# Good for Bots report: square9\.ai

Website: https://square9\.ai
Report: https://goodforbots.com/r/square9.ai
Scan: cmuthqdo800h501p3hlitccl5
Scanned at: 2026-10-04T07:21:19.532Z
Status: completed
Rubric: 0\.9\.0
Score: 11/100 (Poor)

Site description and bot’s-eye view: unavailable.

## Access & usage policy

The scan did not obtain an eligible homepage response for interpreting its content policy\. Unknown: no eligible homepage response was available\.

Sampled URL: https://square9\.ai/

Crawler identities:

- goodforbotsbot: Good for Bots, Site diagnostics.
- \*: Unspecified, Default robots group.
- oai\-searchbot: OpenAI, ai\-search.
- claude\-searchbot: Anthropic, ai\-search.
- perplexitybot: Perplexity, ai\-search.
- mistralai\-index: Mistral, ai\-search.
- kimi\-searchbot: Moonshot AI, ai\-search.
- amzn\-searchbot: Amazon, ai\-search.
- meta\-webindexer: Meta, ai\-search.
- exasearchbot: Exa, ai\-search.
- aiwebindex: Lyrenth, ai\-search.
- duckassistbot: DuckDuckGo, ai\-search.
- shapbot: Parallel, ai\-search.
- yandexadditional: Yandex, ai\-search.
- yandexadditionalbot: Yandex, ai\-search.
- gptbot: OpenAI, ai\-training.
- claudebot: Anthropic, ai\-training.
- mistralai\-training: Mistral, ai\-training.
- kimibot: Moonshot AI, ai\-training.
- ai2bot: Unspecified, Unknown.
- applebot\-extended: Apple, ai\-training.
- webzio\-extended: Webz\.io, ai\-training.
- chatgpt\-user: OpenAI, user\-fetch.
- claude\-user: Anthropic, user\-fetch.
- perplexity\-user: Perplexity, user\-fetch.
- mistralai\-user: Mistral, user\-fetch.
- kimi\-user: Moonshot AI, user\-fetch.
- amzn\-user: Amazon, user\-fetch.
- diffbot\-user: Diffbot, user\-fetch.
- firecrawlagent: Firecrawl, extraction.
- webzio: Webz\.io, extraction.
- meta\-externalfetcher: Meta, user\-fetch, agent.
- google\-extended: Google, ai\-training, grounding.
- meta\-externalagent: Meta, ai\-training, product\-improvement.
- amazonbot: Amazon, ai\-training, product\-improvement.
- ccbot: Common Crawl, open\-dataset, ai\-training.
- googlebot: Google, search.
- bingbot: Microsoft, search.

### Declared crawling rules

No matching refusal for this URL was found for the listed identities\.

- GoodForBotsBot/1\.0 \(\+https://goodforbots\.com/bot\): The recorded robots admission decision allowed our crawler to proceed\.
  Source: Scan admission; URL: https://square9\.ai/; scope: GoodForBotsBot admission along the homepage request chain; state: allowed.

[Related check: robots\-txt](https://goodforbots.com/standards?rubric=0.9.0#robots-txt)

- goodforbotsbot, \*, oai\-searchbot, claude\-searchbot, perplexitybot, mistralai\-index, kimi\-searchbot, amzn\-searchbot, meta\-webindexer, exasearchbot, aiwebindex, duckassistbot, shapbot, yandexadditional, yandexadditionalbot, gptbot, claudebot, mistralai\-training, kimibot, ai2bot, applebot\-extended, webzio\-extended, chatgpt\-user, claude\-user, perplexity\-user, mistralai\-user, kimi\-user, amzn\-user, diffbot\-user, firecrawlagent, webzio, meta\-externalfetcher, google\-extended, meta\-externalagent, amazonbot, ccbot, googlebot, bingbot: No matching refusal for this URL in the applicable robots group\. This is a declaration, not an access test\.
  Source: robots\.txt; URL: https://square9\.ai/robots\.txt; scope: Acquisition of https://square9\.ai/; state: allowed.

```text
User-agent: *
allow: /
```

[Related check: robots\-txt](https://goodforbots.com/standards?rubric=0.9.0#robots-txt)

[Related check: ai\-crawler\-rules](https://goodforbots.com/standards?rubric=0.9.0#ai-crawler-rules)

[Related check: ai\-crawler\-access](https://goodforbots.com/standards?rubric=0.9.0#ai-crawler-access)

### Observed access

The scan did not obtain an eligible homepage response for interpreting its content policy\.

- GoodForBotsBot/1\.0 \(\+https://goodforbots\.com/bot\): A cloudflare bot challenge answered our request\.
  Source: Direct request; URL: https://square9\.ai; scope: Our recorded direct transport attempt; intermediate attempt URLs are not retained; state: observed.

```text
HTTP 403
```

[Related check: waf\-challenge](https://goodforbots.com/standards?rubric=0.9.0#waf-challenge)

- GoodForBotsBot/1\.0 \(\+https://goodforbots\.com/bot\): The scan did not obtain an eligible homepage response for interpreting its content policy\.
  Source: Final homepage response; URL: https://square9\.ai/; scope: homepage response; state: observed.

```text
HTTP 403
Transport: direct
```

[Related check: homepage\-availability](https://goodforbots.com/standards?rubric=0.9.0#homepage-availability)

[Related check: waf\-challenge](https://goodforbots.com/standards?rubric=0.9.0#waf-challenge)

### Indexing directives

Unknown: no eligible homepage response was available\.

- Scope unresolved: Unknown: no eligible homepage response was available\.
  Source: Homepage directives; URL: https://square9\.ai/; scope: homepage response; state: unknown.

[Related check: indexing\-blocks](https://goodforbots.com/standards?rubric=0.9.0#indexing-blocks)

### Search snippets

Unknown: no eligible homepage response was available\.

- Scope unresolved: Unknown: no eligible homepage response was available\.
  Source: Homepage directives; URL: https://square9\.ai/; scope: homepage response; state: unknown.

[Related check: indexing\-blocks](https://goodforbots.com/standards?rubric=0.9.0#indexing-blocks)

### Search usage

The available evidence does not establish a preference for this use\.

- goodforbotsbot, \*, oai\-searchbot, claude\-searchbot, perplexitybot, mistralai\-index, kimi\-searchbot, amzn\-searchbot, meta\-webindexer, exasearchbot, aiwebindex, duckassistbot, shapbot, yandexadditional, yandexadditionalbot, gptbot, claudebot, mistralai\-training, kimibot, ai2bot, applebot\-extended, webzio\-extended, chatgpt\-user, claude\-user, perplexity\-user, mistralai\-user, kimi\-user, amzn\-user, diffbot\-user, firecrawlagent, webzio, meta\-externalfetcher, google\-extended, meta\-externalagent, amazonbot, ccbot, googlebot, bingbot: No applicable AIPREF preference was established for this purpose\.
  Source: AIPREF Content\-Usage; URL: https://square9\.ai/; scope: Purpose: search; applicable robots group/path and this response's header; state: unknown.

[Related check: content\-signals](https://goodforbots.com/standards?rubric=0.9.0#content-signals)

### AI input and use

The available evidence does not establish a preference for this use\.

- goodforbotsbot, \*, oai\-searchbot, claude\-searchbot, perplexitybot, mistralai\-index, kimi\-searchbot, amzn\-searchbot, meta\-webindexer, exasearchbot, aiwebindex, duckassistbot, shapbot, yandexadditional, yandexadditionalbot, gptbot, claudebot, mistralai\-training, kimibot, ai2bot, applebot\-extended, webzio\-extended, chatgpt\-user, claude\-user, perplexity\-user, mistralai\-user, kimi\-user, amzn\-user, diffbot\-user, firecrawlagent, webzio, meta\-externalfetcher, google\-extended, meta\-externalagent, amazonbot, ccbot, googlebot, bingbot: No applicable AIPREF preference was established for this purpose\.
  Source: AIPREF Content\-Usage; URL: https://square9\.ai/; scope: Purpose: ai\-use; applicable robots group/path and this response's header; state: unknown.

[Related check: content\-signals](https://goodforbots.com/standards?rubric=0.9.0#content-signals)

### AI training

The available evidence does not establish a preference for this use\.

- goodforbotsbot, \*, oai\-searchbot, claude\-searchbot, perplexitybot, mistralai\-index, kimi\-searchbot, amzn\-searchbot, meta\-webindexer, exasearchbot, aiwebindex, duckassistbot, shapbot, yandexadditional, yandexadditionalbot, gptbot, claudebot, mistralai\-training, kimibot, ai2bot, applebot\-extended, webzio\-extended, chatgpt\-user, claude\-user, perplexity\-user, mistralai\-user, kimi\-user, amzn\-user, diffbot\-user, firecrawlagent, webzio, meta\-externalfetcher, google\-extended, meta\-externalagent, amazonbot, ccbot, googlebot, bingbot: No applicable AIPREF preference was established for this purpose\.
  Source: AIPREF Content\-Usage; URL: https://square9\.ai/; scope: Purpose: train\-ai; applicable robots group/path and this response's header; state: unknown.

[Related check: content\-signals](https://goodforbots.com/standards?rubric=0.9.0#content-signals)

- Crawler coverage includes the registered identities and up to 50 user\-agent entries from robots\.txt\. Source excerpts and detail groups are bounded; omissions are labelled\.
- Observed access describes GoodForBotsBot only\. Other crawler entries describe declared rules, not tests of those operators' access\.
- Coverage is the sampled homepage response and collected robots\.txt files\. No indexing or citation is guaranteed\. Usage preferences are declarations, not a legal determination of permission\.
- This explanation adds no points or penalties\. Any score effects belong to the linked checks\.
- AIPREF and Content Signals keep their own definitions\. AIPREF search can include processing used exclusively for search; training preferences are not a blanket ruling on every search process\.

## Site profile

Login: not established.
API: not established.
Commerce: not established.

Not established means the scan found no proof, not that the site lacks it. The profile decides which conditional checks apply.

Robots verdict: allowed

## Scan statistics

```json
{
  "pagesScanned": 0,
  "requestCount": 18,
  "bytesFetched": 506348,
  "durationMs": 95974
}
```

## Pages read

The homepage and up to three content pages chosen from the sitemaps and homepage links. Structured data, page structure, Markdown negotiation and typed links check every page read and take the median page; other checks read the homepage.

- Homepage: https://square9\.ai
- No other eligible page was found in the sitemaps or the homepage links.

## Score breakdown

Readable base: 7.5; agent layer: 18.75; penalties: 15.
Final points are rounded and cannot fall below zero.

[How scoring works · current methodology](https://goodforbots.com/standards?rubric=0.9.0#scoring)

```json
{
  "block1Raw": 9,
  "block1Max": 60,
  "block2Raw": 15,
  "block2Max": 40,
  "coverage": 1,
  "cappedAt": null
}
```

## Detected capabilities

llms\-txt, robots\-txt, llms\-txt\-quality

## Checks

### llms\.txt is present and well formed

ID: llms-txt; version: 2; kind: achievement; status: pass.
Contribution: 11.25; maximum magnitude: 11.25.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=llms-txt&version=2#llms-txt)

/llms\.txt is well formed: 122 links across 8 sections\.

```json
{
  "links": 122,
  "title": "Square9",
  "errors": [],
  "sections": 9,
  "charLength": 33395,
  "hasSummary": true,
  "sectionsWithLinks": 8
}
```

### robots\.txt is present and valid

ID: robots-txt; version: 2; kind: achievement; status: pass.
Contribution: 3.3333333333333335; maximum magnitude: 3.3333333333333335.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=robots-txt&version=2#robots-txt)

robots\.txt is valid, with 1 user\-agent group\.

```json
{
  "errors": [],
  "groups": 1,
  "sitemaps": 2,
  "directives": 5
}
```

### Sitemap is present and parses

ID: sitemap; version: 4; kind: achievement; status: warn.
Contribution: 4.166666666666667; maximum magnitude: 8.333333333333334.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=sitemap&version=4#sitemap)

robots\.txt names a sitemap, but the server refused it to our crawler \(a bot challenge, HTTP 403\)\.

```json
{
  "reason": "declared-but-refused",
  "urlCount": 0,
  "documents": [
    {
      "url": "https://square9.ai/sitemap.xml",
      "kind": "missing",
      "urls": 0,
      "cause": "refused",
      "error": "a bot challenge, HTTP 403",
      "valid": false,
      "children": 0,
      "compressed": false
    },
    {
      "url": "https://square9.ai/blog-sitemap.xml",
      "kind": "missing",
      "urls": 0,
      "cause": "refused",
      "error": "a bot challenge, HTTP 403",
      "valid": false,
      "children": 0,
      "compressed": false
    }
  ],
  "declaredInRobots": true
}
```

### llms\.txt is descriptive, not a bare link list

ID: llms-txt-quality; version: 2; kind: achievement; status: pass.
Contribution: 7.5; maximum magnitude: 7.5.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=llms-txt-quality&version=2#llms-txt-quality)

/llms\.txt is descriptive: a summary plus descriptions on 100% of links\.

```json
{
  "links": 122,
  "charLength": 33395,
  "hasDetails": true,
  "hasSummary": true,
  "describedLinks": 122,
  "descriptionRatio": 1,
  "unconventionalSeparators": 0
}
```

### Serves markdown at its own URL

ID: llms-full-txt; version: 3; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 12.5.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=llms-full-txt&version=3#llms-full-txt)

No /llms\-full\.txt and no markdown versions linked from llms\.txt\.

```json
{
  "reason": "none",
  "llmsFullTxt": {
    "status": 404,
    "usable": false,
    "rejected": null,
    "truncated": false,
    "byteLength": 0
  },
  "markdownLinksInLlmsTxt": 0,
  "servesMarkdownOnRequest": false
}
```

### Serves markdown when asked for it

ID: markdown-negotiation; version: 3; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 10.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=markdown-negotiation&version=3#markdown-negotiation)

Asking the homepage for markdown returned HTTP 403\.

```json
{
  "pages": [
    {
      "url": "https://square9.ai/",
      "reason": "error-status",
      "status": "fail",
      "summary": "Asking the homepage for markdown returned HTTP 403.",
      "homepage": true
    }
  ],
  "reason": "error-status",
  "status": 403
}
```

### States a position on AI crawlers

ID: ai-crawler-rules; version: 5; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 5.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=ai-crawler-rules&version=5#ai-crawler-rules)

robots\.txt names no AI crawlers, so every operator has to guess\.

```json
{
  "allowed": [],
  "blocked": [],
  "purposes": [],
  "crawlersNamed": 0,
  "wildcardBlocksEverything": false
}
```

### Declares AI usage preferences

ID: content-signals; version: 3; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 2.5.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=content-signals&version=3#content-signals)

No usage declaration found in robots\.txt or the final successful homepage response header\.

```json
{
  "carriers": [],
  "contentUsage": [],
  "vocabularies": [],
  "contentSignal": [],
  "contentUsageHeader": null,
  "recognisedUsageCategories": [],
  "recognisedSignalCategories": []
}
```

### Describes itself to machines with schema\.org JSON\-LD

ID: schema-org; version: 4; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 8.333333333333334.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=schema-org&version=4#schema-org)

The homepage did not return an HTML document, so there is no markup to read\.

```json
{
  "nodes": 0,
  "pages": [
    {
      "url": "https://square9.ai/",
      "reason": "no-html",
      "status": "fail",
      "summary": "The homepage did not return an HTML document, so there is no markup to read.",
      "homepage": true
    }
  ],
  "types": [],
  "blocks": 0,
  "reason": "no-html",
  "contexts": [],
  "rdfaTypes": [],
  "truncated": false,
  "validBlocks": 0,
  "brokenBlocks": [],
  "unknownTypes": [],
  "pagesExamined": 0,
  "skippedBlocks": 0,
  "topLevelNodes": 0,
  "microdataTypes": [],
  "missingProperties": [],
  "unnamedTopLevelTypes": []
}
```

### Content is marked up so a reader can find it

ID: semantic-html; version: 4; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 10.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=semantic-html&version=4#semantic-html)

The homepage did not return an HTML document, so there is no markup to read\.

```json
{
  "pages": [
    {
      "url": "https://square9.ai/",
      "reason": "no-html",
      "status": "fail",
      "summary": "The homepage did not return an HTML document, so there is no markup to read.",
      "homepage": true
    }
  ],
  "reason": "no-html"
}
```

### Navigation links expose usable destinations

ID: crawlable-navigation; version: 2; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 8.333333333333334.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=crawlable-navigation&version=2#crawlable-navigation)

The homepage did not supply usable HTML to assess navigation links\.

```json
{
  "reason": "no-html"
}
```

### Links and buttons have accessible names

ID: control-names; version: 1; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 4.166666666666667.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=control-names&version=1#control-names)

The homepage did not supply usable HTML to assess links and buttons\.

```json
{
  "reason": "no-html"
}
```

### Form fields have names and recognizable semantics

ID: form-semantics; version: 1; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 2.5.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=form-semantics&version=1#form-semantics)

The homepage did not supply usable HTML to assess form fields\.

```json
{
  "reason": "no-html"
}
```

### Controls expose roles, states and relationships

ID: control-semantics; version: 1; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 2.5.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=control-semantics&version=1#control-semantics)

The homepage did not supply usable HTML to assess controls and role declarations\.

```json
{
  "reason": "no-html"
}
```

### Advertises machine\-readable resources with typed links

ID: link-headers; version: 4; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 1.25.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=link-headers&version=4#link-headers)

The homepage carries no typed links, in either a Link header or the markup\.

```json
{
  "pages": [
    {
      "url": "https://square9.ai/",
      "reason": "no-links",
      "status": "fail",
      "summary": "The homepage carries no typed links, in either a Link header or the markup.",
      "homepage": true
    }
  ],
  "reason": "no-links",
  "sources": [],
  "totalLinks": 0,
  "markdownAlternates": [],
  "meaningfulRelations": []
}
```

### Each page declares one usable canonical URL

ID: canonical-url; version: 1; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 1.6666666666666667.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=canonical-url&version=1#canonical-url)

The homepage did not supply usable HTML to read a canonical URL from\.

```json
{
  "pages": [
    {
      "url": "https://square9.ai/",
      "reason": "no-html",
      "status": "fail",
      "summary": "The homepage did not supply usable HTML to read a canonical URL from.",
      "homepage": true
    }
  ],
  "reason": "no-html",
  "readings": [
    {
      "url": "https://square9.ai/"
    }
  ]
}
```

### Section links reach an element on the page

ID: section-links; version: 1; kind: achievement; status: fail.
Contribution: 0; maximum magnitude: 0.8333333333333334.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=section-links&version=1#section-links)

The homepage did not supply usable HTML to assess its section links\.

```json
{
  "pages": [
    {
      "url": "https://square9.ai/",
      "reason": "no-html",
      "status": "fail",
      "summary": "The homepage did not supply usable HTML to assess its section links.",
      "homepage": true
    }
  ],
  "reason": "no-html",
  "readings": [
    {
      "url": "https://square9.ai/"
    }
  ]
}
```

### Serves our crawler without a challenge

ID: waf-challenge; version: 2; kind: penalty; status: fail.
Contribution: -15; maximum magnitude: 15.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=waf-challenge&version=2#waf-challenge)

A Cloudflare challenge identified by the cf\-mitigated header\. A model fetching this page gets the challenge, not the content\.

```json
{
  "where": null,
  "marker": "challenge",
  "reason": "cloudflare",
  "status": 403,
  "vendor": "cloudflare",
  "provenBy": "cf-mitigated",
  "recoveredAtRung": null
}
```

### The homepage does not block indexing or snippets

ID: indexing-blocks; version: 5; kind: penalty; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=indexing-blocks&version=5#indexing-blocks)

A bot challenge answered instead of the homepage, so its indexing rules were never read\. The challenge is a separate penalty\.

```json
{
  "error": null,
  "status": 403,
  "deferredTo": "waf-challenge"
}
```

### Serves its content without JavaScript

ID: javascript-required; version: 4; kind: penalty; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=javascript-required&version=4#javascript-required)

A bot challenge answered instead of the homepage, so its markup is not the site's\.

```json
{
  "error": null,
  "status": 403,
  "deferredTo": "waf-challenge"
}
```

### Allows search and user\-fetch crawlers

ID: ai-crawler-access; version: 5; kind: penalty; status: pass.
Contribution: 0; maximum magnitude: 25.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=ai-crawler-access&version=5#ai-crawler-access)

robots\.txt allows every known search and user\-fetch crawler to reach the homepage\.

```json
{
  "path": "/",
  "capped": false,
  "blocked": [],
  "blockedCount": 0,
  "penaltyPoints": 0
}
```

### Serves the homepage over HTTPS with HTTP 200

ID: homepage-availability; version: 2; kind: penalty; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=homepage-availability&version=2#homepage-availability)

A bot challenge owns the refused response, so its HTTP status is not charged again\.

```json
{
  "error": null,
  "secure": true,
  "status": 403,
  "finalUrl": "https://square9.ai/",
  "deferredTo": "waf-challenge",
  "requestedUrl": "https://square9.ai"
}
```

### Provides a title and meta description

ID: page-metadata; version: 2; kind: penalty; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=page-metadata&version=2#page-metadata)

A bot challenge answered instead of the homepage, so its metadata was not graded\.

```json
{
  "error": null,
  "status": 403,
  "deferredTo": "waf-challenge"
}
```

### Reaches the homepage within two redirects

ID: redirect-chain; version: 2; kind: penalty; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=redirect-chain&version=2#redirect-chain)

A bot challenge answered instead of the homepage, so its redirect chain was not charged separately\.

```json
{
  "error": null,
  "status": 403,
  "redirects": 0,
  "deferredTo": "waf-challenge"
}
```

### Returns the homepage within three seconds

ID: response-time; version: 2; kind: penalty; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=response-time&version=2#response-time)

A bot challenge answered the direct request, so its timing belongs to the WAF penalty\.

```json
{
  "deferredTo": "waf-challenge"
}
```

### Publishes an API catalog

ID: api-catalog; version: 4; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=api-catalog&version=4#api-catalog)

No API catalog published\.

```json
{
  "wellKnown": {
    "status": 404,
    "problem": "absent",
    "profile": null,
    "contentType": null
  },
  "advertisedVia": []
}
```

### Publishes an auth\.md for agents

ID: auth-md; version: 2; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=auth-md&version=2#auth-md)

No /auth\.md published\.

```json
{
  "error": null,
  "reason": "absent",
  "status": 403,
  "contentType": "text/html"
}
```

### Lists an MCP server card in its AI Catalog

ID: mcp-server-card; version: 3; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=mcp-server-card&version=3#mcp-server-card)

No AI Catalog published, so no MCP server card can be discovered\.

```json
{
  "reason": "absent",
  "catalog": {
    "status": 404,
    "entries": 0,
    "problem": "absent",
    "contentType": null,
    "specVersion": null,
    "malformedEntries": 0
  }
}
```

### Publishes an A2A Agent Card

ID: a2a-agent-card; version: 3; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=a2a-agent-card&version=3#a2a-agent-card)

No A2A Agent Card at /\.well\-known/agent\-card\.json, and none listed in an AI Catalog\.

```json
{
  "cards": [
    {
      "via": "well-known",
      "name": null,
      "error": null,
      "notes": [],
      "shape": null,
      "skills": 0,
      "source": "https://square9.ai/.well-known/agent-card.json",
      "status": 404,
      "usable": false,
      "problem": "absent",
      "version": null,
      "bindings": [],
      "identifier": null,
      "interfaces": []
    }
  ],
  "reason": "absent",
  "catalog": {
    "status": 404,
    "entries": 0,
    "problem": "absent"
  },
  "wellKnown": {
    "status": 404,
    "problem": "absent",
    "contentType": "text/html"
  }
}
```

### Publishes an Agent Skills index

ID: agent-skills-index; version: 3; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=agent-skills-index&version=3#agent-skills-index)

No usable Agent Skills index was found at either well\-known path or in the AI Catalog\.

```json
{
  "reason": "absent",
  "catalog": {
    "status": 404,
    "problem": "absent",
    "individualSkills": 0
  },
  "indexes": [
    {
      "via": "well-known",
      "error": null,
      "notes": [],
      "total": 0,
      "format": null,
      "issues": [],
      "schema": null,
      "source": "https://square9.ai/.well-known/agent-skills/index.json",
      "status": 404,
      "usable": 0,
      "entries": [],
      "problem": "absent",
      "rejected": 0,
      "identifier": null
    },
    {
      "via": "well-known",
      "error": null,
      "notes": [],
      "total": 0,
      "format": null,
      "issues": [],
      "schema": null,
      "source": "https://square9.ai/.well-known/skills/index.json",
      "status": 404,
      "usable": 0,
      "entries": [],
      "problem": "absent",
      "rejected": 0,
      "identifier": null
    }
  ],
  "artifactVerification": "not-performed"
}
```

### Declares WebMCP tools for browser agents

ID: webmcp; version: 1; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=webmcp&version=1#webmcp)

No usable HTML was available to inspect for WebMCP declarations\.

```json
{
  "pages": [],
  "reason": "no-html",
  "detection": "static",
  "pageCount": 0,
  "references": [],
  "parseErrors": 0,
  "usableCount": 0,
  "declarations": [],
  "referenceCount": 0,
  "declarationCount": 0,
  "runtimeVerification": "not-performed"
}
```

### Publishes a Web Bot Auth key directory

ID: web-bot-auth; version: 2; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=web-bot-auth&version=2#web-bot-auth)

No Web Bot Auth key directory at /\.well\-known/http\-message\-signatures\-directory\.

```json
{
  "keys": {
    "total": 0,
    "sample": [],
    "usable": 0,
    "testKeys": 0,
    "evaluated": 0,
    "privateMaterial": 0
  },
  "notes": [
    "media-type",
    "unsigned"
  ],
  "shape": null,
  "reason": "absent",
  "signature": {
    "total": 0,
    "status": "absent",
    "ignored": 0,
    "coverage": null,
    "malformed": false,
    "signatures": []
  },
  "wellKnown": {
    "status": 404,
    "problem": "absent",
    "finalUrl": "https://square9.ai/.well-known/http-message-signatures-directory",
    "redirects": 0,
    "contentType": null
  },
  "extraMembers": [],
  "signatureAgent": "https://square9.ai"
}
```

### Accepts agent payments with x402 or MPP

ID: x402-mpp; version: 2; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=x402-mpp&version=2#x402-mpp)

No HTTP 402 payment challenge on the homepage or robots\.txt, and no manifest at /\.well\-known/x402\.

```json
{
  "reason": "absent",
  "manifest": {
    "kind": null,
    "notes": [],
    "shape": null,
    "status": 404,
    "problem": "absent",
    "finalUrl": "https://square9.ai/.well-known/x402",
    "resources": {
      "total": 0,
      "sample": [],
      "skipped": {},
      "eligible": 0,
      "examined": 0
    },
    "contentType": null
  },
  "protocols": [],
  "responses": [],
  "verification": null,
  "paymentVerification": "not-performed"
}
```

### Publishes ACP discovery metadata

ID: acp; version: 1; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=acp&version=1#acp)

No ACP discovery declaration established at /\.well\-known/acp\.json\.

```json
{
  "api": false,
  "key": "well-known-acp",
  "issues": [],
  "marked": false,
  "reason": "absent",
  "status": 404,
  "usable": false,
  "problem": "absent",
  "version": null,
  "commerce": false,
  "services": [],
  "transports": [],
  "capabilities": [],
  "transactionVerification": "not-performed"
}
```

### Publishes UCP discovery metadata

ID: ucp; version: 1; kind: capability; status: na.
Contribution: 0; maximum magnitude: 0.

[Current methodology](https://goodforbots.com/standards?rubric=0.9.0&check=ucp&version=1#ucp)

No UCP discovery declaration established at /\.well\-known/ucp\.

```json
{
  "api": false,
  "key": "well-known-ucp",
  "issues": [],
  "marked": false,
  "reason": "absent",
  "status": 404,
  "usable": false,
  "problem": "absent",
  "version": null,
  "commerce": false,
  "services": [],
  "transports": [],
  "capabilities": [],
  "transactionVerification": "not-performed"
}
```

## Observations

### robots

```json
{
  "status": 200,
  "contentType": "text/plain",
  "bodyHash": "03087edeea887b948b31b2d226ff1d050c9432b429a27e2c0802b7305615b89c",
  "error": null,
  "durationMs": 112,
  "key": "robots",
  "url": "https://square9.ai/robots.txt",
  "finalUrl": "https://square9.ai/robots.txt",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 219,
  "truncated": false,
  "attempts": [
    {
      "status": 200,
      "contentType": "text/plain",
      "bodyHash": "03087edeea887b948b31b2d226ff1d050c9432b429a27e2c0802b7305615b89c",
      "error": null,
      "durationMs": 112,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### robots:https://api\.github\.com

```json
{
  "status": 404,
  "contentType": "application/json; charset=utf-8",
  "bodyHash": "edbd0367cec893df36f67acb56c3aa23810be28850977c35e0fedaf64aad286b",
  "error": null,
  "durationMs": 583,
  "key": "robots:https://api.github.com",
  "url": "https://api.github.com/robots.txt",
  "finalUrl": "https://api.github.com/robots.txt",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 106,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "application/json; charset=utf-8",
      "bodyHash": "edbd0367cec893df36f67acb56c3aa23810be28850977c35e0fedaf64aad286b",
      "error": null,
      "durationMs": 583,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### homepage

```json
{
  "status": 403,
  "contentType": "text/html; charset=UTF-8",
  "bodyHash": "a22059d6bc33f61bb6a6d45a025507a90029c5e583d491d5a8c81a094f06eb8c",
  "error": null,
  "durationMs": 23,
  "key": "homepage",
  "url": "https://square9.ai",
  "finalUrl": "https://square9.ai/",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 5891,
  "truncated": false,
  "attempts": [
    {
      "status": 403,
      "contentType": "text/html; charset=UTF-8",
      "bodyHash": "a22059d6bc33f61bb6a6d45a025507a90029c5e583d491d5a8c81a094f06eb8c",
      "error": null,
      "durationMs": 23,
      "rung": "direct",
      "reason": "A Cloudflare challenge identified by the cf-mitigated header."
    },
    {
      "status": null,
      "contentType": null,
      "bodyHash": null,
      "error": "Browser transport failed: The operation timed out",
      "durationMs": 2180,
      "rung": "render",
      "reason": "Browser transport failed: The operation timed out"
    },
    {
      "status": 403,
      "contentType": "text/html; charset=UTF-8",
      "bodyHash": "835ac805d3c11918b6c5c2e5de91b783412d01ef21bd4379849eeb1a987c9648",
      "error": null,
      "durationMs": 1957,
      "rung": "render-dc",
      "reason": "A Cloudflare challenge identified by the cf-mitigated header."
    }
  ]
}
```

### llms\-txt

```json
{
  "status": 200,
  "contentType": "text/plain",
  "bodyHash": "cf404bb6b9d766322fce5f764a3770418bcd936c6a11bdfd379ea8f5863f8e99",
  "error": null,
  "durationMs": 78,
  "key": "llms-txt",
  "url": "https://square9.ai/llms.txt",
  "finalUrl": "https://square9.ai/llms.txt",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 33402,
  "truncated": false,
  "attempts": [
    {
      "status": 200,
      "contentType": "text/plain",
      "bodyHash": "56e2c1dd7f649e7b1faaafef050f3849f0796d4f15acebfb316097dc340fa582",
      "error": null,
      "durationMs": 78,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### llms\-full\-txt

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 38,
  "key": "llms-full-txt",
  "url": "https://square9.ai/llms-full.txt",
  "finalUrl": "https://square9.ai/llms-full.txt",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 38,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### markdown\-negotiation

```json
{
  "status": 403,
  "contentType": "text/html; charset=UTF-8",
  "bodyHash": "4ce1a5473c0da98ef644e63e6bdba6aa49b6737b2a49c007d1f49a13ea001fa5",
  "error": null,
  "durationMs": 24,
  "key": "markdown-negotiation",
  "url": "https://square9.ai",
  "finalUrl": "https://square9.ai/",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 5913,
  "truncated": false,
  "attempts": [
    {
      "status": 403,
      "contentType": "text/html; charset=UTF-8",
      "bodyHash": "4ce1a5473c0da98ef644e63e6bdba6aa49b6737b2a49c007d1f49a13ea001fa5",
      "error": null,
      "durationMs": 24,
      "rung": "direct",
      "reason": "A Cloudflare challenge identified by the cf-mitigated header."
    }
  ]
}
```

### sitemap:https://square9\.ai/sitemap\.xml

```json
{
  "status": 403,
  "contentType": "text/html; charset=UTF-8",
  "bodyHash": "a8b1b7535b9aab2d3b59e930e7ed4b8a1abe0b6762a29b987755d0d9e5a0918a",
  "error": null,
  "durationMs": 26,
  "key": "sitemap:https://square9.ai/sitemap.xml",
  "url": "https://square9.ai/sitemap.xml",
  "finalUrl": "https://square9.ai/sitemap.xml",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 5945,
  "truncated": false,
  "attempts": [
    {
      "status": 403,
      "contentType": "text/html; charset=UTF-8",
      "bodyHash": "a8b1b7535b9aab2d3b59e930e7ed4b8a1abe0b6762a29b987755d0d9e5a0918a",
      "error": null,
      "durationMs": 26,
      "rung": "direct",
      "reason": "A Cloudflare challenge identified by the cf-mitigated header."
    }
  ]
}
```

### sitemap:https://square9\.ai/blog\-sitemap\.xml

```json
{
  "status": 403,
  "contentType": "text/html; charset=UTF-8",
  "bodyHash": "4ce2c0ff42ec196d5da4a315db7ad19aa0cb66c8e226a7f4e6143399d87df173",
  "error": null,
  "durationMs": 21,
  "key": "sitemap:https://square9.ai/blog-sitemap.xml",
  "url": "https://square9.ai/blog-sitemap.xml",
  "finalUrl": "https://square9.ai/blog-sitemap.xml",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 5960,
  "truncated": false,
  "attempts": [
    {
      "status": 403,
      "contentType": "text/html; charset=UTF-8",
      "bodyHash": "4ce2c0ff42ec196d5da4a315db7ad19aa0cb66c8e226a7f4e6143399d87df173",
      "error": null,
      "durationMs": 21,
      "rung": "direct",
      "reason": "A Cloudflare challenge identified by the cf-mitigated header."
    }
  ]
}
```

### well\-known\-api\-catalog

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 32,
  "key": "well-known-api-catalog",
  "url": "https://square9.ai/.well-known/api-catalog",
  "finalUrl": "https://square9.ai/.well-known/api-catalog",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 32,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### well\-known\-ai\-catalog

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 30,
  "key": "well-known-ai-catalog",
  "url": "https://square9.ai/.well-known/ai-catalog.json",
  "finalUrl": "https://square9.ai/.well-known/ai-catalog.json",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 30,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### well\-known\-agent\-card

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 40,
  "key": "well-known-agent-card",
  "url": "https://square9.ai/.well-known/agent-card.json",
  "finalUrl": "https://square9.ai/.well-known/agent-card.json",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 40,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### well\-known\-agent\-skills

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 112,
  "key": "well-known-agent-skills",
  "url": "https://square9.ai/.well-known/agent-skills/index.json",
  "finalUrl": "https://square9.ai/.well-known/agent-skills/index.json",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 112,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### well\-known\-skills

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 34,
  "key": "well-known-skills",
  "url": "https://square9.ai/.well-known/skills/index.json",
  "finalUrl": "https://square9.ai/.well-known/skills/index.json",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 34,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### well\-known\-http\-message\-signatures\-directory

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 33,
  "key": "well-known-http-message-signatures-directory",
  "url": "https://square9.ai/.well-known/http-message-signatures-directory",
  "finalUrl": "https://square9.ai/.well-known/http-message-signatures-directory",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 33,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### well\-known\-x402

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 34,
  "key": "well-known-x402",
  "url": "https://square9.ai/.well-known/x402",
  "finalUrl": "https://square9.ai/.well-known/x402",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 34,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### well\-known\-acp

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 31,
  "key": "well-known-acp",
  "url": "https://square9.ai/.well-known/acp.json",
  "finalUrl": "https://square9.ai/.well-known/acp.json",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 31,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### well\-known\-ucp

```json
{
  "status": 404,
  "contentType": "text/html",
  "bodyHash": "7774ba7f5e7836ebfefc341a351a37242c841693f5490239390cd2b64ee0e9f8",
  "error": null,
  "durationMs": 183,
  "key": "well-known-ucp",
  "url": "https://square9.ai/.well-known/ucp",
  "finalUrl": "https://square9.ai/.well-known/ucp",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 44300,
  "truncated": false,
  "attempts": [
    {
      "status": 404,
      "contentType": "text/html",
      "bodyHash": "95c0211b6911ad792057f64b4de9bf1b943ee086cb79e673e733e977b1a4f811",
      "error": null,
      "durationMs": 183,
      "rung": "direct",
      "reason": null
    }
  ]
}
```

### auth\-md

```json
{
  "status": 403,
  "contentType": "text/html; charset=UTF-8",
  "bodyHash": "3d59275198210ed84fb25490e372478ae661604a9f99e0f48ebf9d5381c7ba73",
  "error": null,
  "durationMs": 24,
  "key": "auth-md",
  "url": "https://square9.ai/auth.md",
  "finalUrl": "https://square9.ai/auth.md",
  "rung": "direct",
  "redirects": 0,
  "byteLength": 5912,
  "truncated": false,
  "attempts": [
    {
      "status": 403,
      "contentType": "text/html; charset=UTF-8",
      "bodyHash": "3d59275198210ed84fb25490e372478ae661604a9f99e0f48ebf9d5381c7ba73",
      "error": null,
      "durationMs": 24,
      "rung": "direct",
      "reason": "A Cloudflare challenge identified by the cf-mitigated header."
    }
  ]
}
```

## Fixes

Showing 3 of 25 fixes.

### Serve our crawler without a challenge

Recoverable contribution: 15 points.

Score with this fix and the ones above it: 26/100.

A Cloudflare challenge identified by the cf\-mitigated header\. A model fetching this page gets the challenge, not the content\.

````text
My website square9.ai scored 11/100 on Good for Bots (Poor). Good for Bots measures one thing: whether a language model can read a site and cite it.

I need you to: let the Good for Bots crawler through the WAF.

The check it fails is "Serves our crawler without a challenge", a penalty taking 15 points off the score. What the scanner saw: A Cloudflare challenge identified by the cf-mitigated header. A model fetching this page gets the challenge, not the content.

The challenge is Cloudflare's. Bot Fight Mode and the Managed Challenge are the usual
culprits, and neither is switched off by marking anything as a verified bot. What works is
a WAF custom rule matching the user agent with the *Skip* action, with the boxes ticked
for Bot Fight Mode, rate limiting and the managed rules. Put it above the rules that issue
the challenge, because order decides which one fires.

When something in front of a site answers a crawler with an interstitial, a CAPTCHA or a
flat refusal, none of the work that site has done for machines is reachable. The same
thing happens to model crawlers, which is the part that matters: a challenge nobody can
solve is indistinguishable, from the other side, from having no content at all.

The crawler sends exactly one user agent on every request:

```
GoodForBotsBot/1.0 (+https://goodforbots.com/bot)
```

It makes roughly twenty requests per scan, sequentially, and it obeys `robots.txt`.

Add an allowlist rule for that user agent in whatever sits in front of this site:

- **Cloudflare**: a WAF custom rule matching the user agent with the *Skip* action,
  skipping Bot Fight Mode, Managed Challenge and rate limiting. A Bot Management
  "verified bot" exception is not enough on its own; the skip rule is.
- **AWS WAF**: a rule with `Allow` above the bot-control rule group, matching the
  `User-Agent` header.
- **Akamai**: a Bot Manager exception for the user agent; a rate policy alone is not
  enough.
- **Imperva / Incapsula**: an allowlist entry for the user agent under bot access
  control.
- **Vercel**: exclude the user agent from the Attack Challenge Mode or firewall rule.
- **Fastly, nginx, or a hand-rolled rule**: whatever matches on `User-Agent` before the
  challenge is issued.

If the intention is to block us, do that in `robots.txt` instead. A `Disallow` for this
crawler is honoured immediately and without argument, it costs no points, and it is the
honest way to say no. Only `robots.txt` counts as a refusal; a challenge is read as a
site a model cannot use.

Do not widen the rule beyond this one user agent, and do not disable bot protection
generally. One allowlist entry is the whole change.

The whole report, as markdown, is at https://goodforbots.com/r/square9.ai.md?scan=cmuthqdo800h501p3hlitccl5. Read it first: this prompt covers one finding, and the report has everything the scan saw.

When you are done, summarise what you changed and how to check it against a running instance. Do not try to run the Good for Bots scan yourself: it only sees what is already deployed, it is rate-limited, and re-running it is the site owner's call once the change ships.
````

### Serve Markdown at its own URL

Recoverable contribution: 12.5 points.

Score with this fix and the ones above it: 39/100.

No /llms\-full\.txt and no markdown versions linked from llms\.txt\.

````text
My website square9.ai scored 11/100 on Good for Bots (Poor). Good for Bots measures one thing: whether a language model can read a site and cite it.

I need you to: serve the content as markdown at its own URLs.

The check it fails is "Serves markdown at its own URL", worth 12.5 points. What the scanner saw: No /llms-full.txt and no markdown versions linked from llms.txt.

A model that can only reach this site's content through HTML pays to parse markup and
loses structure doing it: navigation, cookie banners and script tags arrive alongside
the prose, and headings, tables and code blocks come out flattened. Markdown at its own
address removes HTML from the path entirely: what is fetched is the content and nothing
else.

Two routes satisfy this, and it is worth being clear about which one the specification
asks for. llmstxt.org asks for a markdown version of each page **at the same URL as the
original**, either with `.md` appended (`page.html.md`) or with the extension replaced
(`page.md`). `llms-full.txt`, the single bundle holding everything, does not appear in
the specification at all. It is a community convention that grew up around it and is
now widespread. Both are accepted here. The per-page form is the one the document
asks for.

Either of these passes:

- **The bundle.** `/llms-full.txt`, one document, real markdown rather than HTML,
  carrying the site's actual content rather than a placeholder.
- **Per-page mirrors.** A markdown twin for each page at `page.md` or `page.html.md`,
  **and linked from `/llms.txt`**. That second half is load-bearing: mirrors are counted
  from the links in the index, so twins that nothing points at are invisible to this scan
  and, more to the point, to anything crawling the site.

For the mirror route, the index carries them as ordinary link lines:

```markdown
## Docs

- [Quickstart](/docs/quickstart.md): create an account and take a first payment
- [Concepts](/docs/concepts.md): customers, subscriptions, invoices and proration
- [Webhooks](/docs/webhooks.md): events, signature verification, retry schedule
```

Both `/docs/quickstart` and `/docs/quickstart.md` have to answer 200: the HTML for
people, the markdown for everything else.

Serving markdown through content negotiation does **not** satisfy this, and that is
deliberate rather than an oversight. A negotiated response only exists for a client that
knows to send `Accept: text/markdown`, and most crawlers send no preference at all. A
`.md` address sits in the open: it is found by ordinary crawling, it can be linked to,
and it can be cited. If this site already negotiates markdown, the report says so in
these words: *"Markdown is served on request, but not at any URL a crawler would find on
its own"*. That is a different check passing on its own terms, not a contradiction.

Four things about how this is measured. The bundle is judged by size, by being markdown
rather than a page or JSON, and by not merely repeating `llms.txt`; its content is never
sampled beyond that, so a couple of kilobytes of boilerplate would pass. Do not take that
as permission, since the point of the file is the content in it. `.mdx` counts as markdown
although the specification names only `.md`, because excluding it would punish a large
part of the documentation ecosystem for its toolchain. The number of mirrors we want
before calling it a convention on this site is our judgement, not the specification's.
And the mirror URLs listed in the index are counted, never fetched, so a list of `.md`
addresses that 404 passes this check and helps nobody at all.

The whole report, as markdown, is at https://goodforbots.com/r/square9.ai.md?scan=cmuthqdo800h501p3hlitccl5. Read it first: this prompt covers one finding, and the report has everything the scan saw.

When you are done, summarise what you changed and how to check it against a running instance. Do not try to run the Good for Bots scan yourself: it only sees what is already deployed, it is rate-limited, and re-running it is the site owner's call once the change ships.
````

### Serve Markdown when asked for it

Recoverable contribution: 10 points.

Score with this fix and the ones above it: 49/100.

Asking the homepage for markdown returned HTTP 403\.

```text
My website square9.ai scored 11/100 on Good for Bots (Poor). Good for Bots measures one thing: whether a language model can read a site and cite it.

I need you to: serve markdown through content negotiation on all public HTML routes.

The check it fails is "Serves markdown when asked for it", worth 10 points. What the scanner saw: Asking the homepage for markdown returned HTTP 403.

Implement content negotiation across all public HTML routes, including page types
outside the scan's sample. Put it in the shared response handling or the handlers
for each page type, so new pages receive it too. Agents need the content of any
page they follow, including pages the report did not name.

When a request arrives with `text/markdown` in its `Accept` header, the same URL that
serves HTML to a browser should return a markdown rendering of that page's content.
Requests without that header must keep getting the HTML exactly as they do now.

The response must:

- set `Content-Type: text/markdown; charset=utf-8`;
- include `Accept` in the `Vary` header, so shared caches never serve the markdown to a
  browser or the HTML to an agent (RFC 9110 says a server SHOULD send `Vary` whenever
  the representation depends on a request header);
- contain real markdown, not HTML with a different header on it;
- drop `ETag` and `Last-Modified` for the converted response, since a conditional request
  cannot be honoured against a body generated on the fly.

Work out how to do this in whatever stack this project uses. If the site is behind
Cloudflare on a paid plan, the "Markdown for Agents" zone setting does all of the above
and is the least invasive option. Otherwise implement it in the framework: middleware
inspecting the `Accept` header, a route handler that returns the markdown source, or
whatever fits the architecture here.

Strip navigation, headers, footers and cookie banners from the markdown. The point is the
content, without the page furniture around it.

Verify HTML and Markdown responses for each public page type, including URLs
outside the reported sample. Check that each Markdown response contains that
page's content and that ordinary browser requests still receive HTML.

The whole report, as markdown, is at https://goodforbots.com/r/square9.ai.md?scan=cmuthqdo800h501p3hlitccl5. Read it first: this prompt covers one finding, and the report has everything the scan saw.

When you are done, summarise what you changed and how to check it against a running instance. Do not try to run the Good for Bots scan yourself: it only sees what is already deployed, it is rate-limited, and re-running it is the site owner's call once the change ships.
```

22 more fixes come with Pro, each with a prompt. Only the listing's verified owner can upgrade it, and Pro never changes the score. [Pro for this listing](https://goodforbots.com/pricing?host=square9.ai#upgrade)

Deployed your fixes? [Rescan to update your score](https://goodforbots.com/r/square9.ai#rescan). Only the listing's verified owner can request a rescan; claiming is free.

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "ItemPage",
      "@id": "https://goodforbots.com/r/square9.ai#webpage",
      "url": "https://goodforbots.com/r/square9.ai",
      "name": "square9.ai AI visibility report",
      "description": "square9.ai scores 11/100 for AI visibility. Scanned 4 Oct 2026. Review bot access, content checks and available fixes in the full report.",
      "inLanguage": "en",
      "isPartOf": {
        "@id": "https://goodforbots.com/#website"
      },
      "breadcrumb": {
        "@id": "https://goodforbots.com/r/square9.ai#breadcrumb"
      },
      "mainEntity": {
        "@id": "https://goodforbots.com/r/square9.ai#site"
      },
      "about": {
        "@id": "https://goodforbots.com/r/square9.ai#site"
      },
      "dateModified": "2026-10-04T07:21:19.532Z"
    },
    {
      "@type": "BreadcrumbList",
      "@id": "https://goodforbots.com/r/square9.ai#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://goodforbots.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Directory",
          "item": "https://goodforbots.com/directory"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "square9.ai",
          "item": "https://goodforbots.com/r/square9.ai"
        }
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://goodforbots.com/r/square9.ai#site",
      "name": "square9.ai",
      "url": "https://square9.ai"
    },
    {
      "@type": "Organization",
      "@id": "https://goodforbots.com/#organization",
      "name": "Good for Bots",
      "url": "https://goodforbots.com",
      "logo": "https://goodforbots.com/icon-512.png",
      "founder": {
        "@id": "https://goodforbots.com/#person-mateusz-pawlica"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "support@goodforbots.com",
        "url": "https://goodforbots.com/contact"
      }
    },
    {
      "@type": "WebSite",
      "@id": "https://goodforbots.com/#website",
      "name": "Good for Bots",
      "url": "https://goodforbots.com",
      "description": "Check if AI crawlers can access and read your website, free. Get a score out of 100 with every finding and fix prompts, then browse reports in the directory.",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://goodforbots.com/#organization"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://goodforbots.com/directory?q={q}"
        },
        "query-input": "required maxlength=120 name=q"
      }
    },
    {
      "@type": "Person",
      "@id": "https://goodforbots.com/#person-mateusz-pawlica",
      "name": "Mateusz Pawlica",
      "givenName": "Mateusz",
      "familyName": "Pawlica",
      "jobTitle": "Founder of Good for Bots",
      "description": "Web developer who builds directories and AI-powered products, and the founder of Good for Bots.",
      "url": "https://goodforbots.com/about#founder",
      "sameAs": [
        "https://pl.linkedin.com/in/mateusz-pawlica-65238816b",
        "https://pawlicaweb.pl/o-mnie"
      ],
      "knowsAbout": [
        "llms.txt",
        "robots.txt",
        "AI crawlers",
        "Markdown content negotiation",
        "Structured data",
        "Technical SEO",
        "Web directories",
        "Next.js",
        "TypeScript",
        "Generative AI"
      ],
      "worksFor": {
        "@id": "https://goodforbots.com/#organization"
      }
    }
  ]
}
```
