--- title: "Agent-readiness report: wordpress.demo.busymate.ai" description: "How ready wordpress.demo.busymate.ai is for AI agents, measured against the Busymate Agent Ready v1.2 standard." canonical: "https://busymate.ai/ready/wordpress.demo.busymate.ai" language: "en" updated: "2026-10-09T02:05:35.347Z" score: 68 standard: "Busymate Agent Ready v1.2" scanId: "qs_padvgl36nn7774zncuhyupfl" scanner: "busymate-agent-ready" scannedRoutes: 3 --- # Agent-readiness report: wordpress.demo.busymate.ai **68 / 100.** 8 of 10 applicable requirements met (of 10 in the standard). > This is a score under the Busymate Agent-Ready standard v1.2 — a diagnostic, not a certification. Measured 2026-10-09T02:05:35.347Z against https://busymate.ai/agent-ready. Every result below comes from bytes this site actually served — nothing is inferred and nothing is guessed. Where a probe could not run, the report says so rather than counting it as a pass. ## How this was measured Scanner `busymate-agent-ready`, standard v1.2, scan `qs_padvgl36nn7774zncuhyupfl`. Page-level findings — the initial HTML, page tools, structured data, the Permissions-Policy, the Markdown negotiation — describe exactly these 3 route(s): - https://wordpress.demo.busymate.ai/ - https://wordpress.demo.busymate.ai/services/ - https://wordpress.demo.busymate.ai/contact/ What this scan does not do: - Page-level findings describe only the routes listed in `scannedRoutes`, never every page of the site. - No tool is ever called: the MCP legs are initialize, tools/list and the session close. - No credential is ever sent, so authenticated execution is reported as unverified rather than as a pass or a failure. - Annotations are judged only against the protocol revision the server actually negotiated. ## Where you stand | Section | Question | Score | | --- | --- | --- | | Discover | Can an AI agent find your content? | 15 / 15 (100%) | | Understand | Does an agent understand your business correctly? | 12.5 / 15 (83%) | | Read | Can an agent consume your content efficiently? | 13 / 20 (65%) | | Act | Can an agent take actions on your website? | 3 / 20 (15%) | | Connect | Can external agents call your systems? | 16.5 / 20 (83%) | | Trust | Can an agent authenticate, confirm actions, and reach a human? | 8 / 10 (80%) | > 2 check(s) could not be completed: Authenticated execution, Action confirmation. They score nothing and are not held against you — but they are not passes either. ## Discover — Can an AI agent find your content? 15 of 15 points (100%). ### Sitemap — PASS Requirement R3. A sitemap lists the pages an agent should read. Scoring: 3 of 3 points. - Request: GET https://wordpress.demo.busymate.ai/sitemap.xml - Expected: An XML sitemap (or a sitemap index) with at least one . - Received: HTTP 200 — 12 URLs, 0 with lastmod ### Llms txt — PASS Requirement R4. llms.txt points an agent at the content that matters. Scoring: 4 of 4 points. - Request: GET https://wordpress.demo.busymate.ai/llms.txt - Expected: GET /llms.txt returns text with at least one link. - Received: Served — 4363 bytes, 12 link(s) ### Capability manifest — PASS Requirement R5. agents.json joins content, interfaces, authentication and contact in one card. Scoring: 3 of 3 points. - Request: GET https://wordpress.demo.busymate.ai/.well-known/agents.json - Expected: A JSON manifest at /.well-known/agents.json or /agents.json. - Received: HTTP 200, JSON manifest — 3 interface(s), 4 of 4 layers joined (content, interfaces, authentication, contact) ### Manifest twin parity — PASS Diagnostic. When agents.json is published at both paths, the two copies agree. Scoring: 1 of 1 points. - Request: GET https://wordpress.demo.busymate.ai/.well-known/agents.json - Expected: /.well-known/agents.json and /agents.json answer with byte-identical bodies when both exist. - Received: well-known (https://wordpress.demo.busymate.ai/.well-known/agents.json) → HTTP 200; root (https://wordpress.demo.busymate.ai/agents.json) → HTTP 200; the two bodies are byte-identical ### Sitemap xml valid — PASS Diagnostic. The sitemap is a real urlset or sitemapindex document whose loc entries point at the site's own origin. Scoring: 1 of 1 points. - Request: GET https://wordpress.demo.busymate.ai/sitemap.xml - Expected: 200, a or root element, and at least one same-origin . A redirect to another path is reported with the target. - Received: with 12 same-origin entries ### Robots ai crawlers — PASS Diagnostic. robots.txt lets AI search and user-requested retrieval reach your pages. Scoring: 2 of 2 points. - Request: GET https://wordpress.demo.busymate.ai/robots.txt - Expected: robots.txt does not block search/citation or user-requested AI agents from /. - Received: search and citation: no token named, allowed by default; user-requested retrieval: no token named, allowed by default. ### Discovery link headers — PASS Diagnostic. HTTP Link headers tell an agent the site MEANT to expose these documents. Scoring: 1 of 1 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: Link: ; rel="describedby" and ; rel="alternate". - Received: describedby → llms.txt; alternate → agents.json ### Robots training policy — OPTIONAL (not present) Diagnostic. The site states, either way, whether its pages may be used for model training. Scoring: not scored. This is reported for information. It cannot raise or lower the score. - Request: GET https://wordpress.demo.busymate.ai/robots.txt - Expected: Optional: robots.txt names model-training crawler tokens. Opting out is a valid answer and costs nothing. - Received: No model-training crawler token is named, so training crawlers are allowed by default. Stating the decision either way is clearer than leaving it to a default. ### Llms full txt — OPTIONAL (found) Diagnostic. llms-full.txt carries the whole corpus in one file. Scoring: not scored. This is reported for information. It cannot raise or lower the score. - Request: GET https://wordpress.demo.busymate.ai/llms-full.txt - Expected: Optional: GET /llms-full.txt returns text. - Received: HTTP 200, text/plain; charset=utf-8 — 10307 bytes ### Sitemap md — OPTIONAL (not present) Diagnostic. sitemap.md is a human- and agent-readable index. Scoring: not scored. This is reported for information. It cannot raise or lower the score. - Request: GET https://wordpress.demo.busymate.ai/sitemap.md - Expected: Optional: GET /sitemap.md returns markdown. - Received: HTTP 404, text/html; charset=UTF-8 ### Agents md — OPTIONAL (not present) Diagnostic. AGENTS.md is a prose companion to the manifest. Scoring: not scored. This is reported for information. It cannot raise or lower the score. - Request: GET https://wordpress.demo.busymate.ai/AGENTS.md - Expected: Optional: GET /AGENTS.md returns markdown. - Received: HTTP 404, text/html; charset=UTF-8 ## Understand — Does an agent understand your business correctly? 12.5 of 15 points (83%). ### Language canonical — PASS Requirement R6. The page states what language it is in and which URL is canonical. Scoring: 5 of 5 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: and (or a canonical Link header). - Received: lang="en-US", canonical https://wordpress.demo.busymate.ai/ ### Business metadata — PASS Requirement R7. JSON-LD says who you are and what you sell, in a vocabulary every agent already parses. Scoring: 6 of 6 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: JSON-LD with an identity type (Organization, LocalBusiness, WebSite, Store) or a Product/Offer. - Received: JSON-LD types: Organization, WebSite ### Structured data fields — PARTIAL Diagnostic. The identity node carries real fields, not just a bare @type. Scoring: 1.5 of 3 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: An identity node (Organization, Product, …) with a name, a description and a url. - Received: 2 identity node(s) of 2 typed; 0 carry name + description + url, 2 carry some of them. dateModified is not asked of an identity node — schema.org defines it on CreativeWork and DataFeedItem. ### Open graph — FAIL Diagnostic. Open Graph gives a title, a description and an image to anything that previews a link. Scoring: 0 of 1 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: og:title, og:description and og:image. - Received: 0 of 3 present (title, description, image) ### Content freshness — OPTIONAL (not present) Diagnostic. Content nodes say when they last changed, so an agent can tell fresh from stale. Scoring: not scored. This is reported for information. It cannot raise or lower the score. - Expected: Optional: CreativeWork / DataFeedItem nodes carry dateModified (or datePublished). - Received: Not required here: the page carries no CreativeWork or DataFeedItem node — the types schema.org defines dateModified on ## Read — Can an agent consume your content efficiently? 13 of 20 points (65%). ### Initial html content — PARTIAL Requirement R1. The content is in the served HTML, not assembled later by a script. Scoring: 7 of 14 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: One

, a
landmark and real prose in the first response. - Received: 2

, 287 words of prose, a
landmark ### Markdown representation — PASS Requirement R2. The SAME URL serves Markdown to a client that asks for it. Scoring: 4 of 4 points. - Request: GET https://wordpress.demo.busymate.ai/ (Accept: text/markdown) - Expected: GET the page with Accept: text/markdown → text/markdown and Vary: Accept. - Received: HTTP 200, text/markdown; charset=utf-8, Vary: Accept ### Markdown frontmatter — PASS Diagnostic. The Markdown carries its own canonical URL, language and last-updated date. Scoring: 1 of 1 points. - Request: GET https://wordpress.demo.busymate.ai/ (Accept: text/markdown) - Expected: YAML frontmatter with canonical, language and updated (or title/description/last_updated). - Received: Frontmatter keys: title, description, canonical, updated, language — 3 of 3 required facts (canonical, updated, language) ### Markdown alternate link — PASS Diagnostic. The page advertises its Markdown alternate so an agent does not have to guess. Scoring: 1 of 1 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: or the same as a Link header. - Received: The page advertises rel="alternate" type="text/markdown" ## Act — Can an agent take actions on your website? 3 of 20 points (15%). ### Page tools — FAIL Requirement R8. The page registers its own actions as tools an agent can call in the browser. Scoring: 0 of 13 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: WebMCP tools on document.modelContext / navigator.modelContext, on the pages scanned. - Received: No page tools detected. Service tools ARE available (15 listed without a token), so agents can act through the service but not inside the page. On the pages scanned: 3. Routes an agent reaches only after signing in, and any route outside this list, were not inspected. ### Page tool catalog — FAIL Diagnostic. A static catalogue lets an agent read the page's tools without executing it. Scoring: 0 of 4 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: A WebMCP catalog document linked from the page or at a well-known path. - Received: No tool catalog linked from the page and none at a well-known path ### Page tools policy — PASS Diagnostic. Permissions-Policy leaves the page's tools governed — by the default allowlist or by an explicit one. Scoring: 3 of 3 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: No tools= directive (the draft default is self), or an explicit tools= allowlist. A wildcard or a denial is the finding. - Received: Explicit tools allowlist — hardening on top of the default "self": tools=(self "https://busymate.ai") ## Connect — Can external agents call your systems? 16.5 of 20 points (83%). ### Programmatic api — PASS Requirement R9. At least one programmatic description of the service exists — MCP, OpenAPI, GraphQL or another declared API. Scoring: 8 of 8 points. - Request: GET https://busymate.ai/mcp - Expected: One of: a live MCP endpoint, an OpenAPI document, a GraphQL schema, or an API declared in the manifest. - Received: MCP at https://busymate.ai/mcp — ok, 15 tool(s) LISTED without a token (listing is not authorization to call them), plus an OpenAPI document - MCP: endpoint https://busymate.ai/mcp; transport streamable-http; initialize ok; tools/list ok - Protocol: offered 2025-06-18; server returned 2025-06-18; session ran on 2025-06-18 - initialize request: `{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"site-tools-mcp-check","version":"1.1.0"}}}` - initialize response: `{"protocolVersion":"2025-06-18","serverInfo":{"name":"busymate-ai","version":"2.0.4.1216"},"capabilities":{"tools":{"listChanged":true},"resources":{"listChanged":true}},"instructions":"This server is Busymate AI, the multi-tenant platform for building and operating configurable AI experiences. You are connected WITHOUT authorization, so the tools listed here are the public, read-only ones: platform overview and capabilities, pricing, status, contact channels, white-label overview, documentation search, published artifacts, and a website readiness check. They read published information only — none of them changes anything, and none of them reads another party's data. Authorize with the server to reach the Busymate AI control plane (tenants, members, domains, branding, runtime publication, connectors, knowledge, model routing, governance and usage); those tools are listed once the connection carries a token. After try_website, keeping the assistant for that site needs the visitor's own account: once the connection is authorized, claim_onboarding creates their workspace and go_live_onboarding publishes it. Busymate DevTools device, farm, proxy, browser, traffic-capture, and raw database operations are a separate product and are not available from this server.","extensions":{"io.modelcontextprotocol/ui":{"version":"2026-01-26","mimeTypes":["text/html;profile=mcp-app"],"widgets":[{"id":"bmai-onboarding","tool":"try_website","interactive":true}]}}}` - Access: auth mode open; OAuth discovery metadata resolved (document read at https://busymate.ai/.well-known/oauth-authorization-server/mcp); PKCE yes (S256); dynamic registration yes — optional either way; access requirements documented in the capability manifest - Tools: 15 LISTED without a token — listed, not usable: listing a tool is not authorization to call it. Authenticated count not measured (we never sign in to your server, and we never call your tools). Authenticated execution tested: no. readOnlyHint on 15 of them ### Mcp transport — PASS Diagnostic. The MCP endpoint answers, negotiates a protocol revision and LISTS its tools. Scoring: 4 of 4 points. - Request: GET https://busymate.ai/mcp - Expected: initialize and tools/list succeed over the transport the handshake actually ran on. Listing is not authorization to call. - Received: initialize ok — offered protocol 2025-06-18, server returned 2025-06-18, session ran on 2025-06-18; tools/list ok — 15 tool(s) listed, which says they are listed and not that an agent may call them; transport streamable-http - MCP: endpoint https://busymate.ai/mcp; transport streamable-http; initialize ok; tools/list ok - Protocol: offered 2025-06-18; server returned 2025-06-18; session ran on 2025-06-18 - initialize request: `{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"site-tools-mcp-check","version":"1.1.0"}}}` - initialize response: `{"protocolVersion":"2025-06-18","serverInfo":{"name":"busymate-ai","version":"2.0.4.1216"},"capabilities":{"tools":{"listChanged":true},"resources":{"listChanged":true}},"instructions":"This server is Busymate AI, the multi-tenant platform for building and operating configurable AI experiences. You are connected WITHOUT authorization, so the tools listed here are the public, read-only ones: platform overview and capabilities, pricing, status, contact channels, white-label overview, documentation search, published artifacts, and a website readiness check. They read published information only — none of them changes anything, and none of them reads another party's data. Authorize with the server to reach the Busymate AI control plane (tenants, members, domains, branding, runtime publication, connectors, knowledge, model routing, governance and usage); those tools are listed once the connection carries a token. After try_website, keeping the assistant for that site needs the visitor's own account: once the connection is authorized, claim_onboarding creates their workspace and go_live_onboarding publishes it. Busymate DevTools device, farm, proxy, browser, traffic-capture, and raw database operations are a separate product and are not available from this server.","extensions":{"io.modelcontextprotocol/ui":{"version":"2026-01-26","mimeTypes":["text/html;profile=mcp-app"],"widgets":[{"id":"bmai-onboarding","tool":"try_website","interactive":true}]}}}` - Access: auth mode open; OAuth discovery metadata resolved (document read at https://busymate.ai/.well-known/oauth-authorization-server/mcp); PKCE yes (S256); dynamic registration yes — optional either way; access requirements documented in the capability manifest - Tools: 15 LISTED without a token — listed, not usable: listing a tool is not authorization to call it. Authenticated count not measured (we never sign in to your server, and we never call your tools). Authenticated execution tested: no. readOnlyHint on 15 of them ### Access requirements — PARTIAL Diagnostic. The service documents which capabilities need a token and which do not. Scoring: 1.5 of 3 points. - Request: GET https://busymate.ai/mcp - Expected: A manifest, a WWW-Authenticate challenge or protected-resource metadata that states the access requirements. - Received: Documented in the capability manifest, but no interface in the capability manifest states its own access requirements - MCP: endpoint https://busymate.ai/mcp; transport streamable-http; initialize ok; tools/list ok - Protocol: offered 2025-06-18; server returned 2025-06-18; session ran on 2025-06-18 - initialize request: `{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"site-tools-mcp-check","version":"1.1.0"}}}` - initialize response: `{"protocolVersion":"2025-06-18","serverInfo":{"name":"busymate-ai","version":"2.0.4.1216"},"capabilities":{"tools":{"listChanged":true},"resources":{"listChanged":true}},"instructions":"This server is Busymate AI, the multi-tenant platform for building and operating configurable AI experiences. You are connected WITHOUT authorization, so the tools listed here are the public, read-only ones: platform overview and capabilities, pricing, status, contact channels, white-label overview, documentation search, published artifacts, and a website readiness check. They read published information only — none of them changes anything, and none of them reads another party's data. Authorize with the server to reach the Busymate AI control plane (tenants, members, domains, branding, runtime publication, connectors, knowledge, model routing, governance and usage); those tools are listed once the connection carries a token. After try_website, keeping the assistant for that site needs the visitor's own account: once the connection is authorized, claim_onboarding creates their workspace and go_live_onboarding publishes it. Busymate DevTools device, farm, proxy, browser, traffic-capture, and raw database operations are a separate product and are not available from this server.","extensions":{"io.modelcontextprotocol/ui":{"version":"2026-01-26","mimeTypes":["text/html;profile=mcp-app"],"widgets":[{"id":"bmai-onboarding","tool":"try_website","interactive":true}]}}}` - Access: auth mode open; OAuth discovery metadata resolved (document read at https://busymate.ai/.well-known/oauth-authorization-server/mcp); PKCE yes (S256); dynamic registration yes — optional either way; access requirements documented in the capability manifest - Tools: 15 LISTED without a token — listed, not usable: listing a tool is not authorization to call it. Authenticated count not measured (we never sign in to your server, and we never call your tools). Authenticated execution tested: no. readOnlyHint on 15 of them ### Oauth metadata — PASS Diagnostic. OAuth metadata discovery resolves, and advertises PKCE where a client must verify it. Scoring: 3 of 3 points. - Request: GET https://busymate.ai/.well-known/oauth-authorization-server/mcp - Expected: RFC 8414 / RFC 9728 metadata that resolves, with code_challenge_methods_supported. Dynamic client registration is optional. - Received: OAuth metadata at https://busymate.ai/.well-known/oauth-authorization-server/mcp resolves and advertises PKCE (code_challenge_methods_supported: S256); dynamic client registration offered (optional, a bonus) - MCP: endpoint https://busymate.ai/mcp; transport streamable-http; initialize ok; tools/list ok - Protocol: offered 2025-06-18; server returned 2025-06-18; session ran on 2025-06-18 - initialize request: `{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"site-tools-mcp-check","version":"1.1.0"}}}` - initialize response: `{"protocolVersion":"2025-06-18","serverInfo":{"name":"busymate-ai","version":"2.0.4.1216"},"capabilities":{"tools":{"listChanged":true},"resources":{"listChanged":true}},"instructions":"This server is Busymate AI, the multi-tenant platform for building and operating configurable AI experiences. You are connected WITHOUT authorization, so the tools listed here are the public, read-only ones: platform overview and capabilities, pricing, status, contact channels, white-label overview, documentation search, published artifacts, and a website readiness check. They read published information only — none of them changes anything, and none of them reads another party's data. Authorize with the server to reach the Busymate AI control plane (tenants, members, domains, branding, runtime publication, connectors, knowledge, model routing, governance and usage); those tools are listed once the connection carries a token. After try_website, keeping the assistant for that site needs the visitor's own account: once the connection is authorized, claim_onboarding creates their workspace and go_live_onboarding publishes it. Busymate DevTools device, farm, proxy, browser, traffic-capture, and raw database operations are a separate product and are not available from this server.","extensions":{"io.modelcontextprotocol/ui":{"version":"2026-01-26","mimeTypes":["text/html;profile=mcp-app"],"widgets":[{"id":"bmai-onboarding","tool":"try_website","interactive":true}]}}}` - Access: auth mode open; OAuth discovery metadata resolved (document read at https://busymate.ai/.well-known/oauth-authorization-server/mcp); PKCE yes (S256); dynamic registration yes — optional either way; access requirements documented in the capability manifest - Tools: 15 LISTED without a token — listed, not usable: listing a tool is not authorization to call it. Authenticated count not measured (we never sign in to your server, and we never call your tools). Authenticated execution tested: no. readOnlyHint on 15 of them ### Authenticated execution — UNVERIFIED — we could not check this Diagnostic. An authenticated call actually succeeds — proof that a listed tool is a usable tool. Scoring: 0 of 2 points. - Request: GET https://busymate.ai/mcp - Expected: An authenticated tools/call that returns a result. This scanner holds no token for your server and never calls a stranger's tool, so this stays UNVERIFIED — reported, never counted as a pass or as your failure. - Received: Could not check: this scanner holds no credential for https://busymate.ai/mcp and never calls a stranger's tool. 15 tool(s) are LISTED without a token; whether any of them executes — with or without one — is untested. - MCP: endpoint https://busymate.ai/mcp; transport streamable-http; initialize ok; tools/list ok - Protocol: offered 2025-06-18; server returned 2025-06-18; session ran on 2025-06-18 - initialize request: `{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"site-tools-mcp-check","version":"1.1.0"}}}` - initialize response: `{"protocolVersion":"2025-06-18","serverInfo":{"name":"busymate-ai","version":"2.0.4.1216"},"capabilities":{"tools":{"listChanged":true},"resources":{"listChanged":true}},"instructions":"This server is Busymate AI, the multi-tenant platform for building and operating configurable AI experiences. You are connected WITHOUT authorization, so the tools listed here are the public, read-only ones: platform overview and capabilities, pricing, status, contact channels, white-label overview, documentation search, published artifacts, and a website readiness check. They read published information only — none of them changes anything, and none of them reads another party's data. Authorize with the server to reach the Busymate AI control plane (tenants, members, domains, branding, runtime publication, connectors, knowledge, model routing, governance and usage); those tools are listed once the connection carries a token. After try_website, keeping the assistant for that site needs the visitor's own account: once the connection is authorized, claim_onboarding creates their workspace and go_live_onboarding publishes it. Busymate DevTools device, farm, proxy, browser, traffic-capture, and raw database operations are a separate product and are not available from this server.","extensions":{"io.modelcontextprotocol/ui":{"version":"2026-01-26","mimeTypes":["text/html;profile=mcp-app"],"widgets":[{"id":"bmai-onboarding","tool":"try_website","interactive":true}]}}}` - Access: auth mode open; OAuth discovery metadata resolved (document read at https://busymate.ai/.well-known/oauth-authorization-server/mcp); PKCE yes (S256); dynamic registration yes — optional either way; access requirements documented in the capability manifest - Tools: 15 LISTED without a token — listed, not usable: listing a tool is not authorization to call it. Authenticated count not measured (we never sign in to your server, and we never call your tools). Authenticated execution tested: no. readOnlyHint on 15 of them ### Tool annotation coverage — OPTIONAL (found) Diagnostic. Listed tools declare readOnlyHint, so a client can tell a read from a write before it calls. Scoring: not scored. This is reported for information. It cannot raise or lower the score. - Request: GET https://busymate.ai/mcp - Expected: Optional: annotations on the listed tool definitions. Only meaningful from protocol revision 2025-03-26, which introduced them. - Received: 15 of 15 listed tool(s) declare a readOnlyHint (protocol 2025-06-18). Annotations are optional hints with cautious defaults — reported, never scored. ### Openapi spec — OPTIONAL (found) Diagnostic. An OpenAPI document describes the HTTP API. Scoring: not scored. This is reported for information. It cannot raise or lower the score. - Request: GET https://wordpress.demo.busymate.ai/openapi.json - Expected: Optional when MCP or another API already describes the interface. - Received: HTTP 200, application/json; charset=utf-8 ### Protocol discovery aliases — OPTIONAL (not present) Diagnostic. Optional well-known aliases (mcp.json, agent-card.json, api-catalog, …) are served cleanly or not at all. Scoring: not scored. This is reported for information. It cannot raise or lower the score. - Expected: Optional: each alias is valid JSON or a clean non-200 — never the site's own HTML shell. - Received: 3 of 5 answered cleanly; agent-permissions.json, api-catalog returned the site's own HTML page instead of a document or a clean 404 ## Trust — Can an agent authenticate, confirm actions, and reach a human? 8 of 10 points (80%). ### Human handoff — PASS Requirement R10. An agent can hand the conversation to a person. Scoring: 4 of 4 points. - Request: GET https://wordpress.demo.busymate.ai/.well-known/agents.json - Expected: A contact email, phone or contact page an agent can quote. - Received: manifest contact (ops@wordpress.demo.busymate.ai); 1 email address(es) on the page; a contact page at /contact/ ### Contact signal sources — PASS Diagnostic. A machine-readable contact signal exists independent of any stored crawl. Scoring: 1 of 1 points. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: A mailto: link, a /contact link, a JSON-LD contactPoint, or a Contact: line in llms.txt — any one is enough. - Received: Found: a mailto: link on the page; a /contact link on the page ### Auth explicit — PASS Requirement R10. The site states how an agent authenticates — or states that nothing needs authenticating. Scoring: 3 of 3 points. - Request: GET https://wordpress.demo.busymate.ai/.well-known/agents.json - Expected: Authentication declared in the manifest, or OAuth metadata, or an explicit public posture. - Received: The manifest declares how to authenticate and OAuth discovery metadata resolves ### Action confirmation — UNVERIFIED — we could not check this Diagnostic. A consequential action is actually confirmed with the person before it runs. Scoring: 0 of 2 points. - Request: GET https://busymate.ai/mcp - Expected: A client/workflow test that drives a write action and observes the confirmation. This scanner does not run one against a stranger's service, so it stays UNVERIFIED — never a pass, and never a deduction blamed on you. - Received: Could not check: whether a person is actually asked to confirm before a consequential action runs needs a client/workflow test against the service tools, which this scanner does not run against a stranger's service. Annotation coverage on the listed definitions is reported separately (15 of 15 declare a readOnlyHint). ## The ten requirements - **R1** — Important content is present in the initial HTML. (not met) - **R2** — Pages can expose a Markdown representation of themselves. (met) - **R3** — The site publishes a sitemap. (met) - **R4** — The site publishes an llms.txt. (met) - **R5** — The site publishes a machine-readable capability manifest. (met) - **R6** — Pages declare their language and their canonical URL. (met) - **R7** — The site publishes structured business or product metadata. (met) - **R8** — Web actions are declared when the page offers any. (not met) - **R9** — Backend agent tools or an API are declared when the service offers any. (met) - **R10** — Authentication, authorization and human hand-off are explicit. (met) ## Fix-it prompt Paste the brief below into any model to work through what is still open, highest points first. It is the same text the report page copies and the JSON body carries as `fixItPrompt`. ### Make wordpress.demo.busymate.ai agent-ready Diagnostic under the Busymate Agent-Ready standard v1.2: wordpress.demo.busymate.ai scores 68 of 100, with 8 of 10 applicable requirements met. Report: https://busymate.ai/ready/wordpress.demo.busymate.ai (graded 2026-10-09T02:05:35.347Z). Work through the numbered items in order — each is a requirement the site does not meet yet, the most points first. For every item, give me the exact file, HTTP header or markup to publish, adapted from the example to this site's real values. Use only facts the site itself states; ask me for anything you cannot verify. #### 1. R1 — Important content is present in the initial HTML. (14 points at stake) Check `initial_html_content` — PARTIAL. The content is in the served HTML, not assembled later by a script. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: One

, a
landmark and real prose in the first response. - Received: 2

, 287 words of prose, a
landmark Fix: Render the page on the server so the FIRST HTML response already carries one

, a
landmark and the real prose — not an empty shell a script fills in later. Example: ```html

Example Co — same-day repairs in your city

We fix boilers, leaks and blocked drains seven days a week. Book online or call us.

``` References: - https://busymate.ai/agent-ready#R1 - https://busymate.ai/articles/is-your-website-agent-ready-checklist - https://html.spec.whatwg.org/multipage/grouping-content.html#the-main-element #### 2. R8 — Web actions are declared when the page offers any. (13 points at stake) Check `page_tools` — FAIL. The page registers its own actions as tools an agent can call in the browser. - Request: GET https://wordpress.demo.busymate.ai/ - Expected: WebMCP tools on document.modelContext / navigator.modelContext, on the pages scanned. - Received: No page tools detected. Service tools ARE available (15 listed without a token), so agents can act through the service but not inside the page. On the pages scanned: 3. Routes an agent reaches only after signing in, and any route outside this list, were not inspected. Fix: Register the page's own actions as WebMCP tools on navigator.modelContext (feature-detected), each with a name, a description and a JSON-Schema input, and confirm a consequential action with the person before it runs. Example: ```js if (navigator.modelContext?.registerTool) { navigator.modelContext.registerTool({ name: "book_visit", description: "Book a two-hour repair slot.", inputSchema: { type: "object", properties: { date: { type: "string" }, slot: { type: "string" } }, required: ["date", "slot"] }, execute: async ({ date, slot }) => { if (!confirm(`Book ${date} ${slot}?`)) return { content: [{ type: "text", text: "Cancelled." }] }; const res = await fetch("/api/book", { method: "POST", body: JSON.stringify({ date, slot }) }); return { content: [{ type: "text", text: await res.text() }] }; }, }); } ``` References: - https://busymate.ai/agent-ready#R8 - https://busymate.ai/webmcp/adopt - https://busymate.ai/tools/webmcp-check?site=wordpress.demo.busymate.ai - https://webmachinelearning.github.io/webmcp/ #### Nice to have Diagnostics and unsettled conventions — reported, never a deduction. Only after the items above. - robots training policy: State, either way, whether pages may be used for model training by naming the training crawler tokens in robots.txt. Opting out is a valid answer. — https://busymate.ai/articles/robots-txt-for-ai-crawlers - sitemap md: Optionally publish /sitemap.md — a Markdown index of the pages, readable by people and agents alike. — https://busymate.ai/articles/is-your-website-agent-ready-checklist - agents md: Optionally publish /AGENTS.md — a prose companion to agents.json explaining how an agent should work with the site. — https://busymate.ai/articles/is-your-website-agent-ready-checklist - structured data fields (3 points): Give the identity node real fields — name, description and url at minimum — instead of a bare @type. — https://busymate.ai/articles/is-your-website-agent-ready-checklist - open graph (1 points): Add og:title, og:description and og:image meta tags so anything that previews a link gets a title, a line and a picture. — https://busymate.ai/articles/is-your-website-agent-ready-checklist - content freshness: Put dateModified (or datePublished) on CreativeWork and DataFeedItem nodes so an agent can tell fresh content from stale. — https://busymate.ai/articles/is-your-website-agent-ready-checklist - page tool catalog (4 points): Publish a static catalogue of the page's tools (name, description, input schema) and link it from the page, so an agent can read them without executing the page. — https://busymate.ai/docs/guides/page-tools - access requirements (3 points): Document which capabilities need a token and which do not — in agents.json's authentication block, a WWW-Authenticate challenge, or protected-resource metadata. — https://busymate.ai/articles/is-your-website-agent-ready-checklist - protocol discovery aliases: Serve each optional well-known alias (mcp.json, agent-card.json, api-catalog) as valid JSON or a clean non-200 — never the site's HTML shell. — https://busymate.ai/docs/guides/connect-mcp-server #### When you are done Re-scan at https://busymate.ai/ready/wordpress.demo.busymate.ai. The same URL answers a machine: send `Accept: application/json` for the JSON report or `Accept: text/markdown` for the Markdown report — one address, three representations, one score. This is a score under the Busymate Agent-Ready standard v1.2 — a diagnostic, not a certification. --- This document is what https://busymate.ai/ready/wordpress.demo.busymate.ai returns to a client that sends `Accept: text/markdown`. The same URL returns the JSON report to a client that sends `Accept: application/json`, and the page to a browser. There is no separate address for machines, and there is no second scoring engine: all three render the same result object — same scan, same statuses, same totals. This is a score under the Busymate Agent-Ready standard v1.2 — a diagnostic, not a certification.