github.com

Journey

· Snapshot & citation

68.4/ 100

C · Needs work

Waymark scored github.com 68.4/100 (C) on 25 Aug 2026.

github.com is blockers remain. Usability is the strongest layer, and Discovery is the open one. Next: openAPI document.

FindMixed
12.8/20
11 of 18 checks passed
DoorMixed
20.2/30
24 of 36 checks passed
ToolsMixed
28.6/40
14 of 19 checks passed
Pay
N/A
No cart or pay rail — out of the denominator.

What should the prompt cover?

24 findings · 19 selected

Failures (16)

Warnings (8)

Group by
1. Can an agent discover and trust you?ROBOTSSITEMAPDISCOVERYSKILLS 44/100

Whether an agent can find this origin from public files and treat it as the real one.

pass
HTTPS reachable 2/2
Evidence. Homepage responded 200 over HTTPS.
Probed homepage.
pass
robots.txt present 2/2
Evidence. Valid robots.txt with User-agent rules.
Probed robots.txt.
failed
XML sitemap 0/2
Evidence. No sitemap.xml.
Recommended fix. Add /sitemap.xml and reference it from robots.txt.
failed
Well-known AI catalog 0/1
Evidence. No ai-plugin.json or ai-catalog.json.
Recommended fix. Add /.well-known/ai-plugin.json or /.well-known/ai-catalog.json.
failed
AGENTS.md 0/1
Evidence. agents.md status 406.
Probed public URLs named in the evidence.
Recommended fix. Publish /agents.md with agent-oriented usage notes.
partial
robots.txt AI policy Required 1/2
Evidence. robots.txt present but no named AI crawlers.
Probed robots.txt.
Recommended fix. Name GPTBot, ClaudeBot, Google-Extended, PerplexityBot and state allow or deny.
failed
Sitemap for agents Recommended 0/2
Evidence. No sitemap.
Recommended fix. Publish /sitemap.xml.
failed
HTTP Link header bonus 0/1
Evidence. No rel=sitemap|describedby|api-catalog|alternate on homepage.
Probed homepage + sitemap.
Recommended fix. Send RFC 8288 Link headers for related machine resources.
failed
ai-plugin.json bonus 0/1
Evidence. No /.well-known/ai-plugin.json.
Probed well-known paths.
Recommended fix. Optionally publish a plugin-style capability manifest.
n/a
API catalog linkset bonus 0/2
Evidence. No public API catalog (N/A).
scanner error
Wikipedia sitelink bonus 0/4
Evidence. Wikidata SPARQL The operation was aborted
Scanner error — not counted as a site fail and not in the score denominator.
scanner error
Wikidata official website bonus 0/3
Evidence. Wikidata SPARQL The operation was aborted
Scanner error — not counted as a site fail and not in the score denominator.
scanner error
Brand official-website match Recommended 0/3
Evidence. Wikidata SPARQL The operation was aborted
Scanner error — not counted as a site fail and not in the score denominator.
pass
Public MCP registry listing bonus 1/1
Evidence. Registry hit at https://registry.modelcontextprotocol.io/v0/servers?search=github.
Probed public URLs named in the evidence.
pass
Package homepage match bonus 1/1
Evidence. npm package homepage matches github.com.
Probed homepage.
n/a
Sitemap lastmod bonus 0/1
Evidence. No sitemap.
n/a
related-website-set bonus 0/1
Evidence. No related-website-set (N/A unless multi-origin).
n/a
ads.txt bonus 0/1
Evidence. No ads inventory (N/A).
2. Do you welcome agents?ROBOTSCRAWLBOT AUTH 93/100

Whether crawlers and signed bots are allowed through rather than blocked at the door.

pass
AI crawlers not blanket-blocked 2/2
Evidence. No blanket Disallow: / for common AI bots.
pass
robots Crawl-delay bonus 1/1
Evidence. Crawl-delay mentioned in robots.txt.
Probed robots.txt.
n/a
Web Bot Auth keys Recommended 0/2
Evidence. No http-message-signatures-directory.
partial
CORS / API hint 0.5/1
Evidence. No CORS header or obvious API path.
Recommended fix. If you expose an API, send Access-Control-Allow-Origin for intended clients.
pass
CSP or X-Frame-Options 1/1
Evidence. CSP or X-Frame-Options present.
pass
robots.txt agent-user policy Required 2/2
Evidence. No Disallow: / for ChatGPT-User, Claude-User, or Perplexity-User (silence passes).
3. Does an agent understand who you are and what you do?HTMLJSON-LDLLMS.TXTSKILLSDOCSNLWEB 53/100

Whether the site explains the product in language a model can ingest.

pass
Title and description 2/2
Evidence. Title and meta description present.
failed
JSON-LD structured data 0/4
Evidence. No JSON-LD on the homepage.
Probed homepage.
Recommended fix. Add JSON-LD (Organization, WebSite, or SoftwareApplication).
pass
html lang attribute 1/1
Evidence. html[lang] is set.
failed
JSON-LD entities Recommended 0/4
Evidence. No JSON-LD.
Recommended fix. Embed Organization, Product, Offer, SoftwareApplication, or FAQPage.
n/a
JSON-LD sameAs bonus 0/2
Evidence. No JSON-LD.
pass
Open Graph basics bonus 2/2
Evidence. Open Graph plus canonical.
pass
llms.txt 2/2
Evidence. Found /llms.txt with content.
pass
llms.txt index Recommended 2/2
Evidence. llms.txt has content.
pass
llms.txt size and links Recommended 2/2
Evidence. llms.txt 28649 chars, 120 URL(s).
pass
llms-full.txt bonus 1/1
Evidence. llms-full.txt present.
n/a
Section llms.txt bonus 0/1
Evidence. No /docs/llms.txt.
n/a
NLWeb schemamap bonus 0/1
Evidence. No schemamap (N/A unless you offer NL search).
failed
Trust pages Recommended 0/2
Evidence. No about/privacy/contact link.
Recommended fix. Link about or privacy from the homepage.
n/a
Speakable markup bonus 0/1
Evidence. No SpeakableSpecification (N/A unless voice content).
n/a
humans.txt bonus 0/1
Evidence. No /humans.txt (optional).
pass
security.txt Recommended 1/1
Evidence. RFC 9116 security.txt with Contact.
failed
RSS or Atom feed 0/1
Evidence. No RSS/Atom link.
Recommended fix. Expose an RSS or Atom feed for machine subscribers.
n/a
RSS or Atom document bonus 0/1
Evidence. No /feed or /rss.xml document.
failed
Agent instruction / when-to-use Required 0/3
Evidence. Agent file exists without when-to-use guidance.
Recommended fix. Tell agents when to reach for you: add a 'when to use this' section to your llms.txt (or a dedicated agent-instructions file) that names your best-fit use cases.
n/a
Organization schema completeness Recommended 0/2
Evidence. No Organization JSON-LD to score completeness.
n/a
Schema type breadth Recommended 0/2
Evidence. No JSON-LD to score type breadth.
pass
Content without JavaScript Required 3/3
Evidence. Raw HTML has H1 and 3172 visible characters without JavaScript.
4. Can an agent integrate with you?LINKSSKILLSDOCSAPIOPSMCPSDK 77/100

Whether there is a documented machine door into the product.

pass
OpenAPI / Swagger link 2/2
Evidence. Homepage links mention OpenAPI or Swagger.
Probed homepage + OpenAPI.
pass
Login or docs link 3/3
Evidence. Login or developer docs link found.
failed
MCP well-known card 0/2
Evidence. MCP mentioned without a well-known card.
Probed well-known paths.
Recommended fix. Publish /.well-known/mcp.json describing your MCP server.
pass
MCP SSE / HTTP hint 1/1
Evidence. Page mentions MCP or SSE transport.
n/a
openapi.json fetchable 0/0
Evidence. OpenAPI linked but not fetchable at common or discovered paths.
Probed OpenAPI.
pass
Webhook or API docs 2/2
Evidence. Webhook or API docs mention found.
n/a
Agent skills index 0/2
Evidence. No agent-skills index (N/A unless you publish skills).
partial
OpenAPI document Required 1/7
Evidence. OpenAPI probe.
Probed OpenAPI.
Recommended fix. Publish an OpenAPI document at a stable URL. Verify: curl -sI https://github.com/openapi.json
pass
Public API surface Recommended 7/7
Evidence. Docs or API paths look callable.
pass
Developer portal Recommended 6/6
Evidence. Developer hub found.
pass
MCP server Recommended 5/6
Evidence. https://api.githubcopilot.com/mcp/ initialize 401 on documented MCP (5/6 until public initialize)
Probed public URLs named in the evidence.
partial
MCP server card Recommended 1/2
Evidence. MCP mentioned without a card.
Recommended fix. Publish /.well-known/mcp.json or mcp/server-card.json.
n/a
Agent Skills files bonus 0/2
Evidence. No SKILL.md surface (N/A).
pass
CLI tool Recommended 3/3
Evidence. CLI mention found.
pass
GraphQL GET hint bonus 2/2
Evidence. GraphQL GET or docs mention.
pass
OpenAPI UI page bonus 1/1
Evidence. Swagger UI or Redoc page found.
n/a
OpenAPI (legacy slot) 0/0
Evidence. Linked but not fetched.
Probed public URLs named in the evidence.
5. Is your integration well-built?APIMCP 50/100

Whether the integration surface is complete enough to call with confidence.

n/a
MCP initialize Required 0/3
Evidence. OAuth-gated MCP at https://api.githubcopilot.com/mcp/ (HTTP 401) — not scored.
Probed public URLs named in the evidence.
partial
MCP server card Recommended 1/2
Evidence. MCP mentioned without a card.
Recommended fix. Publish /.well-known/mcp.json or mcp/server-card.json.
n/a
REST typed error model Recommended 0/1
Evidence. No OpenAPI document to analyze.
Probed OpenAPI.
n/a
REST versioning / deprecation policy Recommended 0/1
Evidence. No OpenAPI document to analyze.
Probed OpenAPI.
n/a
REST pagination pattern Recommended 0/1
Evidence. No OpenAPI document to analyze.
Probed OpenAPI.
n/a
REST async-job pattern Recommended 0/1
Evidence. No OpenAPI document to analyze.
Probed OpenAPI.
n/a
REST response schema coverage Recommended 0/1
Evidence. No OpenAPI document to analyze.
Probed OpenAPI.
n/a
Function calling compatibility Recommended 0/1
Evidence. No OpenAPI document to analyze.
Probed OpenAPI.
n/a
REST batch / bulk endpoint bonus 0/1
Evidence. No OpenAPI document to analyze.
Probed OpenAPI.
n/a
MCP tool listing bonus 0/3
Evidence. OAuth-gated MCP — tools/list not failed.
n/a
MCP tool descriptions bonus 0/3
Evidence. OAuth-gated MCP — tools/list not failed.
n/a
MCP parameter schemas bonus 0/2
Evidence. OAuth-gated MCP — tools/list not failed.
n/a
MCP tool naming bonus 0/2
Evidence. OAuth-gated MCP — tools/list not failed.
n/a
MCP tool annotations bonus 0/2
Evidence. OAuth-gated MCP — tools/list not failed.
n/a
MCP resources exposed Recommended 0/3
Evidence. OAuth-gated MCP — resources/list not failed.
6. Can an agent use you reliably in production?MCPAPIOPS 54/100

Whether errors, idempotency, and limits are visible before a call fails.

partial
Rate limit signal Recommended 1/2
Evidence. API surface without a rate-limit signal.
Recommended fix. Document or send rate-limit headers on APIs.
partial
Idempotency signal Recommended 1/3
Evidence. API surface without idempotency notes.
Recommended fix. Document idempotency keys for mutating calls.
partial
Machine-readable errors Recommended 1/4
Evidence. API surface without a JSON error shape.
Recommended fix. Return a JSON or problem+json error body.
pass
Honest 404 Recommended 2/2
Evidence. 404/410 on probe path.
pass
Sandbox / test environment bonus 2/2
Evidence. Fetched a sandbox/test page.
Probed public URLs named in the evidence.
n/a
Agent onboarding friction Recommended 0/2
Evidence. No OpenAPI spec; onboarding stays N/A (no live signup probe).
Probed OpenAPI.
n/a
MCP error handling bonus 0/2
Evidence. OAuth-gated MCP — bad-call probe skipped.
7. Can an agent authenticate to you?SDKOAUTHAUTH.MDMCP 87/100

Whether an agent can obtain access without a human in the loop.

failed
OAuth / OIDC well-known 0/2
Evidence. No oauth-authorization-server or openid-configuration.
Recommended fix. Publish /.well-known/openid-configuration or oauth-authorization-server if you authenticate agents.
n/a
OAuth 2.0 surface Required 0/5
Evidence. No delegated-access surface (N/A).
n/a
OAuth AS metadata Required 0/3
Evidence. No AS metadata (N/A unless you run an AS).
n/a
PKCE S256 Required 0/2
Evidence. No OAuth metadata to evaluate PKCE.
pass
OAuth protected resource Recommended 2/2
Evidence. oauth-protected-resource found.
pass
Scoped permissions Recommended 5/5
Evidence. Named scopes found.
pass
Scoped permissions Recommended 2/2
Evidence. scopes_supported from OAuth protected resource: repo, delete_repo, read:org, read:user, user:email, read:packages.
n/a
auth.md bonus 0/2
Evidence. No /auth.md (optional).
n/a
auth.md structure bonus 0/2
Evidence. No /auth.md to grade.
pass
change-password well-known bonus 1/1
Evidence. change-password HTTP 200.
pass
MCP auth mechanism bonus 2/2
Evidence. Documented MCP challenges with OAuth.
pass
Agent auth WWW-Authenticate hint bonus 1/1
Evidence. MCP 401 WWW-Authenticate resource_metadata at https://api.githubcopilot.com/mcp/.
Probed public URLs named in the evidence.
8. Can an agent transact with you?PRICINGX402MPPUCPACPAP2 100/100

Whether an agent can price, pay, or check out on a documented rail.

n/a
x402 payment bonus 0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
n/a
Agentic checkout (ACP) bonus 0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
n/a
ACP delegated payment bonus 0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
n/a
Universal Commerce Protocol bonus 0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
n/a
Machine Payments Protocol bonus 0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
n/a
AP2 - Agent Payments Protocol bonus 0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
pass
Pricing page Recommended 3/3
Evidence. Fetched /pricing.
Probed public URLs named in the evidence.
n/a
pricing.md bonus 0/2
Evidence. No /pricing.md (optional).
9. Can a user act through an agent?APPS 100/100

Whether a person can finish a job through an agent-facing UI.

n/a
MCP Apps UI hint bonus 0/1
Evidence. No MCP Apps hint (N/A unless you return UI).
n/a
A2A agent card Required 0/2
Evidence. No agent-card.json (N/A unless A2A).
pass
Web app manifest bonus 1/1
Evidence. Web app manifest fetched.
Probed public URLs named in the evidence.
pass
Listed on skills.sh bonus 1/1
Evidence. Official skills.sh org github/awesome-copilot.
10. Can an agent operate your website directly?MARKDOWNA11YHTMLWEBMCPNLWEBLLMS.TXT 67/100

Whether an agent can read and operate the site itself when there is no API or MCP.

failed
Markdown negotiation bonus 0/1
Evidence. Homepage did not negotiate markdown.
Probed homepage.
Recommended fix. Respond to Accept: text/markdown with a markdown body.
failed
/index.md fallback bonus 0/1
Evidence. index.md status 404.
Probed public URLs named in the evidence.
Recommended fix. Serve a markdown homepage at /index.md.
n/a
WebMCP page tools bonus 0/1
Evidence. No in-page WebMCP (N/A).
pass
NLWeb /ask bonus 1/1
Evidence. NLWeb or /ask signal.
pass
Agent mode view bonus 1/1
Evidence. mode=agent responded.
Probed public URLs named in the evidence.
n/a
NodeInfo bonus 0/1
Evidence. No nodeinfo (N/A).
n/a
oEmbed discovery bonus 0/1
Evidence. No oEmbed (N/A unless embeddable).
n/a
Markdown alternate link bonus 0/1
Evidence. No rel=alternate type=text/markdown.
failed
Markdown frontmatter metadata bonus 0/1
Evidence. Served markdown has no YAML frontmatter block.
Recommended fix. Open served markdown with a --- frontmatter block carrying title plus description, canonical, or last-updated.
n/a
Markdown content negotiation (acceptmarkdown.com) bonus 0/1
Evidence. Homepage does not negotiate markdown.
Probed homepage.
pass
Agent-UA markdown docs bonus 1/1
Evidence. GPTBot Accept: text/markdown returned text/markdown; charset=utf-8.
pass
Accessible document structure bonus 3/3
Evidence. Homepage HTML has main, nav, H1, and a sane heading order.
Probed homepage.
pass
Code fence validity bonus 1/1
Evidence. No fenced blocks to unbalance.
partial
llms.txt links resolve Recommended 1/2
Evidence. 5 real, 0 homepage-shell, 3 dead of 8 sampled links.
Probed homepage.
Recommended fix. Make every link your llms.txt declares resolve to real content, not a homepage shell 200.

About this snapshot & how to cite it

Public technical signals observed by Waymark. A score describes this snapshot; it does not guarantee that an agent will complete a task. Private and authenticated workflows are outside this scan.

Snapshot: . Cite the domain, score, scan time, and report URL. This URL serves the latest completed snapshot and can change after a rescan.

Methodology and limits · Markdown · JSON evidence

Scanner issues (not site fails): , , .

Share this snapshot

Embed the latest score. A badge is a public snapshot, not a certification.

Waymark score badge for github.com
Open badge SVG ↗

Also on the Board

Same-category snapshots, ordered by score. Scan times may differ.

Email me if this score changes

Join the monitoring waitlist. Monitoring is not active yet. This saves your interest; it does not schedule scans or send change alerts.

By joining, you agree to save your email and this domain for monitoring launch contact, for up to 180 days. Request removal via Contact. No billing.

Email this report

Send the current snapshot and a link. One email. Not a list.

We'll send github.com as it stands on this page.