forter.com WebMCP audit

audited Aug 28, 2026in 4s
72/ 100

6 tools registered. Strongest in usefulness, weakest in human experience.

WebMCP use79
Usefulness97
Human experience17
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
list_skills: warning

list_skills

List Forter's agent-skill catalog. Returns the v0.2.0 skill index covering order decisioning, account protection, dispute resolution, agentic commerce, PSP onboarding, tokenization, privacy requests, and contact-sales. Use to find which Forter capability fits a given user need.Answers a question. Declared read only.
pagehttps://www.forter.com/
implementation
viaimperative
entry pointprovideContext
registered after207ms
executepresent
api surfaceTakes no parameters.
annotations
read onlytrue
destructivefalse
idempotentnot declared
open worldtrue
untrusted contentnot declared
titlenot declared
1 finding
warningHuman parity
1.3 / 8
5 of 6 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
list_skills, get_openapi_spec, get_pricing_info, search_documentation, contact_sales
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="list_skills" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "list_skills",
  "description": "List Forter's agent-skill catalog. Returns the v0.2.0 skill index covering order decisioning, account protection, dispute resolution, agentic commerce, PSP onboarding, tokenization, privacy requests, and contact-sales. Use to find which Forter capability fits a given user need.",
  "inputSchema": {
    "type": "object",
    "properties": {},
    "additionalProperties": false
  },
  "annotations": {
    "readOnlyHint": true,
    "destructiveHint": false,
    "openWorldHint": true
  }
}
Showing list_skills

Findings

WebMCP use

79 / 100 · weight 50
passTools registered
4 / 4
5 imperative tools and 1 declarative form registered across 1 page.
failReal-browser eligible
0 / 8
The page's code registers these tools, but a real visitor's browser does not get them yet: WebMCP needs a native modelContext or a current origin trial token, and this page has neither. The 1 declarative form tool on the page stay usable regardless.
passRegistration timing
4 / 4
Every measured tool registered within 207.09999990463257ms of navigation. 1 further tool carried no measurable registration time.
toolget_openapi_spec
passCanonical entry point
4 / 4
All 5 tools register on the canonical document.modelContext entry point.
passSchema validity
5 / 5
All 5 tools declare a structurally valid object input schema.
warningSchema quality
3.3 / 4
1 of 6 tool schemas are harder for an agent to use than they need to be: get_openapi_spec declares no required list, so an agent cannot tell which parameters are mandatory.
toolget_openapi_spec
get_openapi_spec: declares no required list, so an agent cannot tell which parameters are mandatory
fix
{
  name: "get_openapi_spec",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
passStub detection
5 / 5
All 5 tools declare an execute handler.
passAnnotations present
4 / 4
All 5 tools declare a readOnlyHint, so an agent knows which calls change state.
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (5 declared hints checked).
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
5 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

97 / 100 · weight 30
warningNaming quality
1.7 / 2
Tool naming makes selection harder than it needs to be: 2 names do not start with a verb (contact_sales).
toolcontact_sales
fix
{ name: "contact_sales" /* short, unique, verb-based */ }
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
passCoverage vs. site type
8 / 8
The tool set covers the whole core docs flow: search or browse the catalog, read a page or article, navigate the documentation tree.

Human experience

17 / 100 · weight 20
warningHuman parity
1.3 / 8
5 of 6 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toollist_skills
list_skills, get_openapi_spec, get_pricing_info, search_documentation, contact_sales
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="list_skills" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
6
run time
4s
finished
Aug 28, 2026