access & Discovery2510025 / 25
Machine Understanding2510023 / 23
Agent Interfaces201005 / 5
Trust & Commerce159315 / 15
Operability & Efficiency1510016 / 16

Findings

StatusIDTitleSeveritySummary
FAILCORE-SECURITY-003Content-Security-Policy / framing policymediumNeither Content-Security-Policy nor X-Frame-Options is sent.
FAILCORE-SECURITY-004Security-relevant cookie attributesmediumSession-like cookie(s) without Secure+HttpOnly: sessionid.
FAILCORE-SECURITY-006security.txt validity (RFC 9116)mediumExpires is in the past.
WARNCORE-SECURITY-001HTTPS baselinemediumhttps is served, but http:// answers 200 without redirecting to https.
WARNCORE-SECURITY-002HSTS presencelowHSTS missing, unparsable or max-age below one day.
WARNCORE-SECURITY-005Referrer / MIME hygiene headerslowMissing: referrer-policy, x-content-type-options.
WARNCORE-SECURITY-007Credential-like value exposed in a machine-facing surfacemedium1 possible credential-like value(s) (heuristic match, redacted).
WARNCORE-SECURITY-008Internal network reference exposedlow2 internal network reference(s) in public machine-facing documents.
WARNCORE-TRUST-006security.txt discoverabilitymediumsecurity.txt was found but its Expires date has passed.
PASSCORE-ACCESS-001HTTPS reachabilityinfoHTTPS entry URL answered 200.
PASSCORE-ACCESS-002robots.txt availability and syntaxinforobots.txt answered 200 with a well-formed policy.
PASSCORE-ACCESS-003AI search crawler policyinforobots.txt declares all major search and answer-engine crawlers as allowed.
PASSCORE-ACCESS-004Training vs. search crawler separationinfoTraining/content-use crawler(s) GPTBot, Google-Extended are restricted while search/retrieval crawlers remain allowed.
PASSCORE-ACCESS-005Sitemap availabilityinfoA valid urlset sitemap was found at https://example.com/sitemap.xml.
PASSCORE-ACCESS-006Sitemap freshnessinfoSitemap lastmod values look plausible.
PASSCORE-ACCESS-007Canonical URL integrityinfoThe canonical URL matches the entry URL.
PASSCORE-ACCESS-008IndexabilityinfoThe entry page does not declare noindex.
PASSCORE-ACCESS-009llms.txt presence and integrityinfollms.txt is well-formed and its 2 checked references resolve.
PASSCORE-ACCESS-010Content-Signal declarationinfoContent-Signal is declared and internally consistent.
PASSCORE-INTERFACE-001MCP discovery presenceinfoAn MCP discovery file is published and well-formed.
PASSCORE-INTERFACE-002MCP server declaration qualityinfoEvery declared MCP server has a name, url, transport, and a real description.
PASSCORE-MACHINE-001JSON-LD parseabilityinfoEvery JSON-LD block on the sampled pages parses as valid JSON.
PASSCORE-MACHINE-002Organization entityinfoAn Organization entity declares name and url.
PASSCORE-MACHINE-003WebSite/WebPage entityinfoA WebSite or WebPage entity was found on the sampled pages.
PASSCORE-MACHINE-004Product structured datainfoA sampled product page exposes a Product entity with an identifier.
PASSCORE-MACHINE-005Offer price, currency, and availabilityinfoThe product's Offer declares price, currency, and availability.
PASSCORE-MACHINE-006Product identifier countinfoProduct entities declare two or more stable identifiers.
PASSCORE-MACHINE-007BreadcrumbsinfoA sampled non-entry page declares a BreadcrumbList.
PASSCORE-MACHINE-008Metadata qualityinfoThe entry page declares title, description, and Open Graph tags.
PASSCORE-MACHINE-009Heading structureinfoThe entry page has a single H1 and no skipped heading levels.
PASSCORE-MACHINE-010Language declarationinfoThe entry page declares a valid `lang` attribute.
PASSCORE-MACHINE-011Image alt coverageinfo1/1 images have an alt attribute (ratio 100%).
PASSCORE-OPERABILITY-001Server-rendered core contentinfoThe entry page's static HTML carries 337 chars of visible text.
PASSCORE-OPERABILITY-002Redirect chain complexityinfoThe entry URL redirects 0 time(s) before settling.
PASSCORE-OPERABILITY-003Cache validatorsinfoThe entry response carries an ETag or Last-Modified validator.
PASSCORE-OPERABILITY-004Broken machine-consumable endpointsinfoAll 6 checked machine-consumable reference(s) resolve.
PASSCORE-OPERABILITY-005Agent parse costinfoThe entry page's estimated parse cost is ~84 tokens (low).
PASSCORE-OPERABILITY-008Unknown paths return 404infoUnknown paths answer with a real 404.
PASSCORE-OPERABILITY-010Challenge pages are not served as 200infoNo challenge page is served with HTTP 200.
PASSCORE-TRUST-001Contact/support discoverabilityinfoA contact or support link was found on the entry page.
PASSCORE-TRUST-002Shipping policy discoverabilityinfoA shipping policy page was found with substantive content.
PASSCORE-TRUST-003Returns/refund policy discoverabilityinfoA returns/refund policy page was found with substantive content.
PASSCORE-TRUST-004Privacy policy discoverabilityinfoA privacy policy page was found with substantive content.
PASSCORE-TRUST-005Terms/conditions discoverabilityinfoA terms/conditions page was found with substantive content.
PASSCORE-TRUST-007Pricing discoverabilityinfoPrices are exposed as structured product data.
N/ACORE-INTERFACE-003WebMCP static presenceinfoNo static WebMCP marker was found on the sampled pages.
N/ACORE-INTERFACE-005OpenAPI discoveryinfoNot applicable to the commerce profile.
N/ACORE-INTERFACE-006OAuth authorization-server metadatainfoNot applicable to the commerce profile.
N/ACORE-INTERFACE-007OAuth protected-resource metadatainfoNot applicable to the commerce profile.
N/ACORE-OPERABILITY-006Form/control labelsinfoNo forms were found on any sampled page.
N/ACORE-OPERABILITY-009Rate limiting is signalledinfoNo 429 response was observed during this scan.

Experimental (not scored)

N/A: CORE-INTERFACE-004, CORE-INTERFACE-009, CORE-OPERABILITY-007, CORE-SECURITY-010

Evidence

CORE-ACCESS-001 — HTTPS reachability
{
  "final_url": "https://example.com/",
  "input_url": "https://example.com/",
  "redirect_chain": [],
  "redirect_count": 0,
  "status": 200
}
CORE-ACCESS-002 — robots.txt availability and syntax
{
  "error": null,
  "resource": "https://example.com/robots.txt",
  "served_as_html": false,
  "sha256": "a3b24ab6056572a5c127bc7a4dba409e656da1245ef936633bab52b8b395efcf",
  "sitemap_count": 1,
  "status": 200,
  "unknown_directives": []
}
CORE-ACCESS-003 — AI search crawler policy
{
  "declared_policy": {
    "Applebot": true,
    "Bingbot": true,
    "Claude-SearchBot": true,
    "Googlebot": true,
    "OAI-SearchBot": true,
    "PerplexityBot": true
  },
  "http_status": 200,
  "resource": "https://example.com/robots.txt",
  "robots_present": true,
  "user_fetch_policy": {
    "ChatGPT-User": true,
    "Claude-User": true,
    "DuckAssistBot": true,
    "Perplexity-User": true
  }
}
CORE-ACCESS-004 — Training vs. search crawler separation
{
  "explicit_separation": true,
  "http_status": 200,
  "resource": "https://example.com/robots.txt",
  "search_blocked": [],
  "training_blocked": [
    "GPTBot",
    "Google-Extended"
  ]
}
CORE-ACCESS-005 — Sitemap availability
{
  "entry_count": 3,
  "exists": true,
  "kind": "urlset",
  "parse_error": null,
  "probe_error": null,
  "probe_status": 200,
  "served_as_html": false,
  "url": "https://example.com/sitemap.xml",
  "valid": true
}
CORE-ACCESS-006 — Sitemap freshness
{
  "dated_entry_count": 3,
  "entry_count": 3,
  "newest": "2026-08-15",
  "oldest": "2026-07-01",
  "url": "https://example.com/sitemap.xml"
}
CORE-ACCESS-007 — Canonical URL integrity
{
  "canonical_url": "https://example.com/",
  "entry_url": "https://example.com/"
}
CORE-ACCESS-008 — Indexability
{
  "robots_meta": null,
  "x_robots_tag": null
}
CORE-ACCESS-009 — llms.txt presence and integrity
{
  "errors": [],
  "references_broken": [],
  "references_checked": 2,
  "references_unresolved": [],
  "resource": "https://example.com/llms.txt",
  "valid": true
}
CORE-ACCESS-010 — Content-Signal declaration
{
  "declared": true,
  "dimensions": {
    "ai-input": "yes",
    "ai-train": "no",
    "search": "yes"
  },
  "syntax_errors": []
}
CORE-INTERFACE-001 — MCP discovery presence
{
  "declared_name": "delete_all_orders",
  "endpoints": [
    "https://example.com/mcp"
  ],
  "exists": true,
  "http_status": 200,
  "resource": "https://example.com/.well-known/mcp.json",
  "server_card": false,
  "valid": true
}
CORE-INTERFACE-002 — MCP server declaration quality
{
  "servers_count": 1
}
CORE-INTERFACE-003 — WebMCP static presence
{
  "pages_scanned": 3,
  "pages_with_marker": []
}
CORE-MACHINE-001 — JSON-LD parseability
{
  "pages": [
    {
      "parsed": 2,
      "raw": 2,
      "url": "https://example.com/"
    },
    {
      "parsed": 2,
      "raw": 2,
      "url": "https://example.com/products/widget"
    },
    {
      "parsed": 0,
      "raw": 0,
      "url": "https://example.com/contact"
    }
  ],
  "parsed_total": 4,
  "raw_total": 4
}
CORE-MACHINE-002 — Organization entity
{
  "found": true,
  "has_description": false,
  "has_logo": true,
  "has_sameAs": false,
  "name": "Example Shop",
  "pages_parsed": 3,
  "url": "https://example.com/"
}
CORE-MACHINE-003 — WebSite/WebPage entity
{
  "found": true,
  "pages_parsed": 3
}
CORE-MACHINE-004 — Product structured data
{
  "has_identifiers": true,
  "pages_parsed": 3,
  "product_pages": [
    "https://example.com/products/widget"
  ]
}
CORE-MACHINE-005 — Offer price, currency, and availability
{
  "availability": "https://schema.org/InStock",
  "currency": "USD",
  "missing": [],
  "price": 19.99,
  "url": "https://example.com/products/widget"
}
CORE-MACHINE-006 — Product identifier count
{
  "count": 2,
  "identifier_keys": [
    "brand",
    "sku"
  ],
  "pages_parsed": 3
}
CORE-MACHINE-007 — Breadcrumbs
{
  "has_breadcrumb": true,
  "non_entry_pages": [
    "https://example.com/products/widget",
    "https://example.com/contact"
  ],
  "non_entry_parsed": 2
}
CORE-MACHINE-008 — Metadata quality
{
  "entry_url": "https://example.com/",
  "issues": [],
  "meta_description": "Example Shop sells widgets.",
  "missing": [],
  "title": "Example Shop — Widgets"
}
CORE-MACHINE-009 — Heading structure
{
  "entry_url": "https://example.com/",
  "h1_count": 1,
  "heading_count": 2,
  "issues": [],
  "levels": [
    "h1",
    "h2"
  ]
}
CORE-MACHINE-010 — Language declaration
{
  "entry_url": "https://example.com/",
  "html_lang": "en"
}
CORE-MACHINE-011 — Image alt coverage
{
  "covered": 1,
  "empty_alt": 0,
  "pages_parsed": 3,
  "ratio": 1.0,
  "total": 1,
  "with_alt": 1
}
CORE-OPERABILITY-001 — Server-rendered core content
{
  "entry_url": "https://example.com/",
  "spa_shell_marker": false,
  "visible_text_chars": 337
}
CORE-OPERABILITY-002 — Redirect chain complexity
{
  "redirect_chain": [],
  "redirect_count": 0
}
CORE-OPERABILITY-003 — Cache validators
{
  "cache_control": null,
  "etag": "\"security-bad-v1\"",
  "last_modified": null
}
CORE-OPERABILITY-004 — Broken machine-consumable endpoints
{
  "broken": [],
  "broken_count": 0,
  "inconclusive": [
    {
      "source": "mcp_endpoint",
      "status": 404,
      "url": "https://example.com/mcp"
    }
  ],
  "refs_checked": 7,
  "refs_resolved": 6,
  "unresolved": []
}
CORE-OPERABILITY-005 — Agent parse cost
{
  "dom_nodes": 24,
  "estimated_tokens": 84,
  "html_bytes": 1315,
  "level": "LOW",
  "link_count": 7,
  "script_bytes": 247,
  "script_ratio": 0.18783269961977186,
  "structured_bytes": 247,
  "text_chars": 337,
  "token_chars_ratio": 4
}
CORE-OPERABILITY-006 — Form/control labels
{
  "totals": {
    "forms": 0,
    "inputs": 0,
    "unlabeled_inputs": 0,
    "unlabeled_selects": 0,
    "unnamed_buttons": 0
  }
}
CORE-OPERABILITY-008 — Unknown paths return 404
{
  "final_url": "https://example.com/scovant-core-probe-9b580505",
  "probed_url": "https://example.com/scovant-core-probe-9b580505",
  "redirected": false,
  "served_html": false,
  "status": 404
}
CORE-OPERABILITY-009 — Rate limiting is signalled
{
  "observed": []
}
CORE-OPERABILITY-010 — Challenge pages are not served as 200
{
  "honest_challenges": 0,
  "pages": [],
  "pages_checked": 4
}
CORE-SECURITY-001 — HTTPS baseline
{
  "downgrade_attempted": true,
  "downgrade_status": 200,
  "final_scheme": "https",
  "redirected_to_https": false
}
CORE-SECURITY-002 — HSTS presence
{
  "header": "max-age=0",
  "max_age": 0
}
CORE-SECURITY-003 — Content-Security-Policy / framing policy
{
  "csp_present": false,
  "csp_report_only": false,
  "frame_ancestors": false,
  "x_frame_options": null
}
CORE-SECURITY-004 — Security-relevant cookie attributes
{
  "cookies": [
    {
      "classification": "session_like",
      "domain": null,
      "httponly": false,
      "max_age_present": false,
      "name": "sessionid",
      "path": "/",
      "samesite": null,
      "secure": false
    }
  ],
  "failing": [
    "sessionid"
  ],
  "warning": []
}
CORE-SECURITY-005 — Referrer / MIME hygiene headers
{
  "missing": [
    "referrer-policy",
    "x-content-type-options"
  ],
  "referrer_policy": null,
  "x_content_type_options": null
}
CORE-SECURITY-006 — security.txt validity (RFC 9116)
{
  "canonical_location": false,
  "canonical_uris": [],
  "contact": true,
  "expired": true,
  "expires": "2020-01-01T00:00:00Z",
  "found_url": "https://example.com/security.txt"
}
CORE-SECURITY-007 — Credential-like value exposed in a machine-facing surface
{
  "hit_count": 1,
  "hits": [
    {
      "confidence": "medium",
      "kind": "generic_assignment",
      "length": 48,
      "redacted": "f3a9…b2d4",
      "sha256_prefix": "bc399445",
      "source": "llms.txt",
      "surface_kind": "llms_txt"
    }
  ],
  "surfaces_scanned": 7
}
CORE-SECURITY-008 — Internal network reference exposed
{
  "hits": [
    {
      "host": "10.0.0.5",
      "source": "llms.txt",
      "surface_kind": "llms_txt"
    },
    {
      "host": "169.254.169.254",
      "source": "llms.txt",
      "surface_kind": "llms_txt"
    }
  ],
  "surfaces_scanned": 7
}
CORE-TRUST-001 — Contact/support discoverability
{
  "contact_url": "https://example.com/contact",
  "kind": "page"
}
CORE-TRUST-002 — Shipping policy discoverability
{
  "served_as_html": true,
  "status": 200,
  "text_chars": 300,
  "url": "https://example.com/shipping"
}
CORE-TRUST-003 — Returns/refund policy discoverability
{
  "served_as_html": true,
  "status": 200,
  "text_chars": 312,
  "url": "https://example.com/returns"
}
CORE-TRUST-004 — Privacy policy discoverability
{
  "served_as_html": true,
  "status": 200,
  "text_chars": 303,
  "url": "https://example.com/privacy"
}
CORE-TRUST-005 — Terms/conditions discoverability
{
  "served_as_html": true,
  "status": 200,
  "text_chars": 334,
  "url": "https://example.com/terms"
}
CORE-TRUST-006 — security.txt discoverability
{
  "contact": true,
  "expires": "2020-01-01T00:00:00Z",
  "expires_valid": false,
  "found_url": "https://example.com/security.txt",
  "status": 200
}
CORE-TRUST-007 — Pricing discoverability
{
  "structured_price": 19.99,
  "url": "https://example.com/products/widget"
}

Remediation

Limitations

Agentic Security & Trust

PASSIVE SIGNALS ONLY

SignalValue
Critical0
High1
Medium8
Low3
Web baselinePASS 0 WARN 3 FAIL 2
DisclosurePASS 0 WARN 0 FAIL 1
Data exposurePASS 0 WARN 3 FAIL 0
Prompt surfacePASS 3 WARN 3 FAIL 0
CORE-SECURITY-001 (SEC-WEB-001) — HTTPS baseline PASSIVE_OBSERVED

Status: WARN · Severity: medium · Confidence: high

Fix owner: edge_cdn · Domain: web_baseline

https is served, but http:// answers 200 without redirecting to https.

Remediation: Redirect http:// to https:// (301) at the edge.

Limitations: Passive signal only. Scovant Core did not authenticate, submit forms or invoke tools; observed authorization behaviour is not tested.

CORE-SECURITY-002 (SEC-WEB-002) — HSTS presence PASSIVE_OBSERVED

Status: WARN · Severity: low · Confidence: high

Fix owner: edge_cdn · Domain: web_baseline

HSTS missing, unparsable or max-age below one day.

Remediation: Send Strict-Transport-Security: max-age=31536000 (add includeSubDomains once every subdomain is https).

Limitations: Passive signal only. Scovant Core did not authenticate, submit forms or invoke tools; observed authorization behaviour is not tested.

CORE-SECURITY-003 (SEC-WEB-003) — Content-Security-Policy / framing policy PASSIVE_OBSERVED

Status: FAIL · Severity: medium · Confidence: high

Fix owner: frontend · Domain: web_baseline

Neither Content-Security-Policy nor X-Frame-Options is sent.

Remediation: Send a Content-Security-Policy with frame-ancestors, or at least X-Frame-Options: DENY.

Limitations: Passive signal only. Scovant Core did not authenticate, submit forms or invoke tools; observed authorization behaviour is not tested.

CORE-SECURITY-004 (SEC-WEB-004) — Security-relevant cookie attributes PASSIVE_OBSERVED

Status: FAIL · Severity: medium · Confidence: high

Fix owner: backend · Domain: web_baseline

Session-like cookie(s) without Secure+HttpOnly: sessionid.

Remediation: Set Secure and HttpOnly on session cookies; add SameSite=Lax or Strict.

Limitations: Passive signal only. Scovant Core did not authenticate, submit forms or invoke tools; observed authorization behaviour is not tested.

CORE-SECURITY-005 (SEC-WEB-005) — Referrer / MIME hygiene headers PASSIVE_OBSERVED

Status: WARN · Severity: low · Confidence: high

Fix owner: edge_cdn · Domain: web_baseline

Missing: referrer-policy, x-content-type-options.

Remediation: Send Referrer-Policy: strict-origin-when-cross-origin and X-Content-Type-Options: nosniff.

Limitations: Passive signal only. Scovant Core did not authenticate, submit forms or invoke tools; observed authorization behaviour is not tested.

CORE-SECURITY-006 (SEC-TXT-001) — security.txt validity (RFC 9116) DECLARED

Status: FAIL · Severity: medium · Confidence: high

Fix owner: security · Domain: disclosure

Expires is in the past.

Remediation: Set Expires to a future date (RFC 3339) and keep it fresh.

Limitations: Passive signal only. Scovant Core did not authenticate, submit forms or invoke tools; observed authorization behaviour is not tested.

CORE-SECURITY-007 (MACHINE-DATA-001) — Credential-like value exposed in a machine-facing surface DECLARED

Status: WARN · Severity: medium · Confidence: medium

Fix owner: backend · Domain: data_exposure

1 possible credential-like value(s) (heuristic match, redacted).

Remediation: Confirm whether the value is live; rotate and remove if so.

Limitations: Passive signal only. Scovant Core reports declaration and exposure in public machine-facing documents; it never tests exploitability, authenticates or invokes tools.

CORE-SECURITY-008 (MACHINE-DATA-002) — Internal network reference exposed DECLARED

Status: WARN · Severity: low · Confidence: high

Fix owner: devops · Domain: data_exposure

2 internal network reference(s) in public machine-facing documents.

Remediation: Remove internal hostnames/addresses from public documents; keep them in internal docs only.

Limitations: Passive signal only. Scovant Core reports declaration and exposure in public machine-facing documents; it never tests exploitability, authenticates or invokes tools.

CORE-SECURITY-009 (MACHINE-DATA-003) — Privileged endpoint advertised to agents DECLARED

Status: WARN · Severity: medium · Confidence: medium

Fix owner: mcp · Domain: data_exposure

1 administrative/destructive interface(s) advertised to agents.

Remediation: Keep admin/destructive interfaces out of public agent metadata, or gate them behind explicit authorization and confirmation.

Limitations: Passive signal only. Scovant Core reports declared MCP server names and OpenAPI paths; the privileged/destructive classification is a NAME-BASED GUESS, never an inspection of actual behaviour, and it never authenticates, invokes a tool or submits a request.

CORE-SECURITY-013 (PROMPT-SURFACE-003) — External transmission instruction DECLARED

Status: WARN · Severity: high · Confidence: medium

Fix owner: content · Domain: prompt_surface

Machine-facing text instructs sending data to an external host.

Remediation: Remove instructions that direct agents to third-party endpoints.

Limitations: Heuristic passive indicator only: pattern matches over public machine-facing text. It never executes an instruction, never tests a real agent, and a WARN is not a vulnerability claim.

CORE-SECURITY-014 (PROMPT-SURFACE-004) — Policy/role override language DECLARED

Status: WARN · Severity: medium · Confidence: low

Fix owner: content · Domain: prompt_surface

Role/policy override language in machine-facing text.

Remediation: Remove the phrase(s).

Limitations: Heuristic passive indicator only: pattern matches over public machine-facing text. It never executes an instruction, never tests a real agent, and a WARN is not a vulnerability claim.

CORE-SECURITY-016 (PROMPT-SURFACE-006) — Tool/server description trust risk DECLARED

Status: WARN · Severity: medium · Confidence: medium

Fix owner: mcp · Domain: prompt_surface

Tool/server description carries instructions unrelated to its purpose or obfuscated text.

Remediation: Descriptions must describe the tool only; strip imperatives and hidden Unicode.

Limitations: Heuristic passive indicator only: pattern matches over declared MCP server and WebMCP tool descriptions. It never executes an instruction, never invokes a tool, and a WARN is not a vulnerability claim.

This section evaluates tested AI-agent security controls and machine-facing security signals. It is not an overall website or application security rating.

Not tested by Scovant Core

Core vs Cloud

CapabilityCoreCloud
HTTP reachability
robots.txt
Sitemap
llms.txt
Structured data (JSON-LD)
Product/Offer data
Static crawler policy
Content-Signal
MCP discovery
WebMCP static presence
OpenAPI presence
OAuth authorization-server / protected-resource metadata
UCP profile validity✅ (experimental)
Agent discovery surface (A2A cards, AI-plugin, agents.json, Agent Skills)✅ (experimental)
Core Score
Cloud = observed, reproducible, cross-provider, longitudinal
Cloud's full compatibility score
Cloud's full production ruleset
Observed WAF/bot-firewall behavior
Real crawler network access
Browser-based agent simulation
Multi-model execution
MCP tool invocation
WebMCP tool execution/state parity
Tool/UI parity checking
Checkout/task completion
CAPTCHA/challenge behavior
Verified-agent access
Failure attribution
Temporal stability / regressions
Scheduled monitoring
Alerts/webhooks
Hosted, shareable reports
Contextual fix plan

Scovant Core measures passive, machine-facing signals. Scovant Cloud verifies how real agents actually behave, across providers, browser runtimes, security layers and time.

Methodology

Category weights are 25/25/20/15/15. Each check contributes PASS = 1, WARN = 0.5, FAIL = 0 to its category; ERROR lowers coverage (a document that could not be read counts against evidence), and N/A is excluded entirely. A scan scores INSUFFICIENT_EVIDENCE below a 60% coverage floor of its applicable weight. A full-selection scan that clears that floor but falls short of 85% coverage, or that hit any ERROR, is reported as DEGRADED (a score, no letter grade) rather than being silently graded on incomplete evidence. Running with checks narrowed or widened via --include/--exclude/--experimental instead reports a NOT_CANONICAL Subset Diagnostic Score over that subset, not the full Core Score. Full reference: docs/methodology.md.

Provenance

scan_id
local-golden
started_at
2026-09-04T00:00:00Z
completed_at
2026-09-04T00:00:00Z
schema_version
1.1
core_version
0.5.0
profile_detector_version
1.0
ruleset_version
2026.10
ruleset_digest
fd062c67627f
python
<runtime>
platform
<runtime>
user_agent
ScovantCore/0.5.0 (+https://github.com/Scovant/scovant-core)
timeout
60.0
max_pages
5
network_mode
fixture
experimental
False
allow_private_networks
False
scan_scope
CANONICAL
included_checks
[]
excluded_checks
[]
error_count
0
evidence_min_coverage
0.6
canonical_min_coverage
0.85
dependencies
<runtime>
environment_digest
<runtime>