May 25, 2026 · Reference post · App surface
The 200+ DST factors that make or break an app's agentic readiness
Every audit Appkitekt AI runs on a mobile app rolls up to one score on one frame: Discovery · Selection · Trust. Below is a preview of the full list — only a subset of the 200 factors we score on App Store / Play listings, App Intents, AASA and universal links. Run an audit to unlock every detail.
Why DST for apps
A score is only useful if it tells you where you're losing. DST gives every app factor a home in one of three places an agent's decision can break:
- Discovery (30%) — can the agent find your app at all? Store metadata, AASA, App Intents catalog, registry presence, indexable deep links.
- Selection (45%) — once you're in the consideration set, do you get picked? Listing craft, ratings velocity, mindshare, head-to-head against the top five competitors.
- Trust (25%) — will the agent actually recommend installing? Privacy nutrition label, ATT copy, permissions hygiene, evidence, support and developer responsiveness.
App · 200 factors
App surface — DST factor preview
What agents read on App Store / Play listings, App Intents, AASA and universal links.
Discovery · weight 30% · 46 factors
Can an AI agent find this app, identify the publisher, and route a user into it?
Identity & Authenticity · 14
- Verified developer account on Apple App Store Connect / Google Play Console
- Seller / developer name matches the legal brand and trademark owner
- Legal entity exists and is registered in a transparent jurisdiction
- Corporate age and continuity (no recent publisher transfer)
- Domain ownership matches the app's marketing and support URLs
- Consistent publisher naming across Apple, Google, and the web
+ 8 factors hidden
Store Listing Findability · 10
- App name / trackName clearly states the function, not just brand (Apple ≤30, Google ≤30)
- Subtitle (Apple, ≤30) reinforces primary agent-detectable use case
- Short description (Google, ≤80) leads with the core job the agent must match
- Keyword field (Apple, 100 chars) covers agent-relevant intents, no duplicates
+ 6 factors hidden
Off-store Entity Presence · 11
- App entity established on Wikidata with sameAs links to both stores
- Wikipedia article (or section) for the app or publisher
- Reviews in high-authority publications (The Verge, TechCrunch, MacStories, Android Police, Wired)
- Mentions in 'Best apps for…' curated roundups
- Active discussion on Reddit and dedicated subreddits
+ 6 factors hidden
Agent Handoff Surfaces · 11
- Universal Links (Apple) registered for every shareable in-app screen
- App Links (Google) verified via Digital Asset Links
- apple-app-site-association file published on the marketing domain
- assetlinks.json published at /.well-known/ on the marketing domain
- App Clips (Apple) for low-friction first use from an agent's web answer
+ 6 factors hidden
26 factors in this section are only visible in a full ARO audit.
Run audit to unlockSelection · weight 45% · 68 factors
When an agent compares 5 apps for the user's task, why does it pick this one?
Listing Conversion Assets · 8
- First 3 screenshots cover the hero benefit, not chrome
- Screenshot captions name the user task in text a vision model can read
- Preview video opens on the core agent-task flow within the first 3 seconds
- Captioned screenshots (Apple) / feature graphic (Google) state value prop in text the vision model can read
+ 4 factors hidden
Decision-Making Data · 10
- Average rating ≥ 4.3 on current version
- Rating count ≥ 1,000 for category credibility
- Recent review velocity (last 30 days) above category median
- Developer responses to negative reviews address concrete bugs
+ 6 factors hidden
Description Craft · 8
- Full description ≥ 400 chars and ≤ 4000 chars
- Capabilities listed as parseable bullets the agent can map to intents
- Use-case scenarios named in the first paragraph (intent matching)
- Social proof line (press quote, award, install milestone) the agent can cite
+ 4 factors hidden
Agent Invocation Surfaces (MCP-pillar signals, scored in app audit) · 20
- App Intents framework (Apple) — the iOS app's native invocation surface; Apple Intelligence and Siri use it to call the app into Shortcuts
- App Shortcuts donations registered so Apple Intelligence can suggest flows proactively
- EntityQuery + AppEntity types implemented so Apple Intelligence can resolve in-app objects by name
- Spotlight semantic indexing payload populated for on-device Apple Intelligence retrieval
- App Actions (Google) registered with Google Assistant and Gemini via Digital Asset Links
- Gemini Extensions integration where the app exposes a public API Google can route to
- ChatGPT Apps SDK manifest published so the app is callable from inside ChatGPT
- Copilot connector / Copilot Studio action published for Microsoft 365 + Windows Copilot handoff
+ 12 factors hidden
Automation Friendliness · 12
- Deterministic intent schemas — same input produces same outcome
- Semantic UI labeling for accessibility tree consumption
- Accessibility tree quality (every actionable element labeled)
- Structured navigation that maps to predictable agent steps
- Headless operation or sandbox / test environment available
+ 7 factors hidden
Outcome & Personalization Fit · 10
- Use-case breadth named in description (multiple agent intents covered)
- Platform and minimum OS fit declared explicitly
- Language and region fit (does the app actually run in the user's locale)
- Offline / on-device capability for privacy-preserving agent flows
+ 6 factors hidden
39 factors in this section are only visible in a full ARO audit.
Run audit to unlockTrust · weight 25% · 86 factors
Will an agent stake its reputation on recommending this app and delegating actions to it?
Developer Identity & Verification · 10
- Seller / developer name matches the legal brand
- Verified developer badge where the store offers one
- App Store Connect / Play Console account in good standing (no policy strikes)
- Support URL resolves to a real, branded help center
+ 6 factors hidden
Privacy & Permissions Hygiene · 13
- Apple Privacy Nutrition Label complete for every data category
- Google Play Data Safety form complete and matched to the privacy policy
- Permissions requested are minimal and justified in-app at request time
- Tracking / IDFA usage declared accurately (Apple App Tracking Transparency)
- No clipboard scraping outside explicit user action
- No contact / SMS / call-log access unless core to function
+ 7 factors hidden
Security Posture · 11
- MFA support for account access
- Passkey / WebAuthn support
- OAuth quality (PKCE, refresh rotation, scope minimization)
- Public bug bounty or vulnerability disclosure program
- SOC 2 / ISO 27001 / equivalent certification
+ 6 factors hidden
Runtime Reliability · 11
- Crash-free sessions rate ≥ 99.5%
- ANR rate (Google) within Play's healthy thresholds
- Cold launch latency within category norms
- Warm launch latency within category norms
- Graceful offline handling and recovery after interruption
+ 6 factors hidden
Behavioral Trust & Honesty · 10
- No dark patterns in onboarding, paywall, or settings
- Honest cancellation flow (no hidden steps, no retention dark patterns)
- Subscription terms (price, period, auto-renew, cancel) disclosed up front
- No aggressive or manipulative notifications
+ 6 factors hidden
Compliance & Governance · 10
- GDPR compliance where users are in the EU/EEA
- CCPA / CPRA compliance for California users
- COPPA compliance and Designed for Families enrollment if targeting kids
- HIPAA alignment for any health data
+ 6 factors hidden
Cross-Surface Consistency · 9
- Listing copy matches what the app actually does on first launch
- Screenshots match the current build's UI
- Pricing in the listing matches the IAP / subscription configured
- Marketing site, store listing, and in-app copy use the same tagline
+ 5 factors hidden
AI-Native Trust (forward-looking) · 12
- Machine-readable trust manifest on the developer domain
- Capability manifest enumerating what an agent may invoke
- Cryptographic attestations / signed outputs for agent-facing endpoints
- Provenance chains for content the app generates
- Agent permission delegation with audit trails
+ 7 factors hidden
49 factors in this section are only visible in a full ARO audit.
Run audit to unlockNext step
Unlock the complete factor list.
Run an ARO audit to see every signal scored for your app.