AgentGrade

What this client asked www.pathwren.workers.dev for, when, and what it got. Every number below is from this host's own server-side request log, 2026-09-01 02:53:17Z to 2026-09-01 02:53:29Z UTC.

AgentGrade/1.0 (security research; agentgrade.net)

67 request(s) from 1 distinct address(es), 18 distinct path(s), first seen 2026-09-01 02:53:17Z, last seen 2026-09-01 02:53:29Z UTC. 1 separate visit(s), counting a gap of more than 30 minutes as a new one.

It describes itself, inside its own user-agent, as security research; agentgrade.net. That is the client's own words, quoted; this page makes no claim about what it is for.

The user-agent strings, exactly as they arrived

user-agentrequestsaddressesfirst seenlast seen
AgentGrade/1.0 (security research; agentgrade.net)6712026-09-01 02:53:17Z2026-09-01 02:53:29Z

What it asked for, in the order it asked

First request to each path, oldest first.

#pathat (UTC)status
1/mcp2026-09-01 02:53:17Z200
2/admin2026-09-01 02:53:17Z404
3/dashboard2026-09-01 02:53:17Z404
4/_internal2026-09-01 02:53:17Z404
5/2026-09-01 02:53:18Z200
6/.env2026-09-01 02:53:19Z404
7/.git/config2026-09-01 02:53:19Z404
8/.git/HEAD2026-09-01 02:53:19Z404
9/debug2026-09-01 02:53:19Z404
10/server-status2026-09-01 02:53:19Z404
11/.env.local2026-09-01 02:53:19Z404
12/config.json2026-09-01 02:53:19Z404
13/appsettings.json2026-09-01 02:53:19Z404
14/package.json2026-09-01 02:53:20Z404
15/agentgrade-404-check-xyz2026-09-01 02:53:20Z404
16/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA2026-09-01 02:53:20Z404
17/c/mcp-registry-official/mcp2026-09-01 02:53:21Z200
18/c/mcp-registry-official/mcp/triage2026-09-01 02:53:25Z200

Everything it asked for

pathrequestsstatus codesfirstlast
/21200×212026-09-01 02:53:18Z2026-09-01 02:53:27Z
/.env3404×32026-09-01 02:53:19Z2026-09-01 02:53:27Z
/.env.local3404×32026-09-01 02:53:19Z2026-09-01 02:53:28Z
/.git/HEAD3404×32026-09-01 02:53:19Z2026-09-01 02:53:27Z
/.git/config3404×32026-09-01 02:53:19Z2026-09-01 02:53:27Z
/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA3404×32026-09-01 02:53:20Z2026-09-01 02:53:29Z
/_internal3404×32026-09-01 02:53:17Z2026-09-01 02:53:26Z
/admin3404×32026-09-01 02:53:17Z2026-09-01 02:53:26Z
/agentgrade-404-check-xyz3404×32026-09-01 02:53:20Z2026-09-01 02:53:28Z
/appsettings.json3404×32026-09-01 02:53:19Z2026-09-01 02:53:28Z
/config.json3404×32026-09-01 02:53:19Z2026-09-01 02:53:28Z
/dashboard3404×32026-09-01 02:53:17Z2026-09-01 02:53:26Z
/debug3404×32026-09-01 02:53:19Z2026-09-01 02:53:28Z
/package.json3404×32026-09-01 02:53:20Z2026-09-01 02:53:28Z
/server-status3404×32026-09-01 02:53:19Z2026-09-01 02:53:28Z
/c/mcp-registry-official/mcp/triage2200×22026-09-01 02:53:25Z2026-09-01 02:53:26Z
/c/mcp-registry-official/mcp1200×12026-09-01 02:53:21Z2026-09-01 02:53:21Z
/mcp1200×12026-09-01 02:53:17Z2026-09-01 02:53:17Z

What it asked for that did not exist

path it asked forwhat it gotfirst askedsince then
/admin404×32026-09-01 02:53:17Zstill absent — on purpose: There is no admin interface, because there is nothing to administer at the edge: content is rebuilt and redeployed wholesale, never edited in place.
/dashboard404×32026-09-01 02:53:17Zstill absent — on purpose: Same: no dashboard exists
/_internal404×32026-09-01 02:53:17Zstill absent — on purpose: No route on this host is internal
/.env404×32026-09-01 02:53:19Zstill absent — on purpose: Secrets are Cloudflare Worker secrets, never files in the served directory
/.git/config404×32026-09-01 02:53:19Zstill absent — on purpose: No repository is deployed
/.git/HEAD404×32026-09-01 02:53:19Zstill absent — on purpose: Same as /.git/config.
/debug404×32026-09-01 02:53:19Zstill absent — on purpose: No framework, no interpreter, no debug mode
/server-status404×32026-09-01 02:53:19Zstill absent — on purpose: There is no Apache here — this is a Cloudflare Worker in front of static assets, so mod_status does not exist to expose
/.env.local404×32026-09-01 02:53:19Zstill absent — on purpose: Same as /.env.
/config.json404×32026-09-01 02:53:19Zstill absent — on purpose: No configuration is served
/appsettings.json404×32026-09-01 02:53:19Zstill absent — on purpose: No .NET, and no configuration served.
/package.json404×32026-09-01 02:53:20Zstill absent — on purpose: The build's manifest is not deployed to the assets host.
/agentgrade-404-check-xyz404×32026-09-01 02:53:20Zstill absent
/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA404×32026-09-01 02:53:20Zstill absent

What it got, and what it sent

Status codes
404×42, 200×25
Accept headers
*/*
Bytes served
353315
Attributed to a channel
mcp-registry-official (3)
Our instrument classed it
agent×67 — that is our classifier's label from the user-agent, not the operator's, and it has been wrong before.

How to verify it is really them

not observed.

Checked 2026-09-01 against our own request log.

What it publishes about you afterwards

Not observed. We have not seen this client publish a grade, a listing or a record about this host anywhere, and we make no claim that it does or does not.

Its own documentation

Not observed. It carries no URL and no contact address in its user-agent, so there is nowhere documented to ask what it is.

Self-described in its own user-agent as 'security research; agentgrade.net'.

Checked 2026-09-01 against our own request log.

Its probe set is in the log below: thirteen paths in twelve seconds, including /agentgrade-404-check-xyz — a control probe carrying the scanner's own name, whose answer establishes whether this host's 404 is a real 404. We make no claim about what it does with the result.

This page as data

curl -s https://www.pathwren.workers.dev/bot/agentgrade.json
curl -s https://www.pathwren.workers.dev/data/observed-clients.json   # every client, one request

JSON · markdown · all clients seen here · index as JSON

Method, and what this page will not say

Rows come from a server-side log written before anything is served, so clients that run no JavaScript are counted exactly like browsers. The window is the whole life of the log, 2026-09-01 02:53:17Z to 2026-09-01 02:53:29Z UTC, and it is stated on every number because a count without a window is not a fact. Addresses are stored as salted hashes and counted, never printed. Our own checks send X-Self: 1 and are excluded, together with every request the analyst flagged as one of our own agents reaching for a URL through a model provider's fetch tool (the numbers are on the index). Nothing here is a claim about intent: where this page does not know something it says not observed.