AI Exposure Scan
What can an AI agent do with your domain?
Enter a domain. AxioRank reads its public AI-facing surfaces and grades what an autonomous agent could discover or abuse, from leaked secrets in llms.txt to unauthenticated MCP tools. Free, no signup.
Enter a domain to map its AI attack surface.
We read only public, well-known files, the same requests a search crawler makes. No signup, no login, nothing intrusive.
What we check
A read-only sweep of your AI-facing surfaces
The scan probes a fixed set of well-known files and scores what it finds with the same engine that guards live agent traffic. Presence of a file is neutral; only risky content moves the grade.
Discovery files
robots.txt AI directives, llms.txt, llms-full.txt, and ai.txt. What models are told they may read, and where a secret sometimes gets pasted by mistake.
Agent surfaces
MCP server cards, A2A agent cards, NANDA AgentFacts, and plugin manifests. Scored for dangerous or unauthenticated tools an assistant could call.
Identity & auth
OAuth authorization-server and protected-resource metadata, did:web documents. Whether agent access is gated, and whether identity keys are domain-bound.
Content inspection
Every fetched surface runs through the same engine that guards live agent traffic, flagging leaked secrets, PII, and indirect prompt injection.
Passive and crawler-equivalent
AI Exposure Index
How well-known domains score
A point-in-time index of common domains, scored on their public AI-facing surfaces only. Grades reflect what is publicly readable and are not an affiliation, endorsement, or judgment of any listed company.
| Domain | Grade | Surfaces | Findings | Risk |
|---|---|---|---|---|
| zapier.com | Blimited | 3 | 1 | 35/100 |
| resend.com | Blimited | 7 | 1 | 35/100 |
| weaviate.io | Aminimal | 3 | 1 | 18/100 |
| sentry.io | Aminimal | 6 | 1 | 18/100 |
| notion.so | Aminimal | 0 | 0 | 0/100 |
| linear.app | Aminimal | 6 | 0 | 0/100 |
| supabase.com | Aminimal | 3 | 0 | 0/100 |
| perplexity.ai | Aminimal | 1 | 0 | 0/100 |
| shopify.com | Aminimal | 1 | 0 | 0/100 |
| langchain.com | Aminimal | 0 | 0 | 0/100 |
| llamaindex.ai | Aminimal | 0 | 0 | 0/100 |
| modal.com | Aminimal | 2 | 0 | 0/100 |
| fly.io | Aminimal | 1 | 0 | 0/100 |
| hubspot.com | Aminimal | 0 | 0 | 0/100 |
| n8n.io | Aminimal | 3 | 0 | 0/100 |
| cloudflare.com | Aminimal | 0 | 0 | 0/100 |
| pinecone.io | Aminimal | 0 | 0 | 0/100 |
| cursor.com | Aminimal | 3 | 0 | 0/100 |
| clerk.com | Aminimal | 4 | 0 | 0/100 |
| browserbase.com | Aminimal | 0 | 0 | 0/100 |
| firecrawl.dev | Aminimal | 0 | 0 | 0/100 |
| mintlify.com | Aminimal | 0 | 0 | 0/100 |
| cohere.com | Aminimal | 2 | 0 | 0/100 |
| stripe.com | Aminimal | 3 | 0 | 0/100 |
| mistral.ai | Aminimal | 2 | 0 | 0/100 |
| together.ai | Aminimal | 1 | 0 | 0/100 |
| huggingface.co | Aminimal | 5 | 0 | 0/100 |
| replicate.com | Aminimal | 2 | 0 | 0/100 |
| elevenlabs.io | Aminimal | 3 | 0 | 0/100 |
| render.com | Aminimal | 4 | 0 | 0/100 |
| railway.app | Aminimal | 0 | 0 | 0/100 |
| vercel.com | Aminimal | 4 | 0 | 0/100 |
| workos.com | Aminimal | 1 | 0 | 0/100 |
| openai.com | Aminimal | 2 | 0 | 0/100 |
| anthropic.com | Aminimal | 0 | 0 | 0/100 |
| github.com | Aminimal | 3 | 0 | 0/100 |
FAQ
AI exposure, explained
What is an AI attack surface?
It is everything about your domain that an autonomous AI agent can discover and act on without logging in: your robots AI directives, llms.txt and ai.txt files, published agent or MCP cards, plugin manifests, and OAuth metadata. The more you expose, and the less it is authenticated, the more an agent (or an attacker steering one) can do.
Does the scan touch my servers or require access?
No. The scan only issues read-only GET requests for standard public files at well-known paths, the same requests a search engine crawler makes. It never authenticates, never calls a tool, and never enumerates beyond that fixed list. It is fully passive.
What is llms.txt?
llms.txt is an emerging convention: a plain-text file at your site root that maps your canonical content for large language models. It is useful, but because it is often generated or hand-edited, it is also a place API keys and internal notes occasionally leak. The scan reads it and flags anything sensitive.
How is the grade calculated?
Each surface we find is scored by AxioRank's detection engine for leaked secrets, PII, prompt injection, and dangerous or unauthenticated capabilities. Those signals combine into a 0 to 100 risk score, which maps to a letter grade from A (minimal exposure) to F (critical exposure). Merely publishing an AI-facing file never lowers your grade; only risky content does.
Do I need to sign up?
No. The scan and the full report are free and public. Signup is only for continuous monitoring and enforcement through the AxioRank gateway.
Keep exploring
Continue across the control plane.
A scan is a snapshot. Close the surface for good.
AxioRank continuously verifies the agents that reach your surfaces, scores every tool call, and enforces policy at the gateway. Start free, no card.