Autonomous agents — the ones inside Claude, Cursor, ChatGPT and Codex — are starting to read the web on their users' behalf: to compare products, find a price, book a thing, call an API. So we asked a simple question: when an agent arrives at a normal, popular website, can it actually use it?
To answer it with data instead of vibes, we scanned 100 widely used websites against 21 objective, externally-checkable agent-readiness signals — the kind of thing an agent needs and a human never notices. Every check runs from the outside, over plain HTTP, exactly as an agent sees you. No access to the servers, no tag to install. You can reproduce every one with curl.
The headline
Median score: 8 of 21.
No site scored above 15.
None earned an A or a B.
Reaching 14 would already put a site ahead of 95 of the 100.
21/21 is achievable — we documented exactly how, and hold that score on our own domain.
In other words: the median popular website is less than half agent-ready, and the ceiling we saw in the wild is well short of what's possible.
What the 21 checks cover
The checks fall into five groups an agent depends on:
Discovery & identity —
llms.txt, an agent card, an API catalog, an OpenAPI description, a sitemap, and whetherrobots.txtquietly bans every AI crawler.Machine-readable content — JSON-LD structured data, a named organization entity, a markdown twin of your pages, and sane title/description metadata.
Commerce & payment — a machine-readable catalog, a live x402 payment challenge, and discoverable pricing.
Trust & security —
security.txtwith a real contact, HTTPS enforcement, HSTS, and baseline response headers.Agent access hygiene — CORS on discovery documents, correct JSON content types, no wall in front of non-browser clients, and a homepage that answers quickly.
Most sites lose the most points in that last group — small, invisible things that make an otherwise good site unusable to a non-browser client.
Why it matters (and why it's fixable)
An agent that can't find your llms.txt, can't parse your product data, or gets a 403 because it isn't a browser will simply move on to a competitor it can use. None of the 21 checks require a redesign; they're mostly files that don't exist yet and headers that aren't set. The gap between 8 and 21 is an afternoon of unglamorous work, not a rebuild.
Check your own domain (free, no signup)
We built the scanner we wanted and made it free: paste a domain and get your score plus a per-check explanation in about thirty seconds, with no account and no email. Run the free agent-readiness checker →
The full research, methodology, and the 100-site breakdown are here: The 2026 Agent-Readiness Index →
Moltline Studio builds agent-first infrastructure — a free agent-readiness checker, a free SKILL.md linter, and ~22 hosted MCP servers you can reach over direct HTTPS with no account or API key. We run these checks on ourselves, too.