SSL / TLS
Valid HTTPS · 500ms
x402 discovery
n/a
Agent discovery
/.well-known/agent.json returned HTTP 404 (should be 200) · 334ms
llms.txt
HTTP 404 · 334ms
security.txt
Not found · 334ms
CORS headers
No CORS header (OK if server-to-server only) · 665ms
Security headers
5/5 present (all critical headers set) · 669ms
Response time
683ms avg · 683ms
MCP server
/mcp returns 200 (not JSON) · 641ms
API endpoints
1 endpoints found
Error handling
Returns 200 for unknown paths · 790ms
x402 compliance
n/a
Rate limiting
No rate-limit headers (may still be rate-limited server-side) · 967ms
Documentation
/docs found · 962ms
robots.txt AI crawlers
No AI crawler directives (GPTBot, ClaudeBot, etc.) · 858ms
AI plugin manifest
No ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec
No OpenAPI/Swagger spec found
Privacy / GDPR
/privacy found (30105 chars) · 1010ms
Status / Health
/status found · 1020ms
EU AI Act disclosure
No AI model card or disclosure endpoint
Travel Rule (FATF)
n/a
A2A Protocol (Google)
No agent.json for A2A discovery
DNSSEC
DNSSEC check failed
CAA Records
CAA check failed
DMARC / SPF
No DMARC or SPF records found
Auth maturity
No authentication detected — open API or check failed
API versioning
No versioned paths or version headers found
Human oversight
/agent/stop — active (EU AI Act Art. 14) · 1143ms
Terms of Service
/terms found (30031 chars) · 1146ms
Content-Type
No application/json responses (1 paths tested)
OASF Classification
No OASF or agent service classification found
MCP Transport Security
/mcp active · HSTS · 1144ms
Voice AI Disclosure
n/a
Synthetic Voice Labeling
n/a
Synthetic Content Labeling
n/a
Emotion Recognition Declaration
n/a
Call Recording Consent
n/a
FCC/TCPA Compliance
n/a
Operator Identity & KYB
n/a
Opt-out & Human Escalation
n/a
Voice Call Policy
n/a
Caller Identity Declaration
n/a
Wallet trust
n/a
ERC-8004 on-chain
n/a
Critical — 1Warning — 18Agent discovery needs attention/.well-known/agent.json returned HTTP 404 (should be 200)
security.txt needs attentionNot found
CORS headers needs attentionNo CORS header (OK if server-to-server only)
Response time needs attention683ms avg
Error handling needs attentionReturns 200 for unknown paths
Rate limiting needs attentionNo rate-limit headers (may still be rate-limited server-side)
robots.txt AI crawlers needs attentionNo AI crawler directives (GPTBot, ClaudeBot, etc.)
AI plugin manifest needs attentionNo ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec needs attentionNo OpenAPI/Swagger spec found
EU AI Act disclosure needs attentionNo AI model card or disclosure endpoint
A2A Protocol (Google) needs attentionNo agent.json for A2A discovery
DNSSEC needs attentionDNSSEC check failed
CAA Records needs attentionCAA check failed
DMARC / SPF needs attentionNo DMARC or SPF records found
Auth maturity needs attentionNo authentication detected — open API or check failed
API versioning needs attentionNo versioned paths or version headers found
Content-Type needs attentionNo application/json responses (1 paths tested)
OASF Classification needs attentionNo OASF or agent service classification found