---
title: "Waymark report for github.com"
canonical: "https://waymark.genedai.me/score/github.com"
last-updated: "2026-08-25T04:40:09.140Z"
---

# Waymark report for github.com

Waymark scored github.com 68.4/100 (C) on 25 Aug 2026.
Score: 68.4/100 — Blockers remain
Scanned: 2026-08-25T04:40:09.140Z
Canonical report: https://waymark.genedai.me/score/github.com

## Layer breakdown

- Discovery: 12.8/20 (11 of 18 eligible checks passed)
- Access: 20.2/30 (24 of 36 eligible checks passed)
- Usability: 28.6/40 (14 of 19 eligible checks passed)
- Payments: N/A (excluded from the denominator)

## Findings

### 1. XML sitemap

- Layer: discovery
- Result: failed
- Evidence: No sitemap.xml.
- Recommended fix: Add /sitemap.xml and reference it from robots.txt.

### 2. AGENTS.md

- Layer: discovery
- Result: failed
- Evidence: agents.md status 406.
- Recommended fix: Publish /agents.md with agent-oriented usage notes.

### 3. Well-known AI catalog

- Layer: discovery
- Result: failed
- Evidence: No ai-plugin.json or ai-catalog.json.
- Recommended fix: Add /.well-known/ai-plugin.json or /.well-known/ai-catalog.json.

### 4. JSON-LD structured data

- Layer: access
- Result: failed
- Evidence: No JSON-LD on the homepage.
- Recommended fix: Add JSON-LD (Organization, WebSite, or SoftwareApplication).

### 5. RSS or Atom feed

- Layer: access
- Result: failed
- Evidence: No RSS/Atom link.
- Recommended fix: Expose an RSS or Atom feed for machine subscribers.

### 6. CORS / API hint

- Layer: access
- Result: partial
- Evidence: No CORS header or obvious API path.
- Recommended fix: If you expose an API, send Access-Control-Allow-Origin for intended clients.

### 7. OAuth / OIDC well-known

- Layer: access
- Result: failed
- Evidence: No oauth-authorization-server or openid-configuration.
- Recommended fix: Publish /.well-known/openid-configuration or oauth-authorization-server if you authenticate agents.

### 8. MCP well-known card

- Layer: usability
- Result: failed
- Evidence: MCP mentioned without a well-known card.
- Recommended fix: Publish /.well-known/mcp.json describing your MCP server.

### 9. robots.txt AI policy

- Layer: discovery
- Result: partial
- Evidence: robots.txt present but no named AI crawlers.
- Recommended fix: Name GPTBot, ClaudeBot, Google-Extended, PerplexityBot and state allow or deny.

### 10. Sitemap for agents

- Layer: discovery
- Result: failed
- Evidence: No sitemap.
- Recommended fix: Publish /sitemap.xml.

### 11. HTTP Link header

- Layer: discovery
- Result: failed
- Evidence: No rel=sitemap|describedby|api-catalog|alternate on homepage.
- Recommended fix: Send RFC 8288 Link headers for related machine resources.

### 12. JSON-LD entities

- Layer: access
- Result: failed
- Evidence: No JSON-LD.
- Recommended fix: Embed Organization, Product, Offer, SoftwareApplication, or FAQPage.

### 13. Markdown negotiation

- Layer: access
- Result: failed
- Evidence: Homepage did not negotiate markdown.
- Recommended fix: Respond to Accept: text/markdown with a markdown body.

### 14. /index.md fallback

- Layer: access
- Result: failed
- Evidence: index.md status 404.
- Recommended fix: Serve a markdown homepage at /index.md.

### 15. MCP server card

- Layer: usability
- Result: partial
- Evidence: MCP mentioned without a card.
- Recommended fix: Publish /.well-known/mcp.json or mcp/server-card.json.

### 16. ai-plugin.json

- Layer: discovery
- Result: failed
- Evidence: No /.well-known/ai-plugin.json.
- Recommended fix: Optionally publish a plugin-style capability manifest.

### 17. Rate limit signal

- Layer: usability
- Result: partial
- Evidence: API surface without a rate-limit signal.
- Recommended fix: Document or send rate-limit headers on APIs.

### 18. Idempotency signal

- Layer: usability
- Result: partial
- Evidence: API surface without idempotency notes.
- Recommended fix: Document idempotency keys for mutating calls.

### 19. Machine-readable errors

- Layer: usability
- Result: partial
- Evidence: API surface without a JSON error shape.
- Recommended fix: Return a JSON or problem+json error body.

### 20. OpenAPI document

- Layer: access
- Result: partial
- Evidence: OpenAPI probe.
- Recommended fix: Publish an OpenAPI document at a stable URL.

### 21. Trust pages

- Layer: access
- Result: failed
- Evidence: No about/privacy/contact link.
- Recommended fix: Link about or privacy from the homepage.

### 22. Agent instruction / when-to-use

- Layer: access
- Result: failed
- Evidence: Agent file exists without when-to-use guidance.
- Recommended fix: Tell agents when to reach for you: add a 'when to use this' section to your llms.txt (or a dedicated agent-instructions file) that names your best-fit use cases.

### 23. llms.txt links resolve

- Layer: access
- Result: partial
- Evidence: 5 real, 0 homepage-shell, 3 dead of 8 sampled links.
- Recommended fix: Make every link your llms.txt declares resolve to real content, not a homepage shell 200.

### 24. Markdown frontmatter metadata

- Layer: access
- Result: failed
- Evidence: Served markdown has no YAML frontmatter block.
- Recommended fix: Open served markdown with a --- frontmatter block carrying title plus description, canonical, or last-updated.

## Interpretation

Public technical snapshot; not a guarantee of task completion. Private and authenticated workflows are outside this scan. Cite scanned_at and the canonical report URL; the URL serves the latest completed snapshot and can change after a rescan.

The official Waymark score is Discovery 20 / Access 30 / Usability 40 / Payments 10. N/A and scanner-error checks drop out of the denominator; they are not scored as failures. An observed agent journey is supporting evidence and does not change the numeric score.
