# Faherty Brand: agent door 57, human door not measured
- Site: fahertybrand.com
- Scanned: 2026-09-04
- Scan type: Basic scan
- Business type: unknown
- Report: https://www.seconddoor.io/r/fahertybrand-28w6ja
- Scanner version: 10
A Shopify storefront with strong machine discoverability but no programmatic API for agents to integrate with the business.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 57/100 |
| Composite | 57/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The agent got through 11 of 17 requests, but could not find a contact route for machines. It came up empty on 5 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- ok      read a product page as data
- ok      read the returns and shipping terms
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **No security contact or vulnerability disclosure policy is published, leaving no clear path for researchers to report security issues.** (machine_fetchable_trust)
2. **No API documentation or programmatic integration path is published for third parties to build on Faherty's catalog or order system.** (programmatic_onboarding)
3. **The Universal Commerce Protocol endpoint is not discoverable through standard MCP manifest paths, requiring agents to know the endpoint URL in advance.** (agent_aware_instrumentation)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/fahertybrand-28w6ja
## Files generated from this scan
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Put Yotpo reviews in the page** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds review text in the server HTML of a product page.
- **Link the policy pages from the product page** at `notes`, 30 minutes, no developer needed. Verify: The next scan finds the returns and shipping policy pages linked from a product page.
- **Variants missing a GTIN or a brand** at `catalog-identifiers.csv`, 5 minutes, no developer needed. Verify: The next scan reads the catalogue feed and finds a valid GTIN on at least nine in ten variants and a brand on at least nine in ten products.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/fahertybrand-28w6ja
## The agent door
- **machine_discoverability** 100/100. No AI crawler is blocked by robots.txt; the site serves a real browser normally and publishes llms.txt. The sitemap lists 704 URLs including products themselves. Structured data includes 19 schema.org types on the homepage.
- **programmatic_onboarding** 10/100. No API documentation is linked from the homepage or discoverable in the site structure. No OpenAPI spec exists at any of the 6 standard paths checked.
- **pricing_legibility** 85/100. Prices appear in raw HTML on the homepage and all 3 product pages checked, without requiring JavaScript. Product structured data publishes price and currency on every offer. Availability is also published. A GTIN identifies each product.
- **agent_aware_instrumentation** 57/100. A Universal Commerce Protocol manifest is published at version 2026-08-25, declaring 8 capabilities and 3 payment handlers. A storefront MCP endpoint answers agent calls.
- **machine_fetchable_trust** 77/100. No security.txt is published. The returns policy and shipping policy both read as plain text. Return policy and shipping terms are published in structured data.
- **commercial_rails** 10/100. The site is a Shopify storefront with a Universal Commerce Protocol manifest, so an agent can call the MCP endpoint to add items to cart and proceed to checkout. No other integration path is documented or discoverable.
## The human door
- **steps_to_first_value** null/100. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** null/100. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** null/100. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** null/100. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
