audited Aug 28, 2026in 4s
55/ 100

4 tools registered. Strongest in usefulness, weakest in human experience.

WebMCP use66
Usefulness75
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
check_mail_security: fail

check_mail_security

Run a live SPF, DMARC, DKIM, MX, TXT, DNS, and registrar posture check for a public domain. Returns a compact summary with SPF/DMARC/DKIM records, DKIM selector, MX hosts, external DMARC destinations, score/grade, and report URL. Invocation: browser WebMCP only — open this site, discover tools via the page runtime, then execute here. There is no public HTTP execute_url; do not reverse-engineer the app bundle for a REST path. Agent-friendly: no interactive CAPTCHA.Takes an action on the site.
pagehttps://dmarc.networkthinking.com/
implementation
viaimperative
entry pointdocument
registered after317ms
executepresent
api surface
domainrequired
annotations
read onlynot declared
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
2 findings
failAnnotations present
0 / 4
4 of 4 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
check_mail_security, export_mail_security_report, open_get_started, open_sign_in
fix
{
  name: "check_mail_security",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
check_mail_security, export_mail_security_report, open_get_started, open_sign_in
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="check_mail_security" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "check_mail_security",
  "description": "Run a live SPF, DMARC, DKIM, MX, TXT, DNS, and registrar posture check for a public domain. Returns a compact summary with SPF/DMARC/DKIM records, DKIM selector, MX hosts, external DMARC destinations, score/grade, and report URL. Invocation: browser WebMCP only — open this site, discover tools via the page runtime, then execute here. There is no public HTTP execute_url; do not reverse-engineer the app bundle for a REST path. Agent-friendly: no interactive CAPTCHA.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "domain": {
        "type": "string",
        "description": "Domain to analyze, e.g. example.com"
      }
    },
    "required": [
      "domain"
    ],
    "additionalProperties": false
  },
  "annotations": {}
}
Showing check_mail_security

Findings

WebMCP use

66 / 100 · weight 50
passTools registered
4 / 4
4 tools registered across 1 page.
failReal-browser eligible
0 / 8
The page's code registers these tools, but a real visitor's browser does not get them yet: WebMCP needs a native modelContext or a current origin trial token, and this page has neither.
passRegistration timing
4 / 4
Every measured tool registered within 317.60000014305115ms of navigation.
toolopen_get_started
passCanonical entry point
4 / 4
All 4 tools register on the canonical document.modelContext entry point.
passSchema validity
5 / 5
All 4 tools declare a structurally valid object input schema.
passSchema quality
4 / 4
All 4 tool schemas describe their parameters and stay within Chrome's size guidance.
passStub detection
5 / 5
All 4 tools declare an execute handler.
failAnnotations present
0 / 4
4 of 4 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
toolcheck_mail_security
check_mail_security, export_mail_security_report, open_get_started, open_sign_in
fix
{
  name: "check_mail_security",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
not applicableAnnotation mismatch
0 / 3
No tool declares a readOnlyHint, so there is no safety claim to contradict.
warningUntrusted content hint
0 / 2
3 of 3 tools look like they return text written by other people but declare no untrustedContentHint, so an agent will treat the response as the site speaking.
toolexport_mail_security_report
export_mail_security_report: email, mail; open_get_started: user, email; open_sign_in: user, email
fix
{ name: "export_mail_security_report", annotations: { untrustedContentHint: true } }
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
4 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

75 / 100 · weight 30
warningNaming quality
1.5 / 2
Tool naming makes selection harder than it needs to be: 2 names do not start with a verb (open_get_started).
toolopen_get_started
fix
{ name: "open_get_started" /* short, unique, verb-based */ }
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
not applicableCoverage vs. site type
0 / 8
This tool set does not place the site in a category with a known expected tool shape, so there is no coverage baseline to score it against.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolcheck_mail_security
check_mail_security, export_mail_security_report, open_get_started, open_sign_in
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="check_mail_security" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
4
run time
4s
finished
Aug 28, 2026