toban.app WebMCP audit

audited Aug 28, 2026in 4s
69/ 100

16 tools registered. Strongest in usefulness, weakest in human experience.

WebMCP use81
Usefulness96
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
list_schedules: fail

list_schedules

List all duty rosters (当番表) the user has. Returns each roster's name, member count, and group count; the currently displayed roster is marked. Use to see what rosters exist or before switching rosters.Answers a question. Declared read only.
pagehttps://toban.app/
implementation
viaimperative
entry pointnavigator
registered after450ms
executepresent
api surfaceTakes no parameters.
annotations
read onlytrue
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contenttrue
titlenot declared
2 findings
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
warningHuman parity
0 / 8
16 of 16 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
list_schedules, get_current_assignments, get_schedule_details, get_share_link, switch_schedule
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="list_schedules" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "list_schedules",
  "description": "List all duty rosters (当番表) the user has. Returns each roster's name, member count, and group count; the currently displayed roster is marked. Use to see what rosters exist or before switching rosters.",
  "inputSchema": {
    "type": "object",
    "properties": {}
  },
  "annotations": {
    "readOnlyHint": true,
    "untrustedContentHint": true
  }
}
Showing list_schedules

Findings

WebMCP use

81 / 100 · weight 50
passTools registered
4 / 4
16 tools registered across 1 page.
passReal-browser eligible
8 / 8
A real browser exposes modelContext natively on this page, so the tools registered here are visible to an agent today.
passRegistration timing
4 / 4
Every measured tool registered within 450.30000019073486ms of navigation.
toolcreate_schedule
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
toollist_schedules
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
passSchema validity
5 / 5
All 16 tools declare a structurally valid object input schema.
warningSchema quality
3.5 / 4
2 of 16 tool schemas are harder for an agent to use than they need to be: update_schedule declares no required list, so an agent cannot tell which parameters are mandatory.
toolupdate_schedule
update_schedule: declares no required list, so an agent cannot tell which parameters are mandatory; configure_rotation: 3 parameters have no description (skip_saturday, skip_sunday, skip_holidays)
fix
{
  name: "update_schedule",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
passStub detection
5 / 5
All 16 tools declare an execute handler.
warningAnnotations present
1 / 4
12 of 16 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
toolswitch_schedule
switch_schedule, advance_rotation, change_view, create_schedule, update_schedule
fix
{
  name: "switch_schedule",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (4 declared hints checked).
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
16 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

96 / 100 · weight 30
warningNaming quality
1.6 / 2
Tool naming makes selection harder than it needs to be: 6 names do not start with a verb (switch_schedule).
toolswitch_schedule
fix
{ name: "switch_schedule" /* short, unique, verb-based */ }
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
passCoverage vs. site type
8 / 8
The tool set covers the whole core saas flow: search or browse the catalog, read one item in detail, create a record or start a job, update or move an existing record.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
16 of 16 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toollist_schedules
list_schedules, get_current_assignments, get_schedule_details, get_share_link, switch_schedule
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="list_schedules" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
16
run time
4s
finished
Aug 28, 2026