Results for https://www.antler.co/LEVEL1Scanned just now
Basic Web Presence
Discoverability
50
2 pass · 2 fail
Content Accessibility
0
0 pass · 1 fail
Bot Access Control
50
1 pass · 1 fail
Discovery
0
0 pass · 7 fail
Commerce
Not checked
02 / 04 pass
Discoverability
- Goal
- Publish a robots.txt so agents and crawlers can discover crawl policy for this origin.
- How to implement
- Create /robots.txt on this origin with at least one User-agent group and sensible Allow/Disallow rules. Serve it as text/plain.
- Resources
- fetchGET /robots.txt200
# Per http://www.robotstxt.org/robotstxt.html User-agent: mauibot Disallow: / User-agent: ahrefsbot Disallow: / User-agent: blexbot Disallow: / User-agent: * Disallow: /admin User-agent: * Crawl-delay: 10 User-agent: * Disallow: /countries-hub/ Disallow: /disclosure/
- concluderobots.txt present with User-agent directive
{"contentType":"text/plain; charset=utf-8"}
- Goal
- Expose a valid XML sitemap so agents can enumerate important URLs.
- How to implement
- Add a valid XML sitemap and reference it with a Sitemap: line in robots.txt (or serve /sitemap.xml).
- Resources
- fetchGET /sitemap.xml200
<?xml version="1.0" encoding="UTF-8"?> <urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml"> <url> <loc> https://www.antler.co </loc> </url> <url> <loc> https://www.antler.co/about </loc> </url> <url> <loc> https://www.antler.co/careers </loc> </url> <url> <loc> https://www.antler.co/elevate - parseValid XML sitemap structure detected
- concludeSitemap OK at https://www.antler.co/sitemap.xml
{"url":"https://www.antler.co/sitemap.xml"}
- Goal
- Advertise agent-useful Link relations on the homepage so discovery is machine-readable.
- Issue
- Link header present but no agent-useful relations
- How to implement
- Add RFC 8288 Link response headers on GET / for agent-useful relations such as api-catalog, describedby, service-desc, or service-doc.
- Resources
- fetchGET /200
- parseParsed 3 Link entries
- concludeNo agent-useful Link relations
{"links":[{"rel":"preconnect","href":"https://cdn.prod.website-files.com"},{"rel":"preload","href":"https://cdn.prod.website-files.com/68c1084e137e63873a526f0f/css/antler-lumos.shared.6543bae57.min.css"},{"rel":"preload","href":"https://cdn.jsdelivr.net/npm/swiper@8/swiper-bundle.min.css"}]}
- Goal
- Publish DNS-AID SVCB records under _agents so agents can find services via DNS.
- Issue
- No DNSSEC-validated DNS-AID SVCB/HTTPS/TXT ServiceMode records found
- How to implement
- Publish DNSSEC-validated SVCB/HTTPS records for _index._agents, _mcp._agents, and/or _a2a._agents on the apex (and www if used).
- Resources
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- dnsAD=true status=3 answers=0
- concludeNo DNSSEC-validated (AD=true) ServiceMode DNS-AID records
00 / 01 pass
Content Accessibility
- Goal
- Serve text/markdown when clients Accept: text/markdown so agents can read a clean page summary.
- Issue
- Homepage does not return text/markdown for Accept: text/markdown
- How to implement
- When GET / is requested with Accept: text/markdown, respond with Content-Type including text/markdown (e.g. Cloudflare Markdown for Agents or an equivalent).
- Resources
- fetchGET /200
<!DOCTYPE html><!-- Last Published: Wed Jul 22 2026 18:02:10 GMT+0000 (Coordinated Universal Time) --><!--$--> <html data-wf-domain="www.antler.co" data-wf-page="68c1093f38180cc137714618" data-wf-site="68c1084e137e63873a526f0f" lang="en"><!--$--><head><meta charset="utf-8"/><!--$--><link href="https://cdn.prod.website-files.com" rel="preconnect" crossorigin="anonymous"/><!--/$--><title>Antler | Where Founders Go Further, Faster</title><meta content="Antler is the world’s most active early-stage …
- concludeNo markdown negotiation (content-type=text/html; charset=utf-8)
{"status":200,"contentType":"text/html; charset=utf-8"}
01 / 03 pass
Bot Access Control
- Goal
- Declare AI crawler rules in robots.txt so bot access policy is explicit.
- How to implement
- Add explicit User-agent rules for known AI crawlers (GPTBot, ClaudeBot, PerplexityBot, etc.) or a clear User-agent: * policy in robots.txt.
- Resources
- parseParsed 5 user-agent group(s)
- concludeFound AI crawler rules or User-agent: * policy
- Goal
- Publish Content-Signal directives so AI training/search/input preferences are machine-readable.
- Issue
- robots.txt missing Content-Signal ai-train/search/ai-input directives
- How to implement
- Add Content-Signal: lines in robots.txt with ai-train / search / ai-input directives stating your preferences for AI use of the site.
- Resources
- parseContent-Signal lines: 0
- concludeNo Content-Signal directives with ai-train/search/ai-input
- Goal
- Publish an HTTP Message Signatures directory so bots can authenticate cryptographically.
- How to implement
- Serve a valid JWKS directory at /.well-known/http-message-signatures-directory for cryptographic bot authentication.
- Resources
- fetchGET /.well-known/http-message-signatures-directory404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - concludeDirectory missing or invalid — reporting neutral
{"status":404}
00 / 08 pass
Discovery
- Goal
- Publish an RFC 9727 API catalog so agents can discover your API surfaces.
- Issue
- api-catalog not found
- How to implement
- Serve /.well-known/api-catalog as application/linkset+json with a linkset array describing your API surfaces.
- Resources
- fetchGET /.well-known/api-catalog404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - concludeHTTP 404
- Goal
- Publish OAuth/OIDC discovery metadata so agents can authenticate with your APIs.
- Issue
- No OAuth/OIDC discovery metadata with issuer + auth/token endpoints
- How to implement
- Serve /.well-known/openid-configuration or /.well-known/oauth-authorization-server with issuer, authorization_endpoint, and token_endpoint.
- Resources
- fetchGET /.well-known/openid-configuration404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - fetchGET /.well-known/oauth-authorization-server404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - concludeNo valid OAuth/OIDC discovery document
- Goal
- Publish OAuth protected resource metadata so agents know which auth servers protect your API.
- Issue
- oauth-protected-resource missing resource + authorization_servers
- How to implement
- Serve /.well-known/oauth-protected-resource with resource and authorization_servers, and advertise it via WWW-Authenticate where relevant.
- Resources
- fetchGET /.well-known/oauth-protected-resource404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - concludePRM missing or incomplete
- Goal
- Publish /auth.md so agents have human-readable registration and auth guidance.
- Issue
- Need auth.md plus discoverable PRM or agent_auth, with registration methods documented
- How to implement
- Serve /auth.md as text/markdown documenting how agents register/authenticate, discoverable via PRM and/or AS metadata agent_auth.
- Resources
- fetchGET /auth.md404
<!DOCTYPE html><!-- Last Published: Wed Jul 22 2026 18:02:10 GMT+0000 (Coordinated Universal Time) --><html data-wf-domain="www.antler.co" data-wf-page="68c1084e137e63873a526f02" data-wf-site="68c1084e137e63873a526f0f" lang="en"><head><meta charset="utf-8"/><link href="https://cdn.prod.website-files.com" rel="preconnect" crossorigin="anonymous"/><title>Not Found</title><meta content="Not Found" property="og:title"/><meta content="Not Found" name="twitter:title"/><meta content="width=device-width…
- fetchGET /.well-known/oauth-protected-resource404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - parseauthMd=false prm=false agent_auth=false registrationDocs=true
- concludeauth.md discovery incomplete
{"authOk":false,"prmOk":false,"agentAuth":false,"mentionsRegistration":true}
- Goal
- Publish an MCP server card and reachable Streamable HTTP endpoint so agents can list tools.
- Issue
- No MCP server card (serverInfo.name/name) or live Streamable HTTP endpoint
- How to implement
- Publish /.well-known/mcp/server-card.json (or mcp.json) with serverInfo.name, and expose a Streamable HTTP MCP endpoint that answers initialize + tools/list.
- Resources
- fetchGET /.well-known/mcp.json404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - fetchGET /.well-known/mcp/server-cards.json404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - fetchGET /.well-known/mcp/server-card.json404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - fetchPOST /api/mcp/mcp405
<html> <head><title>405 Not Allowed</title></head> <body> <center><h1>405 Not Allowed</h1></center> <hr><center>openresty</center> </body> </html>
- concludeNo MCP card or live endpoint
- Goal
- Publish an A2A agent card so agents can discover your A2A interface.
- How to implement
- Serve /.well-known/agent-card.json with name, version, and supportedInterfaces per the A2A Agent Card spec.
- Resources
- concludeCheck disabled for this scan
- Goal
- Publish an agent-skills index so agents can find skill docs for this origin.
- Issue
- No valid agent-skills index.json (v0.2 skills array)
- How to implement
- Serve /.well-known/agent-skills/index.json (v0.2) listing skills agents can use against this origin.
- Resources
- fetchGET /.well-known/agent-skills/index.json404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - fetchGET /.well-known/skills/index.json404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - concludeNo valid agent-skills index
- Goal
- Register WebMCP tools on the homepage so headless scanners discover browser-side tools.
- Issue
- Homepage has no WebMCP tools on navigator.modelContext
- How to implement
- On page load, register at least one WebMCP tool via navigator.modelContext (provideContext/registerTool) so headless scanners can discover it.
- Resources
- fetchLaunching Browser Rendering session for WebMCP inspection
- parseCaptured 0 WebMCP tool registration(s)
- concludeNo tools recorded via provideContext/registerTool
00 / 05 pass
Commerce
- Goal
- Advertise x402 payment challenges on payable API routes so agents can pay per request.
- How to implement
- Return HTTP 402 with a valid x402 payment challenge (PAYMENT-REQUIRED / payment required body) on payable API routes such as /api/v1.
- Resources
- concludeCoinbase Bazaar discovery not queried (skipped in v1 scanner)
- fetchGET /200
<!DOCTYPE html><!-- Last Published: Wed Jul 22 2026 18:02:10 GMT+0000 (Coordinated Universal Time) --><!--$--> <html data-wf-domain="www.antler.co" data-wf-page="68c1093f38180cc137714618" data-wf-site="68c1084e137e63873a526f0f" lang="en"><!--$--><head><meta charset="utf-8"/><!--$--><link href="https://cdn.prod.website-files.com" rel="preconnect" crossorigin="anonymous"/><!--/$--><title>Antler | Where Founders Go Further, Faster</title><meta content="Antler is the world’s most active early-stage …
- fetchGET /api404
<!DOCTYPE html><!-- Last Published: Wed Jul 22 2026 18:02:10 GMT+0000 (Coordinated Universal Time) --><html data-wf-domain="www.antler.co" data-wf-page="68c1084e137e63873a526f02" data-wf-site="68c1084e137e63873a526f0f" lang="en"><head><meta charset="utf-8"/><link href="https://cdn.prod.website-files.com" rel="preconnect" crossorigin="anonymous"/><title>Not Found</title><meta content="Not Found" property="og:title"/><meta content="Not Found" name="twitter:title"/><meta content="width=device-width…
- fetchGET /api/v1404
<!DOCTYPE html><!-- Last Published: Wed Jul 22 2026 18:02:10 GMT+0000 (Coordinated Universal Time) --><html data-wf-domain="www.antler.co" data-wf-page="68c1084e137e63873a526f02" data-wf-site="68c1084e137e63873a526f0f" lang="en"><head><meta charset="utf-8"/><link href="https://cdn.prod.website-files.com" rel="preconnect" crossorigin="anonymous"/><title>Not Found</title><meta content="Not Found" property="og:title"/><meta content="Not Found" name="twitter:title"/><meta content="width=device-width…
- concludeNo 402 x402 challenge found
- Goal
- Declare Machine Payments Protocol extensions in OpenAPI so payable ops are discoverable.
- How to implement
- Serve /openapi.json with x-payment-info extensions describing payable operations.
- Resources
- fetchGET /openapi.json404
<!DOCTYPE html><!-- Last Published: Wed Jul 22 2026 18:02:10 GMT+0000 (Coordinated Universal Time) --><html data-wf-domain="www.antler.co" data-wf-page="68c1084e137e63873a526f02" data-wf-site="68c1084e137e63873a526f0f" lang="en"><head><meta charset="utf-8"/><link href="https://cdn.prod.website-files.com" rel="preconnect" crossorigin="anonymous"/><title>Not Found</title><meta content="Not Found" property="og:title"/><meta content="Not Found" name="twitter:title"/><meta content="width=device-width…
- concludeHTTP 404
- Goal
- Publish Universal Commerce Protocol metadata for agent commerce discovery.
- How to implement
- Serve /.well-known/ucp with protocol_version and services.
- Resources
- fetchGET /.well-known/ucp404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - concludeHTTP 404
- Goal
- Publish Agentic Commerce Protocol metadata for agent commerce discovery.
- How to implement
- Serve /.well-known/acp.json with protocol name/version, api_base_url, transports, and capabilities.
- Resources
- fetchGET /.well-known/acp.json404
<!DOCTYPE html> <html> <body> <p>Invalid .well-known request</p> </body> </html> - concludeHTTP 404
- Goal
- Advertise AP2 extensions on the A2A agent card for agent payment flows.
- How to implement
- Extend /.well-known/agent-card.json with an AP2 extension that declares a role.
- Resources
- concludeCheck disabled for this scan
Improve the score
Next: Level 2 — Bot-Aware
Publish Content-Signal directives in robots.txt
Next level
Level 2 — Bot-Aware