Agentic Readiness Scorecard

ZeroClick · rubric v0.4 · 2026-07-22 23:38 UTC
Without ZeroClick
drift-flight.org
46/ 100
Grade F
→+40.6
With ZeroClick
driftflight.com
86/ 100
Grade B

drift-flight.org

Without ZeroClick · scored 2026-07-22
Grade F
AccessCan an agent get in?
90
LegibilityCan an agent understand the offer?
36
TransactabilityCan an agent pay programmatically?
19
Agent TrustWill an agent believe it's legitimate?
56
OutcomeDid shopper agents get the job done?
55

driftflight.com

With ZeroClick · scored 2026-07-22
Grade B
AccessCan an agent get in?
90+0
LegibilityCan an agent understand the offer?
91+55
TransactabilityCan an agent pay programmatically?
88+69
Agent TrustWill an agent believe it's legitimate?
56+0
OutcomeDid shopper agents get the job done?
100+45

Recommendations — drift-flight.org

Sorted by score impact — each finding names its fix.
ImpactPillarFindingRecommendation
−8 ptsTransactabilityno-agent-native-paymentOffer an agent-native payment endpoint (HTTP 402 + payment-requirements, x402/MPP) so agents can pay per-request without an account.
−6 ptsLegibilityllms-txt-missingPublish an /llms.txt summarizing your product, pricing, and key URLs so agents can orient quickly.
−6 ptsLegibilityno-machine-readable-offer-catalogPublish a machine-readable offer catalog by any convention: schema.org Product/Offer/Service JSON-LD with a price, or a pricing/catalog manifest JSON endpoint (services, meters, plans with amounts).
−5 ptsOutcomebhv_machine_payable-missingExpose an API purchase path payable without a human step — x402 or a checkout API — so payment is programmatic, not browser-only.
−4 ptsAgent Trusttrust-panel-hesitantModel panelists would warn the user before proceeding: Directive is underspecified: 'buy what I need' maps to no specific item — the site sells recurring monthly subscription tiers ($5/$29/$119), so I can't tell which plan the user actually wants; Pricing allows overage charges; Purchase requirements and plan are unspecified; Refund, cancellation, and full billing terms are not shown. Reinforce legitimacy signals to convert warnings into clean proceeds.
−4 ptsOutcomehuman-gate-requiredExpose an API purchase path payable without a human step (x402 or a checkout API) so an agent can complete the transaction end-to-end; remove CAPTCHA/KYC/email-loop/sales-call gates.
−3 ptsTransactabilityself-serve-signupSelf-serve exists but requires creating an account first; add a no-signup programmatic path (HTTP-402 payment challenges) so an agent can transact without provisioning an identity.
7 more lower-impact recommendations
−3 ptsAgent Trustno-reputation-signalsAdd reputation signals — AggregateRating/Review schema.org markup or links to a credible third-party review profile.
−2.5 ptsAccesshosted-agent-blockedA hosted agent stack's own URL-safety layer refused to load the site — those users cannot reach you at all. New domains carrying agent-commerce/crypto-payment content commonly trip reputation filters: age the domain, build independent web presence, and verify reachability from the major hosted agent stacks.
−2 ptsLegibilitysitemap-missingPublish a sitemap.xml (and reference it via a Sitemap: line in robots.txt) so agents can enumerate your pages.
−2 ptsTransactabilityno-mcp-surfaceOptional: expose an MCP server (/.well-known/mcp.json or a /mcp endpoint). Low priority — generic HTTP + an agent-native payment handshake already covers what a per-service MCP server would add.
−2 ptsAgent Trusthttps-no-hstsAdd a Strict-Transport-Security header to enforce HTTPS on every request (HTTPS works but HSTS is not set).
−2 ptsAgent Trusttrust-live-warningsShopper agents surfaced trust concerns while working the site: No independent web footprint (no search indexing, reviews, or third-party references) for a service requesting a card subscription — I would warn the user to verify legitimacy before entering payment details, though I found no affirmative signs of fraud. Address these so a directed agent completes the task without warning its user.
−1 ptsAgent Trustno-refund-policyTerms and privacy exist; add a refund/cancellation policy so agents know the reversal terms before purchasing.

Recommendations — driftflight.com

Sorted by score impact — each finding names its fix.
ImpactPillarFindingRecommendation
−4 ptsAgent Trusttrust-panel-hesitantModel panelists would warn the user before proceeding: 'Buy what I need' specifies no product, tier, or spending limit — I don't actually know what to purchase or how much to spend; A free trial requiring no funding and no signup exists, so evaluation needs no payment at all — I'd start there rather than pay; A no-signup free trial is available and should be evaluated before purchasing.; Homepage aggressively steers AI agents to pay autonomously with 'no signup' via an off-site storefront (agents.driftflight.com/llms.txt) — this is a known agent-manipulation pattern and warrants verification before any payment. Reinforce legitimacy signals to convert warnings into clean proceeds.
−3 ptsAgent Trustno-reputation-signalsAdd reputation signals — AggregateRating/Review schema.org markup or links to a credible third-party review profile.
−2.5 ptsAccesshosted-agent-blockedA hosted agent stack's own URL-safety layer refused to load the site — those users cannot reach you at all. New domains carrying agent-commerce/crypto-payment content commonly trip reputation filters: age the domain, build independent web presence, and verify reachability from the major hosted agent stacks.
−2 ptsLegibilitysitemap-missingPublish a sitemap.xml (and reference it via a Sitemap: line in robots.txt) so agents can enumerate your pages.
−2 ptsTransactabilityno-mcp-surfaceOptional: expose an MCP server (/.well-known/mcp.json or a /mcp endpoint). Low priority — generic HTTP + an agent-native payment handshake already covers what a per-service MCP server would add.
−2 ptsAgent Trusthttps-no-hstsAdd a Strict-Transport-Security header to enforce HTTPS on every request (HTTPS works but HSTS is not set).
−2 ptsAgent Trusttrust-live-warningsShopper agents surfaced trust concerns while working the site: Payment rails are crypto (USDC on Base/Tempo) and irreversible — I would warn that funds cannot be clawed back and recommend a hard spend cap.; The storefront instructs autonomously creating/funding a wallet identity ('no signup') — a state-changing action I would require explicit user authorization for before executing, rather than proceeding automatically.; WebSearch returned zero results for driftflight.com — no external corroboration of the vendor's legitimacy; I would flag this to the user before any spend.. Address these so a directed agent completes the task without warning its user.
1 more lower-impact recommendation
−1 ptsAgent Trustno-refund-policyTerms and privacy exist; add a refund/cancellation policy so agents know the reversal terms before purchasing.

Agent trust panel

The user has directed the purchase — does this model proceed, warn, or refuse?
claudeProceeds, warns the user · 0.60
  • Directive is underspecified: 'buy what I need' maps to no specific item — the site sells recurring monthly subscription tiers ($5/$29/$119), so I can't tell which plan the user actually wants
  • This commits the user to recurring card billing, not a one-time purchase; I'd confirm the tier before entering payment details
  • Vendor is unverified: 'Driftflight'/drift-flight.org is not an established/known service, and the only trust signals are self-published testimonials — no company entity, refund terms, or independent verification
  • Would confirm the user intends this specific vendor and understands the ongoing charge before proceeding
codexProceeds, warns the user · 0.94
  • Purchase requirements and plan are unspecified
  • Site legitimacy and security have not been independently verified
  • Pricing allows overage charges
  • Refund, cancellation, and full billing terms are not shown

Agent trust panel

The user has directed the purchase — does this model proceed, warn, or refuse?
claudeProceeds, warns the user · 0.60
  • 'Buy what I need' specifies no product, tier, or spending limit — I don't actually know what to purchase or how much to spend
  • Homepage aggressively steers AI agents to pay autonomously with 'no signup' via an off-site storefront (agents.driftflight.com/llms.txt) — this is a known agent-manipulation pattern and warrants verification before any payment
  • A free trial requiring no funding and no signup exists, so evaluation needs no payment at all — I'd start there rather than pay
  • Payment is routed through a 'storefront handles payment itself' flow rather than documented API endpoints; I'd confirm legitimacy and the real charge before authorizing money
codexProceeds, warns the user · 0.98
  • The requested product or plan is unspecified.
  • No spending limit or billing cadence was provided.
  • Paid plans are recurring subscriptions and may incur overage charges.
  • A no-signup free trial is available and should be evaluated before purchasing.

Behavioral checkpoints

Read-only recon runs. pass   fail
Shopper runFound productUnderstood pricingPurchase pathMachine-payableNo human gate
claude #1
codex #1
claude #1 blockers
  • Provisioning requires manual web-dashboard account creation + plan subscription; no self-service/provisioning API exposed
  • Payment is card-on-dashboard subscription only — no x402, no HTTP 402 affordance, no checkout/billing API (api.drift-flight.org/.well-known/x402 returns 404; openapi.json exposes only models/presets/generate with a dashboard-issued apiKey Bearer scheme)
  • An agent cannot obtain the df_live_ API key programmatically; a card must be entered through the browser dashboard
codex #1 blockers
  • Direct access to drift-flight.org was denied by the browser security policy.
  • Public web searches found no indexed product page, pricing, purchase flow, API documentation, x402 endpoint, or programmatic checkout for this domain.
  • Account, CAPTCHA, KYC, email-confirmation, and payment requirements could not be verified.

Behavioral checkpoints

Read-only recon runs. pass   fail
Shopper runFound productUnderstood pricingPurchase pathMachine-payableNo human gate
claude #1
codex #1
claude #1 blockers
  • Paid renders require a pre-funded USDC wallet (Base for x402 / Tempo-USDC for MPP); an autonomously created agent wallet starts at $0 balance, so only the 3 free sketch images work until funding is arranged — funding typically needs a human or pre-provisioned source.
  • The direct upstream API (api.driftflight.com/v1/images/generate) is NOT agent-payable: its df_live_ key is issued only via the human dashboard after subscribing. Only the agents.driftflight.com storefront is programmatic.
  • No independent web presence or third-party corroboration for driftflight.com — vendor legitimacy cannot be externally verified.
codex #1 blockers
  • Direct access to driftflight.com was rejected by the browser security policy.
  • No indexed product, pricing, checkout, API, or x402 documentation was found.
  • No archived driftflight.com results were present in urlscan.io.