Model Context Protocol
relative to the checks that apply to this site; global measures it against a maximally agent-ready site.
Discoverability
5 / 6/robots.txt present SHOULD PASS
Goal: Publish robots.txt and state your crawl policy explicitly.
Result: Verified (https://modelcontextprotocol.io/robots.txt -> 200)
/sitemap.xml present MAY PASS
Goal: Publish sitemap.xml so agents can enumerate your content URLs.
Result: Verified (https://modelcontextprotocol.io/sitemap.xml -> 200)
Resources: sitemaps.org · Fix skill
404 body is markdown with a recovery link SHOULD MISSING
Goal: Serve a short markdown 404 that links at least one agent recovery surface.
Result: Not found (https://modelcontextprotocol.io/anc-web-audit-no-such-page -> 404 (content-type "application/json" !~ /markdown|text/plain/))
Fix: When `Accept: text/markdown` hits an unknown path, return 404 or 410 with a short markdown body that includes at least one recovery link: sitemap, `llms.txt`, a docs index, or an equivalent same-origin href. Linking both sitemap and `llms.txt` as absolute URLs is the stronger pattern. Zero links is a miss even when the status is correct.
Resources: llmstxt.org · Fix skill
Homepage sends RFC 8288 Link headers pointing at agent resources SHOULD PASS
Goal: Advertise machine surfaces in a Link response header on / for header-only discovery.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: RFC 8288 (Link) · RFC 8631 (service links) · RFC 9727 (api-catalog) · Fix skill
Root HTML links to machine surfaces via <link rel> SHOULD PASS
Goal: Point link rel elements at your machine surfaces from the root HTML head.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: RFC 8631 (service-desc/doc) · Fix skill
DNS for AI Discovery (DNS-AID) records under _agents (IETF draft) MAY N/A
Goal: Publish DNSSEC-signed SVCB records under _agents for DNS-level agent discovery.
Result: Not implemented, optional (no DNS-AID records)
Resources: DNS-AID draft · Fix skill
Unknown paths return HTTP 404 or 410 SHOULD PASS
Goal: Return a real HTTP 404 or 410 for unknown paths instead of a 200 SPA shell.
Result: Verified (https://modelcontextprotocol.io/anc-web-audit-no-such-page -> 404)
Resources: RFC 9110 status codes · Fix skill
Content for agents
10 / 14/llms.txt present with a summary and link index SHOULD PASS
Goal: Serve /llms.txt with a title, summary, and categorized link index.
Result: Verified (https://modelcontextprotocol.io/llms.txt -> 200)
Resources: llmstxt.org · Fix skill
/llms-full.txt present (single-fetch full corpus) MAY PASS
Goal: Serve the whole docs corpus as markdown at /llms-full.txt for one-fetch ingestion.
Result: Verified (https://modelcontextprotocol.io/llms-full.txt -> 200)
Resources: llmstxt.org · Fix skill
Accept text/markdown content negotiation returns markdown SHOULD PASS
Goal: Honor Accept text/markdown on content URLs with raw markdown, not HTML chrome.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: RFC 7763 (text/markdown) · Fix skill
llms.txt has H1, summary, and a link index SHOULD MISSING
Goal: Structure /llms.txt with an H1, a blockquote summary, and a markdown link index.
Result: Not found (https://modelcontextprotocol.io/llms.txt -> error (link index present))
Fix: Follow the llmstxt.org shape: start with `# Title`, add a `>` summary blockquote, then a categorized list of markdown links. A file that is present but is only a heading, or only a blob of prose, fails this row even when the presence check passes.
Resources: llmstxt.org · Fix skill
llms.txt has a when-to-use or programmatic-access section SHOULD MISSING
Goal: Tell agents when to use the MCP or docs from a short llms.txt heading.
Result: Not found (https://modelcontextprotocol.io/llms.txt -> error (no when-to-use heading))
Fix: Add a heading such as `## When to use` or `## Programmatic access` with a few lines on when an agent should connect (for example: "Use the MCP when you need to search or score a CLI"). The audit looks for that heading; it does not grade the prose with an LLM.
Resources: llmstxt.org · Fix skill
Bare CLI User-Agent receives the markdown twin MAY N/A
Goal: Serve the markdown twin to shell HTTP clients that state no content-type preference.
Result: Not implemented, optional (https://modelcontextprotocol.io/ -> 200 (content-type "text/html; charset=utf-8" !~ /markdown|text/plain/))
Resources: RFC 7763 (text/markdown) · RFC 9110 (User-Agent) · Fix skill
AI user-fetch User-Agent receives the markdown twin MAY PASS
Goal: Serve the markdown twin to AI on-demand user-fetchers that state no content-type preference.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: RFC 7763 (text/markdown) · OpenAI bots and User-Agents · Fix skill
Negotiated responses carry Vary Accept, User-Agent SHOULD PASS
Goal: Emit Vary Accept, User-Agent so shared caches never serve one client the wrong variant.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: RFC 9110 (Vary) · Fix skill
Accept text/plain returns the markdown twin MAY PASS
Goal: Treat Accept text/plain as a request for the raw markdown source.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: RFC 7763 (text/markdown) · Fix skill
Root HTML has a descriptive <meta name="description"> SHOULD MISSING
Goal: Add a meta description naming what the service does and its agent entry points.
Result: Not found (https://modelcontextprotocol.io/ -> 200 (body no match /<meta[^>]+name=["']description["']/))
Fix: Add a `<meta name="description">` to your root HTML that states what the service does and names its agent entry points (MCP endpoint, `llms.txt`, OpenAPI). It is the cheapest machine-readable summary and it feeds link previews and search snippets too.
Resources: MDN meta description · Fix skill
Root HTML embeds Schema.org JSON-LD MAY PASS
Goal: Embed Schema.org JSON-LD so agents get typed facts without inference.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: Schema.org · Fix skill
Root HTML has an H1 and readable text without JavaScript SHOULD PASS
Goal: Put an H1 and enough visible text in the raw root HTML that a non-JS agent can read the page.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: llmstxt.org · Fix skill
Root HTML uses semantic landmarks MAY PASS
Goal: Use semantic landmarks so the HTML path is parseable structure, not div soup.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: MDN content sectioning · Fix skill
Root HTML has a <noscript> with machine entry points SHOULD MISSING
Goal: Give non-JS agents a noscript block listing your machine entry points.
Result: Not found (https://modelcontextprotocol.io/ -> 200 (body no match /<noscript/))
Fix: Add a `<noscript>` block to your root HTML that links your machine entry points: `llms.txt`, your OpenAPI or MCP endpoint, and any `.well-known` cards. It hands a fetch-only crawler or a non-JS agent a concrete, in-body list of where the structured surfaces live, so it never has to run the client bundle or infer them from the visible page.
Resources: MDN noscript · Fix skill
Markdown twin carries YAML frontmatter MAY N/A
Goal: Prefix the markdown twin with a YAML frontmatter block so agents read page metadata without parsing the body.
Result: Not implemented, optional (https://modelcontextprotocol.io/ -> 200 (no leading frontmatter fence))
Resources: YAML front matter (Jekyll) · RFC 7763 (text/markdown) · Fix skill
llms.txt links resolve SHOULD PASS
Goal: Make every markdown href in /llms.txt fetchable.
Result: Verified (https://modelcontextprotocol.io/docs/2026-07-28/getting-started/intro.md -> 200)
Resources: llmstxt.org · Fix skill
Per-section llms.txt files resolve under content subdirectories MAY N/A
Goal: Serve a scoped llms.txt inside each major content section.
Result: Not implemented, optional (https://modelcontextprotocol.io/docs/llms.txt -> 404)
Resources: llmstxt.org · Fix skill
Per-section llms-full.txt files resolve under content subdirectories MAY N/A
Goal: Serve a scoped llms-full.txt corpus inside each major content section.
Result: Not implemented, optional (https://modelcontextprotocol.io/docs/llms-full.txt -> 404)
Resources: llmstxt.org · Fix skill
Bot & crawl policy
4 / 4AI user-fetch User-Agent can reach the homepage SHOULD PASS
Goal: Let on-demand user-fetchers GET / with Accept */* and receive 2xx, not a challenge page.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: OpenAI user-fetchers · Fix skill
robots.txt declares Content-Signal AI-usage preferences SHOULD PASS
Goal: Declare Content-Signal AI-usage preferences in robots.txt.
Result: Verified (https://modelcontextprotocol.io/robots.txt -> 200)
Resources: contentsignals.org · Fix skill
robots.txt declares AI-crawler rules (RFC 9309) SHOULD PASS
Goal: State your AI-crawler policy in robots.txt with explicit User-agent rules.
Result: Verified (https://modelcontextprotocol.io/robots.txt -> 200)
Web Bot Auth signature directory present (informational) MAY N/A
Goal: Publish an HTTP Message Signatures directory if your site sends signed bot traffic.
Result: Not implemented, optional (https://modelcontextprotocol.io/.well-known/http-message-signatures-directory -> 404 (status 404 not in [200]))
Resources: Web Bot Auth draft · Fix skill
API
0 / 0No checks in this category apply to this site.
An OpenAPI description is published MUST N/A
Goal: Publish an OpenAPI description so non-MCP agents can call your HTTP API.
Result: Not applicable (no API surface detected)
Resources: OpenAPI 3.1 · Fix skill
Referenced JSON Schemas resolve as application/schema+json MAY N/A
Goal: Serve the JSON Schemas your API references so agents can validate payloads pre-flight.
Result: Not applicable (no JSON Schema references detected)
Resources: JSON Schema · Fix skill
/.well-known/api-catalog published (RFC 9727) MAY N/A
Goal: Serve an RFC 9727 api-catalog linkset indexing your API descriptions.
Result: Not applicable (no API surface detected)
API client errors return JSON, not HTML SHOULD N/A
Goal: Return a JSON error body on client-error API responses so agents can parse the failure.
Result: Not applicable (no API surface detected)
Resources: RFC 9457 (problem+json) · Fix skill
API responses advertise rate-limit headers SHOULD N/A
Goal: Advertise remaining quota on API responses so agents can back off instead of retrying blindly.
Result: Not applicable (no API surface detected)
Resources: IETF RateLimit header draft · Fix skill
MCP
19 / 20initialize handshake returns serverInfo + protocolVersion MUST PASS
Goal: Answer JSON-RPC initialize with serverInfo and protocolVersion so clients can begin a session.
Result: Verified (serverInfo Model Context Protocol, protocol 2025-06-18)
Resources: MCP lifecycle · Fix skill
server/discover answers with server identity on the modern lane SHOULD PASS
Goal: Answer server/discover with supported versions, capabilities, and server identity.
Result: Verified (supports 2026-07-28, serverInfo Model Context Protocol)
Resources: MCP lifecycle (2026-07-28) · Fix skill
header-routed tools/list (2026-07-28) returns tools without initialize MUST PASS
Goal: Answer a modern header-routed tools/list without requiring an initialize handshake.
Result: Verified (3 tools, 3 with input schema)
Resources: MCP lifecycle (2026-07-28) · MCP tools (2026-07-28) · Fix skill
resources/list returns at least one resource when advertised SHOULD PASS
Goal: Honor capabilities.resources with a non-empty resources/list result.
Result: Verified (https://modelcontextprotocol.io/mcp -> 200)
Resources: MCP resources · Fix skill
unknown JSON-RPC method returns -32601 SHOULD PASS
Goal: Reject unknown JSON-RPC methods with error -32601 instead of a hang or 500.
Result: Verified (error code -32601)
Resources: JSON-RPC 2.0 · Fix skill
tools/list returns a tools array with input schemas MUST PASS
Goal: Return tools/list entries with name, description, and a JSON inputSchema.
Result: Verified (3 tools, 3 with input schema)
initialize advertises capabilities (tools / resources / prompts) SHOULD PASS
Goal: Advertise the capability groups your MCP server implements in the initialize result.
Result: Verified (serverInfo Model Context Protocol, protocol 2025-06-18)
Resources: MCP lifecycle · Fix skill
a non-JSON body draws -32700 (or a typed HTTP 400/415 refusal) SHOULD PASS
Goal: Refuse an unparseable request body with a parse-error envelope or a typed HTTP refusal.
Result: Verified (error code -32700)
Resources: JSON-RPC 2.0 · Fix skill
an unknown method on the modern lane returns -32601 SHOULD PASS
Goal: Reject unknown header-routed methods with -32601 on the 2026-07-28 lane.
Result: Verified (error code -32601)
Resources: JSON-RPC 2.0 · MCP lifecycle (2026-07-28) · Fix skill
a batch carrying a modern-envelope request is rejected -32600 SHOULD PASS
Goal: Refuse JSON array batches that carry modern-era envelopes with -32600.
Result: Verified (error code -32600)
Resources: JSON-RPC 2.0 · MCP transports (2026-07-28) · Fix skill
tools/call with an unknown tool name returns -32602 SHOULD PASS
Goal: Reject an unknown tool name with -32602 instead of a hang, a 500, or a fake result.
Result: Verified (error code -32602)
Resources: MCP tools · JSON-RPC 2.0 · Fix skill
_meta missing clientCapabilities is rejected (-32602 or -32600) SHOULD PASS
Goal: Enforce the mandatory clientCapabilities key on every modern request.
Result: Verified (error code -32602)
Resources: MCP lifecycle (2026-07-28) · Fix skill
an Mcp-Method header disagreeing with the body method draws -32020 SHOULD PASS
Goal: Validate the SEP-2243 header mirror between Mcp-Method and the body method.
Result: Verified (error code -32020)
Resources: MCP lifecycle (2026-07-28) · Fix skill
modern resources/read with an unknown URI returns -32602 SHOULD PASS
Goal: Answer an unknown resource URI with the typed miss code, not a hang or a fake result.
Result: Verified (error code -32602)
Resources: MCP resources (2026-07-28) · JSON-RPC 2.0 · Fix skill
an unsatisfiable Accept draws a 406 rather than an unasked-for type SHOULD PASS
Goal: Refuse an Accept you cannot satisfy with 406, never a 200 carrying a type the client did not request.
Result: Verified (https://modelcontextprotocol.io/mcp -> 406)
Resources: RFC 9110 section 15.5.7 (406 Not Acceptable) · MCP transports · Fix skill
an unsupported protocol version is rejected -32022 with data.supported SHOULD PASS
Goal: Refuse unsupported protocol version claims with -32022 and advertise the served revisions.
Result: Verified (error code -32022)
Resources: MCP lifecycle (2026-07-28) · Fix skill
a JSON-only Accept is answered without SSE framing SHOULD PASS
Goal: Serve a single application/json response to a client whose Accept names only application/json.
Result: Verified (https://modelcontextprotocol.io/mcp -> 406)
Resources: MCP transports · RFC 9110 section 12.5.1 (Accept) · Fix skill
Root HTML exposes WebMCP browser tools MAY PASS
Goal: Expose page tools to browser agents via WebMCP.
Result: Verified (https://modelcontextprotocol.io/ -> 200)
Resources: WebMCP spec · Fix skill
GET on the MCP endpoint answers fast (not a held-open hang) SHOULD PASS
Goal: Answer GET on the MCP endpoint fast (a fast-fail status or a documented surface), never a held-open hang.
Result: Verified (https://modelcontextprotocol.io/mcp -> 405)
Resources: MCP transports · Fix skill
CORS preflight (OPTIONS) succeeds with Access-Control-Allow-* headers SHOULD N/A
Goal: Serve one consistent CORS posture on the MCP endpoint, full preflight support or none.
Result: Deliberate posture, not scored (no Allow-Origin on the preflight or the POST: consistent no-CORS posture)
Resources: MDN CORS preflight · Fix skill
POST response carries Access-Control-Allow-Origin SHOULD N/A
Goal: Mirror the declared CORS posture on the actual MCP POST response.
Result: Deliberate posture, not scored (no Allow-Origin on the preflight or the POST: consistent no-CORS posture)
A .well-known MCP server card is published (SEP-1649) SHOULD BROKEN
Goal: Publish an MCP server card at the canonical SEP-1649 path and 301 the legacy aliases to it.
Result: Present but broken (https://modelcontextprotocol.io/.well-known/mcp/server-card.json -> 200 (body matches /mcp_endpoint|serverInfo|transport|"name"/))
Fix: Publish an MCP server card at `/.well-known/mcp/server-card.json` (SEP-1649) naming the endpoint, transport, and capabilities: include `mcp_endpoint` (or `url`, or `transport.endpoint`), `serverInfo`, and the transport type. Serve the legacy pointer paths (`/.well-known/mcp`, `/.well-known/mcp.json`, `/mcp.json`) as `301` redirects to the canonical, never as duplicate inline copies.
A human/agent usage doc for the server resolves MAY N/A
Goal: Publish a one-fetch markdown usage doc for your MCP server.
Result: Not implemented, optional (https://modelcontextprotocol.io/mcp-skill.md -> 404 (status 404 not in [200]))
Resources: anc.dev example · Fix skill
Agent discovery & auth
2 / 2OAuth/OIDC discovery metadata published MAY N/A
Goal: Publish OAuth/OIDC discovery metadata if agents authenticate to your service.
Result: Not applicable (no auth surface detected)
OAuth Protected Resource Metadata published (RFC 9728) MAY N/A
Goal: Publish RFC 9728 protected-resource metadata for your authenticated MCP server.
Result: Not applicable (MCP endpoint does not challenge for auth)
Agent auth/registration metadata doc published MAY N/A
Goal: Publish an auth.md telling agents how to obtain credentials.
Result: Not applicable (no auth surface detected)
Resources: anc.dev example · Fix skill
A2A Agent Card published for agent-to-agent discovery MAY PASS
Goal: Publish an A2A Agent Card for agent-to-agent discovery.
Result: Verified (https://modelcontextprotocol.io/.well-known/agent-card.json -> 200)
Resources: A2A protocol · Fix skill
/.well-known/ai-catalog.json published (ARD) MAY N/A
Goal: Publish an Agentic Resource Discovery catalog so agents can enumerate your AI artifacts.
Result: Not implemented, optional (https://modelcontextprotocol.io/.well-known/ai-catalog.json -> 404 (status 404 not in [200]))
Resources: AI Catalog · Fix skill
Agent-skills discovery index published MAY PASS
Goal: Publish an agent-skills discovery index so agents can enumerate your skills.
Result: Verified (https://modelcontextprotocol.io/.well-known/agent-skills/index.json -> 200)
Resources: Agent Skills Discovery · Fix skill
This scorecard reflects the target's public agent-facing surface at audit time. Re-run the audit from anc.dev/web-audit to refresh it, or call the audit_website MCP tool.