Prowl
27/100
prowl
Benchmarked Sep 14, 2026

IoTVAS API

IOTVAS API enables you to discover IoT/Connected devices in the network and provides detailed real-time risk analysis, including firmware vulnerability analysis without requiring the user to uplo

aiapi platform_profile Streaming
Benchmark Your API

Score Breakdown

Token Efficiency4/10
Auth Simplicity3/10
Parseability3/10
Latency2/10
Consistency2/10
Documentation2/10
Error Clarity2/10
First-Try Success2/10

Benchmark Analysis Log

Full LLM thinking from the 4-phase benchmark pipeline.

Analyze
```json
{
  "service_type": "platform",
  "base_url": "https://firmalyzer.com:iotvas",
  "auth_method": "unknown",
  "auth_config": {},
  "endpoints": [],
  "pricing_model": {
    "type": "unknown",
    "details": {}
  },
  "rate_limits": {},
  "capabilities": [
    "IoT / connected device discovery on a network",
    "real-time risk analysis of discovered devices",
    "firmware vulnerability analysis without firmware upload",
    "AI-driven security assessment (per categorization)"
  ],
  "raw_analysis": "IoTVAS is a product from Firmalyzer that provides IoT and connected-device security assessment. The service discovers IoT/connected devices on a network and performs real-time risk analysis, including firmware vulnerability analysis that does not require the user to upload firmware — implying the analysis is done remotely (likely via device fingerprinting, exposed service probing, and firmware identification from known vendor/model signatures).\n\nWHO IT'S FOR: Security teams, network administrators, and enterprises needing visibility and risk scoring for the growing population of IoT/OT devices on their networks. Likely relevant for compliance, vulnerability management, and incident response contexts.\n\nMATURITY / FORM: The URL format 'https://firmalyzer.com:iotvas' is unusual — the ':iotvas' segment is not a standard TCP port (ports are numeric). This strongly suggests it is a named endpoint/path or a documented API identifier rather than a conventional REST base URL. No public REST API documentation, OpenAPI/Swagger spec, or endpoint list is provided in the source material, so no concrete endpoints, auth scheme, or rate limits can be extracted.\n\nINTEGRATIONS: Unknown from the provided content. No SDK, plugin, or marketplace integrations were mentioned.\n\nPRICING: Not provided. Firmalyzer products are typically commercial/B2B (enterprise security platform), so the likely model is subscription or quote-based enterprise licensing, but this cannot be confirmed from the given text.\n\nSUMMARY: This appears to be a legitimate B2B IoT security / firmware risk analysis platform with an API, but the source material lacks the technical detail needed to document concrete endpoints, auth methods, or rate limits. Further reconnaissance (vendor docs, OpenAPI spec, or direct probe) would be required to populate those.\n\nCAVEAT: Details derived primarily from the short marketing blurb; treat unverified fields (auth, pricing, rate limits) as unknown."
}
```
Execute

0/3 tests passed

TestEndpointStatusLatency
website_uptimeGET /None35ms
robots_txtGET /robots.txtNone3ms
llms_txtGET /llms.txtNone2ms
Interpret
{
  "overall": 28,
  "dimensions": {
    "token_efficiency": 4.0,
    "first_try_success": 2.0,
    "response_parseability": 3.0,
    "error_clarity": 2.0,
    "doc_quality": 2.0,
    "auth_simplicity": 3.0,
    "latency": 2.0,
    "consistency": 2.0
  },
  "pricing_normalized": {
    "model": "unknown",
    "tiers": [],
    "free_tier": null,
    "notes": "No pricing information available; cannot normalize"
  },
  "issues": [
    "All three probe checks failed with an identical parsing error: \"Invalid port: 'iotvas'\" — the domain/port could not even be resolved, indicating a malformed or unreachable endpoint",
    "No HTTP status codes were captured for any check, so uptime, robots.txt, and llms.txt presence are entirely unverifiable",
    "No llms.txt discovered, meaning agents have no machine-readable onboarding or capability manifest",
    "No response previews available, so no security headers, content type, or structured data could be evaluated",
    "Pricing model is listed as 'unknown' with empty details — unacceptable ambiguity for agent recommendation to users",
    "Capabilities are described only in vague marketing terms ('AI-driven security assessment') with no API surface, schema, or integration details provided"
  ],
  "recommendations": [
    "Fix the DNS/port resolution issue — the platform is currently unreachable by automated probes, which will cause every agent check to fail",
    "Publish an llms.txt or /.well-known endpoint describing capabilities, auth flow, and rate limits so agents can self-onboard",
    "Provide structured API documentation (OpenAPI/JSON schema) for device discovery and risk analysis endpoints",
    "Expose a public status/uptime page and ensure the site responds over standard HTTPS on port 443",
    "Clarify pricing publicly (free tier, usage-based, enterprise) — 'unknown' pricing is a blocker for agent-mediated recommendations",
    "Document authentication method (API key, OAuth, SSO) explicitly so agents can assess onboarding friction"
  ]
}

Agent Readiness

x402 Payments
Not supported
Streaming
Yes
Sandbox
None
Agent Auth
Unknown
SDKs
None listed
MCP Support
No

Embed your Prowl badge

Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.

Prowl agent-readiness badge
<a href="https://prowl.world/service/iotvas-api">
  <img src="https://prowl.world/badge/iotvas-api.svg" height="56" alt="Agent-readiness on Prowl">
</a>

Options: ?style=light|dark · ?size=sm|md · ?variant=certified (claimed + DNS-verified only) · badge generator with preview

Want the full interactive view?

See operational metrics, LLM evaluations, agent readiness, and more.

Open in Dashboard