waniwani.ai WebMCP audit

audited Oct 9, 2026in 14s
67/ 100100% of the applicable check weight evaluated

3 tools registered. Strongest in shared experience, weakest in tool selection.

Shared experience87
Tool selection18
Tool quality85
Trust76
https://waniwani.ai
Captured view of https://waniwani.ai

Tools

2 read, 0 write, 1 undeclared
Loading map
search: warning

search

Search the knowledge base and return the passages that match a query. Use this for general questions about the product or service — what it covers, pricing, eligibility, policy details, and the like. Answer only from the passages it returns, and if it returns none, say the knowledge base doesn't cover the question instead of answering from general knowledge. Do not use it for anything specific to this user's own account or records.Answers a question. Declared read only.
pagehttps://www.waniwani.ai/
implementation
viaimperative
entry pointdocument
registered after1024ms
executepresent
api surface
queryrequired
telemetryoptional
annotations
read onlytrue
untrusted contentnot declared
titleSearch knowledge base
destructive (MCP-only)false
idempotent (MCP-only)true
open world (MCP-only)false
1 finding
warningInjection surface
weight 3
3 of 3 tools carry instruction-shaped text in their own metadata: search description instructs agent how to answer and what not to do.
search: description instructs agent how to answer and what not to do; show-book-call: description instructs agent on tool use order; book_demo: description instructs agent on when to use the tool
fix
{
  name: "search",
  // Metadata DESCRIBES the tool - it never addresses the agent reading it.
  // Rewrite any name, description, title, or schema field description that
  // instructs the agent (which tool to prefer, what to output, rules to
  // ignore) so it states what the tool does and what it returns instead.
  description: "Searches the catalog and returns matching items with prices."
}
tool json
{
  "name": "search",
  "description": "Search the knowledge base and return the passages that match a query. Use this for general questions about the product or service — what it covers, pricing, eligibility, policy details, and the like. Answer only from the passages it returns, and if it returns none, say the knowledge base doesn't cover the question instead of answering from general knowledge. Do not use it for anything specific to this user's own account or records.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "query": {
        "type": "string",
        "description": "What to look up. The search is semantic, so the user's question in their own words works better than keywords."
      },
      "telemetry": {
        "description": "For analytics only; the tool ignores it.",
        "type": "object",
        "properties": {
          "intent": {
            "description": "Summary of the user's latest message, in their words. Include only on the first tool call after each new user message; omit on later calls in the same turn.",
            "type": "string"
          },
          "context": {
            "description": "What led the user here (page, trigger). Include with intent only when it is new.",
            "type": "string"
          }
        }
      }
    },
    "required": [
      "query"
    ],
    "$schema": "http://json-schema.org/draft-07/schema#"
  },
  "annotations": {
    "readOnlyHint": true,
    "destructiveHint": false,
    "idempotentHint": true,
    "openWorldHint": false,
    "title": "Search knowledge base"
  }
}
Showing search

Findings

Shared experience

87 / 100 · weight 30
not applicableVisible effect
weight 6
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
passPage experience
weight 16
1 of 4 page-experience marks came back short: obstruction A large green box partially covers the main content of the page..
obstruction: weak
passHuman parity
weight 8
The person co-browsing can see and use this page - the same page the agent's tools act on.

Tool selection

18 / 100 · weight 25
not applicableInvoke success rate
weight 6
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
failTool selection
weight 12
An agent chose an existing tool and built a schema-valid call that held up on 0 of 3 canonical intents; on "Find the record for a company called Northwind." no tool on the page served it. Nothing was executed, so this verifies selection, not outcomes.
warningCoverage vs. site type
weight 7
The tool set covers 2 of the 4 things an agent needs on a saas site; it cannot create a record or start a job or update or move an existing record.

Tool quality

85 / 100 · weight 25
warningRegistration timing
weight 1
The slowest tool took 1024ms to register, past the 1000ms an agent reading the registry at first paint would wait for.
toolbook_demo
book_demo: registered at 1024ms
fix
// Register tools as soon as they're ready, not behind a deferred/async chunk.
document.modelContext.registerTool({ /* ... */ });
passCanonical entry point
weight 3
All 3 tools register on the canonical document.modelContext entry point.
passSchema validity
weight 4
All 3 declared input schemas are structurally valid object schemas.
warningSchema quality
weight 4
1 of 3 tool schemas are harder for an agent to use than they need to be: book_demo 3 parameter descriptions are over Chrome's 150-character guidance.
toolbook_demo
book_demo: 3 parameter descriptions are over Chrome's 150-character guidance
fix
{
  name: "book_demo",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
warningNaming quality
weight 2
Tool naming makes selection harder than it needs to be: names mix kebab and snake conventions.
fix
{ name: "your_tool_name" /* short, unique, verb-based */ }
passStub detection
weight 4
All 3 tools declare an execute handler.
passRegistration errors
weight 2
No tool registration threw during the capture.
passDescription quality
weight 5
1 of 3 tool descriptions leave an agent guessing: show-book-call Omits what comes back, what changes, and when to use it over similar tools.
toolshow-book-call
show-book-call: weak

Trust

76 / 100 · weight 20
passAnnotations present
weight 5
All 2 read-shaped tools declare readOnlyHint: true - the one declared claim that lets an agent treat a call as safe to make without asking.
passAnnotation mismatch
weight 5
No tool claims to be read-only while its own name or description says it writes (2 declared hints checked).
not applicableUntrusted content hint
weight 3
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
not applicableHint vs. observed
weight 4
Not invoked on this run: this audit did not call any tool. Scheduled re-audits only read the registry; a live audit from the report page calls the tools that declare readOnlyHint: true.
warningInjection surface
weight 3
3 of 3 tools carry instruction-shaped text in their own metadata: search description instructs agent how to answer and what not to do.
toolsearch
search: description instructs agent how to answer and what not to do; show-book-call: description instructs agent on tool use order; book_demo: description instructs agent on when to use the tool
fix
{
  name: "search",
  // Metadata DESCRIBES the tool - it never addresses the agent reading it.
  // Rewrite any name, description, title, or schema field description that
  // instructs the agent (which tool to prefer, what to output, rules to
  // ignore) so it states what the tool does and what it returns instead.
  description: "Searches the catalog and returns matching items with prices."
}

Tool selection

0% across 3 intents
Find the record for a company called Northwind.missed
choseno toolexpected record searchkind not applicable
No tool was picked for this intent.
arguments
{}
Show me everything on that record.missed
choseno toolexpected record detailkind not applicable
No tool was picked for this intent.
arguments
{}
Create a new contact called Dana Reeve.missed
choseno toolexpected record createkind not applicable
No tool was picked for this intent.
arguments
{}
model: gemini-2.5-flash

Add the tools this site is missing

Our scanner reads your website and suggests the right WebMCP tools for it.
Reads the site's public pages; takes a few seconds.
The open source webmcp plugin teaches your coding agent to audit a site, implement tools on document.modelContext, and verify them in a real browser. npx @ora-ai/webmcp-verify runs the verification on its own. No signup, no hosted service.
how this was captured
observed via
capture shim (Chromium 151.0.7922.34)
chrome
151.0.7922.34
capture shim
v3
spec snapshot
2026-08-26
mode
fast
pages
1 - entry page only
tools
3
invoked
not invoked; a live audit calls them
run time
14s
finished
Oct 9, 2026
Checked the way in-browser agents discover tools: the top-level document's modelContext registry, read after the page settles.
Listed in the community directory.