> the remote server could deny requests from such automated user
> agents, only allowing clients that look like browsers

Here is what I have been able to observe:

If wait for some time, then try to access http://www.malacards.org/
using cURL, I start getting 403 errors in both cURL and browser.

If wait for some time, then go to http://www.malacards.org/ using a
browser and click on a few links, subsequent access using cURL from
the same IP address also starts working (for a while).

Given the paranoid nature of the website's security system, it's hard
to offer a good solution to your problem: linking to it may place
people running R CMD check into temporary ban, while not linking to it
does not seem polite.

