HONEST VERDICTS ON THE AGENTIC WEB

AI agents read your website, cite it, and buy from it. No Hacks tells you what's actually changed and whether it's worth acting on yet.

The web now has visitors who aren't human. AI agents read your website, cite it, and increasingly buy from it, acting for the people who used to visit themselves.

No Hacks is where you find out what actually changed, whether it's real, and whether your website is ready for it. The articles, weekly podcast, and newsletter stay plain and back every claim with receipts.

Available on Apple Podcasts, Spotify, YouTube, and more

No Hacks

A Publication About
the Agentic Web

60

Articles

231

Episodes

Weekly

Articles + Episodes

Evergreen and reference

The
Agentic
Web

These articles get revised rather than archived. Start with the definitions, then the two references that track every new crawler and agentic browser as it ships.

One email.
Every week.

New articles, the latest podcast episode, and a few links worth keeping. Practical strategies for making your website work for AI agents and the humans using it.

AI CrawlersCloudflareAgentic Web
7 min read

The Web Started Checking ID, And 119 Of 153 AI Crawlers Cannot Prove Who They Are

IPScanner's directory counts 153 AI crawler tokens and finds that only 34 publish anything a website owner could check them against. Two days later Cloudflare made bot verification automatic. The check on whether a crawler is who it says it is became a gate at the edge in the same month somebody counted how few crawlers have anything to present to it.

Read article
AI AgentsAgentic WebAgent Identity
9 min read

Meta Published Two Documents About Muse And Only One Mentions Attacks

Meta launched Muse with a consumer announcement and an engineering post on the same day. The announcement never uses the words risk, attack or mistake. The engineering post uses them constantly, and it is the only one that tells you Muse will appear as your activity to every website it visits.

Read article
Agentic WebAI CrawlersBot Management
18 min read

What Courts Say About robots.txt, Terms of Service, and Blocking AI Bots

A reference to what each website access control is worth in court. robots.txt, terms of service, anti-bot systems, rate limits, login gates, and cease-and-desist letters, with what courts have actually held about each one and how settled each answer is, which tells you how much weight it carries.

Read article
Agentic WebAgentic BrowsersCloudflare
6 min read

Cloudflare Built A Browser That Throws Away The Pixels

Cloudflare launched Kitesurf, a browser for AI agents that treats rendering as optional: "visual perfection, smooth 60-fps scrolling is not" important. Four weeks earlier OpenAI retired Atlas, a browser built so a person could watch an agent work. Anything your website communicates only in painted pixels, the trust badges and the reassurances, is now definitively invisible to the visitor reading you.

Read article
Agentic WebAI CrawlersCloudflare
9 min read

The Biggest “AI Crawler” On My Website Was Hunting For Credentials

Cloudflare's CFO told analysts that non-human traffic could be 1,000 times human traffic within five years and that humans will be "a rounding error on the internet." So I looked at my own crawler logs. The single largest AI crawler on nohacks.co arrived under Common Crawl's name and spent the day asking for my SSH keys, my .env files, and my MCP config.

Read article
Agentic CommerceWebMCPShopify
9 min read

Shopify Gave Every Store An Agent API Before The Agents Arrived

Shopify switched on WebMCP for every Liquid storefront on August 5: catalog, cart, and checkout are now tools an AI agent can call, with nothing to install. I checked three real storefronts: search already returns products and prices in a stock Chrome, checkout dies on an internal error, and no agent is calling any of it. Why this is not another llms.txt, and what to test before the agents arrive.

Read article
EP 23017 min

230: A Shoe Company And A Cookie Company Now Say The Exact Same Thing To AI Agents

On August 5 Shopify switched on a second way into every store on its platform, built for AI agents instead of people. Nothing to install, no merchant asked. I opened three unrelated stores, Allbirds, Brooklinen and Partake Foods, and asked each what it could do for a machine. All three answered with the same roughly 800 words, identical character f...
Listen now
EP 22919 min

229: Does llms.txt Work? What 137,000 Domains' Server Logs Show

Most of what's sold as AI search optimization has never been tested by the people selling it, and this episode is me checking the biggest one against server logs. Ahrefs looked at 137,000 domains in June: 97% of llms.txt files got zero requests in May, and the biggest readers of the rest were SEO audit tools. I also lay out the line I use to sort e...
Listen now
EP 22817 min

228: OpenAI Killed Its AI Browser

I came back from a month off the grid to find OpenAI had killed Atlas, its most glamorously launched product, nine months after the keynote. It barely matters, though. The automated, non-human visitor Atlas was sending to your website is still coming, through whatever shell comes next. Build for the visitor, not the browser.
Listen now
EP 22750 min

227: ChatGPT Shopping Is Scraped Google Shopping with Malte Landwehr, CMO/CPO at Peec AI

I sat down with Malte Landwehr, who left VP of SEO at Idealo to become CPO and CMO at Peec AI, the platform that tracks what ChatGPT, Claude, Gemini, and Google AI Overviews actually cite. We open on the strangest finding of the year. GummySearch, a Reddit analytics tool that shut down last November, now sits behind about 0.1% of all ChatGPT citati...
Listen now