fume.finance WebMCP audit

audited Aug 28, 2026in 6s
57/ 100

4 tools registered. Strongest in usefulness, weakest in human experience.

WebMCP use69
Usefulness73
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
search_tokenized_funds: fail

search_tokenized_funds

Search Fume's Tokenized Fund Registry — tokenized investment funds with their manager, strategy, asset class, AUM, chain, token standard, fees and jurisdiction. Returns JSON; every fund carries a `url` to its page on this site.Takes an action on the site.
pagehttps://www.fume.finance/
implementation
viaimperative
entry pointprovideContext
registered after752ms
executepresent
api surface
qoptional
chainoptional
assetClassoptional
jurisdictionoptional
statusoptional
limitoptional
annotations
read onlynot declared
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
2 findings
failAnnotations present
0 / 4
4 of 4 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
search_tokenized_funds, search_fund_service_providers, search_fume_docs, read_page_as_markdown
fix
{
  name: "search_tokenized_funds",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
search_tokenized_funds, search_fund_service_providers, search_fume_docs, read_page_as_markdown
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="search_tokenized_funds" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "search_tokenized_funds",
  "description": "Search Fume's Tokenized Fund Registry — tokenized investment funds with their manager, strategy, asset class, AUM, chain, token standard, fees and jurisdiction. Returns JSON; every fund carries a `url` to its page on this site.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "q": {
        "type": "string",
        "description": "Free-text search over name, manager, issuer, strategy and description."
      },
      "chain": {
        "type": "string",
        "description": "Blockchain to filter by, e.g. Ethereum, Arbitrum, Base."
      },
      "assetClass": {
        "type": "string",
        "description": "Asset class to filter by, e.g. Fixed Income, Private Credit."
      },
      "jurisdiction": {
        "type": "string",
        "description": "Jurisdiction to filter by, e.g. Luxembourg, Cayman Islands."
      },
      "status": {
        "type": "string",
        "description": "Fund status: live, upcoming or closed."
      },
      "limit": {
        "type": "integer",
        "description": "Maximum funds to return (1-200). Defaults to 50.",
        "minimum": 1,
        "maximum": 200
      }
    },
    "required": []
  },
  "annotations": {}
}
Showing search_tokenized_funds

Findings

WebMCP use

69 / 100 · weight 50
passTools registered
4 / 4
4 tools registered across 1 page.
failReal-browser eligible
0 / 8
The page's code registers these tools, but a real visitor's browser does not get them yet: WebMCP needs a native modelContext or a current origin trial token, and this page has neither.
passRegistration timing
4 / 4
Every measured tool registered within 752.1999998092651ms of navigation.
toolsearch_fume_docs
passCanonical entry point
4 / 4
All 4 tools register on the canonical document.modelContext entry point.
passSchema validity
5 / 5
All 4 tools declare a structurally valid object input schema.
passSchema quality
4 / 4
All 4 tool schemas describe their parameters and stay within Chrome's size guidance.
passStub detection
5 / 5
All 4 tools declare an execute handler.
failAnnotations present
0 / 4
4 of 4 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
toolsearch_tokenized_funds
search_tokenized_funds, search_fund_service_providers, search_fume_docs, read_page_as_markdown
fix
{
  name: "search_tokenized_funds",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
not applicableAnnotation mismatch
0 / 3
No tool declares a readOnlyHint, so there is no safety claim to contradict.
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
4 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

73 / 100 · weight 30
passNaming quality
2 / 2
All 4 tool names are consistent, verb-led, and within Chrome's size guidance.
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
warningCoverage vs. site type
5.3 / 8
The tool set covers 2 of the 3 things an agent needs on a docs site; it cannot navigate the documentation tree.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolsearch_tokenized_funds
search_tokenized_funds, search_fund_service_providers, search_fume_docs, read_page_as_markdown
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="search_tokenized_funds" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
4
run time
6s
finished
Aug 28, 2026