# Kosas Cosmetics: 35 point Door Gap
- Site: kosas.com
- Scanned: 2026-09-10
- Scan type: Basic scan
- Business type: ecommerce
- Report: https://www.seconddoor.io/r/kosas-snhf74
- Scanner version: 49
- Scanner release: c49d1def936f56a5ab0871f38c5e6412433ec37a
- Scoring methodology: 1
- Evidence schema: 1
1 human and 4 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 95/100 (1/4 dimensions) |
| Agents | 60/100 (4/6 dimensions) |
| Composite | 78/100 |
| Door Gap | 35 points |
The human score is the mean of the measured human dimensions, the agent score the mean of the measured agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The scanner recorded successful observations for 10 of 17 checks, but could not find a contact route for machines. It came up empty on 6 other checks too. 1 check could not be measured; see the report limitations.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find an MCP manifest at the standard paths checked
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the product catalogue as data
- missing read a product page as data
- ok      read the returns and shipping terms
- ok      discover storefront agent checkout rails
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **No valid security.txt was identified at /.well-known/security.txt.** (machine_fetchable_trust)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/kosas-snhf74
## Files generated from this scan
- **Complete product markup for Mini Lip Pulse Gift** at `/products/mini-lip-pulse-gift`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in this Product markup, with the structured price matching the catalogue feed.
- **Complete product markup for Soulgazer Set** at `/products/soulgazer-set-1`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in this Product markup, with the structured price matching the catalogue feed.
- **Complete product markup for Tinted Skincare Lineup™ Set** at `/products/tinted-skincare-lineup-dreambeam`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in this Product markup, with the structured price matching the catalogue feed.
- **Complete the merchant fields in product markup** at `snippets/seconddoor-product-jsonld.liquid`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in the Product markup it samples.
- **Put Okendo reviews in the page** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds review text in the server HTML of a product page.
- **Return policy and shipping structured data** at `product page`, 30 minutes, developer. Verify: The next scan reads a MerchantReturnPolicy on the product pages, and OfferShippingDetails when the shipping node was published.
- **Variants missing a GTIN or a brand** at `catalog-identifiers.csv`, 5 minutes, no developer needed. Verify: The next scan reads the catalogue feed and finds a valid GTIN on at least nine in ten variants and a brand on at least nine in ten products.
- **OpenAI product feed** at `openai-product-feed.tsv`, 20 minutes, no developer needed. Verify: The next scan finds a valid GTIN and a brand on the sampled variants and the product pages carry the fields a feed listing needs.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/kosas-snhf74
## The agent door
- **machine_discoverability** 97/100. No restriction on the tested crawler names was found in robots.txt. On its first visit, our browser read the homepage. No user agent rule refused the tested retrieval crawler names. A sitemap listing 72 URLs.
- **programmatic_onboarding** 30/100. No general API documentation or OpenAPI specification was identified through the paths checked. A storefront MCP endpoint answered the tested tools/list discovery request; authentication and use were not tested.
- **pricing_legibility** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
- **agent_aware_instrumentation** 49/100. No MCP manifest was identified at the discovery paths checked. A Universal Commerce Protocol manifest is published. A storefront MCP endpoint answered the tested tools/list request. The catalogue answers as data at /products.json.
- **machine_fetchable_trust** 65/100. No security.txt was identified at the checked path. The returns policy reads as text. The shipping policy reads as text. The homepage answers automated requests.
- **commercial_rails** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
## The human door
- **steps_to_first_value** 95/100. A product priced at $34 was reached in 2 steps; a purchase control was visible.
- **required_fields** not measured. Not measured: this scan did not reach the page or action needed to verify it.
- **verification_walls** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
- **error_recovery** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
