HonestClaw
What is Agent Readiness?

Agent Readiness Score

hackerone.com

39 — Limited. Agents will struggle to discover or use this site without human help.

45 of 45 checks conclusive · Confidence High · Evidence coverage 100%

HonestClaw measured how well hackerone.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability11.7/24
Content Accessibility11.2/24
Bot Access Control0/12
Protocol & Capability Discovery13.5/41
Authentication & Credentials4.6/19
Documentation Quality6.8/10
Structured Data I/O8/13
Observable State & Reliability1.8/15
Agent Safety & Trust8.5/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepBoth an API-family and a docs-family subdomain are live (api.hackerone.com, docs.hackerone.com).Useful
robots.txtrobots-txtrobots.txt at https://hackerone.com/robots.txt declares a sitemap. Declared sitemap https://hackerone.com/sitemap.xml resolves as valid XML.Cross-verified
Canonical domaincanonical-domainRoot and www converge on www.hackerone.com, with a matching canonical tag.Cross-verified
sitemap.xmlsitemap-xmlhttps://hackerone.com/sitemap.xml is a valid sitemap (38 location(s)), but without lastmod or non-homepage URLs.Parseable
API existenceapi-existenceA real API surface is declared at https://hackerone.com/api-docs/v1/customers/swagger.json: the spec lists servers and paths. (source: spec)Parseable
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog.Not detected
API versioningapi-versioningThe API version is declared in the spec (info.version) at https://hackerone.com/api-docs/v1/customers/swagger.json. (source: spec)Parseable

Content Accessibility

Raw content extractabilityraw-content-extractabilityModerate-to-strong main content (46% of visible text) is extractable from raw HTML on the homepage.Useful
Freshness signalsfreshness-signalsFreshness signals present: Last-Modified header, ETag header.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredSitemap index declares 38 child sitemaps — high crawl cost; page URL inventory is not directly observable from the index.Detected
llms.txtllms-txtA curated llms.txt index is published on a non-top subdomain at https://docs.hackerone.com/llms.txt: 348 links across 20 sections. Its credit is capped at useful because it is not published on the main domain.Useful
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected
Markdown twinmarkdown-twinNo markdown twin found alongside probed docs HTML surfaces.Not detected

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt is readable but declares no AI-bot-specific rules.Not detected
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

MCP descriptormcp-descriptorInformational — not scoredNo MCP descriptor found at the standard locations an agent would check.Not detected
SDK availabilitysdk-availabilityNo SDK or client library documentation found.Not detected
MCP supportmcp-supportFirst-party documentation at https://docs.hackerone.com/en/articles/16069077-hackerone-mcp-server-setup-tool-reference identifies the MCP endpoint https://hackerone.com/mcp and explains both its capabilities and how clients connect or authenticate.Cross-verified
Link headerslink-headersNo RFC 8288 Link headers found on any probed response.Not detected
OpenAPI specificationopenapi-specValid OpenAPI 3.0.1 spec at https://hackerone.com/api-docs/v1/customers/swagger.json: 152 operations, 155 schemas, 100% response coverage, servers declared.Cross-verified
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.hackerone.com.Not detected
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
Auth discoveryauth-discoveryA drivable auth-discovery descriptor is published.Useful
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued).Not detected
Rate limit documentationrate-limit-docsNo rate limit documentation found at the standard docs locations an agent would check.Not detected
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify

Authentication & Credentials

Sandbox environmentsandbox-environmentNo sandbox or test environment documentation found at the standard docs locations an agent would check.Not detected
Programmatic auth flowprogrammatic-auth-flowNo programmatic authentication documentation found at the standard docs locations an agent would check.Not detected
Credential managementcredential-managementCredential management is documented at https://docs.hackerone.com/en/articles/8505567-asset-based-credential-management, covering how to rotate or revoke credentials. To reach the top level, it would need rotation, revocation, and scoping/expiry all documented.Useful
Auth documentationauth-documentationAn authentication documentation page exists at https://docs.hackerone.com/en/articles/8410217-two-factor-authentication, but it doesn't name a specific method or show how a request is authenticated.Parseable

Documentation Quality

API reference depthapi-reference-depthAn API reference page exists at https://docs.hackerone.com/en/articles/16069077-hackerone-mcp-server-setup-tool-reference, but it doesn't show parameters with example requests and responses.Parseable
Changelog presencechangelog-presenceA changelog is published at https://docs.hackerone.com/en/articles/10069355-october-2024-changelog with multiple recent dated entries, indicating it is actively maintained.Cross-verified

Structured Data I/O

Structured data I/Ostructured-data-ioThe spec at https://hackerone.com/api-docs/v1/customers/swagger.json declares typed, consistent response schemas (98% of operations) with a pagination pattern and a structured error envelope. (source: spec)Cross-verified
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify).Not detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected

Observable State & Reliability

Status & health endpointsstatus-and-healthNo health or status endpoint found.Not detected
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Webhook documentationwebhook-documentationA webhook documentation page exists at https://docs.hackerone.com/en/articles/8588351-webhooks, but it doesn't list specific event types with their payload shape.Parseable
Error documentationerror-documentationNo error documentation found at the standard docs locations an agent would check.Not detected
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe.Couldn't verify

Agent Safety & Trust

Org identity signalsorg-identityHomepage exposes two org-identity signal types (legal_name, social).Parseable
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
security.txtsecurity-txtsecurity.txt at https://hackerone.com/security.txt includes Contact, a future Expires date, and Encryption or Policy.Cross-verified
Legal policy pageslegal-pagesBoth privacy and terms policies are discoverable with substantive content.Useful