Blog

Why our scanner sometimes wears other agents' names

If you look closely at your logs during an AgentScore scan, you'll see a few requests that say they're ChatGPT, Claude, Perplexity or Googlebot. They aren't. They're our scanner, borrowing those agents' user agents to see how your site treats them. Here's why we do it, exactly what we send, and what the result can and can't tell you.

The question we're trying to answer

One of the most common reasons an AI agent fails on a website has nothing to do with the website's design. The agent is turned away at the door. A bot protection rule, a firewall setting or a CDN feature decides that anything calling itself an AI agent gets a challenge page, an error, or a stripped-down page with no prices.

Nobody notices, because people never see it. The site works perfectly in a browser. The only way to find out is to knock as the agent and compare what comes back with what a browser gets.

We can't send the real ChatGPT to your site on demand. So for a handful of requests, our scanner sends the same User-Agent header those agents send, and compares the answer with a normal browser's.

Exactly what we send

Name we useWhat we requestSigned?
AgentScore/1.0, our own namerobots.txt, sitemaps, llms.txt, well-known files (MCP and agentic commerce discovery), and checks for common pages such as /pricing and /cartYes
A normal Chrome browserThe home page, your llms.txt, and the key pages, before and after JavaScript runs. This is the baseline everything is compared withNo
ChatGPT-User, Claude-User, Perplexity-User, OAI-SearchBot and GooglebotThe home page, once eachNo
ChatGPT-UserThe product, pricing and cart pages we found, once eachNo
ChatGPT-User, Claude-User and Perplexity-UserThe cart and checkout, once eachNo

The imitated requests use the user agent strings those operators publish, so they look the way the real thing does. We picked these agents because they're the ones that fetch pages for people in real time or power AI search, which are the visits most likely to turn into customers.

Training crawlers such as GPTBot and ClaudeBot are handled differently. We read your robots.txt rules for them, along with every other AI agent we track, but we don't request pages as them. Blocking training is a business choice, and it doesn't cost points. Our guide to blocking or allowing AI crawlers covers that decision.

How we compare the answers

For each imitated request, we line the response up against the browser's:

  • Blocked: the agent got an error (HTTP 400 or above) where the browser didn't, or a challenge page such as "Just a moment" or "Verify you are human" where the browser got the real page.
  • Degraded: the agent got less than half the visible text the browser got, which usually means a placeholder or stripped-down page.
  • Same page: neither of the above.

On the home page, any blocked agent fails the Bot protection lets AI agents through check, and a degraded one is a warning. A similar comparison, looking for errors and challenge pages (and, at checkout, CAPTCHAs), runs on your product, pricing and cart pages for AI agents can open your product, pricing and cart pages, and on the cart and checkout for AI agents aren't blocked or shown a CAPTCHA at the cart and checkout. How AgentScore works explains how those checks add up.

Why those requests aren't signed

Everything the scanner sends under its own name is signed with Web Bot Auth, so your CDN can prove it came from us. We explain how in Why we sign every request our agents send.

The imitated requests are deliberately unsigned. If we signed them, a CDN that recognizes and trusts our signature might wave them through, and we'd be measuring how your site treats Ghost Agent Labs, not how it treats ChatGPT. Unsigned, they get exactly the treatment any request with that name gets.

What the result can't tell you

Our imitation is honest about one thing it can't do: it can't pass identity checks. The requests come from our servers, not from OpenAI's, Anthropic's, Perplexity's or Google's, and they carry none of those companies' signatures.

So if your bot protection verifies agents properly, checking published IP ranges or reverse DNS and blocking impostors, it may block our imitation too. That's the right behavior, and it will show up as a failed check. When that happens:

  1. Look at the evidence in the report. It shows which agents were blocked and what status they got.
  2. Check your CDN or bot protection settings: is the rule "block requests that claim to be an AI agent but fail verification", or "block AI agents"? The first is good practice. The second turns customers away.
  3. Confirm in your logs, or on the verification page in the Ghost Agent Labs app, that verified requests from the real agent are getting through.

If the real agents get through and only impostors are blocked, you're in good shape, whatever the check says. Our guides to telling whether an AI crawler is real and bot protection that lets AI agents through cover how to set that up.

The opposite limit applies too. A site that treats these agents well when they come from our servers will probably treat the real ones well, but real products differ in details we can't copy, such as where their requests come from. Treat the result as a strong signal, not a guarantee.

Keeping it small

Imitated requests are a small part of a scan: a few page loads per agent at most, never a crawl. The scanner reads public pages only and never adds to a cart, submits a form or places an order. On the free AgentScore page, a domain's result is reused for 24 hours, so repeated requests for the same site don't cause repeated visits.

If you see these requests in your logs: they'll arrive close together with a scan from AgentScore/1.0. The AgentScore bot page explains how to verify our signed requests and how to opt out, including from the comparison requests.

If you want to see the result: run AgentScore on your own site and open the Access checks.

← All blog Test your site with AgentScore →

Can AI agents use your site?

Get your free AgentScore in under a minute. No sign-up needed.