hayalows.com WebMCP audit

audited Aug 28, 2026in 3s
49/ 100

4 tools registered. Strongest in WebMCP use, weakest in human experience.

WebMCP use78
Usefulness33
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
ask_hayalows: warning

ask_hayalows

Find authoritative Hayalows information when a visitor asks about services, business fit, approach, enquiries, payments, refunds, privacy or terms. Read-only. Returns a stable JSON object with schemaVersion, schemaUrl, query, matches (each with id, title, text, tags and url), note, and contact (an object or null). The machine-readable AskHayalowsResult contract is published at https://hayalows.com/webmcp/results.schema.json.Answers a question. Declared read only.
pagehttps://hayalows.com/
implementation
viaimperative
entry pointdocument
registered after232ms
executepresent
api surface
queryrequired
annotations
read onlytrue
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
2 findings
warningNaming quality
1.3 / 2
Tool naming makes selection harder than it needs to be: 3 names do not start with a verb (ask_hayalows).
fix
{ name: "ask_hayalows" /* short, unique, verb-based */ }
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
ask_hayalows, browse_hayalows_services, prepare_hayalows_enquiry, navigate_hayalows
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="ask_hayalows" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "ask_hayalows",
  "description": "Find authoritative Hayalows information when a visitor asks about services, business fit, approach, enquiries, payments, refunds, privacy or terms. Read-only. Returns a stable JSON object with schemaVersion, schemaUrl, query, matches (each with id, title, text, tags and url), note, and contact (an object or null). The machine-readable AskHayalowsResult contract is published at https://hayalows.com/webmcp/results.schema.json.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "query": {
        "type": "string",
        "minLength": 2,
        "maxLength": 300,
        "description": "The visitor's question or the Hayalows topic to find."
      }
    },
    "required": [
      "query"
    ],
    "additionalProperties": false
  },
  "annotations": {
    "readOnlyHint": true
  }
}
Showing ask_hayalows

Findings

WebMCP use

78 / 100 · weight 50
passTools registered
4 / 4
4 tools registered across 1 page.
failReal-browser eligible
0 / 8
The page's code registers these tools, but a real visitor's browser does not get them yet: WebMCP needs a native modelContext or a current origin trial token, and this page has neither.
passRegistration timing
4 / 4
Every measured tool registered within 231.69999980926514ms of navigation.
toolbrowse_hayalows_services
passCanonical entry point
4 / 4
All 4 tools register on the canonical document.modelContext entry point.
passSchema validity
5 / 5
All 4 tools declare a structurally valid object input schema.
warningSchema quality
3 / 4
1 of 4 tool schemas are harder for an agent to use than they need to be: prepare_hayalows_enquiry description is 533 characters, over Chrome's 500-character guidance.
toolprepare_hayalows_enquiry
prepare_hayalows_enquiry: description is 533 characters, over Chrome's 500-character guidance
fix
{
  name: "prepare_hayalows_enquiry",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
passStub detection
5 / 5
All 4 tools declare an execute handler.
passAnnotations present
4 / 4
All 4 tools declare a readOnlyHint, so an agent knows which calls change state.
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (4 declared hints checked).
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
4 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

33 / 100 · weight 30
warningNaming quality
1.3 / 2
Tool naming makes selection harder than it needs to be: 3 names do not start with a verb (ask_hayalows).
toolask_hayalows
fix
{ name: "ask_hayalows" /* short, unique, verb-based */ }
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
failCoverage vs. site type
2 / 8
The tool set covers 1 of the 4 things an agent needs on a saas site; it cannot read one item in detail or create a record or start a job or update or move an existing record.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolask_hayalows
ask_hayalows, browse_hayalows_services, prepare_hayalows_enquiry, navigate_hayalows
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="ask_hayalows" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
4
run time
3s
finished
Aug 28, 2026