audited Sep 29, 2026in 13s
57/ 100100% of the applicable check weight evaluated

4 tools registered. Strongest in shared experience, weakest in trust.

Shared experience100
Tool selection39
Tool quality72
Trust0
https://boldreports.com
Captured view of https://boldreports.com

Tools

0 read, 0 write, 4 undeclared
Loading map
request-demo: fail

request-demo

Request a live demo of Bold ReportsNo behaviour hints declared. Agents should treat it as possibly state-changing.
pagehttps://www.boldreports.com/
implementation
viaimperative
entry pointprovideContext
registered after834ms
executepresent
api surface
namerequired
emailrequired
companyoptional
annotations
read onlynot declared
untrusted contentnot declared
titlenot declared
3 findings
failCanonical entry point
weight 3
Every tool uses the removed provideContext API; register each tool with document.modelContext.registerTool().
fix
// document.modelContext is the canonical entry point - the navigator.modelContext alias is deprecated.
document.modelContext.registerTool({ /* ... */ });
warningNaming quality
weight 2
Tool naming makes selection harder than it needs to be: 2 names do not start with a verb (request-demo).
fix
{ name: "request-demo" /* short, unique, verb-based */ }
warningDescription quality
weight 5
4 of 4 tool descriptions leave an agent guessing: request-demo Omits what comes back, or what changes when it runs..
request-demo: weak; start-free-trial: weak; search-site: weak; contact-sales: weak
fix
{
  name: "request-demo",
  description: "Describe what this tool does, when to use it, and what it returns."
}
tool json
{
  "name": "request-demo",
  "description": "Request a live demo of Bold Reports",
  "inputSchema": {
    "type": "object",
    "properties": {
      "name": {
        "type": "string",
        "description": "Full name"
      },
      "email": {
        "type": "string",
        "description": "Work email address"
      },
      "company": {
        "type": "string",
        "description": "Company name"
      }
    },
    "required": [
      "name",
      "email"
    ]
  },
  "annotations": {}
}
Showing request-demo

Findings

Shared experience

100 / 100 · weight 30
not applicableVisible effect
weight 6
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
passPage experience
weight 16
The page a person sees holds up next to the agent surface: a working interface, visible actions, readable content, nothing in the way.
passHuman parity
weight 8
The person co-browsing can see and use this page - the same page the agent's tools act on.

Tool selection

39 / 100 · weight 25
not applicableInvoke success rate
weight 6
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
failTool selection
weight 12
An agent chose an existing tool and built a schema-valid call that held up on 1 of 3 canonical intents; on "Show me everything on that record." the tool it chose does not look like the kind of tool the intent needs. Nothing was executed, so this verifies selection, not outcomes.
toolsearch-site
warningCoverage vs. site type
weight 7
The tool set covers 2 of the 4 things an agent needs on a saas site; it cannot read one item in detail or update or move an existing record.

Tool quality

72 / 100 · weight 25
passRegistration timing
weight 1
Every measured tool registered within 834ms of navigation.
toolstart-free-trial
failCanonical entry point
weight 3
Every tool uses the removed provideContext API; register each tool with document.modelContext.registerTool().
toolrequest-demo
fix
// document.modelContext is the canonical entry point - the navigator.modelContext alias is deprecated.
document.modelContext.registerTool({ /* ... */ });
passSchema validity
weight 4
All 4 declared input schemas are structurally valid object schemas.
warningSchema quality
weight 4
1 of 4 tool schemas are harder for an agent to use than they need to be: contact-sales 2 parameters have no description (name, email).
toolcontact-sales
contact-sales: 2 parameters have no description (name, email)
fix
{
  name: "contact-sales",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
warningNaming quality
weight 2
Tool naming makes selection harder than it needs to be: 2 names do not start with a verb (request-demo).
toolrequest-demo
fix
{ name: "request-demo" /* short, unique, verb-based */ }
passStub detection
weight 4
All 4 tools declare an execute handler.
passRegistration errors
weight 2
No tool registration threw during the capture.
warningDescription quality
weight 5
4 of 4 tool descriptions leave an agent guessing: request-demo Omits what comes back, or what changes when it runs..
toolrequest-demo
request-demo: weak; start-free-trial: weak; search-site: weak; contact-sales: weak
fix
{
  name: "request-demo",
  description: "Describe what this tool does, when to use it, and what it returns."
}

Trust

0 / 100 · weight 20
failAnnotations present
weight 5
1 of 1 read-shaped tools do not declare readOnlyHint: true, so an agent has to treat them as possible writes and ask before calling. (Declaring readOnlyHint: false earns nothing - it is the default.)
toolsearch-site
search-site
fix
{
  name: "search-site",
  // Declare readOnlyHint: true on tools that truly have no side effects -
  // that is the claim that lets an agent relax confirmation on reads.
  // (false is the default, so declaring it adds no information.)
  annotations: { readOnlyHint: true }
}
not applicableAnnotation mismatch
weight 5
No tool declares a readOnlyHint, so there is no safety claim to contradict.
not applicableUntrusted content hint
weight 3
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
not applicableHint vs. observed
weight 4
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
not applicableInjection surface
weight 3
No tool's metadata carries instruction-shaped text aimed at the agent reading it. This check only ever flags; it never credits a site.

Tool selection

33% across 3 intents
Find the record for a company called Northwind.ok
chosesearch-siteexpected record searchkind matched
arguments
{
  "query": "Northwind company record"
}
Show me everything on that record.missed
chosesearch-siteexpected record detailkind mismatch
The tool the model chose does not look like the kind of tool this intent needs.
arguments
{
  "query": "Northwind company record details"
}
Create a new contact called Dana Reeve.missed
choseno toolexpected record createkind not applicable
No tool was picked for this intent.
arguments
{}
model: gemini-2.5-flash

Add the tools this site is missing

Our scanner reads your website and suggests the right WebMCP tools for it.
Reads the site's public pages; takes a few seconds.
The open source webmcp plugin teaches your coding agent to audit a site, implement tools on document.modelContext, and verify them in a real browser. npx @ora-ai/webmcp-verify runs the verification on its own. No signup, no hosted service.
how this was captured
observed via
capture shim (Chromium 151.0.7922.34)
chrome
151.0.7922.34
capture shim
v3
spec snapshot
2026-08-26
mode
fast
pages
1 - entry page only
tools
4
invoked
not invoked; a live audit calls them
run time
13s
finished
Sep 29, 2026
Checked the way in-browser agents discover tools: the top-level document's modelContext registry, read after the page settles.