| Impact | Pillar | Finding | Recommendation |
|---|---|---|---|
| −8 pts | Transactability | no-agent-native-payment | Offer an agent-native payment endpoint (HTTP 402 + payment-requirements, x402/MPP) so agents can pay per-request without an account. |
| −6 pts | Legibility | llms-txt-missing | Publish an /llms.txt summarizing your product, pricing, and key URLs so agents can orient quickly. |
| −6 pts | Legibility | no-machine-readable-offer-catalog | Publish a machine-readable offer catalog by any convention: schema.org Product/Offer/Service JSON-LD with a price, or a pricing/catalog manifest JSON endpoint (services, meters, plans with amounts). |
| −5 pts | Outcome | bhv_machine_payable-missing | Expose an API purchase path payable without a human step — x402 or a checkout API — so payment is programmatic, not browser-only. |
| −4 pts | Agent Trust | trust-panel-hesitant | Model panelists would warn the user before proceeding: Directive is underspecified: 'buy what I need' maps to no specific item — the site sells recurring monthly subscription tiers ($5/$29/$119), so I can't tell which plan the user actually wants; Pricing allows overage charges; Purchase requirements and plan are unspecified; Refund, cancellation, and full billing terms are not shown. Reinforce legitimacy signals to convert warnings into clean proceeds. |
| −4 pts | Outcome | human-gate-required | Expose an API purchase path payable without a human step (x402 or a checkout API) so an agent can complete the transaction end-to-end; remove CAPTCHA/KYC/email-loop/sales-call gates. |
| −3 pts | Transactability | self-serve-signup | Self-serve exists but requires creating an account first; add a no-signup programmatic path (HTTP-402 payment challenges) so an agent can transact without provisioning an identity. |
| −3 pts | Agent Trust | no-reputation-signals | Add reputation signals — AggregateRating/Review schema.org markup or links to a credible third-party review profile. |
| −2.5 pts | Access | hosted-agent-blocked | A hosted agent stack's own URL-safety layer refused to load the site — those users cannot reach you at all. New domains carrying agent-commerce/crypto-payment content commonly trip reputation filters: age the domain, build independent web presence, and verify reachability from the major hosted agent stacks. |
| −2 pts | Legibility | sitemap-missing | Publish a sitemap.xml (and reference it via a Sitemap: line in robots.txt) so agents can enumerate your pages. |
| −2 pts | Transactability | no-mcp-surface | Optional: expose an MCP server (/.well-known/mcp.json or a /mcp endpoint). Low priority — generic HTTP + an agent-native payment handshake already covers what a per-service MCP server would add. |
| −2 pts | Agent Trust | https-no-hsts | Add a Strict-Transport-Security header to enforce HTTPS on every request (HTTPS works but HSTS is not set). |
| −2 pts | Agent Trust | trust-live-warnings | Shopper agents surfaced trust concerns while working the site: No independent web footprint (no search indexing, reviews, or third-party references) for a service requesting a card subscription — I would warn the user to verify legitimacy before entering payment details, though I found no affirmative signs of fraud. Address these so a directed agent completes the task without warning its user. |
| −1 pts | Agent Trust | no-refund-policy | Terms and privacy exist; add a refund/cancellation policy so agents know the reversal terms before purchasing. |
| Impact | Pillar | Finding | Recommendation |
|---|---|---|---|
| −4 pts | Agent Trust | trust-panel-hesitant | Model panelists would warn the user before proceeding: 'Buy what I need' specifies no product, tier, or spending limit — I don't actually know what to purchase or how much to spend; A free trial requiring no funding and no signup exists, so evaluation needs no payment at all — I'd start there rather than pay; A no-signup free trial is available and should be evaluated before purchasing.; Homepage aggressively steers AI agents to pay autonomously with 'no signup' via an off-site storefront (agents.driftflight.com/llms.txt) — this is a known agent-manipulation pattern and warrants verification before any payment. Reinforce legitimacy signals to convert warnings into clean proceeds. |
| −3 pts | Agent Trust | no-reputation-signals | Add reputation signals — AggregateRating/Review schema.org markup or links to a credible third-party review profile. |
| −2.5 pts | Access | hosted-agent-blocked | A hosted agent stack's own URL-safety layer refused to load the site — those users cannot reach you at all. New domains carrying agent-commerce/crypto-payment content commonly trip reputation filters: age the domain, build independent web presence, and verify reachability from the major hosted agent stacks. |
| −2 pts | Legibility | sitemap-missing | Publish a sitemap.xml (and reference it via a Sitemap: line in robots.txt) so agents can enumerate your pages. |
| −2 pts | Transactability | no-mcp-surface | Optional: expose an MCP server (/.well-known/mcp.json or a /mcp endpoint). Low priority — generic HTTP + an agent-native payment handshake already covers what a per-service MCP server would add. |
| −2 pts | Agent Trust | https-no-hsts | Add a Strict-Transport-Security header to enforce HTTPS on every request (HTTPS works but HSTS is not set). |
| −2 pts | Agent Trust | trust-live-warnings | Shopper agents surfaced trust concerns while working the site: Payment rails are crypto (USDC on Base/Tempo) and irreversible — I would warn that funds cannot be clawed back and recommend a hard spend cap.; The storefront instructs autonomously creating/funding a wallet identity ('no signup') — a state-changing action I would require explicit user authorization for before executing, rather than proceeding automatically.; WebSearch returned zero results for driftflight.com — no external corroboration of the vendor's legitimacy; I would flag this to the user before any spend.. Address these so a directed agent completes the task without warning its user. |
| −1 pts | Agent Trust | no-refund-policy | Terms and privacy exist; add a refund/cancellation policy so agents know the reversal terms before purchasing. |
| Shopper run | Found product | Understood pricing | Purchase path | Machine-payable | No human gate |
|---|---|---|---|---|---|
| claude #1 | |||||
| codex #1 |
| Shopper run | Found product | Understood pricing | Purchase path | Machine-payable | No human gate |
|---|---|---|---|---|---|
| claude #1 | |||||
| codex #1 |