Skip to content

mesa.dev

Strong technical baseline

94/ 100

Technical readiness score

What should the prompt cover?

12 findings · 5 selected

Failures (5)

Warnings (7)

The agent completed the observed task

One run shows how an agent performed, but it does not determine the technical score.

Task

What does mesa.dev do and who is it for? Explain it back to me.

20 steps8 reasoning steps4 searches

home
docs
docs
docs
search
docs
/features/filesystem
docs
search
/features/git-server
search
search
1 observed runView journey ↗

Critical access needs attention

These checks describe whether an ordinary agent can enter, read, and operate the public site.

  • Agents can reach the site

    Crawler access, bot defenses, and explicit agent policy.

    3 / 3 passed
  • Core content is available

    Useful content remains accessible without a fragile browser-only path.

    2 / 2 passed
  • Navigation fails safely

    Redirects and missing pages give agents a recoverable path.

    1 / 2 passed
  • Controls are understandable

    Forms and interactive controls expose usable names and structure.

    3 / 3 passed

Advertised capabilities have material gaps

Optional surfaces appear only when the scan finds positive evidence that the site offers them.

Public website

Ready with gaps

77%

12 of 19 mature checks passed

API

Ready with gaps

70%

5 of 9 mature checks passed

MCP

Needs work

67%

2 of 3 mature checks passed

Fix these gaps first

Critical access gaps come first, followed by gaps in capabilities the site advertises.

  1. 01

    Agent-friendly 404s

    Return a real HTTP 404 (or 410) status for nonexistent paths - never a 200 with your app shell, which makes agents believe every path exists. For full credit, give the 404 response a short markdown body pointing agents at your sitemap, llms.txt, or docs index. Verify with `curl -s -o /dev/null -w "%{http_code}" https://yourdomain.com/some-path-that-does-not-exist` - it must print 404.

    Critical access
  2. 02

    Developer resource discoverability

    Make your developer resources (API docs, OpenAPI spec, auth docs, webhooks, MCP server) discoverable by name. Publish them at predictable URLs, list them in llms.txt, and include your product name in page titles and headings so search engines surface them for name-based queries.

    Advertised capabilities
  3. 03

    Brand name discoverability

    Make sure a clean search for your brand name returns your own domain in the top results. If it does not, your brand may be too generic, conflict with a more established term, or not yet indexed. Strengthen brand-name search by claiming consistent NAP across listings, earning press mentions that link to the canonical domain, and avoiding redirect chains that mask the apex domain in search results.

    Advertised capabilities
  4. 04

    MCP server / manifest

    Build an MCP (Model Context Protocol) server exposing your API as tools. Use Streamable HTTP transport for full score. This lets Claude, ChatGPT, and other AI agents call your product natively.

    Advertised capabilities
  5. 05

    API schema complexity analysis

    Make your API spec self-describing: a unique operationId and a description on every operation, typed parameters, and response schemas. For GraphQL, a fully typed schema with a documented cost or rate limit reads best.

    Advertised capabilities

Audit the checks behind the score

Applicable evidence is grouped by how it contributes to this preview model. Bonus checks appear only when they add points.

Essential9 of 10 passed · 76 / 80 points
  • Content without JavaScriptPassed
  • Not blocked by bot detectionPassed
  • robots.txt agent-user policyPassed
  • Redirect hygienePassed
  • Content behind authPassed
  • OpenAPI spec publishedPassed
  • Agent crawler reachabilityPassed
  • JSON error responsesPassed
  • MCP resources exposedPassed
  • Agent-friendly 404sPartial (50%)
Recommended10 of 21 passed · 12.9 / 20 points
  • Developer resource discoverabilityFailed
  • Brand name discoverabilityFailed
  • robots.txt AI crawler policyPartial (50%)
  • Sitemap existsPassed
  • Content efficiencyPassed
  • JSON-LD structured dataPassed
  • Public API/docs linked from homepagePassed
  • Agent instruction / when-to-usePartial (67%)
  • Metadata completenessPassed
  • Organization schema completenessPartial (50%)
  • Trust anchor pagesPartial (50%)
  • Page token budgetPassed
  • Code fence validityPassed
  • Developer portalPassed
  • Public API with reachable endpointsPassed
  • MCP server / manifestFailed
  • CLI tool availablePartial (67%)
  • Multi-language SDK packagesPartial (67%)
  • API schema complexity analysisFailed
  • Function calling compatibilityFailed
  • MCP resource qualityPassed
Bonus signals22 positive · +5 points
  • NPM/PyPI SDK packagePassed
  • MCP well-known discoveryPassed
  • Sitemap freshness (lastmod)Passed
  • llms.txt existsPassed
  • llms.txt formattingPassed
  • JSON-LD entity linking (sameAs)Partial (50%)
  • Schema type breadthPartial (50%)
  • llms.txt links resolvePassed
  • MCP tool descriptionsPassed
  • MCP parameter schemasPassed
  • MCP server identityPassed
  • MCP tool listingPassed
  • MCP tool namingPassed
  • MCP auth mechanismPassed
  • MCP error handlingPassed
  • MCP modern transportPassed
  • MCP tool annotationsPassed
  • MCP server-card.jsonPassed
  • Accessible document structurePassed
  • Native interactive controlsPassed
  • Accessible names on controlsPassed
  • Accessibility-tree injection safety (bonus)Passed

Inspect the underlying audit

The complete Ora audit uses evidence from the scan on . After applying changes, run another scan from the homepage to refresh these recommendations.

Score alerts

A weekly report with ranking changes, new agent feedback, and score alerts for mesa.dev.

Source: Ora API

Snapshot 2026-08-19T21-20-38-547Z