Skip to content
Good for Bots

Client-side secret and PII scanner for text before pasting into AI chatbots

Click badge to copy

Changed your site? Run a new scan.

Claim to rescan

Claiming is free. Verify ownership to request a rescan after deploying your changes.

Unclaimed listings are checked automatically every 90 days.

Good for Bots report

PasteGuard scores 23 of 100: 17 of the 50 base points, 6 of the 50 agent-layer points, no penalties.

Earned

17 of the 50 base points above the line, 6 of the 50 agent-layer points below it.

23

3 prompts away

Copy them below ↓

33

Still open

Behind the checks below, with prompts in Pro.

44
Penalties0
How scoring works · current methodology →

Through a bot’s eyes

“PasteGuard is a free, client-side text scanner that runs in the browser to detect API keys, private keys, and PII before you paste into AI chatbots.”

Simulated from the response GoodForBotsBot received on , not a live answer from any AI assistant.

What it can read, and what stays hidden →

What a bot can read

A language model reading the provided homepage and llms.txt files learns that PasteGuard is a free, in-browser security tool for detecting secrets and personal data before sending text to AI tools like ChatGPT, Claude, or Copilot. The text covers its core functions, including local browser execution, offline support, sample testing, and redaction capabilities. The llms.txt file adds specific usage steps, a link to the open source GitHub repository, and explicit agent notes clarifying that the site is a human-facing tool rather than an API service. Pricing is explicitly stated as free with no account required, and contact or support details are absent beyond the repository link.

What is PasteGuard?

PasteGuard is a client-side text scanning tool designed to detect API keys, bearer tokens, private keys, and common personally identifiable information before users paste text into artificial intelligence chat interfaces. It is built for individuals who use AI chatbots and want to prevent the accidental leakage of sensitive data.

Read more →

The application runs entirely within the user's web browser, ensuring that all scanning happens locally without uploading text or collecting analytics. It offers features such as live scanning as you type, sample text testing, copy redaction, and offline functionality once loaded.

3 prompts, 33 points

For Claude Code, Cursor or Codex. The score moves after the next scan.

+12.5score from 23 to 35

Serve Markdown at its own URL

No /llms-full.txt and no markdown versions linked from llms.txt.

Read prompt

+10.2score from 35 to 46

Publish a sitemap that parses

No sitemap was found.

Read prompt

+10.2score from 46 to 56

Describe the site with schema.org JSON-LD

The homepage publishes no structured data at all: no JSON-LD, no microdata, no RDFa.

Read prompt

Pro

19 more prompts in Pro

Pro shows a prompt for every fix and drafts your llms.txt and robots.txt. It never changes the score.

$9 once, per listingSee Pro

Deployed your fixes? Rescan to update your score →

Ready-made files

Pro drafts these for this site.

Pro

A ready-made llms.txt and robots.txt

Pro drafts both files for PasteGuard from its scan, keeps only links and rules our parsers can verify, and hands them over ready to review and publish. It never changes the score.

See Pro

Select a check to see what we found and how it is graded.

Readable base

17.4 / 50

Fails.

0 of 4.1 points.

No robots.txt at /robots.txt (HTTP 404).

Prompt in Pro →
Fails.

0 of 10.2 points.

No sitemap was found.

Fails.

0 of 10.2 points.

The homepage publishes no structured data at all: no JSON-LD, no microdata, no RDFa.

Half passes.

6.1 of 12.2 points.

The homepage is partly structured: No <main> element and nothing carrying role="main".

Prompt in Pro →
Not applicable.

0 of 0 points.

No applicable navigation links were observed in the homepage HTML.

Passes.

5.1 of 5.1 points.

16 of 16 assessed homepage links and buttons have a nonempty accessible name.

Passes.

3.1 of 3.1 points.

1 of 1 assessed homepage form fields meet the static naming and field-semantics checks.

Passes.

3.1 of 3.1 points.

18 of 18 assessed homepage controls and role declarations meet the static role, state and relationship checks.

Fails.

0 of 2 points.

The homepage declares no canonical URL, in a Link header or a <link> element.

Prompt in Pro →

Agent layer

5.6 / 50

Half passes.

5.6 of 11.3 points.

/llms.txt has a title but lists no links to follow.

Prompt in Pro →
Fails.

0 of 7.5 points.

/llms.txt lists no links, so there is nothing to describe.

Prompt in Pro →
Fails.

0 of 12.5 points.

No /llms-full.txt and no markdown versions linked from llms.txt.

Fails.

0 of 10 points.

Asking the homepage for markdown still returns text/html.

Prompt in Pro →
Fails.

0 of 5 points.

No robots.txt, so no rules for AI crawlers either.

Prompt in Pro →
Fails.

0 of 2.5 points.

No usage declaration found in robots.txt or the final successful homepage response header.

Prompt in Pro →

Penalties

− 0

Passes.

Penalty: 0 of 15 points.

Our crawler reaches the page without being challenged.

Passes.

Penalty: 0 of 20 points.

Nothing on the homepage tells a crawler to skip it or to withhold its snippet.

Not applicable.

Penalty: 0 of 0 points.

The homepage contains text or potentially meaningful elements; JavaScript dependence is not established.

Passes.

Penalty: 0 of 25 points.

No applicable robots.txt rules block search or user-fetch crawlers from the homepage.

Passes.

Penalty: 0 of 10 points.

The homepage is served over HTTPS and returns HTTP 200.

Passes.

Penalty: 0 of 3 points.

The homepage provides both a non-empty title and meta description.

Passes.

Penalty: 0 of 3 points.

The homepage is reached in 0 redirects.

Passes.

Penalty: 0 of 3 points.

The homepage reached a plain crawler in 321 ms.

Agent capabilities

0 of 10 · no points

Each one found adds +1 to the badge.

Not applicable.

Adds +1 to the badge when found.

No API catalog published.

Not applicable.

Adds +1 to the badge when found.

No /auth.md published.

Not applicable.

Adds +1 to the badge when found.

No AI Catalog published, so no MCP server card can be discovered.

Not applicable.

Adds +1 to the badge when found.

No A2A Agent Card at /.well-known/agent-card.json, and none listed in an AI Catalog.

Not applicable.

Adds +1 to the badge when found.

No usable Agent Skills index was found at either well-known path or in the AI Catalog.

Not applicable.

Adds +1 to the badge when found.

No WebMCP declarations were found in the collected HTML or inline scripts. External scripts were not inspected.

Not applicable.

Adds +1 to the badge when found.

No Web Bot Auth key directory at /.well-known/http-message-signatures-directory.

Not applicable.

Adds +1 to the badge when found.

No HTTP 402 payment challenge on the homepage or robots.txt, and no manifest at /.well-known/x402.

Not applicable.

Adds +1 to the badge when found.

No ACP discovery declaration established at /.well-known/acp.json.

Not applicable.

Adds +1 to the badge when found.

No UCP discovery declaration established at /.well-known/ucp.

Access & usage policy

Who can read this page, and for what purpose?

GoodForBotsBot received HTTP 200 via a direct request. No indexing restriction was observed in the supported homepage directives.

Sampled URL: https://pasteguard-exp2.netlify.app/

Declared crawling rules

Other crawlers' declared access could not be established.

Sources and scope: declared crawling rules
  • Declared allow · Scan admission

    • GoodForBotsBot/1.0 (+https://goodforbots.com/bot)

    The recorded robots admission decision allowed our crawler to proceed.

    GoodForBotsBot admission along the homepage request chain

    https://pasteguard-exp2.netlify.app/

    robots.txt is present and valid

  • Unknown · robots.txt

    • goodforbotsbot (Site diagnostics)
    • * (Default robots group)
    • oai-searchbot (ai-search)
    • claude-searchbot (ai-search)
    • perplexitybot (ai-search)
    • mistralai-index (ai-search)
    • kimi-searchbot (ai-search)
    • amzn-searchbot (ai-search)
    • meta-webindexer (ai-search)
    • exasearchbot (ai-search)
    • aiwebindex (ai-search)
    • duckassistbot (ai-search)
    • shapbot (ai-search)
    • yandexadditional (ai-search)
    • yandexadditionalbot (ai-search)
    • gptbot (ai-training)
    • claudebot (ai-training)
    • mistralai-training (ai-training)
    • kimibot (ai-training)
    • ai2bot (Unknown)
    • applebot-extended (ai-training)
    • webzio-extended (ai-training)
    • chatgpt-user (user-fetch)
    • claude-user (user-fetch)
    • perplexity-user (user-fetch)
    • mistralai-user (user-fetch)
    • kimi-user (user-fetch)
    • amzn-user (user-fetch)
    • diffbot-user (user-fetch)
    • firecrawlagent (extraction)
    • webzio (extraction)
    • meta-externalfetcher (user-fetch, agent)
    • google-extended (ai-training, grounding)
    • meta-externalagent (ai-training, product-improvement)
    • amazonbot (ai-training, product-improvement)
    • ccbot (open-dataset, ai-training)
    • googlebot (search)
    • bingbot (search)

    A complete, successful robots.txt was not available for this origin; no other crawler's rules are inferred.

    Acquisition of https://pasteguard-exp2.netlify.app/

    https://pasteguard-exp2.netlify.app/robots.txt

    robots.txt is present and validStates a position on AI crawlersAllows search and user-fetch crawlers

Observed access

GoodForBotsBot received HTTP 200 via a direct request.

Sources and scope: observed access
Coverage and interpretation
  • Crawler coverage includes the registered identities and up to 50 user-agent entries from robots.txt. Source excerpts and detail groups are bounded; omissions are labelled.
  • Observed access describes GoodForBotsBot only. Other crawler entries describe declared rules, not tests of those operators' access.
  • Coverage is the sampled homepage response and collected robots.txt files. No indexing or citation is guaranteed. Usage preferences are declarations, not a legal determination of permission.
  • This explanation adds no points or penalties. Any score effects belong to the linked checks.
  • AIPREF and Content Signals keep their own definitions. AIPREF search can include processing used exclusively for search; training preferences are not a blanket ruling on every search process.

In its category

24th of 24 in Developer Tools & APIs

Whole category →
  1. 1Good for Botsgoodforbots.com
  2. 2Chrome Goldminechromegoldmine.com
  3. 24PasteGuard · this reportpasteguard-exp2.netlify.app

The prompts above would take PasteGuard to 56, 12th in its category.

To the prompts ↑

Category average 56. The percentile appears once the catalogue holds a few hundred sites.

Scanned

Site profile

Login
Not established
API
Not established
Commerce
Not established

It decides which conditional checks apply. “Not established” means no proof in what we read, not proof of absence.

Scan details

Every scan is kept. Pro draws the history as a chart →

Scanned
3 Oct 2026
Rubric
0.9.0
Requests
18
Fetched
134.2 KB
Took
12.5 s
Homepage
321 ms · direct
Pages read
1
robots.txt
allowed

More like PasteGuard:Developer Tools & APIsSecurity & PrivacyDevelopersOpen Source

Same category

goodforbots.com

Evaluates website readability for AI crawlers and language models with a scoring rubric

Same category

jomatter.online

Free browser-based tools for formatting, validating, and testing HTML, CSS and JavaScript

Same category

speejax.online

Free browser-based tools to minify code, compress images, and optimize website performance

Same category

agentskills.codes

Open registry of installable skills and instruction files for AI coding assistants

Same category

huntbug.com

Crowdsourced bug bounty platform connecting security researchers with companies

Same category

enjoyseos.online

Free online toolkit for SEO previews, schema generation, sitemaps, and redirects