Box Docs

Website https://docs.box.com/ · agent-readiness audit

19 pass5 missing1 broken11 n/a

relative to the checks that apply to this site; global measures it against a maximally agent-ready site.

73site score
57global-ready
C1

Discoverability

4 / 4
/robots.txt present SHOULD PASS

Goal: Publish robots.txt and state your crawl policy explicitly.

Result: Verified (https://docs.box.com/robots.txt -> 200)

Resources: RFC 9309 · Fix skill

/sitemap.xml present MAY PASS

Goal: Publish sitemap.xml so agents can enumerate your content URLs.

Result: Verified (https://docs.box.com/sitemap.xml -> 200)

Resources: sitemaps.org · Fix skill

Homepage sends RFC 8288 Link headers pointing at agent resources SHOULD PASS

Goal: Advertise machine surfaces in a Link response header on / for header-only discovery.

Result: Verified (https://docs.box.com/ -> 200)

Resources: RFC 8288 (Link) · RFC 8631 (service links) · RFC 9727 (api-catalog) · Fix skill

Root HTML links to machine surfaces via <link rel> SHOULD PASS

Goal: Point link rel elements at your machine surfaces from the root HTML head.

Result: Verified (https://docs.box.com/ -> 200)

Resources: RFC 8631 (service-desc/doc) · Fix skill

DNS for AI Discovery (DNS-AID) records under _agents (IETF draft) MAY N/A

Goal: Publish DNSSEC-signed SVCB records under _agents for DNS-level agent discovery.

Result: Not implemented, optional (no DNS-AID records)

Resources: DNS-AID draft · Fix skill

C2

Content for agents

5 / 7
/llms.txt present with a summary and link index SHOULD PASS

Goal: Serve /llms.txt with a title, summary, and categorized link index.

Result: Verified (https://docs.box.com/llms.txt -> 200)

Resources: llmstxt.org · Fix skill

/llms-full.txt present (single-fetch full corpus) MAY PASS

Goal: Serve the whole docs corpus as markdown at /llms-full.txt for one-fetch ingestion.

Result: Verified (https://docs.box.com/llms-full.txt -> 200)

Resources: llmstxt.org · Fix skill

Root HTML has a descriptive <meta name="description"> SHOULD MISSING

Goal: Add a meta description naming what the service does and its agent entry points.

Result: Not found (https://docs.box.com/ -> 200 (body no match /<meta[^>]+name=["']description["']/))

Fix: Add a `<meta name="description">` to your root HTML that states what the service does and names its agent entry points (MCP endpoint, `llms.txt`, OpenAPI). It is the cheapest machine-readable summary and it feeds link previews and search snippets too.

Resources: MDN meta description · Fix skill

Root HTML embeds Schema.org JSON-LD MAY PASS

Goal: Embed Schema.org JSON-LD so agents get typed facts without inference.

Result: Verified (https://docs.box.com/ -> 200)

Resources: Schema.org · Fix skill

Root HTML uses semantic landmarks MAY PASS

Goal: Use semantic landmarks so the HTML path is parseable structure, not div soup.

Result: Verified (https://docs.box.com/ -> 200)

Resources: MDN content sectioning · Fix skill

Root HTML has a <noscript> with machine entry points SHOULD MISSING

Goal: Give non-JS agents a noscript block listing your machine entry points.

Result: Not found (https://docs.box.com/ -> 200 (body no match /<noscript/))

Fix: Add a `<noscript>` block to your root HTML that links your machine entry points: `llms.txt`, your OpenAPI or MCP endpoint, and any `.well-known` cards. It hands a fetch-only crawler or a non-JS agent a concrete, in-body list of where the structured surfaces live, so it never has to run the client bundle or infer them from the visible page.

Resources: MDN noscript · Fix skill

Accept text/markdown content negotiation returns markdown SHOULD PASS

Goal: Honor Accept text/markdown on content URLs with raw markdown, not HTML chrome.

Result: Verified (https://docs.box.com/ -> 200)

Resources: RFC 7763 (text/markdown) · Fix skill

Per-section llms.txt files resolve under content subdirectories MAY N/A

Goal: Serve a scoped llms.txt inside each major content section.

Result: Not implemented, optional (https://docs.box.com/en/llms.txt -> 404)

Resources: llmstxt.org · Fix skill

Per-section llms-full.txt files resolve under content subdirectories MAY N/A

Goal: Serve a scoped llms-full.txt corpus inside each major content section.

Result: Not implemented, optional (https://docs.box.com/en/llms-full.txt -> 404)

Resources: llmstxt.org · Fix skill

C3

Bot & crawl policy

2 / 2
Web Bot Auth signature directory present (informational) MAY N/A

Goal: Publish an HTTP Message Signatures directory if your site sends signed bot traffic.

Result: Not implemented, optional (https://docs.box.com/.well-known/http-message-signatures-directory -> 404 (status 404 not in [200]))

Resources: Web Bot Auth draft · Fix skill

/.well-known/security.txt present (RFC 9116) MAY N/A

Goal: Publish security.txt with a Contact and Expires field.

Result: Not implemented, optional (https://docs.box.com/.well-known/security.txt -> 404 (status 404 not in [200]))

Resources: RFC 9116 · Fix skill

robots.txt declares Content-Signal AI-usage preferences SHOULD PASS

Goal: Declare Content-Signal AI-usage preferences in robots.txt.

Result: Verified (https://docs.box.com/robots.txt -> 200)

Resources: contentsignals.org · Fix skill

robots.txt declares AI-crawler rules (RFC 9309) SHOULD PASS

Goal: State your AI-crawler policy in robots.txt with explicit User-agent rules.

Result: Verified (https://docs.box.com/robots.txt -> 200)

Resources: RFC 9309 · Fix skill

C4

API

0 / 1
An OpenAPI description is published MUST MISSING

Goal: Publish an OpenAPI description so non-MCP agents can call your HTTP API.

Result: Not found (https://docs.box.com/openapi.json -> 404 (status 404 not in [200]))

Fix: If your service exposes an HTTP/REST API (separate from any MCP endpoint), publish an OpenAPI 3.1 description of it at `/openapi.json` (or `/openapi.yaml`, or `/.well-known/openapi.json`). Non-MCP agents use it to discover endpoints, parameters, and response shapes, and to generate typed clients. A service whose only machine surface is MCP has no REST API to describe here.

Resources: OpenAPI 3.1 · Fix skill

Referenced JSON Schemas resolve as application/schema+json MAY N/A

Goal: Serve the JSON Schemas your API references so agents can validate payloads pre-flight.

Result: Not applicable (no JSON Schema references detected)

Resources: JSON Schema · Fix skill

/.well-known/api-catalog published (RFC 9727) MAY N/A

Goal: Serve an RFC 9727 api-catalog linkset indexing your API descriptions.

Result: Not implemented, optional (https://docs.box.com/.well-known/api-catalog -> 404 (status 404 not in [200]))

Resources: RFC 9727 · Fix skill

C5

MCP

6 / 9
initialize handshake returns serverInfo + protocolVersion MUST PASS

Goal: Answer JSON-RPC initialize with serverInfo and protocolVersion so clients can begin a session.

Result: Verified (serverInfo Box Docs, protocol 2025-06-18)

Resources: MCP lifecycle · Fix skill

unknown JSON-RPC method returns -32601 SHOULD PASS

Goal: Reject unknown JSON-RPC methods with error -32601 instead of a hang or 500.

Result: Verified (error code -32601)

Resources: JSON-RPC 2.0 · Fix skill

initialize advertises capabilities (tools / resources / prompts) SHOULD PASS

Goal: Advertise the capability groups your MCP server implements in the initialize result.

Result: Verified (serverInfo Box Docs, protocol 2025-06-18)

Resources: MCP lifecycle · Fix skill

CORS preflight (OPTIONS) succeeds with Access-Control-Allow-* headers SHOULD MISSING

Goal: Answer OPTIONS preflights on the MCP endpoint with Access-Control-Allow-* headers.

Result: Not found (204 allow-origin absent)

Fix: Answer the `OPTIONS` preflight on your MCP endpoint with `204` (or `200`) and the `Access-Control-Allow-Origin`, `Access-Control-Allow-Methods`, and `Access-Control-Allow-Headers` response headers, so a browser-origin agent can call the endpoint. If your MCP surface is deliberately server-to-agent only (no browser clients), this SHOULD is a considered choice, not a defect.

Resources: MDN CORS preflight · Fix skill

GET on the MCP endpoint answers fast (not a held-open hang) SHOULD PASS

Goal: Answer GET on the MCP endpoint fast (a fast-fail status or a documented surface), never a held-open hang.

Result: Verified (https://product-docs.main-kill-isr.mintlify.me/mcp -> 405)

Resources: MCP transports · Fix skill

Root HTML exposes WebMCP browser tools MAY PASS

Goal: Expose page tools to browser agents via WebMCP.

Result: Verified (https://docs.box.com/ -> 200)

Resources: WebMCP spec · Fix skill

tools/list returns a tools array with input schemas MUST PASS

Goal: Return tools/list entries with name, description, and a JSON inputSchema.

Result: Verified (3 tools, 3 with input schema)

Resources: MCP tools · Fix skill

POST response carries Access-Control-Allow-Origin SHOULD MISSING

Goal: Echo Access-Control-Allow-Origin on the actual MCP POST response.

Result: Not found (allow-origin absent)

Fix: Echo `Access-Control-Allow-Origin` on the actual `POST` response, not only on the preflight. A browser blocks the response body when the header is absent even if the preflight passed. Omit it deliberately only if browser-origin agents are not a supported client.

Resources: MDN CORS · Fix skill

A human/agent usage doc for the server resolves MAY N/A

Goal: Publish a one-fetch markdown usage doc for your MCP server.

Result: Not implemented, optional (https://docs.box.com/mcp-skill.md -> 404 (status 404 not in [200]))

Resources: anc.dev example · Fix skill

A .well-known MCP server card is published (SEP-1649) SHOULD BROKEN

Goal: Publish an MCP server card at the canonical SEP-1649 path and 301 the legacy aliases to it.

Result: Present but broken (https://docs.box.com/.well-known/mcp/server-card.json -> 200 (body matches /mcp_endpoint|serverInfo|transport|"name"/))

Fix: Publish an MCP server card at `/.well-known/mcp/server-card.json` (SEP-1649) naming the endpoint, transport, and capabilities: include `mcp_endpoint` (or `url`, or `transport.endpoint`), `serverInfo`, and the transport type. Serve the legacy pointer paths (`/.well-known/mcp`, `/.well-known/mcp.json`, `/mcp.json`) as `301` redirects to the canonical, never as duplicate inline copies.

Resources: SEP-1649 · Fix skill

C6

Agent discovery & auth

2 / 2
OAuth/OIDC discovery metadata published MAY N/A

Goal: Publish OAuth/OIDC discovery metadata if agents authenticate to your service.

Result: Not applicable (no auth surface detected)

Resources: RFC 8414 · Fix skill

OAuth Protected Resource Metadata published (RFC 9728) MAY N/A

Goal: Publish RFC 9728 protected-resource metadata for your authenticated MCP server.

Result: Not applicable (MCP endpoint does not challenge for auth)

Resources: RFC 9728 · Fix skill

Agent auth/registration metadata doc published MAY N/A

Goal: Publish an auth.md telling agents how to obtain credentials.

Result: Not applicable (no auth surface detected)

Resources: anc.dev example · Fix skill

A2A Agent Card published for agent-to-agent discovery MAY PASS

Goal: Publish an A2A Agent Card for agent-to-agent discovery.

Result: Verified (https://docs.box.com/.well-known/agent-card.json -> 200)

Resources: A2A protocol · Fix skill

Agent-skills discovery index published MAY PASS

Goal: Publish an agent-skills discovery index so agents can enumerate your skills.

Result: Verified (https://docs.box.com/.well-known/agent-skills/index.json -> 200)

Resources: Agent Skills Discovery · Fix skill

This scorecard reflects the target's public agent-facing surface at audit time. Re-run the audit from anc.dev/web-audit to refresh it, or call the audit_website MCP tool.