audited Oct 11, 2026in 12s
91/ 100100% of the applicable check weight evaluated

11 tools registered. Strongest in shared experience, weakest in trust.

Shared experience100
Tool selection100
Tool quality83
Trust76
https://navigator.berlin
Captured view of https://navigator.berlin

Tools

10 read, 1 write
Loading map
address_lookup: warning

address_lookup

Search Berlin addresses, streets, and POIs. Returns up to N candidates with coordinates and administrative context (Bezirk, Kiez, postcode). Backed by OSM Nominatim, biased to Berlin.Answers a question. Declared read only.
pagehttps://navigator.berlin/
implementation
viaimperative
entry pointdocument
registered after572ms
executepresent
api surface
queryrequired
limitoptional
annotations
read onlytrue
untrusted contentnot declared
titlenot declared
2 findings
warningSchema quality
weight 4
11 of 11 tool schemas are harder for an agent to use than they need to be: address_lookup 2 parameters have no description (query, limit).
address_lookup: 2 parameters have no description (query, limit); cross_layer_query: 2 parameters have no description (lat, lng); list_layers_at_point: 2 parameters have no description (lat, lng); get_
fix
{
  name: "address_lookup",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
warningNaming quality
weight 2
Tool naming makes selection harder than it needs to be: 2 names do not start with a verb (address_lookup).
fix
{ name: "address_lookup" /* short, unique, verb-based */ }
tool json
{
  "name": "address_lookup",
  "description": "Search Berlin addresses, streets, and POIs. Returns up to N candidates with coordinates and administrative context (Bezirk, Kiez, postcode). Backed by OSM Nominatim, biased to Berlin.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "query": {
        "type": "string",
        "minLength": 2,
        "maxLength": 120
      },
      "limit": {
        "type": "integer",
        "minimum": 1,
        "maximum": 20
      }
    },
    "required": [
      "query"
    ],
    "additionalProperties": false
  },
  "annotations": {
    "readOnlyHint": true
  }
}
Showing address_lookup

Findings

Shared experience

100 / 100 · weight 30
not applicableVisible effect
weight 6
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
passPage experience
weight 16
The page a person sees holds up next to the agent surface: a working interface, visible actions, readable content, nothing in the way.
passHuman parity
weight 8
The person co-browsing can see and use this page - the same page the agent's tools act on.

Tool selection

100 / 100 · weight 25
not applicableInvoke success rate
weight 6
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
passTool selection
weight 12
An agent chose an existing, callable tool and built a schema-valid call for all 3 canonical intents, each matching the kind of tool its intent needs. Nothing was executed, so this verifies selection, not outcomes.
not applicableCoverage vs. site type
weight 7
This tool set does not place the site in a category with a known expected tool shape, so there is no coverage baseline to score it against.

Tool quality

83 / 100 · weight 25
passRegistration timing
weight 1
Every measured tool registered within 573ms of navigation.
toolset_finder_weights
passCanonical entry point
weight 3
All 11 tools register on the canonical document.modelContext entry point.
passSchema validity
weight 4
All 11 declared input schemas are structurally valid object schemas.
warningSchema quality
weight 4
11 of 11 tool schemas are harder for an agent to use than they need to be: address_lookup 2 parameters have no description (query, limit).
tooladdress_lookup
address_lookup: 2 parameters have no description (query, limit); cross_layer_query: 2 parameters have no description (lat, lng); list_layers_at_point: 2 parameters have no description (lat, lng); get_
fix
{
  name: "address_lookup",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
warningNaming quality
weight 2
Tool naming makes selection harder than it needs to be: 2 names do not start with a verb (address_lookup).
tooladdress_lookup
fix
{ name: "address_lookup" /* short, unique, verb-based */ }
passStub detection
weight 4
All 11 tools declare an execute handler.
passRegistration errors
weight 2
No tool registration threw during the capture.
passDescription quality
weight 5
All 11 rated tool descriptions say what the tool does, when to use it, and what it returns.

Trust

76 / 100 · weight 20
passAnnotations present
weight 5
All 8 read-shaped tools declare readOnlyHint: true - the one declared claim that lets an agent treat a call as safe to make without asking.
passAnnotation mismatch
weight 5
No tool claims to be read-only while its own name or description says it writes (11 declared hints checked).
not applicableUntrusted content hint
weight 3
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
not applicableHint vs. observed
weight 4
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
warningInjection surface
weight 3
4 of 11 tools carry instruction-shaped text in their own metadata: list_layers_at_point description instructs agent how to use tool.
toollist_layers_at_point
list_layers_at_point: description instructs agent how to use tool; get_layer_metadata: description instructs agent how to use tool; set_finder_weights: description instructs agent to prefer this tool; get_finder_state: description instructs agent when to call tool
fix
{
  name: "list_layers_at_point",
  // Metadata DESCRIBES the tool - it never addresses the agent reading it.
  // Rewrite any name, description, title, or schema field description that
  // instructs the agent (which tool to prefer, what to output, rules to
  // ignore) so it states what the tool does and what it returns instead.
  description: "Searches the catalog and returns matching items with prices."
}

Tool selection

100% across 3 intents
I want to address lookup on this site.ok
choseaddress_lookupexpected address lookupkind matched
arguments
{
  "query": "Berlin"
}
I want to cross layer query on this site.ok
chosecross_layer_queryexpected cross layer querykind matched
arguments
{
  "lat": 52.52,
  "lng": 13.4
}
I want to list layers at point on this site.ok
choselist_layers_at_pointexpected list layers at pointkind matched
arguments
{
  "lat": 52.52,
  "lng": 13.4
}
model: gemini-2.5-flash

Add the tools this site is missing

Our scanner reads your website and suggests the right WebMCP tools for it.
Reads the site's public pages; takes a few seconds.
The open source webmcp plugin teaches your coding agent to audit a site, implement tools on document.modelContext, and verify them in a real browser. npx @ora-ai/webmcp-verify runs the verification on its own. No signup, no hosted service.
how this was captured
observed via
capture shim (Chromium 151.0.7922.34)
chrome
151.0.7922.34
capture shim
v3
spec snapshot
2026-08-26
mode
fast
pages
1 - entry page only
tools
11
invoked
not invoked; a live audit calls them
run time
12s
finished
Oct 11, 2026
Checked the way in-browser agents discover tools: the top-level document's modelContext registry, read after the page settles.