tuqo

What AI breaks in sites: 14 checks explained

A site written by an AI model breaks in predictable ways: an API key stays in the files, paths lead nowhere, the form sends nothing, and images are pasted right into the HTML. So on every publish Tuqo reads the site’s files and shows a What to improve on the site report: 14 checks on two levels. Nothing is blocked. The site is published either way, and the issues wait next to its address.

Worth fixing

These keep the site from working as intended or expose too much. The chip turns yellow.

Link to a file that doesn’t exist. “The page refers to a file that isn’t in the set: styles won’t apply, the image won’t show, the script won’t run.” The model says “create style.css” in its reply, while the markup points to styles.css or assets/style.css. Add the file or fix the path; letter case and folders matter.

A Tuqo key found in the files. A tqk_… key gives access to the project through the API and MCP: “any visitor could change your sites”. Agents paste the key into a script “to make it work”. Remove it from the files, publish again and reissue the key in API keys.

Something that looks like a secret. A Telegram bot token, a cloud key, a private key: “as good as publishing a password”. A static site has no server-side secrets by definition. Remove it, publish again and revoke it with the service that issued it.

Links to localhost or local files. “It worked on the developer’s computer; visitors won’t be able to open it.” Typical for code the model wrote “to run locally”: http://localhost:3000/api, file:///Users/.... Replace them with addresses on the published site, or remove them.

Resources over http:// on a secure site. The site opens over HTTPS, “and the browser blocks scripts and styles loaded over http and marks images as insecure”. Models pull libraries from old CDN addresses they remember. Switch to https:// or put the files into the site’s set.

The site is hidden from search. <meta name="robots" content="noindex">: “search engines won’t show the site in results. Often left over from a template or a test build.” Remove the tag if the site should be found in search.

robots.txt blocks crawling of the whole site. A Disallow: / line means “crawlers won’t visit a single page”. Remove it or narrow it down to specific sections.

No meta viewport. “Without it a phone renders the page as if on a desktop monitor, and the text is unreadable without zooming.” Add to the head: <meta name="viewport" content="width=device-width, initial-scale=1">.

Images embedded in HTML. The most common problem with Claude artifacts: “the whole page has to load before the first paint, and base64 doesn’t compress. On a phone, visitors wait several seconds.” Pass images as separate files (in deploy_files with encoding: base64), keep only links in the HTML, and scale the images down to their actual on-screen size.

A form with no submit address. “The Submit button doesn’t send anything.” The model writes action="#" or alert('Thank you!') because it has no server side. Take the form code from the site’s Forms tab: submissions will arrive in Tuqo, in notifications and in the auto-reply. More on forms.

Could be improved

Advice on how the site looks in search and messengers, and on forms. The chip is teal.

The page title is “Document”. A template default the model forgot to replace. “The title shows in the browser tab, in bookmarks and in search results.” Put the name and the point of the page in <title>.

No favicon. “The browser tab and bookmarks show the site with a blank icon.” Put favicon.svg or favicon.png in the root and add <link rel="icon"> to the head.

No link preview for messengers. “A link to the site in Telegram, WhatsApp or VK shows up without an image or a description.” Add og:title, og:description and og:image with a 1200×630 image.

The form sends submissions to a third-party service. Models reach for formspree.io and the like out of habit. “If this is intended, leave it as is.” But Tuqo receives submissions too: they land on the Forms tab, in notifications and in the auto-reply.

Where to find the report

The chip next to the site’s address: yellow if something is worth fixing, teal if it’s advice only. On the checklist page every issue has a reason, a fix and a location (file and line, up to 10 places). Mark as done and Hide are remembered in your browser.

AI agents get the issues over MCP and REST in the recommendations field of the publish response, the deploy status and the site card: the first five plus a count of the rest.

A “fix the issues” prompt

The panel has a Copy for AI button that turns the issues into a ready prompt. If you want your own:

Here is Tuqo's check report for my site. Fix every "worth fixing" item.
[paste the list of issues]

Rules: relative paths only, no links to localhost or http://,
no keys or tokens in the files, images as separate files, not base64.
The head must have meta charset UTF-8, meta viewport, a meaningful title,
og:title/og:description/og:image and a favicon link.
Leave the form without a submit address: I'll paste the code from the Forms tab.
Output the changed files in full and publish again.

FAQ

Can the checks block a publish?

No, they are recommendations. The only thing Tuqo never publishes is service files such as .git, .env and SSH keys: they are dropped on upload.

How do I turn them off?

Site settings have a toggle, Show recommendations after publishing. Turn it off and the chip and the recommendations field disappear. You can also hide a single item with Hide.

Which plans include the checks?

All of them, including Free: the checks are part of publishing, not a paid feature.

Why only 14 checks?

This is the first wave: the things that most often break sites made by AI models. The list grows on demand, so the checklist stays short and honest.

All 14 checks → · Why a deploy failed →