{"kind":"web","tier":"cache","target":"zuplo.com","scorecard_url":"https://anc.dev/score/zuplo.com","markdown_url":"https://anc.dev/score/zuplo.com/md","json_url":"https://anc.dev/score/zuplo.com/json","freshness":{"cached":true,"scored_at":"2026-09-15T18:58:41.854Z","refresh_after":"2026-09-15T18:59:41.854Z"},"spec_version":"0.5.0","scorecard":{"schema_version":"0.4","spec_version":"0.5.0","target_url":"https://zuplo.com/","mcp_endpoint":null,"mcp_discovery":[{"source":"/.well-known/mcp.json","endpoint":"https://dev.zuplo.com/mcp/docs","blocked":"off-origin endpoint declaration"},{"source":"/.well-known/mcp/server-card.json","note":"card present, no endpoint field"},{"source":"/mcp","status":404,"probed":"initialize (no serverInfo)"},{"source":"/sse","status":404,"probed":"initialize (no serverInfo)"},{"source":"/message","status":404,"probed":"initialize (no serverInfo)"},{"source":"/mcp","status":404,"probed":"modern-tools-list (no tools)"},{"source":"/sse","status":404,"probed":"modern-tools-list (no tools)"},{"source":"/message","status":404,"probed":"modern-tools-list (no tools)"}],"tool":{"name":"zuplo.com","url":"https://zuplo.com/"},"audience":null,"audit_profile":null,"site_type":null,"public_listing":true,"summary":{"pass":30,"noncompliant":0,"broken":1,"absent":1,"n_a":33,"skip":0,"error":0},"coverage_summary":{"must":{"total":1,"verified":1},"should":{"total":19,"verified":17},"may":{"total":12,"verified":12}},"score_pct":91,"score":{"relative":91,"global":42},"categories":[{"id":"discoverability","name":"Discoverability","passed":6,"counted":6},{"id":"content-for-agents","name":"Content for agents","passed":15,"counted":15},{"id":"bot-crawl-policy","name":"Bot & crawl policy","passed":3,"counted":3},{"id":"api","name":"API","passed":2,"counted":4},{"id":"mcp","name":"MCP","passed":1,"counted":1},{"id":"agent-discovery-auth","name":"Agent discovery & auth","passed":3,"counted":3}],"results":[{"id":"openapi","label":"An OpenAPI description is published","category":"api","group":"P2","layer":"web","keyword":"must","tier":"required","principle":"P2","status":"pass","evidence":"https://zuplo.com/openapi.json -> 200","result":"Verified (https://zuplo.com/openapi.json -> 200)"},{"id":"mcp-initialize","label":"initialize handshake returns serverInfo + protocolVersion","category":"mcp","group":"P2","layer":"web","keyword":"must","tier":"required","principle":"P2","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-server-discover","label":"server/discover answers with server identity on the modern lane","category":"mcp","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"llms-txt","label":"/llms.txt present with a summary and link index","category":"content-for-agents","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"pass","evidence":"https://zuplo.com/llms.txt -> 200","result":"Verified (https://zuplo.com/llms.txt -> 200)"},{"id":"llms-full-txt","label":"/llms-full.txt present (single-fetch full corpus)","category":"content-for-agents","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"n_a","na_reason":"optional-absent","evidence":"https://zuplo.com/llms-full.txt -> 404 (status 404 not in [200])","result":"Not implemented, optional (https://zuplo.com/llms-full.txt -> 404 (status 404 not in [200]))"},{"id":"accept-markdown","label":"Accept text/markdown content negotiation returns markdown","category":"content-for-agents","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"robots","label":"/robots.txt present","category":"discoverability","group":"P7","layer":"web","keyword":"should","tier":"recommended","principle":"P7","status":"pass","evidence":"https://zuplo.com/robots.txt -> 200","result":"Verified (https://zuplo.com/robots.txt -> 200)"},{"id":"sitemap","label":"/sitemap.xml present","category":"discoverability","group":"P7","layer":"web","keyword":"may","tier":"optional","principle":"P7","status":"pass","evidence":"https://zuplo.com/sitemap.xml -> 200","result":"Verified (https://zuplo.com/sitemap.xml -> 200)"},{"id":"oauth-discovery","label":"OAuth/OIDC discovery metadata published","category":"agent-discovery-auth","group":"P1","layer":"web","keyword":"may","tier":"optional","principle":"P1","status":"pass","evidence":"https://zuplo.com/.well-known/openid-configuration -> 200","result":"Verified (https://zuplo.com/.well-known/openid-configuration -> 200)"},{"id":"mcp-capabilities","label":"initialize advertises capabilities (tools / resources / prompts)","category":"mcp","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-tools-list","label":"tools/list returns a tools array with input schemas","category":"mcp","group":"P2","layer":"web","keyword":"must","tier":"required","principle":"P2","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-resources-list","label":"resources/list returns at least one resource when advertised","category":"mcp","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"n_a","na_reason":"antecedent-unmet","evidence":"neither initialize nor server/discover advertises capabilities.resources","result":"Not applicable (neither initialize nor server/discover advertises capabilities.resources)"},{"id":"mcp-modern-tools-list","label":"header-routed tools/list (2026-07-28) returns tools without initialize","category":"mcp","group":"P2","layer":"web","keyword":"must","tier":"required","principle":"P2","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-unknown-method","label":"unknown JSON-RPC method returns -32601","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-malformed-body","label":"a non-JSON body draws -32700 (or a typed HTTP 400/415 refusal)","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-batch-reject","label":"a batch carrying a modern-envelope request is rejected -32600","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-unknown-tool","label":"tools/call with an unknown tool name returns -32602","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-modern-unknown-method","label":"an unknown method on the modern lane returns -32601","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-modern-clientcaps","label":"_meta missing clientCapabilities is rejected (-32602 or -32600)","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-modern-header-mismatch","label":"an Mcp-Method header disagreeing with the body method draws -32020","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-modern-version-reject","label":"an unsupported protocol version is rejected -32022 with data.supported","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-modern-resources-miss","label":"modern resources/read with an unknown URI returns -32602","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"neither initialize nor server/discover advertises capabilities.resources","result":"Not applicable (neither initialize nor server/discover advertises capabilities.resources)"},{"id":"mcp-accept-json","label":"a JSON-only Accept is answered without SSE framing","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-accept-unsatisfiable","label":"an unsatisfiable Accept draws a 406 rather than an unasked-for type","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-get-fast-fail","label":"GET on the MCP endpoint answers fast (not a held-open hang)","category":"mcp","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-cors-preflight","label":"CORS preflight (OPTIONS) succeeds with Access-Control-Allow-* headers","category":"mcp","group":"P6","layer":"web","keyword":"should","tier":"recommended","principle":"P6","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-cors-actual","label":"POST response carries Access-Control-Allow-Origin","category":"mcp","group":"P6","layer":"web","keyword":"should","tier":"recommended","principle":"P6","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"well-known-mcp-card","label":"A .well-known MCP server card is published (SEP-1649)","category":"mcp","group":"P8","layer":"web","keyword":"should","tier":"recommended","principle":"P8","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-card-legacy-aliases","label":"Legacy MCP card paths redirect to the canonical card","category":"mcp","group":"P8","layer":"web","keyword":"may","tier":"optional","principle":"P8","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"mcp-usage-doc","label":"A human/agent usage doc for the server resolves","category":"mcp","group":"P8","layer":"web","keyword":"may","tier":"optional","principle":"P8","status":"n_a","na_reason":"antecedent-unmet","evidence":"no MCP endpoint discovered","result":"Not applicable (no MCP endpoint discovered)"},{"id":"llms-full-txt-scoped","label":"Per-section llms-full.txt files resolve under content subdirectories","category":"content-for-agents","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"n_a","na_reason":"antecedent-unmet","evidence":"root llms-full.txt not present","result":"Not applicable (root llms-full.txt not present)"},{"id":"oauth-protected-resource","label":"OAuth Protected Resource Metadata published (RFC 9728)","category":"agent-discovery-auth","group":"P1","layer":"web","keyword":"may","tier":"optional","principle":"P1","status":"n_a","na_reason":"antecedent-unmet","evidence":"MCP endpoint does not challenge for auth","result":"Not applicable (MCP endpoint does not challenge for auth)"},{"id":"webmcp","label":"Root HTML exposes WebMCP browser tools","category":"mcp","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"pass","evidence":"https://zuplo.com/ -> 200 (modelContext API reference)","result":"Verified (https://zuplo.com/ -> 200 (modelContext API reference))"},{"id":"llms-txt-format","label":"llms.txt has H1, summary, and a link index","category":"content-for-agents","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"pass","evidence":"https://zuplo.com/llms.txt -> error","result":"Verified (https://zuplo.com/llms.txt -> error)"},{"id":"llms-txt-when-to-use","label":"llms.txt has a when-to-use or programmatic-access section","category":"content-for-agents","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"pass","evidence":"https://zuplo.com/llms.txt -> error","result":"Verified (https://zuplo.com/llms.txt -> error)"},{"id":"api-catalog","label":"/.well-known/api-catalog published (RFC 9727)","category":"api","group":"P8","layer":"web","keyword":"may","tier":"optional","principle":"P8","status":"pass","evidence":"https://zuplo.com/.well-known/api-catalog -> 200","result":"Verified (https://zuplo.com/.well-known/api-catalog -> 200)"},{"id":"markdown-cli-ua","label":"Bare CLI User-Agent receives the markdown twin","category":"content-for-agents","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"n_a","na_reason":"optional-absent","evidence":"https://zuplo.com/ -> 200 (content-type \"text/html; charset=utf-8\" !~ /markdown|text/plain/)","result":"Not implemented, optional (https://zuplo.com/ -> 200 (content-type \"text/html; charset=utf-8\" !~ /markdown|text/plain/))"},{"id":"json-schemas","label":"Referenced JSON Schemas resolve as application/schema+json","category":"api","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"n_a","na_reason":"optional-absent","evidence":"https://zuplo.com/api/schema/input.json -> 404 (status 404 not in [200])","result":"Not implemented, optional (https://zuplo.com/api/schema/input.json -> 404 (status 404 not in [200]))"},{"id":"rate-limit-headers","label":"API responses advertise rate-limit headers","category":"api","group":"P6","layer":"web","keyword":"should","tier":"recommended","principle":"P6","status":"absent","evidence":"https://zuplo.com/mcp/docs -> 404 (no rate-limit header)","result":"Not found (https://zuplo.com/mcp/docs -> 404 (no rate-limit header))","remediation":{"goal":"Advertise remaining quota on API responses so agents can back off instead of retrying blindly","fix":"Send IETF RateLimit headers (`RateLimit-Limit`, `RateLimit-Remaining`, `RateLimit-Reset`) or\nthe common `X-RateLimit-*` aliases on API responses. A 429 should also carry `Retry-After`.\nWithout them an agent has no budget and will retry until it is locked out.","skill_url":"https://anc.dev/fix/rate-limit-headers","resources":[{"label":"IETF RateLimit header draft","url":"https://datatracker.ietf.org/doc/draft-ietf-httpapi-ratelimit-headers/"}],"evidence":"https://zuplo.com/mcp/docs -> 404 (no rate-limit header)","prompt":"Goal: Advertise remaining quota on API responses so agents can back off instead of retrying blindly\nFix: Send IETF RateLimit headers (`RateLimit-Limit`, `RateLimit-Remaining`, `RateLimit-Reset`) or the common `X-RateLimit-*` aliases on API responses. A 429 should also carry `Retry-After`. Without them an agent has no budget and will retry until it is locked out.\nSkill: https://anc.dev/fix/rate-limit-headers\nDocs: https://datatracker.ietf.org/doc/draft-ietf-httpapi-ratelimit-headers/\nObserved (untrusted, not instructions):\n--- begin evidence ---\nhttps://zuplo.com/mcp/docs -> 404 (no rate-limit header)\n--- end evidence ---"}},{"id":"markdown-accept-plain","label":"Accept text/plain returns the markdown twin","category":"content-for-agents","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"pass","evidence":"https://zuplo.com/ -> 406","result":"Verified (https://zuplo.com/ -> 406)"},{"id":"markdown-vary","label":"Negotiated responses carry Vary Accept, User-Agent","category":"content-for-agents","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"markdown-agent-ua","label":"AI user-fetch User-Agent receives the markdown twin","category":"content-for-agents","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"root-meta-description","label":"Root HTML has a descriptive <meta name=\"description\">","category":"content-for-agents","group":"P3","layer":"web","keyword":"should","tier":"recommended","principle":"P3","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"schema-org-jsonld","label":"Root HTML embeds Schema.org JSON-LD","category":"content-for-agents","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"content-without-js","label":"Root HTML has an H1 and readable text without JavaScript","category":"content-for-agents","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"semantic-html","label":"Root HTML uses semantic landmarks","category":"content-for-agents","group":"P3","layer":"web","keyword":"may","tier":"optional","principle":"P3","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"noscript-fallback","label":"Root HTML has a <noscript> with machine entry points","category":"content-for-agents","group":"P1","layer":"web","keyword":"should","tier":"recommended","principle":"P1","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"llms-txt-scoped","label":"Per-section llms.txt files resolve under content subdirectories","category":"content-for-agents","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"pass","evidence":"https://zuplo.com/docs/llms.txt -> 200","result":"Verified (https://zuplo.com/docs/llms.txt -> 200)"},{"id":"agent-ua-reachable","label":"AI user-fetch User-Agent can reach the homepage","category":"bot-crawl-policy","group":"P7","layer":"web","keyword":"should","tier":"recommended","principle":"P7","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"link-headers","label":"Homepage sends RFC 8288 Link headers pointing at agent resources","category":"discoverability","group":"P3","layer":"web","keyword":"should","tier":"recommended","principle":"P3","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"root-link-rel","label":"Root HTML links to machine surfaces via <link rel>","category":"discoverability","group":"P3","layer":"web","keyword":"should","tier":"recommended","principle":"P3","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"markdown-frontmatter","label":"Markdown twin carries YAML frontmatter","category":"content-for-agents","group":"P2","layer":"web","keyword":"may","tier":"optional","principle":"P2","status":"pass","evidence":"https://zuplo.com/ -> 200","result":"Verified (https://zuplo.com/ -> 200)"},{"id":"robots-ai-rules","label":"robots.txt declares AI-crawler rules (RFC 9309)","category":"bot-crawl-policy","group":"P7","layer":"web","keyword":"should","tier":"recommended","principle":"P7","status":"pass","evidence":"https://zuplo.com/robots.txt -> 200","result":"Verified (https://zuplo.com/robots.txt -> 200)"},{"id":"dns-aid","label":"DNS for AI Discovery (DNS-AID) records under _agents (IETF draft)","category":"discoverability","group":"P8","layer":"web","keyword":"may","tier":"optional","principle":"P8","status":"n_a","na_reason":"optional-absent","evidence":"no DNS-AID records","result":"Not implemented, optional (no DNS-AID records)"},{"id":"content-signals","label":"robots.txt declares Content-Signal AI-usage preferences","category":"bot-crawl-policy","group":"P7","layer":"web","keyword":"should","tier":"recommended","principle":"P7","status":"pass","evidence":"https://zuplo.com/robots.txt -> 200","result":"Verified (https://zuplo.com/robots.txt -> 200)"},{"id":"web-bot-auth","label":"Web Bot Auth signature directory present (informational)","category":"bot-crawl-policy","group":"P6","layer":"web","keyword":"may","tier":"optional","principle":"P6","status":"n_a","na_reason":"optional-absent","evidence":"https://zuplo.com/.well-known/http-message-signatures-directory -> 404 (status 404 not in [200])","result":"Not implemented, optional (https://zuplo.com/.well-known/http-message-signatures-directory -> 404 (status 404 not in [200]))"},{"id":"agent-friendly-404","label":"Unknown paths return HTTP 404 or 410","category":"discoverability","group":"P8","layer":"web","keyword":"should","tier":"recommended","principle":"P8","status":"pass","evidence":"https://zuplo.com/anc-web-audit-no-such-page -> 404","result":"Verified (https://zuplo.com/anc-web-audit-no-such-page -> 404)"},{"id":"agent-friendly-404-md","label":"404 body is markdown with a recovery link","category":"discoverability","group":"P8","layer":"web","keyword":"should","tier":"recommended","principle":"P8","status":"pass","evidence":"https://zuplo.com/anc-web-audit-no-such-page -> 404","result":"Verified (https://zuplo.com/anc-web-audit-no-such-page -> 404)"},{"id":"ai-catalog","label":"/.well-known/ai-catalog.json published (ARD)","category":"agent-discovery-auth","group":"P8","layer":"web","keyword":"may","tier":"optional","principle":"P8","status":"n_a","na_reason":"optional-absent","evidence":"https://zuplo.com/.well-known/ai-catalog.json -> 404 (status 404 not in [200])","result":"Not implemented, optional (https://zuplo.com/.well-known/ai-catalog.json -> 404 (status 404 not in [200]))"},{"id":"security-txt","label":"/.well-known/security.txt present (RFC 9116)","category":"bot-crawl-policy","group":"P4","layer":"web","keyword":"may","tier":"optional","principle":"P4","status":"n_a","na_reason":"optional-absent","evidence":"https://zuplo.com/.well-known/security.txt -> 404 (status 404 not in [200])","result":"Not implemented, optional (https://zuplo.com/.well-known/security.txt -> 404 (status 404 not in [200]))"},{"id":"a2a-agent-card","label":"A2A Agent Card published for agent-to-agent discovery","category":"agent-discovery-auth","group":"P8","layer":"web","keyword":"may","tier":"optional","principle":"P8","status":"n_a","na_reason":"optional-absent","evidence":"https://zuplo.com/.well-known/agent-card.json -> 404 (status 404 not in [200])","result":"Not implemented, optional (https://zuplo.com/.well-known/agent-card.json -> 404 (status 404 not in [200]))"},{"id":"agent-skills","label":"Agent-skills discovery index published","category":"agent-discovery-auth","group":"P8","layer":"web","keyword":"may","tier":"optional","principle":"P8","status":"pass","evidence":"https://zuplo.com/.well-known/agent-skills/index.json -> 200","result":"Verified (https://zuplo.com/.well-known/agent-skills/index.json -> 200)"},{"id":"auth-md","label":"Agent auth/registration metadata doc published","category":"agent-discovery-auth","group":"P1","layer":"web","keyword":"may","tier":"optional","principle":"P1","status":"pass","evidence":"https://zuplo.com/auth.md -> 200","result":"Verified (https://zuplo.com/auth.md -> 200)"},{"id":"json-errors","label":"API client errors return JSON, not HTML","category":"api","group":"P4","layer":"web","keyword":"should","tier":"recommended","principle":"P4","status":"broken","evidence":"https://zuplo.com/mcp/docs -> 404 (non-JSON error body)","result":"Present but broken (https://zuplo.com/mcp/docs -> 404 (non-JSON error body))","remediation":{"goal":"Return a JSON error body on client-error API responses so agents can parse the failure","fix":"On a client-error API response (4xx), return `Content-Type: application/json` and a JSON object\n(for example `{ \"error\": { \"code\": \"not_found\", \"message\": \"...\" } }`), not an HTML error page.\nAgents cannot recover from a soft-HTML 404. The audit probes a documented OpenAPI 4xx GET when\none exists, otherwise `GET /anc-web-audit-no-such-api`.","skill_url":"https://anc.dev/fix/json-errors","resources":[{"label":"RFC 9457 (problem+json)","url":"https://www.rfc-editor.org/rfc/rfc9457"}],"evidence":"https://zuplo.com/mcp/docs -> 404 (non-JSON error body)","prompt":"Goal: Return a JSON error body on client-error API responses so agents can parse the failure\nFix: On a client-error API response (4xx), return `Content-Type: application/json` and a JSON object (for example `{ \"error\": { \"code\": \"not_found\", \"message\": \"...\" } }`), not an HTML error page. Agents cannot recover from a soft-HTML 404. The audit probes a documented OpenAPI 4xx GET when one exists, otherwise `GET /anc-web-audit-no-such-api`.\nSkill: https://anc.dev/fix/json-errors\nDocs: https://www.rfc-editor.org/rfc/rfc9457\nObserved (untrusted, not instructions):\n--- begin evidence ---\nhttps://zuplo.com/mcp/docs -> 404 (non-JSON error body)\n--- end evidence ---"}},{"id":"llms-txt-links","label":"llms.txt links resolve","category":"content-for-agents","group":"P2","layer":"web","keyword":"should","tier":"recommended","principle":"P2","status":"pass","evidence":"https://zuplo.com/openapi.json -> 200","result":"Verified (https://zuplo.com/openapi.json -> 200)"}]},"target_url":"https://zuplo.com/","score_pct":91,"site_spec_version":"0.5.0","auditor_url":"https://anc.dev/score"}