nekuda.ai WebMCP audit

audited Aug 28, 2026in 6s
55/ 100

4 tools registered. Strongest in WebMCP use, weakest in human experience.

WebMCP use89
Usefulness35
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
ask_site: warning

ask_site

Answer questions about nekuda from the site's own content. Use when the visitor asks what nekuda does, how WebMCP or the webmcp-kit plugin works, what the privacy policy says, or anything covered by the nekuda blog on agentic commerce. Returns the most relevant content sections with their source page paths so you can compose an answer and cite the page; if nothing matches, returns an empty result with an explicit note saying the site has no matching content.Answers a question. Declared read only.
pagehttps://nekuda.ai/
implementation
viaimperative
entry pointdocument
registered after434ms
executepresent
api surface
questionrequired
annotations
read onlytrue
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
2 findings
warningNaming quality
1.5 / 2
Tool naming makes selection harder than it needs to be: 2 names do not start with a verb (ask_site).
fix
{ name: "ask_site" /* short, unique, verb-based */ }
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
ask_site, get_offering, get_latest_posts, request_demo
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="ask_site" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "ask_site",
  "description": "Answer questions about nekuda from the site's own content. Use when the visitor asks what nekuda does, how WebMCP or the webmcp-kit plugin works, what the privacy policy says, or anything covered by the nekuda blog on agentic commerce. Returns the most relevant content sections with their source page paths so you can compose an answer and cite the page; if nothing matches, returns an empty result with an explicit note saying the site has no matching content.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "question": {
        "type": "string",
        "description": "The visitor's question, used for keyword matching against site content"
      }
    },
    "required": [
      "question"
    ],
    "additionalProperties": false
  },
  "annotations": {
    "readOnlyHint": true
  }
}
Showing ask_site

Findings

WebMCP use

89 / 100 · weight 50
passTools registered
4 / 4
4 tools registered across 1 page.
passReal-browser eligible
8 / 8
A real browser exposes modelContext natively on this page, so the tools registered here are visible to an agent today.
passRegistration timing
4 / 4
Every measured tool registered within 434.39999985694885ms of navigation.
toolget_offering
passCanonical entry point
4 / 4
All 4 tools register on the canonical document.modelContext entry point.
passSchema validity
5 / 5
All 4 tools declare a structurally valid object input schema.
warningSchema quality
2 / 4
2 of 4 tool schemas are harder for an agent to use than they need to be: get_latest_posts declares no required list, so an agent cannot tell which parameters are mandatory.
toolget_latest_posts
get_latest_posts: declares no required list, so an agent cannot tell which parameters are mandatory; request_demo: description is 557 characters, over Chrome's 500-character guidance
fix
{
  name: "get_latest_posts",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
passStub detection
5 / 5
All 4 tools declare an execute handler.
passAnnotations present
4 / 4
All 4 tools declare a readOnlyHint, so an agent knows which calls change state.
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (4 declared hints checked).
warningUntrusted content hint
0 / 2
1 of 1 tools look like they return text written by other people but declare no untrustedContentHint, so an agent will treat the response as the site speaking.
toolrequest_demo
request_demo: message, email
fix
{ name: "request_demo", annotations: { untrustedContentHint: true } }
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
4 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

35 / 100 · weight 30
warningNaming quality
1.5 / 2
Tool naming makes selection harder than it needs to be: 2 names do not start with a verb (ask_site).
toolask_site
fix
{ name: "ask_site" /* short, unique, verb-based */ }
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
failCoverage vs. site type
2 / 8
The tool set covers 1 of the 4 things an agent needs on a saas site; it cannot search or browse the catalog or create a record or start a job or update or move an existing record.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolask_site
ask_site, get_offering, get_latest_posts, request_demo
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="ask_site" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
4
run time
6s
finished
Aug 28, 2026