pyrra.net WebMCP audit

audited Aug 28, 2026in 4s
66/ 100

4 tools registered. Strongest in WebMCP use, weakest in human experience.

WebMCP use96
Usefulness60
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
list-blog-posts: warning

list-blog-posts

List all writing published on pyrra.net — nonprofit website guides plus the clearly separated engineering and security notes in Felix’ Lab. Returns title, URL, publication date, category and summary as JSON.Answers a question. Declared read only.
pagehttps://www.pyrra.net/
implementation
viaimperative
entry pointdocument
registered after587ms
executepresent
api surfaceTakes no parameters.
annotations
read onlytrue
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
2 findings
warningUntrusted content hint
1 / 2
1 of 2 tools look like they return text written by other people but declare no untrustedContentHint, so an agent will treat the response as the site speaking.
list-blog-posts: post, note
fix
{ name: "list-blog-posts", annotations: { untrustedContentHint: true } }
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
list-blog-posts, get-blog-post, get-site-context, send-contact-message
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="list-blog-posts" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "list-blog-posts",
  "description": "List all writing published on pyrra.net — nonprofit website guides plus the clearly separated engineering and security notes in Felix’ Lab. Returns title, URL, publication date, category and summary as JSON.",
  "inputSchema": {
    "type": "object",
    "properties": {},
    "additionalProperties": false
  },
  "annotations": {
    "readOnlyHint": true
  }
}
Showing list-blog-posts

Findings

WebMCP use

96 / 100 · weight 50
passTools registered
4 / 4
4 tools registered across 1 page.
passReal-browser eligible
8 / 8
A real browser exposes modelContext natively on this page, so the tools registered here are visible to an agent today.
passRegistration timing
4 / 4
Every measured tool registered within 587.5999999046326ms of navigation.
toolget-site-context
passCanonical entry point
4 / 4
All 4 tools register on the canonical document.modelContext entry point.
passSchema validity
5 / 5
All 4 tools declare a structurally valid object input schema.
passSchema quality
4 / 4
All 4 tool schemas describe their parameters and stay within Chrome's size guidance.
passStub detection
5 / 5
All 4 tools declare an execute handler.
passAnnotations present
4 / 4
All 4 tools declare a readOnlyHint, so an agent knows which calls change state.
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (4 declared hints checked).
warningUntrusted content hint
1 / 2
1 of 2 tools look like they return text written by other people but declare no untrustedContentHint, so an agent will treat the response as the site speaking.
toollist-blog-posts
list-blog-posts: post, note
fix
{ name: "list-blog-posts", annotations: { untrustedContentHint: true } }
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
4 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

60 / 100 · weight 30
passNaming quality
2 / 2
All 4 tool names are consistent, verb-led, and within Chrome's size guidance.
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
warningCoverage vs. site type
4 / 8
The tool set covers 2 of the 4 things an agent needs on a saas site; it cannot create a record or start a job or update or move an existing record.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
4 of 4 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toollist-blog-posts
list-blog-posts, get-blog-post, get-site-context, send-contact-message
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="list-blog-posts" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
4
run time
4s
finished
Aug 28, 2026