Appkitekt logo
Appkitekt AIOne agent for AI agent optimization
Request demo
All posts

May 25, 2026 · Reference post · App surface

The 200+ DST factors that make or break an app's agentic readiness

Every audit Appkitekt AI runs on a mobile app rolls up to one score on one frame: Discovery · Selection · Trust. Below is a preview of the full list — only a subset of the 200 factors we score on App Store / Play listings, App Intents, AASA and universal links. Run an audit to unlock every detail.

Why DST for apps

A score is only useful if it tells you where you're losing. DST gives every app factor a home in one of three places an agent's decision can break:

  • Discovery (30%) — can the agent find your app at all? Store metadata, AASA, App Intents catalog, registry presence, indexable deep links.
  • Selection (45%) — once you're in the consideration set, do you get picked? Listing craft, ratings velocity, mindshare, head-to-head against the top five competitors.
  • Trust (25%) — will the agent actually recommend installing? Privacy nutrition label, ATT copy, permissions hygiene, evidence, support and developer responsiveness.

App · 200 factors

App surface — DST factor preview

What agents read on App Store / Play listings, App Intents, AASA and universal links.

Discovery · weight 30% · 46 factors

Can an AI agent find this app, identify the publisher, and route a user into it?

Identity & Authenticity · 14

  • Verified developer account on Apple App Store Connect / Google Play Console
  • Seller / developer name matches the legal brand and trademark owner
  • Legal entity exists and is registered in a transparent jurisdiction
  • Corporate age and continuity (no recent publisher transfer)
  • Domain ownership matches the app's marketing and support URLs
  • Consistent publisher naming across Apple, Google, and the web

+ 8 factors hidden

Store Listing Findability · 10

  • App name / trackName clearly states the function, not just brand (Apple ≤30, Google ≤30)
  • Subtitle (Apple, ≤30) reinforces primary agent-detectable use case
  • Short description (Google, ≤80) leads with the core job the agent must match
  • Keyword field (Apple, 100 chars) covers agent-relevant intents, no duplicates

+ 6 factors hidden

Off-store Entity Presence · 11

  • App entity established on Wikidata with sameAs links to both stores
  • Wikipedia article (or section) for the app or publisher
  • Reviews in high-authority publications (The Verge, TechCrunch, MacStories, Android Police, Wired)
  • Mentions in 'Best apps for…' curated roundups
  • Active discussion on Reddit and dedicated subreddits

+ 6 factors hidden

Agent Handoff Surfaces · 11

  • Universal Links (Apple) registered for every shareable in-app screen
  • App Links (Google) verified via Digital Asset Links
  • apple-app-site-association file published on the marketing domain
  • assetlinks.json published at /.well-known/ on the marketing domain
  • App Clips (Apple) for low-friction first use from an agent's web answer

+ 6 factors hidden

26 factors in this section are only visible in a full ARO audit.

Run audit to unlock

Selection · weight 45% · 68 factors

When an agent compares 5 apps for the user's task, why does it pick this one?

Listing Conversion Assets · 8

  • First 3 screenshots cover the hero benefit, not chrome
  • Screenshot captions name the user task in text a vision model can read
  • Preview video opens on the core agent-task flow within the first 3 seconds
  • Captioned screenshots (Apple) / feature graphic (Google) state value prop in text the vision model can read

+ 4 factors hidden

Decision-Making Data · 10

  • Average rating ≥ 4.3 on current version
  • Rating count ≥ 1,000 for category credibility
  • Recent review velocity (last 30 days) above category median
  • Developer responses to negative reviews address concrete bugs

+ 6 factors hidden

Description Craft · 8

  • Full description ≥ 400 chars and ≤ 4000 chars
  • Capabilities listed as parseable bullets the agent can map to intents
  • Use-case scenarios named in the first paragraph (intent matching)
  • Social proof line (press quote, award, install milestone) the agent can cite

+ 4 factors hidden

Agent Invocation Surfaces (MCP-pillar signals, scored in app audit) · 20

  • App Intents framework (Apple) — the iOS app's native invocation surface; Apple Intelligence and Siri use it to call the app into Shortcuts
  • App Shortcuts donations registered so Apple Intelligence can suggest flows proactively
  • EntityQuery + AppEntity types implemented so Apple Intelligence can resolve in-app objects by name
  • Spotlight semantic indexing payload populated for on-device Apple Intelligence retrieval
  • App Actions (Google) registered with Google Assistant and Gemini via Digital Asset Links
  • Gemini Extensions integration where the app exposes a public API Google can route to
  • ChatGPT Apps SDK manifest published so the app is callable from inside ChatGPT
  • Copilot connector / Copilot Studio action published for Microsoft 365 + Windows Copilot handoff

+ 12 factors hidden

Automation Friendliness · 12

  • Deterministic intent schemas — same input produces same outcome
  • Semantic UI labeling for accessibility tree consumption
  • Accessibility tree quality (every actionable element labeled)
  • Structured navigation that maps to predictable agent steps
  • Headless operation or sandbox / test environment available

+ 7 factors hidden

Outcome & Personalization Fit · 10

  • Use-case breadth named in description (multiple agent intents covered)
  • Platform and minimum OS fit declared explicitly
  • Language and region fit (does the app actually run in the user's locale)
  • Offline / on-device capability for privacy-preserving agent flows

+ 6 factors hidden

39 factors in this section are only visible in a full ARO audit.

Run audit to unlock

Trust · weight 25% · 86 factors

Will an agent stake its reputation on recommending this app and delegating actions to it?

Developer Identity & Verification · 10

  • Seller / developer name matches the legal brand
  • Verified developer badge where the store offers one
  • App Store Connect / Play Console account in good standing (no policy strikes)
  • Support URL resolves to a real, branded help center

+ 6 factors hidden

Privacy & Permissions Hygiene · 13

  • Apple Privacy Nutrition Label complete for every data category
  • Google Play Data Safety form complete and matched to the privacy policy
  • Permissions requested are minimal and justified in-app at request time
  • Tracking / IDFA usage declared accurately (Apple App Tracking Transparency)
  • No clipboard scraping outside explicit user action
  • No contact / SMS / call-log access unless core to function

+ 7 factors hidden

Security Posture · 11

  • MFA support for account access
  • Passkey / WebAuthn support
  • OAuth quality (PKCE, refresh rotation, scope minimization)
  • Public bug bounty or vulnerability disclosure program
  • SOC 2 / ISO 27001 / equivalent certification

+ 6 factors hidden

Runtime Reliability · 11

  • Crash-free sessions rate ≥ 99.5%
  • ANR rate (Google) within Play's healthy thresholds
  • Cold launch latency within category norms
  • Warm launch latency within category norms
  • Graceful offline handling and recovery after interruption

+ 6 factors hidden

Behavioral Trust & Honesty · 10

  • No dark patterns in onboarding, paywall, or settings
  • Honest cancellation flow (no hidden steps, no retention dark patterns)
  • Subscription terms (price, period, auto-renew, cancel) disclosed up front
  • No aggressive or manipulative notifications

+ 6 factors hidden

Compliance & Governance · 10

  • GDPR compliance where users are in the EU/EEA
  • CCPA / CPRA compliance for California users
  • COPPA compliance and Designed for Families enrollment if targeting kids
  • HIPAA alignment for any health data

+ 6 factors hidden

Cross-Surface Consistency · 9

  • Listing copy matches what the app actually does on first launch
  • Screenshots match the current build's UI
  • Pricing in the listing matches the IAP / subscription configured
  • Marketing site, store listing, and in-app copy use the same tagline

+ 5 factors hidden

AI-Native Trust (forward-looking) · 12

  • Machine-readable trust manifest on the developer domain
  • Capability manifest enumerating what an agent may invoke
  • Cryptographic attestations / signed outputs for agent-facing endpoints
  • Provenance chains for content the app generates
  • Agent permission delegation with audit trails

+ 7 factors hidden

49 factors in this section are only visible in a full ARO audit.

Run audit to unlock

Next step

Unlock the complete factor list.

Run an ARO audit to see every signal scored for your app.

Run audit