A page that must not be indexed and does not say so =================================================== Rule · bucket: mechanical · severity: error · detector: metadata · since: v0.14.0 Section: Things to avoid Group: Search and sharing Forbidden: An admin screen, a sign-in page, an internal tool with no robots directive, kept out of search by nothing but obscurity Instead: `noindex` on the page itself, from its own metadata. In `product` and `operator` this is the default and its absence is the defect. `robots.txt` is not this. It is public, advisory, and read by strangers as a list of interesting places: naming `/admin` there tells everyone where it is. A path is safe to name only when something else protects it — a session guard, an authenticating API — and never because the file asked politely.