# Legion Athletics: agent door 65, human door not measured
- Site: legionathletics.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: ecommerce
- Report: https://www.seconddoor.io/r/legionathletics-buu45j
- Scanner version: 15
A retail storefront with strong product data and no account requirement, but no agent checkout manifest and no programmatic onboarding surface.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 65/100 (6/6 dimensions) |
| Composite | 65/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The site refused automated access at /.well-known/security.txt, so the agent could not find a contact route for machines.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- blocked find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- ok      read a product page as data
- ok      read the returns and shipping terms
## Top issues
1. **Security.txt is blocked from automated access, so an agent cannot verify the site's security contact or incident reporting process.** (machine_fetchable_trust)
2. **No agent checkout manifest is published, so an agent cannot complete a purchase without human handoff.** (agent_aware_instrumentation)
3. **No API documentation or OpenAPI spec is published, so an agent cannot onboard programmatically and must browse the storefront like a human.** (programmatic_onboarding)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/legionathletics-buu45j
## Files generated from this scan
- **Product markup skeleton** at `/products/supplements/whey-protein-powder/`, 2 hours, developer. Verify: The next scan reads price, currency and availability in the Product markup of at least one product page.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Link the policy pages from the product page** at `notes`, 30 minutes, no developer needed. Verify: The next scan finds the returns and shipping policy pages linked from a product page.
- **Agent checkout: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds a UCP manifest, a storefront MCP endpoint or another discovery file answering, and the checkout check passes.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/legionathletics-buu45j
## The agent door
- **machine_discoverability** 100/100. No AI crawler is blocked by robots.txt or user agent rules. A real browser is served the page normally. The sitemap lists 111 URLs including products themselves. Nine schema.org types appear on the homepage. llms.txt is published.
- **programmatic_onboarding** 10/100. No API documentation is linked from the homepage or published at standard paths. No OpenAPI spec exists at any of the 6 standard paths checked. An agent cannot onboard programmatically; it must browse the storefront like a human.
- **pricing_legibility** 90/100. 47 prices appear in the homepage HTML without JavaScript. 176 prices across 3 product pages render as plain text. Product structured data publishes price and currency for every variant.
- **agent_aware_instrumentation** 21/100. No MCP manifest exists at the 3 standard paths checked. WooCommerce supports agent checkout protocols, but no manifest is published yet. Product markup carries identifier, price, currency, availability, brand, rating and return terms, so.
- **machine_fetchable_trust** 89/100. Security.txt could not be verified; automated access was refused at that path. The returns policy and shipping policy both read as plain text. Return policy is published in structured data with 365-day terms.
- **commercial_rails** 77/100. Product markup carries price, currency and identifier. The sitemap lists all products. Return policy is in structured data with 365-day terms. Returns and shipping policies read as text on dedicated pages.
## The human door
- **steps_to_first_value** not measured. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** not measured. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** not measured. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** not measured. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
