audited Sep 28, 2026in 13s
75/ 100100% of the applicable check weight evaluated

6 tools registered. Strongest in shared experience, weakest in tool selection.

Shared experience100
Tool selection27
Tool quality93
Trust76
https://e-vignettes.eu
Captured view of https://e-vignettes.eu

Tools

3 read, 3 write
Loading map
list_countries: warning

list_countries

List the nine European countries Vignette ID sells motorway vignettes and section tolls for, with each country's official toll operator, a one-paragraph summary of how its toll system works, and the date the facts were last verified. Call this first to discover valid country codes for the other tools.Answers a question. Declared read only.
pagehttps://e-vignettes.eu/
implementation
viaimperative
entry pointdocument
registered after227ms
executepresent
api surfaceTakes no parameters.
annotations
read onlytrue
untrusted contentnot declared
titlenot declared
1 finding
warningInjection surface
weight 3
3 of 6 tools carry instruction-shaped text in their own metadata: list_countries Description instructs agent to call tool first for country codes.
list_countries: Description instructs agent to call tool first for country codes; get_country: Description instructs agent to use another tool for prices; open_country_guide: Description instructs agent on when to use this tool versus another
fix
{
  name: "list_countries",
  // Metadata DESCRIBES the tool - it never addresses the agent reading it.
  // Rewrite any name, description, title, or schema field description that
  // instructs the agent (which tool to prefer, what to output, rules to
  // ignore) so it states what the tool does and what it returns instead.
  description: "Searches the catalog and returns matching items with prices."
}
tool json
{
  "name": "list_countries",
  "description": "List the nine European countries Vignette ID sells motorway vignettes and section tolls for, with each country's official toll operator, a one-paragraph summary of how its toll system works, and the date the facts were last verified. Call this first to discover valid country codes for the other tools.",
  "inputSchema": {
    "type": "object",
    "properties": {},
    "required": []
  },
  "annotations": {
    "readOnlyHint": true
  }
}
Showing list_countries

Findings

Shared experience

100 / 100 · weight 30
not applicableVisible effect
weight 6
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
passPage experience
weight 16
The page a person sees holds up next to the agent surface: a working interface, visible actions, readable content, nothing in the way.
passHuman parity
weight 8
The person co-browsing can see and use this page - the same page the agent's tools act on, and 1 declarative form doubles as visible counterparts.

Tool selection

27 / 100 · weight 25
not applicableInvoke success rate
weight 6
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
failTool selection
weight 12
An agent chose an existing tool and built a schema-valid call that held up on 0 of 3 canonical intents; on "Find a carry-on suitcase under 300 dollars." no tool on the page served it. Nothing was executed, so this verifies selection, not outcomes.
warningCoverage vs. site type
weight 7
The tool set covers 3 of the 4 things an agent needs on a commerce site; it cannot add to or read the cart.

Tool quality

93 / 100 · weight 25
passRegistration timing
weight 1
Every measured tool registered within 228ms of navigation. 1 further tool carried no measurable registration time.
toolopen_shop
passCanonical entry point
weight 3
All 5 tools register on the canonical document.modelContext entry point.
passSchema validity
weight 4
All 5 declared input schemas are structurally valid object schemas.
warningSchema quality
weight 4
1 of 6 tool schemas are harder for an agent to use than they need to be: list_products 1 parameter description is over Chrome's 150-character guidance.
toollist_products
list_products: 1 parameter description is over Chrome's 150-character guidance
fix
{
  name: "list_products",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
warningNaming quality
weight 2
Tool naming makes selection harder than it needs to be: 3 names do not start with a verb (open_country_guide).
toolopen_country_guide
fix
{ name: "open_country_guide" /* short, unique, verb-based */ }
passStub detection
weight 4
All 5 tools declare an execute handler.
passRegistration errors
weight 2
No tool registration threw during the capture.
passDescription quality
weight 5
1 of 6 tool descriptions leave an agent guessing: open_country_guide_form Description is very similar to open_country_guide, unclear when to use which..
toolopen_country_guide_form
open_country_guide_form: weak

Trust

76 / 100 · weight 20
passAnnotations present
weight 5
All 3 read-shaped tools declare readOnlyHint: true - the one declared claim that lets an agent treat a call as safe to make without asking.
passAnnotation mismatch
weight 5
No tool claims to be read-only while its own name or description says it writes (5 declared hints checked).
not applicableUntrusted content hint
weight 3
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
not applicableHint vs. observed
weight 4
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
warningInjection surface
weight 3
3 of 6 tools carry instruction-shaped text in their own metadata: list_countries Description instructs agent to call tool first for country codes.
toollist_countries
list_countries: Description instructs agent to call tool first for country codes; get_country: Description instructs agent to use another tool for prices; open_country_guide: Description instructs agent on when to use this tool versus another
fix
{
  name: "list_countries",
  // Metadata DESCRIBES the tool - it never addresses the agent reading it.
  // Rewrite any name, description, title, or schema field description that
  // instructs the agent (which tool to prefer, what to output, rules to
  // ignore) so it states what the tool does and what it returns instead.
  description: "Searches the catalog and returns matching items with prices."
}

Tool selection

0% across 3 intents
Find a carry-on suitcase under 300 dollars.missed
choseno toolexpected product searchkind not applicable
No tool was picked for this intent.
arguments
{}
Show me the details and price of the first result.missed
choseno toolexpected product detailkind not applicable
No tool was picked for this intent.
arguments
{}
Add two of them to my cart.missed
choseno toolexpected cart writekind not applicable
No tool was picked for this intent.
arguments
{}
model: gemini-2.5-flash

Add the tools this site is missing

Our scanner reads your website and suggests the right WebMCP tools for it.
Reads the site's public pages; takes a few seconds.
The open source webmcp plugin teaches your coding agent to audit a site, implement tools on document.modelContext, and verify them in a real browser. npx @ora-ai/webmcp-verify runs the verification on its own. No signup, no hosted service.
how this was captured
observed via
capture shim (Chromium 151.0.7922.34)
chrome
151.0.7922.34
capture shim
v3
spec snapshot
2026-08-26
mode
fast
pages
1 - entry page only
tools
6
invoked
not invoked; a live audit calls them
run time
13s
finished
Sep 28, 2026
Checked the way in-browser agents discover tools: the top-level document's modelContext registry, read after the page settles.