PatchClockBot runs the free CRA readiness check. It identifies itself with the user agent PatchClockBot/0.1 (+https://patchclock.com/bot).
For each check it makes a handful of requests to public pages: /.well-known/security.txt, /security.txt and a few pages that usually describe support policies. When a public GitHub repository is given, it reads SECURITY.md, README.md and lock files from that repository.
It does not log in, submit forms, crawl your site or test for vulnerabilities. Results for the same site are reused for an hour.
If you would like it to stop visiting your site, email hello@patchclock.com.