New addition to our AI shopping agent scanner
New checks added today:
UGC prompt injection — scans your reviews and comments for hidden text that could hijack an AI agent reading your page (e.g. "ignore previous instructions" buried in a review)
Cart API rate limiting — hits your /cart/add.js 5 times rapidly to see if anything stops an agent from squatting your inventory at scale
Checkout bot challenge — checks if your checkout has any CAPTCHA or bot detection, or if agents can automate purchases unchecked
Admin path exposure — probes /admin, /staff, /.env, /api to see if internal paths are accessible without auth
Also added 8 protocol discovery checks (MCP, OAuth, A2A, Markdown negotiation, Agent Skills, x402 wallets, DNS-AID, Link headers) so the scanner now covers the same emerging standards that Cloudflare's scanner checks, plus the shopping/extraction/security layer they don't.
40 checks total now.
Happy to scan your store if you drop a URL.