hiro.is WebMCP audit

audited Aug 28, 2026in 5s
43/ 100

2 tools registered. Strongest in WebMCP use, weakest in human experience.

WebMCP use62
Usefulness40
Human experience0
about:blank

No agent run recorded yet.

No steps recorded
capture followed a redirecthiro.is redirected to hirosecure.com. Everything below was served there.

Tools

/
get_hiro_overview: fail

get_hiro_overview

Return a short overview of Hiro: what it does, which security pillars it covers, and how to contact the team.Answers a question. Declared read only.
pagehttps://hirosecure.com/
implementation
viaimperative
entry pointnavigator
registered after360ms
executepresent
api surfaceTakes no parameters.
annotations
read onlytrue
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
2 findings
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
warningHuman parity
0 / 8
2 of 2 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
get_hiro_overview, book_hiro_demo
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="get_hiro_overview" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "get_hiro_overview",
  "description": "Return a short overview of Hiro: what it does, which security pillars it covers, and how to contact the team.",
  "inputSchema": {
    "type": "object",
    "properties": {},
    "additionalProperties": false
  },
  "annotations": {
    "readOnlyHint": true
  }
}
Showing get_hiro_overview

Findings

WebMCP use

62 / 100 · weight 50
warningTools registered
2 / 4
https://hiro.is/ redirected off its own domain to https://hirosecure.com/, so what follows describes the page that answered, not necessarily the site that was audited. 2 tools registered across 1 page.
https://hiro.is/ -> https://hirosecure.com/
fix
document.modelContext.provideContext({
  tools: [{ name: "your_tool_name", description: "...", inputSchema: { type: "object", properties: {} }, execute: async (args) => { /* ... */ } }],
});
failReal-browser eligible
0 / 8
https://hiro.is/ redirected off its own domain to https://hirosecure.com/, so what follows describes the page that answered, not necessarily the site that was audited. The page's code registers these tools, but a real visitor's browser does not get them yet: WebMCP needs a native modelContext or a current origin trial token, and this page has neither.
passRegistration timing
4 / 4
Every measured tool registered within 360ms of navigation.
toolbook_hiro_demo
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
toolget_hiro_overview
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
passSchema validity
5 / 5
All 2 tools declare a structurally valid object input schema.
passSchema quality
4 / 4
All 2 tool schemas describe their parameters and stay within Chrome's size guidance.
passStub detection
5 / 5
All 2 tools declare an execute handler.
warningAnnotations present
2 / 4
1 of 2 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
toolbook_hiro_demo
book_hiro_demo
fix
{
  name: "book_hiro_demo",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (1 declared hint checked).
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
2 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

40 / 100 · weight 30
passNaming quality
2 / 2
All 2 tool names are consistent, verb-led, and within Chrome's size guidance.
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
failCoverage vs. site type
2 / 8
The tool set covers 1 of the 4 things an agent needs on a saas site; it cannot search or browse the catalog or create a record or start a job or update or move an existing record.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
2 of 2 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolget_hiro_overview
get_hiro_overview, book_hiro_demo
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="get_hiro_overview" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
2
run time
5s
finished
Aug 28, 2026