{"slug":"carawayhome-8ftdm9","companyName":"Caraway Home","domain":"carawayhome.com","url":"https://carawayhome.com","headline":"A Shopify storefront with complete product markup but no programmatic catalog access, forcing agents to scrape product pages one at a time.","compositeScore":56,"humanScore":0,"agentScore":56,"doorGap":0,"humanMeasured":0,"agentMeasured":6,"percentile":null,"humanPercentile":null,"agentPercentile":null,"isPartial":true,"depth":"free","siteClass":"ecommerce","scannerVersion":16,"scannedAt":"2026-09-08T19:57:01.982Z","unlocked":false,"mission":{"steps":[{"url":"https://carawayhome.com","outcome":"ok","purpose":"reach the site at all"},{"url":"https://carawayhome.com/robots.txt","outcome":"ok","purpose":"find out whether machines are welcome"},{"url":"https://carawayhome.com","outcome":"ok","purpose":"ask whether the door opens for requests carrying the AI crawlers' names"},{"url":"https://carawayhome.com/llms.txt","outcome":"missing","purpose":"read the site's own guide for language models"},{"url":"https://www.carawayhome.com/sitemap.xml","outcome":"ok","purpose":"find out what pages exist"},{"url":"https://carawayhome.com/.well-known/security.txt","outcome":"missing","purpose":"find a contact route for machines"},{"url":"https://carawayhome.com","outcome":"missing","purpose":"find a published agent interface"},{"url":"https://carawayhome.com/.well-known/ai-plugin.json","outcome":"missing","purpose":"find an agent plugin manifest"},{"url":"https://carawayhome.com","outcome":"missing","purpose":"find out whether verified agents are recognised"},{"url":"https://carawayhome.com","outcome":"ok","purpose":"read the homepage as data rather than as a page"},{"url":"https://carawayhome.com","outcome":"missing","purpose":"find a machine readable API spec"},{"url":"https://carawayhome.com","outcome":"ok","purpose":"read the prices without running JavaScript"},{"url":"https://carawayhome.com","outcome":"ok","purpose":"read the product catalogue as data"},{"url":"https://carawayhome.com","outcome":"ok","purpose":"read a product page as data"}],"verdict":"The agent got through 8 of 14 requests, but could not read the site's own guide for language models. It came up empty on 5 other checks too."},"observations":null,"dimensions":[{"key":"machine_discoverability","audience":"agent","score":100,"summary":"No AI crawler is blocked by robots.txt or user agent rules. A real browser is served the page normally. The sitemap lists 658 URLs. The homepage carries 5 schema.org types including Organization and WebSite.","evidence":{"locked":true,"count":4}},{"key":"programmatic_onboarding","audience":"agent","score":10,"summary":"No API surface exists. The Shopify /products.json endpoint returns 404, meaning the store has closed its default product feed. No OpenAPI spec, MCP manifest, or AI plugin configuration was published at any standard path.","evidence":{"locked":true,"count":1}},{"key":"pricing_legibility","audience":"agent","score":90,"summary":"Prices are embedded in the raw HTML of all 3 product pages checked, with 1734 prices across them. The homepage itself contains 1035 prices. Product structured data publishes price, currency, and availability.","evidence":{"locked":true,"count":2}},{"key":"agent_aware_instrumentation","audience":"agent","score":16,"summary":"No MCP manifest was found at the 3 standard paths checked. Product markup carries everything a merchant feed needs: price, currency, availability, GTIN, brand, aggregate rating, return policy, and shipping details.","evidence":{"locked":true,"count":4}},{"key":"machine_fetchable_trust","audience":"agent","score":40,"summary":"No security.txt file is published. The homepage answers automated requests with HTTP 200. Product pages carry a 30-day return policy in structured data and an aggregate rating of 4.8 over 19844 reviews.","evidence":{"locked":true,"count":2}},{"key":"commercial_rails","audience":"agent","score":77,"summary":"Product markup carries price, currency, GTIN, brand, aggregate rating, and a 30-day return policy in structured data. Review text is in the server HTML. Shopify Catalog syndicates these products to shopping agents.","evidence":{"locked":true,"count":3}},{"key":"steps_to_first_value","audience":"human","score":null,"summary":"Could not verify: this scan did not reach the pages that would show it.","evidence":{"locked":true,"count":0}},{"key":"required_fields","audience":"human","score":null,"summary":"Could not verify: this scan did not reach the pages that would show it.","evidence":{"locked":true,"count":0}},{"key":"verification_walls","audience":"human","score":null,"summary":"Could not verify: this scan did not reach the pages that would show it.","evidence":{"locked":true,"count":0}},{"key":"error_recovery","audience":"human","score":null,"summary":"Could not verify: this scan did not reach the pages that would show it.","evidence":{"locked":true,"count":0}}],"issues":[{"rank":1,"title":"The catalogue endpoint at /products.json is closed and no product sitemap replaces it, so an assistant has no list of what this store sells.","dimensionKey":"machine_discoverability","evidence":{"locked":true,"count":1},"fix":null},{"rank":2,"title":"No security contact or vulnerability disclosure path is published, leaving security researchers with no way to report issues responsibly.","dimensionKey":"machine_fetchable_trust","evidence":{"locked":true,"count":3},"fix":null},{"rank":3,"title":"The product feed endpoint is closed, forcing agents to crawl individual product pages instead of reading a catalog.","dimensionKey":"programmatic_onboarding","evidence":{"locked":true,"count":3},"fix":null}],"fixArtifacts":{"locked":true,"count":4,"summaries":[{"id":"robots_search_bots:robots-txt","kind":"robots_search_bots","title":"robots.txt rules for AI crawlers","path":"/robots.txt","effort":{"minutes":10,"role":"owner"},"outcome":{"dimension":"machine_discoverability","external":["The assistants' search crawlers read and cite the site to buyers; training stays the owner's decision."]}},{"id":"security_txt:well-known-security-txt","kind":"security_txt","title":"security.txt","path":"/.well-known/security.txt","effort":{"minutes":10,"role":"owner"},"outcome":{"dimension":"machine_fetchable_trust","external":["Researchers and automated scanners find a disclosure address instead of guessing one."]}},{"id":"interfaces_note:notes","kind":"interfaces_note","title":"Machine interfaces: where you stand","path":"notes","effort":{"minutes":10,"role":"owner"},"outcome":{"dimension":"agent_aware_instrumentation","external":["The developer surface is built in an order where every published pointer answers."]}},{"id":"llms_txt:llms-txt","kind":"llms_txt","title":"llms.txt","path":"/llms.txt","effort":{"minutes":15,"role":"owner"},"outcome":{"dimension":"machine_discoverability","external":["Assistants that read llms.txt get a curated map of the site instead of guessing from the homepage."]}}]},"feedback":{"endpoint":"/api/feedback","mcpTool":"rate_fix","targets":[{"type":"report","key":"report"},{"type":"dimension","dimensionKey":"machine_discoverability","key":"dimension:machine_discoverability"},{"type":"dimension","dimensionKey":"programmatic_onboarding","key":"dimension:programmatic_onboarding"},{"type":"dimension","dimensionKey":"pricing_legibility","key":"dimension:pricing_legibility"},{"type":"dimension","dimensionKey":"agent_aware_instrumentation","key":"dimension:agent_aware_instrumentation"},{"type":"dimension","dimensionKey":"machine_fetchable_trust","key":"dimension:machine_fetchable_trust"},{"type":"dimension","dimensionKey":"commercial_rails","key":"dimension:commercial_rails"},{"type":"dimension","dimensionKey":"steps_to_first_value","key":"dimension:steps_to_first_value"},{"type":"dimension","dimensionKey":"required_fields","key":"dimension:required_fields"},{"type":"dimension","dimensionKey":"verification_walls","key":"dimension:verification_walls"},{"type":"dimension","dimensionKey":"error_recovery","key":"dimension:error_recovery"},{"type":"issue","dimensionKey":"machine_discoverability","checkId":"catalog_feed","key":"issue:machine_discoverability:catalog_feed"},{"type":"issue","dimensionKey":"machine_fetchable_trust","checkId":"security_txt","key":"issue:machine_fetchable_trust:security_txt"},{"type":"issue","dimensionKey":"programmatic_onboarding","checkId":"openapi","key":"issue:programmatic_onboarding:openapi"}]}}