Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanUnclassified/Scanned 8 Sept 2026, 14:15 UTC/1 browser pass
A skincare site blocks automated clients at the door while serving real browsers normally, making it inaccessible to AI agents despite publishing signals of intent.
Older scan
This report was produced by an earlier version of the scanner. Some findings may not match how the site is measured now.
Severe. Your human funnel and your agent funnel are different products.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
1 piece of evidence and the recommended fix are recorded for this issue, with notes written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
The site publishes llms.txt and declares 152 robots.txt directives that allow major AI crawlers (ChatGPT, Claude, Gemini, Perplexity and others), but the homepage itself returns HTTP 403 to automated clients while serving a real browser.
4 observations recorded.
Programmatic onboarding
OAuth authorization metadata is published at the standard path, signalling how a remote MCP server would authenticate, but no API documentation is linked from the homepage and no OpenAPI spec exists at any of the 6 standard paths checked.
3 observations recorded.
Pricing legibility
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Agent-aware instrumentation
OAuth authorization metadata is published, which is the remote MCP convention for how an agent would authenticate to a service. No MCP manifest exists at any of the 3 standard paths checked.
4 observations recorded.
Machine-fetchable trust
No security.txt file is published at /.well-known/security.txt. The homepage refuses automated clients outright with HTTP 403, blocking the most basic trust signal: that the site is willing to be read by machines at all.
2 observations recorded.
Commercial rails
OAuth authorization metadata is published, but pricing is walled behind HTTP 403 to automated clients. No machine-readable pricing exists at /pricing.md or elsewhere.
2 observations recorded.
Steps to first value
The product is usable immediately with no signup required. A visitor lands on the site and can access the product without creating an account or providing any information.
1 observation recorded.
Required fields
There is no signup form and no account system. The entry path walk counted 0 fields and 0 required fields. Nothing is asked of a visitor before they can use the product.
1 observation recorded.
Verification walls
There is no account system and no verification step. The site requires no email confirmation, phone verification or identity check. A visitor accesses the product immediately upon arrival.
1 observation recorded.
Error recovery
There is no form to submit, so there are no validation errors to recover from. A visitor cannot make a mistake during signup because signup does not exist.
1 observation recorded.
It got through 4 of 14.
The site refused automated access at jolieskinco.com, so the agent could not reach the site at all.