# Graza: agent door 54, human door not measured
- Site: graza.co
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: ecommerce
- Report: https://www.seconddoor.io/r/graza-9ffjqj
- Scanner version: 16
A Shopify storefront with open product data but no checkout integration for agents, and reviews locked behind JavaScript.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 54/100 (6/6 dimensions) |
| Composite | 54/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The agent got through 9 of 14 requests, but could not find a contact route for machines. It came up empty on 4 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- ok      read a product page as data
## Top issues
1. **Reviews load from Okendo by script, so a client that reads raw HTML sees the products without a single review.** (pricing_legibility)
2. **No security.txt is published, so a machine has no documented route to report a problem.** (machine_fetchable_trust)
3. **No OpenAPI specification was found at the 6 standard paths checked, so a client must be written from prose instead of generated.** (programmatic_onboarding)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/graza-9ffjqj
## Files generated from this scan
- **Product markup snippet for every product page** at `snippets/seconddoor-product-jsonld.liquid`, 30 minutes, developer. Verify: The next scan reads price, currency and availability in the Product markup of every product page it samples, with the structured price matching the catalogue feed.
- **Put Okendo reviews in the page** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds review text in the server HTML of a product page.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Variants missing a GTIN or a brand** at `catalog-identifiers.csv`, 5 minutes, no developer needed. Verify: The next scan reads the catalogue feed and finds a valid GTIN on at least nine in ten variants and a brand on at least nine in ten products.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/graza-9ffjqj
## The agent door
- **machine_discoverability** 100/100. No AI crawler is blocked by robots.txt or user agent rules; ChatGPT, Claude, Gemini and Perplexity are explicitly allowed. The homepage serves 2000 characters to a real browser, the sitemap lists 37 URLs including products, and llms.txt is.
- **programmatic_onboarding** 10/100. No API documentation, OpenAPI spec, or integration surface was found at any of the 6 standard paths checked. The site publishes product data as JSON but offers no programmatic way for an agent to place an order or manage a transaction.
- **pricing_legibility** 90/100. Prices are embedded in the raw HTML of every product page and the homepage, so an agent can read cost without JavaScript. Product structured data carries price in USD and currency code. Availability is published.
- **agent_aware_instrumentation** 14/100. No MCP manifest exists at any of the 3 standard paths checked. The catalogue does answer as JSON at /products.json, which is the only machine-readable instrumentation present. No AI plugin manifest or Web Bot Auth signals were found.
- **machine_fetchable_trust** 40/100. The homepage and all key pages are served to automated clients without blocking. No security.txt file is published at /.well-known/security.txt, so no contact or vulnerability disclosure policy is machine-readable.
- **commercial_rails** 70/100. Product markup carries price, currency, GTIN, brand, and availability. The catalogue is readable as JSON. Shopify Catalog can syndicate these products to shopping agents.
## The human door
- **steps_to_first_value** not measured. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** not measured. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** not measured. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** not measured. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
