# Agent readiness of bombas.com

Verified 3 Oct 2026 by VouchAgent. Report: https://vouchagent.com/s/bombas.com

## Verdict

- Result: Not yet tested by agents
- Verified: 3 Oct 2026

## Static checks (3 Oct 2026)

Our scanner was blocked on the home page by Unknown, so some checks could not run.

### Access

- Not met: Home page reachable (seen: `Home page: HTTP 429`) How to fix: Serve the home page with a 2xx response to automated HTTPS clients.
- Not met: Agents not blocked (seen: `Blocked by unknown: HTTP 429`) How to fix: Allow signed AI agents past the challenge, or publish a Storefront API/MCP path agents can use instead.
- Not met: robots.txt present (seen: `robots.txt: HTTP 429`) How to fix: Publish a plain-text /robots.txt that states which crawlers and agents may access the site.
- Met: AI agents allowed in robots.txt (seen: `No robots.txt rules apply`)
- Partly met: Content signals declared (seen: `No Content-Signal line in robots.txt`) How to fix: Add a Content-Signal line to robots.txt stating whether content may be used for search, AI input and AI training.

### Discovery

- Not met: Sitemap present (seen: `/sitemap.xml: HTTP 429; none listed in robots.txt`) How to fix: Publish an XML sitemap at /sitemap.xml and reference it from robots.txt.
- Not met: llms.txt present (seen: `/llms.txt: HTTP 429`) How to fix: Publish /llms.txt as markdown starting with "\# " and linking your key pages.
- Not met: Link headers for agents (seen: `No Link header on the home page`) How to fix: Add a Link header on the home page with rel="api-catalog" pointing to /.well-known/api-catalog.
- Not met: API catalog (seen: `/.well-known/api-catalog: HTTP 429`) How to fix: Publish an RFC 9727 linkset at /.well-known/api-catalog listing your public APIs.
- Not met: MCP server card (seen: `/.well-known/mcp/server-card.json: HTTP 429`) How to fix: Publish an MCP server card at /.well-known/mcp/server-card.json describing your MCP endpoint.
- Not met: A2A agent card (seen: `/.well-known/agent-card.json: HTTP 429`) How to fix: Publish an A2A agent card at /.well-known/agent-card.json if you run an agent other agents can call.
- Not met: Agent skills index (seen: `/.well-known/agent-skills/index.json: HTTP 429`) How to fix: Publish an agent skills index at /.well-known/agent-skills/index.json listing tasks agents can perform.
- Not met: OAuth server metadata (seen: `/.well-known/oauth-authorization-server: HTTP 429`) How to fix: Publish RFC 8414 metadata at /.well-known/oauth-authorization-server so agents can obtain delegated access.
- Not met: OAuth protected resource metadata (seen: `/.well-known/oauth-protected-resource: HTTP 429`) How to fix: Publish RFC 9728 metadata at /.well-known/oauth-protected-resource naming the authorization server for your APIs.
- Not met: auth.md (seen: `/auth.md: HTTP 429`) How to fix: Publish /auth.md explaining in plain text how agents authenticate to your site or API.

### Content

- Not applicable: Markdown on request (seen: `Home page not retrieved`)
- Not applicable: Content in server HTML (seen: `Home page not retrieved`)

### Commerce data

- Not applicable: Product structured data (seen: `Not a commerce site`)
- Not applicable: Offer details complete (seen: `Not a commerce site`)
- Not applicable: UCP manifest (seen: `Not a commerce site`)
- Not applicable: Shopify Storefront MCP (seen: `Not a commerce site`)
- Not applicable: Shipping and returns policies linked (seen: `Not a commerce site`)

---

Methodology https://vouchagent.com/methodology. Owners can claim this page, request a re-test or opt out at https://vouchagent.com/s/bombas.com.
