Serve our crawler without a challenge
A Cloudflare challenge identified by the cf-mitigated header. A model fetching this page gets the challenge, not the content.
Read prompt
My website theviatlas.com scored 15/100 on Good for Bots (Poor). Good for Bots measures one thing: whether a language model can read a site and cite it. I need you to: let the Good for Bots crawler through the WAF. The check it fails is "Serves our crawler without a challenge", a penalty taking 15 points off the score. What the scanner saw: A Cloudflare challenge identified by the cf-mitigated header. A model fetching this page gets the challenge, not the content. The challenge is Cloudflare's. Bot Fight Mode and the Managed Challenge are the usual culprits, and neither is switched off by marking anything as a verified bot. What works is a WAF custom rule matching the user agent with the *Skip* action, with the boxes ticked for Bot Fight Mode, rate limiting and the managed rules. Put it above the rules that issue the challenge, because order decides which one fires. When something in front of a site answers a crawler with an interstitial, a CAPTCHA or a flat refusal, none of the work that site has done for machines is reachable. The same thing happens to model crawlers, which is the part that matters: a challenge nobody can solve is indistinguishable, from the other side, from having no content at all. The crawler sends exactly one user agent on every request: ``` GoodForBotsBot/1.0 (+https://goodforbots.com/bot) ``` It makes roughly twenty requests per scan, sequentially, and it obeys `robots.txt`. Add an allowlist rule for that user agent in whatever sits in front of this site: - **Cloudflare**: a WAF custom rule matching the user agent with the *Skip* action, skipping Bot Fight Mode, Managed Challenge and rate limiting. A Bot Management "verified bot" exception is not enough on its own; the skip rule is. - **AWS WAF**: a rule with `Allow` above the bot-control rule group, matching the `User-Agent` header. - **Akamai**: a Bot Manager exception for the user agent; a rate policy alone is not enough. - **Imperva / Incapsula**: an allowlist entry for the user agent under bot access control. - **Vercel**: exclude the user agent from the Attack Challenge Mode or firewall rule. - **Fastly, nginx, or a hand-rolled rule**: whatever matches on `User-Agent` before the challenge is issued. If the intention is to block us, do that in `robots.txt` instead. A `Disallow` for this crawler is honoured immediately and without argument, it costs no points, and it is the honest way to say no. Only `robots.txt` counts as a refusal; a challenge is read as a site a model cannot use. Do not widen the rule beyond this one user agent, and do not disable bot protection generally. One allowlist entry is the whole change. The whole report, as markdown, is at https://goodforbots.com/r/theviatlas.com.md?scan=cmuthmels002301p3mb2eronk. Read it first: this prompt covers one finding, and the report has everything the scan saw. When you are done, summarise what you changed and how to check it against a running instance. Do not try to run the Good for Bots scan yourself: it only sees what is already deployed, it is rate-limited, and re-running it is the site owner's call once the change ships.