# Levels: agent door 32, human door not measured
- Site: levels.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: ecommerce
- Report: https://www.seconddoor.io/r/levels-6yskk6
- Scanner version: 15
A health tracking retailer blocks three named AI crawlers at the network edge despite welcoming them in robots.txt, and has no product pages discoverable to agents.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 32/100 (5/6 dimensions) |
| Composite | 32/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The agent got through 6 of 17 requests, but could not ask whether the door opens for requests carrying the AI crawlers' names. It came up empty on 10 other checks too. That is enough missing for a machine to give up before it reaches a purchase.
- ok      reach the site at all
- ok      find out whether machines are welcome
- missing ask whether the door opens for requests carrying the AI crawlers' names
- missing read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- missing read the product catalogue as data
- ok      read a product page as data
- missing read the returns and shipping terms
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **The network edge refuses 3 declared AI crawlers that robots.txt welcomes, so the published policy and the actual behaviour disagree.** (machine_discoverability)
2. **No OpenAPI specification was found at the 6 standard paths checked, so a client must be written from prose instead of generated.** (programmatic_onboarding)
3. **No developer documentation is linked from the homepage, in raw HTML or the rendered page, so integration starts with a search engine.** (programmatic_onboarding)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/levels-6yskk6
## Files generated from this scan
- **Let verified assistants through** at `notes`, 1 hour, developer. Verify: The next scan opens the homepage and the key pages in a real browser and under the search crawler names, and every one is served.
- **Returns and refunds page** at `/returns`, 30 minutes, no developer needed. Verify: The next scan reads the returns policy page as text without JavaScript and finds it linked from a product page.
- **Shipping and delivery page** at `/shipping`, 30 minutes, no developer needed. Verify: The next scan reads the shipping policy page as text without JavaScript and finds it linked from a product page.
- **Agent checkout: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds a UCP manifest, a storefront MCP endpoint or another discovery file answering, and the checkout check passes.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **llms.txt** at `/llms.txt`, 15 minutes, no developer needed. Verify: The next scan fetches /llms.txt as text and the llms.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/levels-6yskk6
## The agent door
- **machine_discoverability** 53/100. Robots.txt names and allows 5 AI crawlers including GPTBot, Claude and Perplexity, and a real browser is served normally. A sitemap lists 1271 URLs.
- **programmatic_onboarding** 10/100. No API documentation is linked from the homepage. No OpenAPI spec exists at any of the 6 standard paths. The site publishes no programmatic route for agents to discover products or place orders.
- **pricing_legibility** 35/100. 15 prices appear in the homepage HTML, ranging from $1 to $1,999. No product pages were reachable to verify whether prices carry currency, availability, or validity dates in structured markup.
- **agent_aware_instrumentation** 20/100. Robots.txt names 5 AI crawlers and allows them, signalling awareness. No MCP manifest exists at any of the 3 standard paths. No UCP manifest or commerce platform integration was detected.
- **machine_fetchable_trust** 40/100. No security.txt file is published. The homepage answers automated requests from an honest client. No trust signals are available for agents to verify the site's identity or security posture.
- **commercial_rails** not measured. Could not verify: this scan did not reach the pages that would show it.
## The human door
- **steps_to_first_value** not measured. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** not measured. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** not measured. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** not measured. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
