HonestClaw
What is Agent Readiness?

Agent Readiness Score

gitlab.com

28 — Limited. Agents will struggle to discover or use this site without human help.

40 of 45 checks conclusive · Confidence High · Evidence coverage 89%

HonestClaw measured how well gitlab.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability9.2/24
Content Accessibility12.3/19
Bot Access Control0/10
Protocol & Capability Discovery10.9/36
Authentication & Credentials1/19
Documentation Quality1.8/10
Structured Data I/O0/9
Observable State & Reliability0.2/15
Agent Safety & Trust8.1/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepBoth an API-family and a docs-family subdomain are live (api.gitlab.com, docs.gitlab.com).Useful
robots.txtrobots-txtrobots.txt at https://gitlab.com/robots.txt is a valid robots file (no Sitemap: declared).Parseable
sitemap.xmlsitemap-xmlhttps://gitlab.com/sitemap.xml is a dated sitemap whose URLs include docs/pricing/api surfaces.Cross-verified
Canonical domaincanonical-domainRoot and www converge on about.gitlab.com, with a matching canonical tag.Cross-verified
API existenceapi-existenceA conventional API path at https://gitlab.com/users/sign_in returned an auth challenge (HTTP 403). (source: live)Detected
API catalogapi-catalogCould not conclusively check for an API Catalog (endpoint unreachable, rate-limited, or behind auth). Blocked by robots.txt for a generic compliant agent (Disallow: /api/v*).Not detected
API versioningapi-versioningVersioning is mentioned at https://gitlab.com/gitlab-org/version-app-codeclimate, but not on a page dedicated to documenting it. (source: docs)Detected

Content Accessibility

Markdown twinmarkdown-twinA markdown twin is published at https://docs.gitlab.com/index.md alongside the docs HTML surface (https://docs.gitlab.com/).Parseable
llms.txtllms-txtA curated llms.txt index is published on a non-top subdomain at https://docs.gitlab.com/llms.txt: 563 links across 7 sections. Its credit is capped at useful because it is not published on the main domain.Useful
Freshness signalsfreshness-signalsFreshness signals present: ETag header, sitemap lastmod.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredLarge sitemap (18,771 page URLs) signals high crawl cost with limited guidance.Detected
Raw content extractabilityraw-content-extractabilityModerate-to-strong main content (62% of visible text) is extractable from raw HTML on the homepage.Useful
llms-full.txtllms-full-txtCould not conclusively check for an llms-full.txt file (endpoints unreachable, rate-limited, or behind auth).Couldn't verify
ai.txtai-txtCould not conclusively check for an ai.txt file (endpoints unreachable, rate-limited, or behind auth).Couldn't verify

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt is readable but declares no AI-bot-specific rules.Not detected
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepCould not conclusively check for a TDMRep policy (unreachable, rate-limited, or behind auth).Couldn't verify

Protocol & Capability Discovery

MCP descriptormcp-descriptorInformational — not scoredNo MCP descriptor found at the standard locations an agent would check.Not detected
.well-known indexwell-known-indexCould not conclusively check /.well-known/ descriptors (unreachable, rate-limited, or behind auth). Blocked by robots.txt for a generic compliant agent (Disallow: /-/user_settings/).Not detected
MCP supportmcp-supportA first-party MCP support page exists at https://gitlab.com/gitlab-org/ai/lazy-mcp, but it does not identify a concrete HTTPS MCP endpoint or fully establish a company-operated service.Parseable
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.gitlab.com.Not detected
GraphQL surfacegraphql-surfaceA GraphQL transport surface is advertised at https://gitlab.com/graphiql (GraphiQL/Playground or Apollo markers).Useful
Link headerslink-headersNo RFC 8288 Link headers found on any probed response. Blocked by robots.txt for a generic compliant agent (Disallow: /api/v*).Not detected
OpenAPI specificationopenapi-specCould not conclusively check for an OpenAPI/Swagger specification (endpoints unreachable, rate-limited, or behind auth). Blocked by robots.txt for a generic compliant agent (Disallow: /api/v*).Not detected
Auth discoveryauth-discoveryA drivable auth-discovery descriptor is published.Useful
SDK availabilitysdk-availabilityGetting-started page at https://gitlab.com/gitlab-org/analytics-section/product-analytics/gl-application-sdk-golang: 1 GitHub repo, 0 registry links, 0 install commands (1 pointer).Useful
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify
Rate limit documentationrate-limit-docsCould not conclusively check for rate limit documentation (endpoints unreachable, rate-limited, or behind auth).Couldn't verify

Authentication & Credentials

Credential managementcredential-managementNo credential management documentation found at the standard docs locations an agent would check.Not detected
Programmatic auth flowprogrammatic-auth-flowNo programmatic authentication documentation found at the standard docs locations an agent would check.Not detected
Auth documentationauth-documentationAuthentication is mentioned at https://gitlab.com/gitlab-org/auth, but not on a page dedicated to documenting it.Detected
Sandbox environmentsandbox-environmentA test environment is mentioned at https://gitlab.com/gitlab-org/graphql-sandbox, but not on a page dedicated to documenting it.Detected

Documentation Quality

API reference depthapi-reference-depthAPI reference documentation lacks depth or was not found.Not detected
Changelog presencechangelog-presenceA changelog page exists at https://gitlab.com/gitlab-org/ci-cd/runner-tools/step-runner-internal/changelog, but it doesn't list dated entries describing actual changes.Parseable

Structured Data I/O

Structured data I/Ostructured-data-ioNo published structured-data contract found (no typed spec response schemas). Blocked by robots.txt for a generic compliant agent (Disallow: /api/v*).Not detected
Machine-readable pricingmachine-readable-pricingCould not conclusively check for a machine-readable pricing endpoint (endpoints unreachable, rate-limited, or behind auth). Blocked by robots.txt for a generic compliant agent (Disallow: /api/v*).Not detected
Data export APIdata-export-apiCould not conclusively check for data export or bulk API documentation (endpoints unreachable, rate-limited, or behind auth).Couldn't verify

Observable State & Reliability

Status & health endpointsstatus-and-healthStatus page found at https://status.gitlab.com/ (HTTP 200).Detected
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe. Blocked by robots.txt for a generic compliant agent (Disallow: /api/v*).Not detected
Webhook documentationwebhook-documentationNo webhook or event documentation found at the standard docs locations an agent would check.Not detected
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Error documentationerror-documentationNo error documentation found at the standard docs locations an agent would check.Not detected

Agent Safety & Trust

security.txtsecurity-txtsecurity.txt at https://gitlab.com/.well-known/security.txt includes Contact, a future Expires date, and Encryption or Policy.Cross-verified
Org identity signalsorg-identityHomepage exposes three org-identity signal types (legal_name, address, social).Useful
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
Legal policy pageslegal-pagesNo terms, privacy, or data-use policy pages found at conventional paths.Not detected