Fewer than one in four tested AI agents can be reached by another agent
Anthropic's commerce blueprint expects storefront traffic from agents that shop on a user's behalf. Across 865 hands-on-tested AI agents classified for programmatic access, 188 expose an MCP surface and 20 clear every readiness axis. The names, the numbers, and what is missing.
By the Hlido Editor · 2026-09-03
On 2 September 2026 Anthropic published a reference blueprint for commerce agents and, in its engineering guide, wrote that "some of the traffic to your storefront will come from agents that shop on behalf of users." That is a claim about other agents: a shopping agent is only useful if the tools and services it needs can be reached by a machine, not just clicked by a person.
So how many of the AI agents on the market today can actually be reached by another agent? We tested them.
The number
Every agent Hlido — an independent review desk that tests AI agents hands-on — reviews is checked against its own public surface, and its record carries a classification of the programmatic surfaces it exposes: MCP, API, SDK, CLI, webhook. Across the 865 reviewed agents classified on that axis, 188 expose an MCP surface — 21.7%. A further 110 reviewed agents have not yet been classified on this axis and are excluded from the denominator rather than counted as closed.
Updated the same day: the first version of this post counted 123 of 800 (15.4%). Classifying 65 more agents from evidence already on file — most of them in the MCP Server category, which had no classification at all — moved the share to 21.7%. The remaining 110 unclassified agents may move it again; the direction of the finding does not change.
| Surface an agent exposes | Agents (of 865 classified) | Share |
|---|---|---|
| MCP | 188 | 21.7% |
| Any programmatic surface (MCP, API, SDK, CLI or webhook) | 374 | 43.2% |
| No programmatic surface found | 491 | 56.8% |
More than half of tested agents are web UIs a person operates. An orchestrator cannot delegate to them at all.
Which categories are reachable
| Category | Reviewed | MCP surface |
|---|---|---|
| Infrastructure | 116 | 49 |
| Coding | 180 | 40 |
| Frameworks & Eval | 85 | 15 |
| Specialized verticals | 34 | 13 |
| MCP Server | 28 | 28 |
| Workflow & Automation | 58 | 8 |
| Productivity | 58 | 5 |
| AI Agent (general assistants) | 197 | 18 |
| Customer Experience | 36 | 0 |
| Voice | 33 | 0 |
The category the commerce blueprint most needs, customer-facing agents, is the least reachable: 18 of 197 general assistants and 0 of 36 customer-experience agents expose an MCP surface. Infrastructure and coding tools, built by and for developers, lead.
The twenty that clear every axis
Reachability is one axis of four. The Agentic-Commerce Readiness index also scores whether the agent's capability was verified in testing rather than claimed, a delegation-safety proxy, and the depth of published evidence. Twenty agents score 75 or above on the combined index:
| Agent | Surfaces | Readiness |
|---|---|---|
| googleapis/genai-toolbox | MCP, API, SDK, CLI | 85 |
| block/goose | MCP, API, SDK, CLI | 85 |
| depwire | MCP, API, SDK, CLI | 85 |
| genomoncology/biomcp | MCP, API, SDK, CLI | 83 |
| TencentCloudBase AI Toolkit | MCP, API, SDK, CLI | 83 |
| rashidazarang/airtable-mcp | MCP, API, CLI, webhook | 82 |
| HKUDS/DeepCode | MCP, API, CLI | 80 |
| txn2/kubefwd | MCP, API, CLI | 79 |
| julien040/anyquery | MCP, API, CLI | 79 |
| VoltAgent | MCP, API, SDK, CLI | 78 |
| tsouth89/toolport | MCP, API, CLI | 77 |
| jovancoding/network-ai | MCP, API, SDK | 77 |
| 1mcp-app/agent | MCP, API, CLI | 76 |
| centralmind/gateway | MCP, API, CLI | 76 |
| portel-dev/ncp | MCP, API, CLI | 76 |
| ethanqc/feishu-user-plugin | MCP, API, CLI, webhook | 76 |
| sbroenne/mcp-server-excel | MCP, API, CLI | 75 |
| srclight | MCP, API, CLI | 75 |
| mymedi.ai MCP server | MCP, API, SDK | 75 |
| sandydasari/openacme | MCP, API, SDK, CLI | 75 |
Every one of the twenty is developer infrastructure or a data connector. None is a shopping, booking or customer-service agent. The scoring weights are private; each agent's record publishes the evidence behind its score.
What this does not say
- It does not say an agent that lacks an MCP surface is a bad product. Most of the 491 are built for a person at a screen and do that job.
- It does not test whether any of these agents speaks a payment or checkout protocol. The index measures reachability, verified behaviour, a safety proxy and evidence depth; a live transaction probe is not part of it.
- The 110 unclassified agents may move the share in either direction when classified.
The data
The full index, every agent's readiness score, band and the exact signals behind it: /data/acr-index.json. The methodology page: /methodology/agentic-commerce-readiness/. The ranked list: /best/agent-ready/.