# Bulletproof: agent door 52, human door not measured
- Site: bulletproof.com
- Scanned: 2026-09-11
- Scan type: Basic scan
- Business type: ecommerce
- Report: https://www.seconddoor.io/r/bulletproof-cr7fap
- Scanner version: 53
- Scanner release: 88fabcf
- Scoring methodology: 1
- Evidence schema: 1
0 human and 5 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 52/100 (5/6 dimensions) |
| Composite | 52/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The scanner recorded successful observations for 10 of 17 checks, but could not find a contact route for machines. It came up empty on 6 other checks too. 1 check could not be measured; see the report limitations.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find an MCP manifest at the standard paths checked
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- ok      read a product page as data
- ok      read the returns and shipping terms
- ok      discover storefront agent checkout rails
## Top issues
1. **The checked /products.json endpoint did not provide a catalogue, and no product sitemap was identified.** (machine_discoverability)
   - Evidence: /products.json answered HTTP 404 at the checked endpoint.
   - Evidence: Checked URL: https://www.bulletproof.com
   - Fix: Check whether your storefront supports a public catalogue endpoint, or publish a product sitemap and declare it in robots.txt.
2. **No valid security.txt was identified at /.well-known/security.txt.** (machine_fetchable_trust)
The evidence and the recommended fix for the rest are on the report page: https://www.seconddoor.io/r/bulletproof-cr7fap
## Files generated from this scan
- **Let verified assistants through** at `notes`, 1 hour, developer. Verify: On a subsequent scan, compare the same endpoint and client response. An unavailable check remains unresolved.
- **Product markup skeleton** at `/products/mood-booster-instant-mushroom-latte-4-7-oz`, 30 minutes, developer. Verify: The next scan reads price, currency and availability in the Product markup of at least one product page.
- **Complete the merchant fields in product markup** at `snippets/seconddoor-product-jsonld.liquid`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in the Product markup it samples.
- **Return policy and shipping structured data** at `product page`, 30 minutes, developer. Verify: The next scan reads a MerchantReturnPolicy on the product pages, and OfferShippingDetails when the shipping node was published.
- **Link the policy pages from the product page** at `notes`, 30 minutes, no developer needed. Verify: The next scan finds the returns and shipping policy pages linked from a product page.
- **Agent checkout: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds a UCP manifest, a storefront MCP endpoint or another discovery file answering, and the checkout check passes.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/bulletproof-cr7fap
## The agent door
- **machine_discoverability** 80/100. No restriction on the tested crawler names was found in robots.txt. Our browser received a refusal or a stripped page at the checked URL. No user agent rule refused the tested retrieval crawler names.
- **programmatic_onboarding** 10/100. No API interface was identified through the discovery paths and homepage links checked.
- **pricing_legibility** 83/100. Product-associated price evidence was identified in the HTTP responses from the 3 product pages checked. Product structured data publishes price and currency, so an agent can parse cost without scraping. Availability is published too.
- **agent_aware_instrumentation** 21/100. No MCP manifest was identified at the discovery paths checked. Shopify was detected; no checkout discovery interface was identified at the endpoints checked.
- **machine_fetchable_trust** 65/100. No security.txt was identified at the checked path. The returns policy reads as text. The shipping policy reads as text. The homepage answers automated requests.
- **commercial_rails** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
## The human door
- **steps_to_first_value** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **required_fields** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **verification_walls** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **error_recovery** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
