---
title: "Waymark report for kernel.sh"
canonical: "https://waymark.genedai.me/score/kernel.sh"
last-updated: "2026-08-26T16:26:40.492Z"
---

# Waymark report for kernel.sh

Waymark scored kernel.sh 86.6/100 (A) on 26 Aug 2026.
Score: 86.6/100 — Mostly ready
Scanned: 2026-08-26T16:26:40.492Z
Canonical report: https://waymark.genedai.me/score/kernel.sh

## Layer breakdown

- Discovery: 14.3/20 (12 of 20 eligible checks passed)
- Access: 27.2/30 (36 of 44 eligible checks passed)
- Usability: 36.4/40 (30 of 32 eligible checks passed)
- Payments: N/A (excluded from the denominator)

## Findings

### 1. AGENTS.md

- Layer: discovery
- Result: failed
- Evidence: agents.md status 404.
- Recommended fix: Publish /agents.md with agent-oriented usage notes.

### 2. Well-known AI catalog

- Layer: discovery
- Result: failed
- Evidence: No ai-plugin.json or ai-catalog.json.
- Recommended fix: Add /.well-known/ai-plugin.json or /.well-known/ai-catalog.json.

### 3. RSS or Atom feed

- Layer: access
- Result: failed
- Evidence: No RSS/Atom link.
- Recommended fix: Expose an RSS or Atom feed for machine subscribers.

### 4. CSP or X-Frame-Options

- Layer: access
- Result: failed
- Evidence: Neither CSP nor X-Frame-Options on homepage.
- Recommended fix: Send Content-Security-Policy or X-Frame-Options.

### 5. CORS / API hint

- Layer: access
- Result: partial
- Evidence: No CORS header or obvious API path.
- Recommended fix: If you expose an API, send Access-Control-Allow-Origin for intended clients.

### 6. robots.txt AI policy

- Layer: discovery
- Result: partial
- Evidence: robots.txt present but no named AI crawlers.
- Recommended fix: Name GPTBot, ClaudeBot, Google-Extended, PerplexityBot and state allow or deny.

### 7. llms-full.txt

- Layer: discovery
- Result: failed
- Evidence: llms-full.txt status 404.
- Recommended fix: Optionally publish /llms-full.txt for one-shot ingest.

### 8. ai-plugin.json

- Layer: discovery
- Result: failed
- Evidence: No /.well-known/ai-plugin.json.
- Recommended fix: Optionally publish a plugin-style capability manifest.

### 9. OAuth protected resource

- Layer: access
- Result: failed
- Evidence: AS present but no resource metadata.
- Recommended fix: Publish RFC 9728 oauth-protected-resource if APIs are OAuth-gated.

### 10. API catalog linkset

- Layer: discovery
- Result: failed
- Evidence: API present without RFC 9727 catalog.
- Recommended fix: Add /.well-known/api-catalog pointing at OpenAPI.

### 11. security.txt

- Layer: access
- Result: failed
- Evidence: No /.well-known/security.txt Contact.
- Recommended fix: Publish /.well-known/security.txt with a Contact field.

### 12. change-password well-known

- Layer: access
- Result: failed
- Evidence: Login surface without /.well-known/change-password.
- Recommended fix: If users have passwords, serve /.well-known/change-password.

### 13. Web app manifest

- Layer: access
- Result: partial
- Evidence: manifest link without a fetchable file.
- Recommended fix: Host /manifest.webmanifest if the site is installable.

### 14. Idempotency signal

- Layer: usability
- Result: partial
- Evidence: API surface without idempotency notes.
- Recommended fix: Document idempotency keys for mutating calls.

### 15. Package homepage match

- Layer: discovery
- Result: failed
- Evidence: No npm package homepage matching kernel.sh.
- Recommended fix: Publish an official package whose homepage is this domain.

### 16. Markdown frontmatter metadata

- Layer: access
- Result: failed
- Evidence: Served markdown has no YAML frontmatter block.
- Recommended fix: Open served markdown with a --- frontmatter block carrying title plus description, canonical, or last-updated.

### 17. Registry branding

- Layer: discovery
- Result: failed
- Evidence: MCP card missing description, icon.
- Recommended fix: Give your MCP server-card a display name, an icon or logo, and a description.

### 18. Multi-language SDK packages

- Layer: usability
- Result: failed
- Evidence: No npm+PyPI official packages whose homepage is this domain.
- Recommended fix: Publish official SDK packages on npm and PyPI whose homepage is this domain.

## Interpretation

Public technical snapshot; not a guarantee of task completion. Private and authenticated workflows are outside this scan. Cite scanned_at and the canonical report URL; the URL serves the latest completed snapshot and can change after a rescan.

The official Waymark score is Discovery 20 / Access 30 / Usability 40 / Payments 10. N/A and scanner-error checks drop out of the denominator; they are not scored as failures. An observed agent journey is supporting evidence and does not change the numeric score.
