hunchbank.com WebMCP audit

audited Aug 28, 2026in 8s
50/ 100

39 tools registered. Strongest in usefulness, weakest in human experience.

WebMCP use62
Usefulness63
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
search_1: fail

search_1

Search for content on this website. Search Acme StoreTakes an action on the site.
pagehttps://hunchbank.com/
implementation
viaimperative
entry pointnavigator
registered after913ms
executepresent
api surface
queryrequired
annotations
read onlyfalse
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
2 findings
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
warningHuman parity
0 / 8
39 of 39 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
search_1, get_products, search_and_list, extract_page_listings, navigate_flight_search
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="search_1" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "search_1",
  "description": "Search for content on this website. Search Acme Store",
  "inputSchema": {
    "type": "object",
    "properties": {
      "query": {
        "type": "string",
        "description": "Search query or keywords"
      }
    },
    "required": [
      "query"
    ]
  },
  "annotations": {
    "readOnlyHint": false
  }
}
Showing search_1

Findings

WebMCP use

62 / 100 · weight 50
passTools registered
4 / 4
39 tools registered across 1 page.
failReal-browser eligible
0 / 8
The page's code registers these tools, but a real visitor's browser does not get them yet: WebMCP needs a native modelContext or a current origin trial token, and this page has neither.
warningRegistration timing
2 / 4
The slowest tool took 2021.8999998569489ms to register, past the 1000ms an agent reading the registry at first paint would wait for.
tooldownload
download: registered at 2021.8999998569489ms
fix
// Register tools as soon as they're ready, not behind a deferred/async chunk.
document.modelContext.provideContext({ tools: [/* ... */] });
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
toolsearch_1
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
passSchema validity
5 / 5
All 39 tools declare a structurally valid object input schema.
passSchema quality
4 / 4
All 39 tool schemas describe their parameters and stay within Chrome's size guidance.
passStub detection
5 / 5
All 39 tools declare an execute handler.
passAnnotations present
4 / 4
All 39 tools declare a readOnlyHint, so an agent knows which calls change state.
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (39 declared hints checked).
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
failRegistration errors
0 / 2
38 tool registrations threw during the capture, so the registry an agent reads is incomplete.
duplicate tool name registered: search_1
fix
try {
  document.modelContext.provideContext({ tools: [/* ... */] });
} catch (err) {
  console.error("WebMCP registration failed", err);
}
warningToolchange coherence
1 / 2
39 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

63 / 100 · weight 30
warningNaming quality
1.3 / 2
Tool naming makes selection harder than it needs to be: 3 names are over Chrome's 30-character guidance; 29 names do not start with a verb (extract_page_listings).
toolsignup_sign_me_up_for_a_free_trial
fix
{ name: "signup_sign_me_up_for_a_free_trial" /* short, unique, verb-based */ }
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
not applicableCoverage vs. site type
0 / 8
This tool set does not place the site in a category with a known expected tool shape, so there is no coverage baseline to score it against.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
39 of 39 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolsearch_1
search_1, get_products, search_and_list, extract_page_listings, navigate_flight_search
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="search_1" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
39
run time
8s
finished
Aug 28, 2026