# Loops: 0 point Door Gap
- Site: loops.so
- Scanned: 2026-09-09
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/loops-w5qfnt
- Scanner version: 25
2 human and 4 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 73/100 (2/4 dimensions) |
| Agents | 73/100 (4/6 dimensions) |
| Composite | 73/100 |
| Door Gap | 0 points |
The human score is the mean of the measured human dimensions, the agent score the mean of the measured agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The scanner recorded successful observations for 10 of 13 checks, but could not find a contact route for machines. It came up empty on 2 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- ok      find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- ok      find a machine readable API spec
- ok      read the developer documentation
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **No valid security.txt was identified at /.well-known/security.txt.** (machine_fetchable_trust)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/loops-w5qfnt
## Files generated from this scan
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/loops-w5qfnt
## The agent door
- **machine_discoverability** 90/100. No restriction on the tested crawler names was found in robots.txt. on its first visit, our browser read the homepage. no user agent rule refused the tested retrieval crawler names. a sitemap listing 232 URLs.
- **programmatic_onboarding** 62/100. A machine readable API spec is published. OAuth authorization metadata is published.
- **pricing_legibility** not measured. Not applicable to this scanned surface.
- **agent_aware_instrumentation** 100/100. An MCP manifest is published. OAuth authorization metadata is published, which is how a remote MCP server is found. pricing.md publishes prices in a form an agent can read directly. a machine readable API spec is published.
- **machine_fetchable_trust** 40/100. No security.txt was identified at the checked path. the homepage answers automated requests.
- **commercial_rails** not measured. Not applicable to this scanned surface.
## The human door
- **steps_to_first_value** 80/100. A signup form was reached in 2 steps from the homepage.
- **required_fields** 65/100. 3 of 3 fields on the observed form are marked required.
- **verification_walls** not measured. Not measured: this scan did not reach the page or action needed to verify it.
- **error_recovery** not measured. Not measured: this scan did not reach the page or action needed to verify it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
