Can agents find your site and its capabilities?
The page registers no tools via the WebMCP browser API (navigator.modelContext).
Fix: Expose your actions to AI agents with the WebMCP browser API: register tools via navigator.modelContext.registerTool. Optionally also publish a /.well-known/webmcp.json tool catalog as a discovery signpost.
Found https://burrow.com/llms.txt.
Found at least one "[name](url)" markdown link.
Found a "> summary" blockquote.
First line is a top-level "# Title" heading.
Crawled 12 of 12 discovered pages beyond the homepage.
Built on Shopify.
Can agents understand your content?
No <h1> tag found on the homepage.
Fix: Add exactly one <h1> that names the page. AI summarisers use it as the document title.
Homepage ignored Accept: text/markdown and returned HTML.
Fix: Serve a markdown version of high-value pages when the client asks for text/markdown. AI summarisers, chatbots and IDE agents prefer markdown — fewer tokens, no DOM noise.
Detected 1 heading level skip (e.g. h2 → h5).
Fix: Tighten the heading order so each level only steps down by one. Skipped levels confuse both screen-readers and AI structural extractors.
Only 52/87 images have width+height — large CLS risk.
Fix: Set width and height on every <img> so the browser reserves space before the image loads. A layout that shifts while loading makes an AI agent mis-click the element it targeted.
Homepage server response contains 1184 words of visible text — content is reachable without executing JavaScript.
Homepage contains ~1405 elements.
Language declared as "en".
87 of 87 <img> tags have alt attributes.
300 internal links found.
All four landmark elements present (main, header, footer, nav).
All 12 reachable key pages have both a <title> and <h1>.
All 12 pages return ≥80 words of visible text without JavaScript.
Can agents actually operate the page?
Lighthouse flagged this audit — agents may be unable to perceive or operate the affected elements.
Fix: Give ARIA buttons/links/menuitems an accessible name.
The page registers no tools via the navigator.modelContext browser API, so an AI agent has no structured way to operate it.
Fix: Expose your site’s actions to AI agents with the WebMCP browser API: call navigator.modelContext.registerTool({ name, description, inputSchema, execute }) from your page so an agent can invoke them. Implement it directly, or with a library like the @mcp-b polyfill (https://mcp-b.ai). Spec: https://github.com/webmachinelearning/webmcp.
1 of 13 agent-critical accessibility audits failed (`button`, `link`, and `menuitem` elements do not have accessible names.) — an agent may be unable to identify or operate the affected elements.
Fix: Fix the failing agent-accessibility audits listed below (accessible names on controls, valid ARIA roles/relationships, nothing interactive hidden from the tree).
Lighthouse accessibility score: 88/100. Agents read the page through its accessibility tree, so this is a proxy for how navigable your site is to an AI agent.
Fix: Resolve the failing accessibility audits below — each one removes an element or relationship an agent would otherwise be blind to.
1.29s (field data from CrUX) — needs improvement.
Fix: Every request an AI agent makes pays this server latency, and agents make many requests per task. Reduce TTFB with edge caching, a CDN, and shipping less server-side work per request.
`[aria-*]` attributes match their roles passed.
`[aria-hidden="true"]` is not present on the document `<body>` passed.
`[aria-hidden="true"]` elements do not contain focusable descendents passed.
`[role]`s have all required `[aria-*]` attributes passed.
`[role]` values are valid passed.
`[aria-*]` attributes are valid and not misspelled passed.
`[aria-*]` attributes have valid values passed.
Buttons have an accessible name passed.
Document has a `<title>` element passed.
ARIA IDs are unique passed.
`<frame>` or `<iframe>` elements have a title passed.
Links have a discernible name passed.
2 of 2 visible interactive form fields have labels.
0.060 (field data from CrUX) — good.
No tool catalog was found at /.well-known/webmcp.json (or /.well-known/webmcp). The catalog is a community convention, not part of the WebMCP standard, so this does not affect WebMCP presence.
Fix: Consider also publishing a tool catalog at /.well-known/webmcp.json: a JSON document with a "spec" of "webmcp/0.1" and a "tools" array, where each tool declares a name and a clear description. It is a community convention (optional, not part of the WebMCP standard) that lets crawlers and agents discover your tools without executing JavaScript.
Can agents safely transact?
/.well-known/oauth-authorization-server returned 404.
Fix: Publish /.well-known/oauth-authorization-server so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
/.well-known/oauth-protected-resource returned 404.
Fix: Publish /.well-known/oauth-protected-resource so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
No Web Bot Auth signature headers — sites can't verify agent identity.
Fix: Web Bot Auth (IETF HTTP Message Signatures over Signature / Signature-Input) lets you cryptographically verify which agent is hitting you. Several CDNs offer turn-key support; otherwise skip until vendor support matures.
HSTS configured (max-age=31536000) but missing includeSubDomains.
Fix: Add `includeSubDomains` so subdomains inherit the policy.
No Referrer-Policy header on the homepage.
Fix: Add `Referrer-Policy: strict-origin-when-cross-origin` so outbound links don't leak full URLs (including query strings) to third parties.
cf-ray: a1eb74f54ec02050-LHR (Cloudflare); Server: cloudflare
CSP header present.
Homepage scheme is https:.
http://burrow.com → https://burrow.com/ (1 hop).
No stack-trace markers in the first 5KB.
Homepage HTML references no http:// resources.
Valid for 51 more days (Sep 10 16:16:03 2026 GMT, issuer: YE2).
Server / X-Powered-By headers don't leak product version.
X-Content-Type-Options: nosniff.
CSP frame-ancestors directive present.
Can agents shop and check out?
No /agents.md at https://burrow.com/agents.md (HTTP 404).
Fix: Shopify auto-ships /agents.md to stores on its agentic-discovery rollout. If yours is missing, check that the store is on a current Online Store version.
Manifest parses as JSON.
Manifest reachable at https://burrow.com/.well-known/ucp.
Services: dev.ucp.shopping.
Transports: mcp, embedded.