# Harry's: 23 point Door Gap
- Site: harrys.com
- Scanned: 2026-09-11
- Scan type: Basic scan
- Business type: ecommerce
- Report: https://www.seconddoor.io/r/harrys-xvth2x
- Scanner version: 54
- Scanner release: 2cdef4a
- Scoring methodology: 1
- Evidence schema: 1
1 human and 5 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 95/100 (1/4 dimensions) |
| Agents | 72/100 (5/6 dimensions) |
| Composite | 84/100 |
| Door Gap | 23 points |
The human score is the mean of the measured human dimensions, the agent score the mean of the measured agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The scanner recorded successful observations for 11 of 15 checks, but could not find a contact route for machines. It came up empty on 3 other checks too. 3 checks could not be measured; see the report limitations.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      find out what pages exist
- missing find a contact route for machines
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- ok      read a product page as data
- ok      read the returns and shipping terms
- ok      discover storefront agent checkout rails
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **No valid security.txt was identified at /.well-known/security.txt.** (machine_fetchable_trust)
   - Evidence: /.well-known/security.txt: not found (404)
   - Evidence: Checked URL: https://www.harrys.com/.well-known/security.txt
   - Fix: Publish /.well-known/security.txt with a contact route.
The full report is at https://www.seconddoor.io/r/harrys-xvth2x
## Files generated from this scan
- **Product markup skeleton** at `/en/products/cooling-eye-kit`, 30 minutes, developer. Verify: The next scan reads price, currency and availability in the Product markup of at least one product page.
- **Complete the merchant fields in product markup** at `snippets/seconddoor-product-jsonld.liquid`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in the Product markup it samples.
- **Return policy and shipping structured data** at `product page`, 30 minutes, developer. Verify: The next scan reads a MerchantReturnPolicy on the product pages, and OfferShippingDetails when the shipping node was published.
- **Link the policy pages from the product page** at `notes`, 30 minutes, no developer needed. Verify: The next scan finds the returns and shipping policy pages linked from a product page.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/harrys-xvth2x
## The agent door
- **machine_discoverability** 100/100. No restriction on the tested crawler names was found in robots.txt. On its first visit, our browser read the homepage. No user agent rule refused the tested retrieval crawler names.
- **programmatic_onboarding** 30/100. No general API documentation or OpenAPI specification was identified through the paths checked. A storefront MCP endpoint answered the tested tools/list discovery request; authentication and use were not tested.
- **pricing_legibility** 88/100. Product-associated price evidence was identified in the HTTP responses from the 3 product pages checked. Product structured data publishes price and currency, so an agent can parse cost without scraping. Availability is published too.
- **agent_aware_instrumentation** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
- **machine_fetchable_trust** 65/100. No security.txt was identified at the checked path. The returns policy reads as text. The shipping policy reads as text. The homepage answers automated requests.
- **commercial_rails** 79/100. Product markup carries price and currency. Products carry an identifier. The sitemap lists the products. A Shopify storefront; product identifier and brand coverage were checked. Returns and shipping terms read as text.
## The human door
- **steps_to_first_value** 95/100. A product priced at $28.00 was reached in 2 steps; a purchase control was visible.
- **required_fields** not measured. Not measured: this scan did not reach the page or action needed to verify it.
- **verification_walls** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
- **error_recovery** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
