zuplo.com Website

CachedScored . Refresh available now. This is cache-reuse eligibility; a fresh audit is still subject to service limits.Markdown · JSON
91site score

42 global-ready

relative to the checks that apply to this site; global measures it against a maximally agent-ready site. Website https://zuplo.com/.

Checks by category

  1. C1

    Discoverability

    6 / 6 checks pass

    /robots.txt present SHOULD PASS

    Goal: Publish robots.txt and state your crawl policy explicitly.

    Result: Verified (https://zuplo.com/robots.txt -> 200)

    Resources: RFC 9309 · Fix skill

    /sitemap.xml present MAY PASS

    Goal: Publish sitemap.xml so agents can enumerate your content URLs.

    Result: Verified (https://zuplo.com/sitemap.xml -> 200)

    Resources: sitemaps.org · Fix skill

    Homepage sends RFC 8288 Link headers pointing at agent resources SHOULD PASS

    Goal: Advertise machine surfaces in a Link response header on / for header-only discovery.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: RFC 8288 (Link) · RFC 8631 (service links) · RFC 9727 (api-catalog) · Fix skill

    Root HTML links to machine surfaces via <link rel> SHOULD PASS

    Goal: Point link rel elements at your machine surfaces from the root HTML head.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: RFC 8631 (service-desc/doc) · Fix skill

    DNS for AI Discovery (DNS-AID) records under _agents (IETF draft) MAY N/A

    Goal: Publish DNSSEC-signed SVCB records under _agents for DNS-level agent discovery.

    Result: Not implemented, optional (no DNS-AID records)

    Resources: DNS-AID draft · Fix skill

    Unknown paths return HTTP 404 or 410 SHOULD PASS

    Goal: Return a real HTTP 404 or 410 for unknown paths instead of a 200 SPA shell.

    Result: Verified (https://zuplo.com/anc-web-audit-no-such-page -> 404)

    Resources: RFC 9110 status codes · Fix skill

    404 body is markdown with a recovery link SHOULD PASS

    Goal: Serve a short markdown 404 that links at least one agent recovery surface.

    Result: Verified (https://zuplo.com/anc-web-audit-no-such-page -> 404)

    Resources: llmstxt.org · Fix skill

    pass
  2. C2

    Content for agents

    15 / 15 checks pass

    /llms.txt present with a summary and link index SHOULD PASS

    Goal: Serve /llms.txt with a title, summary, and categorized link index.

    Result: Verified (https://zuplo.com/llms.txt -> 200)

    Resources: llmstxt.org · Fix skill

    /llms-full.txt present (single-fetch full corpus) MAY N/A

    Goal: Serve the whole docs corpus as markdown at /llms-full.txt for one-fetch ingestion.

    Result: Not implemented, optional (https://zuplo.com/llms-full.txt -> 404 (status 404 not in [200]))

    Resources: llmstxt.org · Fix skill

    Accept text/markdown content negotiation returns markdown SHOULD PASS

    Goal: Honor Accept text/markdown on content URLs with raw markdown, not HTML chrome.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: RFC 7763 (text/markdown) · Fix skill

    Per-section llms-full.txt files resolve under content subdirectories MAY N/A

    Goal: Serve a scoped llms-full.txt corpus inside each major content section.

    Result: Not applicable (root llms-full.txt not present)

    Resources: llmstxt.org · Fix skill

    llms.txt has H1, summary, and a link index SHOULD PASS

    Goal: Structure /llms.txt with an H1, a blockquote summary, and a markdown link index.

    Result: Verified (https://zuplo.com/llms.txt -> error)

    Resources: llmstxt.org · Fix skill

    llms.txt has a when-to-use or programmatic-access section SHOULD PASS

    Goal: Tell agents when to use the MCP or docs from a short llms.txt heading.

    Result: Verified (https://zuplo.com/llms.txt -> error)

    Resources: llmstxt.org · Fix skill

    Bare CLI User-Agent receives the markdown twin MAY N/A

    Goal: Serve the markdown twin to shell HTTP clients that state no content-type preference.

    Result: Not implemented, optional (https://zuplo.com/ -> 200 (content-type "text/html; charset=utf-8" !~ /markdown|text/plain/))

    Resources: RFC 7763 (text/markdown) · RFC 9110 (User-Agent) · Fix skill

    Accept text/plain returns the markdown twin MAY PASS

    Goal: Treat Accept text/plain as a request for the raw markdown source.

    Result: Verified (https://zuplo.com/ -> 406)

    Resources: RFC 7763 (text/markdown) · Fix skill

    Negotiated responses carry Vary Accept, User-Agent SHOULD PASS

    Goal: Emit Vary Accept, User-Agent so shared caches never serve one client the wrong variant.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: RFC 9110 (Vary) · Fix skill

    AI user-fetch User-Agent receives the markdown twin MAY PASS

    Goal: Serve the markdown twin to AI on-demand user-fetchers that state no content-type preference.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: RFC 7763 (text/markdown) · OpenAI bots and User-Agents · Fix skill

    Root HTML has a descriptive <meta name="description"> SHOULD PASS

    Goal: Add a meta description naming what the service does and its agent entry points.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: MDN meta description · Fix skill

    Root HTML embeds Schema.org JSON-LD MAY PASS

    Goal: Embed Schema.org JSON-LD so agents get typed facts without inference.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: Schema.org · Fix skill

    Root HTML has an H1 and readable text without JavaScript SHOULD PASS

    Goal: Put an H1 and enough visible text in the raw root HTML that a non-JS agent can read the page.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: llmstxt.org · Fix skill

    Root HTML uses semantic landmarks MAY PASS

    Goal: Use semantic landmarks so the HTML path is parseable structure, not div soup.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: MDN content sectioning · Fix skill

    Root HTML has a <noscript> with machine entry points SHOULD PASS

    Goal: Give non-JS agents a noscript block listing your machine entry points.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: MDN noscript · Fix skill

    Per-section llms.txt files resolve under content subdirectories MAY PASS

    Goal: Serve a scoped llms.txt inside each major content section.

    Result: Verified (https://zuplo.com/docs/llms.txt -> 200)

    Resources: llmstxt.org · Fix skill

    Markdown twin carries YAML frontmatter MAY PASS

    Goal: Prefix the markdown twin with a YAML frontmatter block so agents read page metadata without parsing the body.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: YAML front matter (Jekyll) · RFC 7763 (text/markdown) · Fix skill

    llms.txt links resolve SHOULD PASS

    Goal: Make every markdown href in /llms.txt fetchable.

    Result: Verified (https://zuplo.com/openapi.json -> 200)

    Resources: llmstxt.org · Fix skill

    pass
  3. C3

    Bot & crawl policy

    3 / 3 checks pass

    AI user-fetch User-Agent can reach the homepage SHOULD PASS

    Goal: Let on-demand user-fetchers GET / with Accept */* and receive 2xx, not a challenge page.

    Result: Verified (https://zuplo.com/ -> 200)

    Resources: OpenAI user-fetchers · Fix skill

    robots.txt declares AI-crawler rules (RFC 9309) SHOULD PASS

    Goal: State your AI-crawler policy in robots.txt with explicit User-agent rules.

    Result: Verified (https://zuplo.com/robots.txt -> 200)

    Resources: RFC 9309 · Fix skill

    robots.txt declares Content-Signal AI-usage preferences SHOULD PASS

    Goal: Declare Content-Signal AI-usage preferences in robots.txt.

    Result: Verified (https://zuplo.com/robots.txt -> 200)

    Resources: contentsignals.org · Fix skill

    Web Bot Auth signature directory present (informational) MAY N/A

    Goal: Publish an HTTP Message Signatures directory if your site sends signed bot traffic.

    Result: Not implemented, optional (https://zuplo.com/.well-known/http-message-signatures-directory -> 404 (status 404 not in [200]))

    Resources: Web Bot Auth draft · Fix skill

    /.well-known/security.txt present (RFC 9116) MAY N/A

    Goal: Publish security.txt with a Contact and Expires field.

    Result: Not implemented, optional (https://zuplo.com/.well-known/security.txt -> 404 (status 404 not in [200]))

    Resources: RFC 9116 · Fix skill

    pass
  4. C4

    API

    2 / 4 checks pass

    An OpenAPI description is published MUST PASS

    Goal: Publish an OpenAPI description so non-MCP agents can call your HTTP API.

    Result: Verified (https://zuplo.com/openapi.json -> 200)

    Resources: OpenAPI 3.1 · Fix skill

    /.well-known/api-catalog published (RFC 9727) MAY PASS

    Goal: Serve an RFC 9727 api-catalog linkset indexing your API descriptions.

    Result: Verified (https://zuplo.com/.well-known/api-catalog -> 200)

    Resources: RFC 9727 · Fix skill

    Referenced JSON Schemas resolve as application/schema+json MAY N/A

    Goal: Serve the JSON Schemas your API references so agents can validate payloads pre-flight.

    Result: Not implemented, optional (https://zuplo.com/api/schema/input.json -> 404 (status 404 not in [200]))

    Resources: JSON Schema · Fix skill

    API responses advertise rate-limit headers SHOULD MISSING

    Goal: Advertise remaining quota on API responses so agents can back off instead of retrying blindly.

    Result: Not found (https://zuplo.com/mcp/docs -> 404 (no rate-limit header))

    Fix: Send IETF RateLimit headers (`RateLimit-Limit`, `RateLimit-Remaining`, `RateLimit-Reset`) or the common `X-RateLimit-*` aliases on API responses. A 429 should also carry `Retry-After`. Without them an agent has no budget and will retry until it is locked out.

    Resources: IETF RateLimit header draft · Fix skill

    API client errors return JSON, not HTML SHOULD BROKEN

    Goal: Return a JSON error body on client-error API responses so agents can parse the failure.

    Result: Present but broken (https://zuplo.com/mcp/docs -> 404 (non-JSON error body))

    Fix: On a client-error API response (4xx), return `Content-Type: application/json` and a JSON object (for example `{ "error": { "code": "not_found", "message": "..." } }`), not an HTML error page. Agents cannot recover from a soft-HTML 404. The audit probes a documented OpenAPI 4xx GET when one exists, otherwise `GET /anc-web-audit-no-such-api`.

    Resources: RFC 9457 (problem+json) · Fix skill

    partial
  5. C5

    MCP

    1 / 1 checks pass

    initialize handshake returns serverInfo + protocolVersion MUST N/A

    Goal: Answer JSON-RPC initialize with serverInfo and protocolVersion so clients can begin a session.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP lifecycle · Fix skill

    server/discover answers with server identity on the modern lane SHOULD N/A

    Goal: Answer server/discover with supported versions, capabilities, and server identity.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP lifecycle (2026-07-28) · Fix skill

    initialize advertises capabilities (tools / resources / prompts) SHOULD N/A

    Goal: Advertise the capability groups your MCP server implements in the initialize result.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP lifecycle · Fix skill

    tools/list returns a tools array with input schemas MUST N/A

    Goal: Return tools/list entries with name, description, and a JSON inputSchema.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP tools · Fix skill

    resources/list returns at least one resource when advertised SHOULD N/A

    Goal: Honor capabilities.resources with a non-empty resources/list result.

    Result: Not applicable (neither initialize nor server/discover advertises capabilities.resources)

    Resources: MCP resources · Fix skill

    header-routed tools/list (2026-07-28) returns tools without initialize MUST N/A

    Goal: Answer a modern header-routed tools/list without requiring an initialize handshake.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP lifecycle (2026-07-28) · MCP tools (2026-07-28) · Fix skill

    unknown JSON-RPC method returns -32601 SHOULD N/A

    Goal: Reject unknown JSON-RPC methods with error -32601 instead of a hang or 500.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: JSON-RPC 2.0 · Fix skill

    a non-JSON body draws -32700 (or a typed HTTP 400/415 refusal) SHOULD N/A

    Goal: Refuse an unparseable request body with a parse-error envelope or a typed HTTP refusal.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: JSON-RPC 2.0 · Fix skill

    a batch carrying a modern-envelope request is rejected -32600 SHOULD N/A

    Goal: Refuse JSON array batches that carry modern-era envelopes with -32600.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: JSON-RPC 2.0 · MCP transports (2026-07-28) · Fix skill

    tools/call with an unknown tool name returns -32602 SHOULD N/A

    Goal: Reject an unknown tool name with -32602 instead of a hang, a 500, or a fake result.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP tools · JSON-RPC 2.0 · Fix skill

    an unknown method on the modern lane returns -32601 SHOULD N/A

    Goal: Reject unknown header-routed methods with -32601 on the 2026-07-28 lane.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: JSON-RPC 2.0 · MCP lifecycle (2026-07-28) · Fix skill

    _meta missing clientCapabilities is rejected (-32602 or -32600) SHOULD N/A

    Goal: Enforce the mandatory clientCapabilities key on every modern request.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP lifecycle (2026-07-28) · Fix skill

    an Mcp-Method header disagreeing with the body method draws -32020 SHOULD N/A

    Goal: Validate the SEP-2243 header mirror between Mcp-Method and the body method.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP lifecycle (2026-07-28) · Fix skill

    an unsupported protocol version is rejected -32022 with data.supported SHOULD N/A

    Goal: Refuse unsupported protocol version claims with -32022 and advertise the served revisions.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP lifecycle (2026-07-28) · Fix skill

    modern resources/read with an unknown URI returns -32602 SHOULD N/A

    Goal: Answer an unknown resource URI with the typed miss code, not a hang or a fake result.

    Result: Not applicable (neither initialize nor server/discover advertises capabilities.resources)

    Resources: MCP resources (2026-07-28) · JSON-RPC 2.0 · Fix skill

    a JSON-only Accept is answered without SSE framing SHOULD N/A

    Goal: Serve a single application/json response to a client whose Accept names only application/json.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP transports · RFC 9110 section 12.5.1 (Accept) · Fix skill

    an unsatisfiable Accept draws a 406 rather than an unasked-for type SHOULD N/A

    Goal: Refuse an Accept you cannot satisfy with 406, never a 200 carrying a type the client did not request.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: RFC 9110 section 15.5.7 (406 Not Acceptable) · MCP transports · Fix skill

    GET on the MCP endpoint answers fast (not a held-open hang) SHOULD N/A

    Goal: Answer GET on the MCP endpoint fast (a fast-fail status or a documented surface), never a held-open hang.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MCP transports · Fix skill

    CORS preflight (OPTIONS) succeeds with Access-Control-Allow-* headers SHOULD N/A

    Goal: Serve one consistent CORS posture on the MCP endpoint, full preflight support or none.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MDN CORS preflight · Fix skill

    POST response carries Access-Control-Allow-Origin SHOULD N/A

    Goal: Mirror the declared CORS posture on the actual MCP POST response.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: MDN CORS · Fix skill

    A .well-known MCP server card is published (SEP-1649) SHOULD N/A

    Goal: Publish an MCP server card at the canonical SEP-1649 path.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: SEP-1649 · Fix skill

    Legacy MCP card paths redirect to the canonical card MAY N/A

    Goal: Point every legacy MCP card path at the canonical card instead of serving its own copy.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: SEP-1649 · Fix skill

    A human/agent usage doc for the server resolves MAY N/A

    Goal: Publish a one-fetch markdown usage doc for your MCP server.

    Result: Not applicable (no MCP endpoint discovered)

    Resources: anc.dev example · Fix skill

    Root HTML exposes WebMCP browser tools MAY PASS

    Goal: Expose page tools to browser agents via WebMCP.

    Result: Verified (https://zuplo.com/ -> 200 (modelContext API reference))

    Resources: WebMCP spec · Fix skill

    pass
  6. C6

    Agent discovery & auth

    3 / 3 checks pass

    OAuth/OIDC discovery metadata published MAY PASS

    Goal: Publish OAuth/OIDC discovery metadata if agents authenticate to your service.

    Result: Verified (https://zuplo.com/.well-known/openid-configuration -> 200)

    Resources: RFC 8414 · Fix skill

    OAuth Protected Resource Metadata published (RFC 9728) MAY N/A

    Goal: Publish RFC 9728 protected-resource metadata for your authenticated MCP server.

    Result: Not applicable (MCP endpoint does not challenge for auth)

    Resources: RFC 9728 · Fix skill

    /.well-known/ai-catalog.json published (ARD) MAY N/A

    Goal: Publish an Agentic Resource Discovery catalog so agents can enumerate your AI artifacts.

    Result: Not implemented, optional (https://zuplo.com/.well-known/ai-catalog.json -> 404 (status 404 not in [200]))

    Resources: AI Catalog · Fix skill

    A2A Agent Card published for agent-to-agent discovery MAY N/A

    Goal: Publish an A2A Agent Card for agent-to-agent discovery.

    Result: Not implemented, optional (https://zuplo.com/.well-known/agent-card.json -> 404 (status 404 not in [200]))

    Resources: A2A protocol · Fix skill

    Agent-skills discovery index published MAY PASS

    Goal: Publish an agent-skills discovery index so agents can enumerate your skills.

    Result: Verified (https://zuplo.com/.well-known/agent-skills/index.json -> 200)

    Resources: Agent Skills Discovery · Fix skill

    Agent auth/registration metadata doc published MAY PASS

    Goal: Publish an auth.md telling agents how to obtain credentials.

    Result: Verified (https://zuplo.com/auth.md -> 200)

    Resources: anc.dev example · Fix skill

    pass

This scorecard reflects the target's public agent-facing surface at audit time. Re-audit from the control above to refresh it, or call the audit_website MCP tool.