# Free Fly Apparel: agent door 57, human door not measured
- Site: freeflyapparel.com
- Scanned: 2026-09-04
- Scan type: Deep scan
- Business type: unknown
- Report: https://www.seconddoor.io/r/freeflyapparel-s89mh8
- Scanner version: 10
Free Fly's storefront is unusually agent-ready on paper, with a UCP checkout manifest and full product JSON, but the actual shopping walk could not find anything to buy.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 57/100 |
| Composite | 57/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The agent got through 10 of 17 requests, but could not find a contact route for machines. It came up empty on 6 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- ok      read a product page as data
- ok      read the returns and shipping terms
- ok      walk the way a visitor would, to a signup form or a product
## What a visitor meets
1. **Landing page first view** (smooth). A popup for 15% off overlays the page immediately, offering an email discount. Behind it, the site is clearly an apparel ecommerce brand: bamboo and sun protective clothing for men, women and kids. Nav bar, search and cart icons are visible. No ambiguity about what is sold.
## Top issues
1. **No security.txt is published, so a machine has no documented route to report a problem.** (machine_fetchable_trust)
2. **Product structured data is missing return policy and shipping details, leaving the merchant feed incomplete even though the policies themselves are published as readable text.** (agent_aware_instrumentation)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/freeflyapparel-s89mh8
## Files generated from this scan
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Put Okendo reviews in the page** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds review text in the server HTML of a product page.
- **Return policy and shipping structured data** at `product page`, 30 minutes, developer. Verify: The next scan reads a MerchantReturnPolicy on the product pages, and OfferShippingDetails when the shipping node was published.
- **Link the policy pages from the product page** at `notes`, 30 minutes, no developer needed. Verify: The next scan finds the returns and shipping policy pages linked from a product page.
- **Variants missing a GTIN or a brand** at `catalog-identifiers.csv`, 5 minutes, no developer needed. Verify: The next scan reads the catalogue feed and finds a valid GTIN on at least nine in ten variants and a brand on at least nine in ten products.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/freeflyapparel-s89mh8
## The agent door
- **machine_discoverability** 100/100. No AI crawler is blocked, robots.txt names 14 assistant agents as allowed, a 425 URL sitemap lists products, and /products.json answers directly. Nothing stands between a bot and the catalog.
- **programmatic_onboarding** 10/100. There is no API product here to onboard to. No developer docs are linked from the homepage, no OpenAPI spec exists at 6 standard paths, and no general MCP manifest was found at 3 standard paths.
- **pricing_legibility** 90/100. Prices sit in raw HTML on the homepage (9 prices) and on product pages (77 prices across 3 pages checked), and Product JSON-LD carries price, currency and availability. An agent can read cost without executing JavaScript.
- **agent_aware_instrumentation** 57/100. No general MCP manifest, but a Universal Commerce Protocol manifest and a storefront MCP endpoint both exist for Shopify checkout. Product markup is 10 of 15 merchant-feed fields complete, missing return policy and shipping schema.
- **machine_fetchable_trust** 65/100. No security.txt at the standard path. Returns and shipping policies read as plain text pages, but neither is embedded in product structured data, so an agent parsing only JSON-LD misses them.
- **commercial_rails** 20/100. A UCP manifest declares 8 capabilities including checkout, cart and order across 3 payment handlers, and a storefront MCP endpoint exists. But the actual agent shopping walk followed 4 pages into the catalog and found nothing purchasable.
## The human door
- **steps_to_first_value** null/100. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** null/100. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** null/100. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** null/100. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
