puzl.no WebMCP audit

audited Aug 28, 2026in 6s
74/ 100

One tool registered. Strongest in usefulness, weakest in human experience.

WebMCP use89
Usefulness100
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
get_services: warning

get_services

Returns Puzl's current catalogue of custom AI consulting services (AI-løsninger) — the same offerings listed on the /tjenester page. Puzl is a Norwegian consultancy that builds bespoke AI systems integrated into a client's existing stack rather than selling off-the-shelf SaaS. Each service includes a short category tag, a one-line summary, and a full description of the problem it solves and the kind of business it fits. Use this to answer what Puzl offers, builds, or sells. Service content is in Norwegian.Answers a question. Declared read only.
pagehttps://www.puzl.no/
implementation
viaimperative
entry pointdocument
registered after542ms
executepresent
api surface
queryoptional
includeDetailsoptional
annotations
read onlytrue
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentfalse
titlenot declared
3 findings
passRegistration timing
4 / 4
Every measured tool registered within 541.5ms of navigation.
warningSchema quality
0 / 4
1 of 1 tool schemas are harder for an agent to use than they need to be: get_services description is 511 characters, over Chrome's 500-character guidance.
get_services: description is 511 characters, over Chrome's 500-character guidance; get_services: 1 parameter description is over Chrome's 150-character guidance
fix
{
  name: "get_services",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
warningHuman parity
0 / 8
1 of 1 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
get_services
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="get_services" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "get_services",
  "description": "Returns Puzl's current catalogue of custom AI consulting services (AI-løsninger) — the same offerings listed on the /tjenester page. Puzl is a Norwegian consultancy that builds bespoke AI systems integrated into a client's existing stack rather than selling off-the-shelf SaaS. Each service includes a short category tag, a one-line summary, and a full description of the problem it solves and the kind of business it fits. Use this to answer what Puzl offers, builds, or sells. Service content is in Norwegian.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "query": {
        "type": "string",
        "description": "Optional free-text filter, matched against service titles, tags and descriptions (e.g. 'kundeservice', 'logistics', 'SEO'). Omit to return the full catalogue."
      },
      "includeDetails": {
        "type": "boolean",
        "description": "Whether to include each service's full multi-sentence description. Set false for a compact title-and-summary listing.",
        "default": true
      }
    },
    "required": [],
    "additionalProperties": false
  },
  "annotations": {
    "readOnlyHint": true,
    "untrustedContentHint": false
  }
}
Showing get_services

Findings

WebMCP use

89 / 100 · weight 50
passTools registered
4 / 4
1 tool registered across 1 page.
passReal-browser eligible
8 / 8
A real browser exposes modelContext natively on this page, so the tools registered here are visible to an agent today.
passRegistration timing
4 / 4
Every measured tool registered within 541.5ms of navigation.
toolget_services
passCanonical entry point
4 / 4
The one registered tool registers on the canonical document.modelContext entry point.
passSchema validity
5 / 5
All 1 tool declare a structurally valid object input schema.
warningSchema quality
0 / 4
1 of 1 tool schemas are harder for an agent to use than they need to be: get_services description is 511 characters, over Chrome's 500-character guidance.
toolget_services
get_services: description is 511 characters, over Chrome's 500-character guidance; get_services: 1 parameter description is over Chrome's 150-character guidance
fix
{
  name: "get_services",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
passStub detection
5 / 5
The one registered tool declares an execute handler.
passAnnotations present
4 / 4
All 1 tool declares a readOnlyHint, so an agent knows which calls change state.
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (1 declared hint checked).
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
1 tool was registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

100 / 100 · weight 30
passNaming quality
2 / 2
All 1 tool name is consistent, verb-led, and within Chrome's size guidance.
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
not applicableCoverage vs. site type
0 / 8
This tool set does not place the site in a category with a known expected tool shape, so there is no coverage baseline to score it against.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
1 of 1 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolget_services
get_services
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="get_services" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
1
run time
6s
finished
Aug 28, 2026