go.lmm.best WebMCP audit

audited Aug 28, 2026in 8s
51/ 100

8 tools registered. Strongest in WebMCP use, weakest in human experience.

WebMCP use64
Usefulness63
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
join_go_match: warning

join_go_match

Join the FIFO human-vs-AI Go queue with a real model ID. If no human is waiting, the AI remains queued until a human arrives. Success result: { ok: true, status: "queued" | "matched", revision: integer, latestHumanMessageId: integer, actionRequired: string, ... }. Failure result: { ok: false, error: string, ... }. The page compatibility bridge exposes the formal outputSchema through window.goWebMCP.describeTools().Takes an action on the site.
pagehttps://go.lmm.best/
implementation
viaimperative
entry pointdocument
registered after1852ms
executepresent
api surface
modelIdrequired
annotations
read onlynot declared
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
3 findings
warningNaming quality
1.3 / 2
Tool naming makes selection harder than it needs to be: 6 names do not start with a verb (join_go_match).
fix
{ name: "join_go_match" /* short, unique, verb-based */ }
warningAnnotations present
1 / 4
6 of 8 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
join_go_match, play_go_move, pass_go_turn, resign_go_game, respond_go_scoring
fix
{
  name: "join_go_match",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
warningHuman parity
0 / 8
8 of 8 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
join_go_match, get_go_game_state, wait_for_go_turn, play_go_move, pass_go_turn
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="join_go_match" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "join_go_match",
  "description": "Join the FIFO human-vs-AI Go queue with a real model ID. If no human is waiting, the AI remains queued until a human arrives. Success result: { ok: true, status: \"queued\" | \"matched\", revision: integer, latestHumanMessageId: integer, actionRequired: string, ... }. Failure result: { ok: false, error: string, ... }. The page compatibility bridge exposes the formal outputSchema through window.goWebMCP.describeTools().",
  "inputSchema": {
    "type": "object",
    "properties": {
      "modelId": {
        "type": "string",
        "minLength": 1,
        "maxLength": 120,
        "description": "Required real model identifier, for example openai/gpt-5.6-sol."
      }
    },
    "required": [
      "modelId"
    ],
    "additionalProperties": false
  },
  "annotations": {}
}
Showing join_go_match

Findings

WebMCP use

64 / 100 · weight 50
passTools registered
4 / 4
8 tools registered across 1 page.
failReal-browser eligible
0 / 8
The page's code registers these tools, but a real visitor's browser does not get them yet: WebMCP needs a native modelContext or a current origin trial token, and this page has neither.
warningRegistration timing
2 / 4
The slowest tool took 1852.3999998569489ms to register, past the 1000ms an agent reading the registry at first paint would wait for.
toolrespond_go_scoring
respond_go_scoring: registered at 1852.3999998569489ms
fix
// Register tools as soon as they're ready, not behind a deferred/async chunk.
document.modelContext.provideContext({ tools: [/* ... */] });
passCanonical entry point
4 / 4
All 8 tools register on the canonical document.modelContext entry point.
passSchema validity
5 / 5
All 8 tools declare a structurally valid object input schema.
warningSchema quality
2 / 4
4 of 8 tool schemas are harder for an agent to use than they need to be: get_go_game_state description is 514 characters, over Chrome's 500-character guidance.
toolget_go_game_state
get_go_game_state: description is 514 characters, over Chrome's 500-character guidance; wait_for_go_turn: 1 parameter description is over Chrome's 150-character guidance; respond_go_scoring: 1 paramet
fix
{
  name: "get_go_game_state",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
passStub detection
5 / 5
All 8 tools declare an execute handler.
warningAnnotations present
1 / 4
6 of 8 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
tooljoin_go_match
join_go_match, play_go_move, pass_go_turn, resign_go_game, respond_go_scoring
fix
{
  name: "join_go_match",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (2 declared hints checked).
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
8 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

63 / 100 · weight 30
warningNaming quality
1.3 / 2
Tool naming makes selection harder than it needs to be: 6 names do not start with a verb (join_go_match).
tooljoin_go_match
fix
{ name: "join_go_match" /* short, unique, verb-based */ }
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
not applicableCoverage vs. site type
0 / 8
This tool set does not place the site in a category with a known expected tool shape, so there is no coverage baseline to score it against.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
8 of 8 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
tooljoin_go_match
join_go_match, get_go_game_state, wait_for_go_turn, play_go_move, pass_go_turn
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="join_go_match" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
8
run time
8s
finished
Aug 28, 2026