readmbox.com WebMCP audit

audited Aug 28, 2026in 4s
55/ 100

6 tools registered. Strongest in usefulness, weakest in human experience.

WebMCP use55
Usefulness92
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
get_mailbox_status: fail

get_mailbox_status

Report whether an MBOX file is open in this tab and what is in it: message count, date span, how many messages the current filters match, and whether the mailbox is fully readable. Call this first.Takes an action on the site.
pagehttps://readmbox.com/
implementation
viaimperative
entry pointnavigator
registered after214ms
executepresent
api surfaceTakes no parameters.
annotations
read onlynot declared
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
3 findings
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
failAnnotations present
0 / 4
6 of 6 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
get_mailbox_status, list_messages, read_message, filter_by_date, clear_filters
fix
{
  name: "get_mailbox_status",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
warningHuman parity
0 / 8
6 of 6 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
get_mailbox_status, list_messages, read_message, filter_by_date, clear_filters
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="get_mailbox_status" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "get_mailbox_status",
  "description": "Report whether an MBOX file is open in this tab and what is in it: message count, date span, how many messages the current filters match, and whether the mailbox is fully readable. Call this first.",
  "inputSchema": {
    "type": "object",
    "properties": {}
  },
  "annotations": {}
}
Showing get_mailbox_status

Findings

WebMCP use

55 / 100 · weight 50
passTools registered
4 / 4
6 tools registered across 1 page.
failReal-browser eligible
0 / 8
The page's code registers these tools, but a real visitor's browser does not get them yet: WebMCP needs a native modelContext or a current origin trial token, and this page has neither.
passRegistration timing
4 / 4
Every measured tool registered within 214.70000004768372ms of navigation.
toolscan_messages
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
toolget_mailbox_status
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
passSchema validity
5 / 5
All 6 tools declare a structurally valid object input schema.
warningSchema quality
2 / 4
3 of 6 tool schemas are harder for an agent to use than they need to be: list_messages declares no required list, so an agent cannot tell which parameters are mandatory.
toollist_messages
list_messages: declares no required list, so an agent cannot tell which parameters are mandatory; filter_by_date: declares no required list, so an agent cannot tell which parameters are mandatory; sca
fix
{
  name: "list_messages",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
passStub detection
5 / 5
All 6 tools declare an execute handler.
failAnnotations present
0 / 4
6 of 6 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
toolget_mailbox_status
get_mailbox_status, list_messages, read_message, filter_by_date, clear_filters
fix
{
  name: "get_mailbox_status",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
not applicableAnnotation mismatch
0 / 3
No tool declares a readOnlyHint, so there is no safety claim to contradict.
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
6 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

92 / 100 · weight 30
warningNaming quality
1.8 / 2
Tool naming makes selection harder than it needs to be: 1 name does not start with a verb (scan_messages).
toolscan_messages
fix
{ name: "scan_messages" /* short, unique, verb-based */ }
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
not applicableCoverage vs. site type
0 / 8
This tool set does not place the site in a category with a known expected tool shape, so there is no coverage baseline to score it against.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
6 of 6 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolget_mailbox_status
get_mailbox_status, list_messages, read_message, filter_by_date, clear_filters
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="get_mailbox_status" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
6
run time
4s
finished
Aug 28, 2026