webmcp.ro WebMCP audit

audited Aug 28, 2026in 5s
69/ 100

6 tools registered. Strongest in WebMCP use, weakest in human experience.

WebMCP use88
Usefulness83
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
validate_website: warning

validate_website

Starts a NEW WebMCP validation scan for a public website. Returns a JSON object with the report link; the scan itself finishes in about 30 seconds, so fetch the report afterwards with get_webmcp_report. Rate limited to a few scans per hour. Use this only when the site has never been scanned or the user explicitly wants fresh results; if a report already exists, get_webmcp_report is instant and does not consume the limit. This is the programmatic path, which hands the result back as data; the scan form on the home page is exposed separately as scan_website and instead renders the report on screen for the user.Takes an action on the site.
pagehttps://www.webmcp.ro/
implementation
viaimperative
entry pointdocument
registered after390ms
executepresent
api surface
urlrequired
annotations
read onlyfalse
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
2 findings
warningSchema quality
2 / 4
3 of 6 tool schemas are harder for an agent to use than they need to be: validate_website description is 616 characters, over Chrome's 500-character guidance.
validate_website: description is 616 characters, over Chrome's 500-character guidance; get_webmcp_report: description is 514 characters, over Chrome's 500-character guidance; get_leaderboard: declares
fix
{
  name: "validate_website",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
warningHuman parity
0 / 8
6 of 6 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
validate_website, get_webmcp_report, get_services, request_quote, get_leaderboard
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="validate_website" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "validate_website",
  "description": "Starts a NEW WebMCP validation scan for a public website. Returns a JSON object with the report link; the scan itself finishes in about 30 seconds, so fetch the report afterwards with get_webmcp_report. Rate limited to a few scans per hour. Use this only when the site has never been scanned or the user explicitly wants fresh results; if a report already exists, get_webmcp_report is instant and does not consume the limit. This is the programmatic path, which hands the result back as data; the scan form on the home page is exposed separately as scan_website and instead renders the report on screen for the user.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "url": {
        "type": "string",
        "description": "Public website URL or domain, e.g. example.com",
        "minLength": 4,
        "maxLength": 300,
        "pattern": "^(https?://)?[a-zA-Z0-9][a-zA-Z0-9.-]*\\.[a-zA-Z]{2,}"
      }
    },
    "required": [
      "url"
    ],
    "additionalProperties": false
  },
  "annotations": {
    "readOnlyHint": false
  }
}
Showing validate_website

Findings

WebMCP use

88 / 100 · weight 50
passTools registered
4 / 4
6 tools registered across 1 page.
passReal-browser eligible
8 / 8
A real browser exposes modelContext natively on this page, so the tools registered here are visible to an agent today.
passRegistration timing
4 / 4
Every measured tool registered within 390.60000014305115ms of navigation.
toolget_leaderboard
passCanonical entry point
4 / 4
All 6 tools register on the canonical document.modelContext entry point.
passSchema validity
5 / 5
All 6 tools declare a structurally valid object input schema.
warningSchema quality
2 / 4
3 of 6 tool schemas are harder for an agent to use than they need to be: validate_website description is 616 characters, over Chrome's 500-character guidance.
toolvalidate_website
validate_website: description is 616 characters, over Chrome's 500-character guidance; get_webmcp_report: description is 514 characters, over Chrome's 500-character guidance; get_leaderboard: declares
fix
{
  name: "validate_website",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
passStub detection
5 / 5
All 6 tools declare an execute handler.
warningAnnotations present
3.3 / 4
1 of 6 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
toolrequest_quote_form
request_quote_form
fix
{
  name: "request_quote_form",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
passAnnotation mismatch
3 / 3
No tool claims to be read-only while its name says it writes (5 declared hints checked).
warningUntrusted content hint
0 / 2
2 of 2 tools look like they return text written by other people but declare no untrustedContentHint, so an agent will treat the response as the site speaking.
toolrequest_quote
request_quote: message, replie, user; request_quote_form: replie, user, email
fix
{ name: "request_quote", annotations: { untrustedContentHint: true } }
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
6 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

83 / 100 · weight 30
warningNaming quality
1.7 / 2
Tool naming makes selection harder than it needs to be: 2 names do not start with a verb (request_quote).
toolrequest_quote
fix
{ name: "request_quote" /* short, unique, verb-based */ }
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
not applicableCoverage vs. site type
0 / 8
This tool set does not place the site in a category with a known expected tool shape, so there is no coverage baseline to score it against.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
6 of 6 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolvalidate_website
validate_website, get_webmcp_report, get_services, request_quote, get_leaderboard
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="validate_website" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
6
run time
5s
finished
Aug 28, 2026