Is cursor.com AI agent ready? B · 66/100

cursor.com

Next.js · 60% confidence
https://cursor.com/
B66 / 100
Grade B · Level 3GovernedGood — solid foundations, with room to polish.
Why we think this is Next.js (2 signals)
  • · hosted on Vercel
  • · /_next/static/ asset

Scan history · 4 public scans of cursor.com

WhenScoreGradeSnapshot
14 Sept 2026, 6:24 UTC0837ac1166/100BView →
13 Sept 2026, 13:00 UTC6c87983466/100BView →
1 Sept 2026, 3:13 UTCdd217a6950/100CView →
23 Jun 2026, 12:16 UTCfd1d649454/100CView →
7 checks need fixing

4 failed · 3 partial out of 15 that apply to your site.

See top fixes

Fix automatically with AIScan

9 open checks (4 failing) can be handed to an AI agent: C3, B2, B3, P2, P4, M4, E1, E2, E5. Pick one route — each returns the full, check-by-check instructions.

Option A — Agent Skill (any runtime)
npx add-skill https://aiscan.site/aiscan-skill.json

Then ask your agent: “Fix the failing AI readiness checks for https://cursor.com/.

Option B — Claude Code (CLAUDE.md)
curl -o CLAUDE.md https://aiscan.site/CLAUDE.md

Drop it in your project root, then ask Claude Code to fix the failing AIScan checks.

Option C — MCP client
https://aiscan.site/api/mcp

Tools: scan_website, get_fixes, get_grade. Call get_fixes { "url": "https://cursor.com/" }.

Option D — REST API
curl -s 'https://aiscan.site/api/public/scan?url=https%3A%2F%2Fcursor.com%2F'

Returns every check with its complete fix guide.

Verify: Re-scan at https://aiscan.site after applying fixes, or run npx aiscan-cli https://cursor.com/. Individual checks that need a specific probe list it in their own guide.

Quick Wins

Top 3 fixes ranked by score impact

  • 01Fail

    Explicit AI bot rules

    +5 pts if fixed

    Add explicit allow/deny rules for GPTBot, ClaudeBot, PerplexityBot, Google-Extended, etc.

    See full details
  • 02Fail

    OAuth discovery metadata

    +4 pts if fixed

    Publish RFC 8414 / RFC 9728 metadata at the /.well-known/oauth-* endpoints.

    See full details
  • 03Fail

    Correct 404 handling

    +4 pts if fixed

    Return a real HTTP 404 (not 200) for missing pages, with a body that names the site and links to your homepage, sitemap, and search so an agent can recover.

    See full details
Hand-off prompt for your coding agent9 issues
# Agent-readiness remediation brief

Site: https://cursor.com/
Platform: nextjs (60% confidence)
AIScan score: 66/100 — Level 3 (Governed)
Rubric: v2026.08.2

## Failing checks (sorted by weight)
- **[M4] Machine-readable pricing** — PARTIAL
  - Evidence: JSON-LD offer on https://cursor.com/pricing (price, priceCurrency): {"@context":"https://schema.org","@type":"SoftwareApplication","@id":"https://cursor.com/pricing","name":"Cursor","description":"Choose the Cursor plan that's right for you. Free f
  - Fix: Publish schema.org Offer / AggregateOffer JSON-LD on your pricing page with price, priceCurrency and the billing period, so an agent can answer "what does this cost?" without scraping prose.
- **[B2] Explicit AI bot rules** — FAIL
  - Evidence: 0 known AI agent(s) addressed in robots.txt
  - Fix: Add explicit allow/deny rules for GPTBot, ClaudeBot, PerplexityBot, Google-Extended, etc.
- **[P2] MCP Server Card** — PARTIAL
  - Evidence: HTTP 200
  - Fix: Optional: publish /.well-known/mcp/server-card.json if you expose an MCP server.
- **[C3] Structured HTML (title, meta, JSON-LD, single H1)** — PARTIAL
  - Evidence: h1: 2, title: true, meta description: true, JSON-LD: true
  - Fix: Ensure a single <h1>, <title>, meta description, and schema.org JSON-LD.
- **[P4] OAuth discovery metadata** — FAIL
  - Evidence: auth-server: 200, protected-resource: 200
  - Fix: Publish RFC 8414 / RFC 9728 metadata at the /.well-known/oauth-* endpoints.
- **[E1] Correct 404 handling** — FAIL
  - Evidence: GET /aiscan-404-probe-wmx2no → HTTP 200 (soft 404 — returns 200 for a missing page), 142860 bytes, text/html
  - Fix: Return a real HTTP 404 (not 200) for missing pages, with a body that names the site and links to your homepage, sitemap, and search so an agent can recover.
- **[B3] Web Bot Auth key directory** — PARTIAL
  - Evidence: HTTP 200
  - Fix: Optional: serve a JWKS-style key directory at /.well-known/http-message-signatures-directory.
- **[E2] Machine-readable API description** — FAIL
  - Evidence: no /openapi.json, /api/openapi.json or swagger document found
  - Fix: Publish an OpenAPI 3.1 document at /openapi.json and reference it from /.well-known/api-catalog as a service-desc link.
- **[E5] Content feed (RSS / Atom / JSON Feed)** — PARTIAL
  - Evidence: ATOM feed at https://cursor.com/atom.xml (found by convention, not declared in <head>)
  - Fix: Publish an RSS, Atom, or JSON Feed of new content and declare it in <head> with <link rel="alternate" type="application/rss+xml">. Feeds give agents a cheap, dated changelog of your site that a sitemap doesn't.

## General guidance
- Static-first: `robots.txt`, `llms.txt`, `/.well-known/*` JSON cards.
- Markdown negotiation: serve `text/markdown` when requested via `Accept` header or `?format=md`.
- Bot access: explicit allow/deny per AI user-agent (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, Applebot-Extended, Bytespider, Amazonbot, CCBot, meta-externalagent, cohere-ai, Diffbot).
- Capabilities: publish an MCP server card and (optionally) an Agent Skills manifest even if the runtime isn't live — discovery first.
- Re-scan at aiscan.site after deploying.

How this score is calculated

Every check earns points against a weight. We divide the points you earned by the points that actually apply to a Next.js — so checks that don't apply never drag you down.

Essential
26 / 37 pts

Baseline every site should meet.

Recommended
23 / 31 pts

Strong signals most sites benefit from.

Bonus earned
4 signals

Emerging standards. Can only add points.

Not counted (2): B1, M3 — either not applicable to this site profile or optional and not yet adopted. Expand any check to see the exact evidence we based it on.

Discoverability

81

Can agents find your pages? robots, sitemaps, llms.txt.

41
  • Your site is missing this right now, so AI agents can't use it. The fix below is what to change.

    ID · E1

    What we found

    GET /aiscan-404-probe-wmx2no → HTTP 200 (soft 404 — returns 200 for a missing page), 142860 bytes, text/html

    How to fix it

    Return a real HTTP 404 (not 200) for missing pages, with a body that names the site and links to your homepage, sitemap, and search so an agent can recover.

    Return a real 404 status

    A missing page must answer 404 (or 410), never 200. A soft 404 makes agents index your error page as real content.

    Make the body recoverable

    The 404 body should name the site and link to the homepage, sitemap, docs, and search so an agent can find its way back instead of dead-ending.

    Verify

    curl -sI https://yoursite.com/this-page-does-not-exist-123 | head -n 1

Content

92

Can agents read your content cleanly? Markdown, structured data.

32

Bot Access

13

Are AI crawlers explicitly allowed or blocked?

11
  • Your site is missing this right now, so AI agents can't use it. The fix below is what to change.

    ID · B2

    What we found

    0 known AI agent(s) addressed in robots.txt

    How to fix it

    Add explicit allow/deny rules for GPTBot, ClaudeBot, PerplexityBot, Google-Extended, etc.

    Add explicit User-agent blocks

    Don't rely on User-agent: * alone. Address each major AI crawler so your policy is unambiguous.

    Recommended block

    User-agent: GPTBot
    Allow: /
    
    User-agent: ClaudeBot
    Allow: /
    
    User-agent: PerplexityBot
    Allow: /
    
    User-agent: Google-Extended
    Allow: /
    
    User-agent: Applebot-Extended
    Allow: /

Capabilities

47

Can agents do things? APIs, auth, MCP, Agent Skills.

212
  • Your site is missing this right now, so AI agents can't use it. The fix below is what to change.

    ID · P4

    What we found

    auth-server: 200, protected-resource: 200

    How to fix it

    Publish RFC 8414 / RFC 9728 metadata at the /.well-known/oauth-* endpoints.

    Publish OAuth discovery metadata

    If your API supports OAuth, serve RFC 8414 metadata at /.well-known/oauth-authorization-server and/or RFC 9728 at /.well-known/oauth-protected-resource.

  • Your site is missing this right now, so AI agents can't use it. The fix below is what to change.

    ID · E2

    What we found

    no /openapi.json, /api/openapi.json or swagger document found

    How to fix it

    Publish an OpenAPI 3.1 document at /openapi.json and reference it from /.well-known/api-catalog as a service-desc link.

    Publish an OpenAPI 3.1 description

    Serve it at /openapi.json (or /openapi.yaml). Describe every public endpoint, its parameters, and its response schema.

    Advertise it

    Reference it from /.well-known/api-catalog as a service-desc link and from a Link response header.

    Link: </openapi.json>; rel="service-desc"; type="application/json"

    Content sites can skip this

    If you expose no programmatic API, this check is informational and costs you nothing.

Commerce

91

Can agents transact? Catalogs, checkout, agentic commerce.

11
Share the result

Share as a social image

Download a 1200×630 social card or post straight to X, LinkedIn or Facebook — sized for every feed.

AIScan share card — cursor.com graded B

Tip: for X and LinkedIn, upload the downloaded PNG with your post so the card shows in the feed. Posts that include just the link will still preview AIScan.site.

Showcase your grade

Embed your AIScan badge

Drop this badge into your site footer, GitHub README, or docs. It links back to a fresh scan of cursor.com on AIScan.site.

AIScan.site grade B
HTML
<!-- AIScan.site agent-readiness badge -->
<a href="https://aiscan.site/?u=https%3A%2F%2Fcursor.com%2F" target="_blank" rel="noopener" title="Agent-Readiness Grade B (66/100) — AIScan.site">
  <img src="https://aiscan.site/api/public/badge.svg?score=66&grade=B&host=cursor.com" alt="AIScan.site Grade B — 66/100" width="240" height="64" loading="lazy" />
</a>
Markdown
[![AIScan.site Grade B — 66/100](https://aiscan.site/api/public/badge.svg?score=66&grade=B&host=cursor.com)](https://aiscan.site/?u=https%3A%2F%2Fcursor.com%2F)

Create a free account to track this site over time

  • Save scan history
  • See score trends
  • Re-scan anytime

Dig deeper

Scan any site from Telegram
Open in Telegram

cursor.com is built on Next.js. AI-agent readiness for Next.js walks through the same checks on that platform.

Scan any site from Telegram
Open in Telegram

This page always shows the most recent public scan for cursor.com.