zuplo.com WebMCP audit

audited Aug 28, 2026in 4s
49/ 100

2 tools registered. Strongest in usefulness, weakest in human experience.

WebMCP use55
Usefulness73
Human experience0
about:blank

No agent run recorded yet.

No steps recorded

Tools

/
search_docs: fail

search_docs

Search Zuplo's documentation for policies, API gateway features, tutorials, and reference material. Returns extracts from docs pages with source URLs. Use this to answer any question about what Zuplo can do or how to configure it.Takes an action on the site.
pagehttps://zuplo.com/
implementation
viaimperative
entry pointnavigator
registered after598ms
executepresent
api surface
queryrequired
annotations
read onlynot declared
destructivenot declared
idempotentnot declared
open worldnot declared
untrusted contentnot declared
titlenot declared
3 findings
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
failAnnotations present
0 / 4
2 of 2 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
search_docs, book_demo
fix
{
  name: "search_docs",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
warningHuman parity
0 / 8
2 of 2 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
search_docs, book_demo
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="search_docs" tooldescription="...">
  <!-- the same action, as UI -->
</form>
tool json
{
  "name": "search_docs",
  "description": "Search Zuplo's documentation for policies, API gateway features, tutorials, and reference material. Returns extracts from docs pages with source URLs. Use this to answer any question about what Zuplo can do or how to configure it.",
  "inputSchema": {
    "type": "object",
    "properties": {
      "query": {
        "type": "string",
        "description": "Natural-language search query, e.g. 'rate limiting by API key' or 'JWT validation policy'."
      }
    },
    "required": [
      "query"
    ]
  },
  "annotations": {}
}
Showing search_docs

Findings

WebMCP use

55 / 100 · weight 50
passTools registered
4 / 4
2 tools registered across 1 page.
failReal-browser eligible
0 / 8
The page's code registers these tools, but a real visitor's browser does not get them yet: WebMCP needs a native modelContext or a current origin trial token, and this page has neither.
passRegistration timing
4 / 4
Every measured tool registered within 597.7999999523163ms of navigation.
toolbook_demo
failCanonical entry point
0 / 4
Every tool registers through the deprecated navigator.modelContext alias; move them to document.modelContext before the alias is removed.
toolsearch_docs
fix
// Use the canonical entry point - navigator.modelContext is deprecated.
document.modelContext.provideContext({ tools: [/* ... */] });
passSchema validity
5 / 5
All 2 tools declare a structurally valid object input schema.
warningSchema quality
2 / 4
1 of 2 tool schemas are harder for an agent to use than they need to be: book_demo declares no required list, so an agent cannot tell which parameters are mandatory.
toolbook_demo
book_demo: declares no required list, so an agent cannot tell which parameters are mandatory
fix
{
  name: "book_demo",
  inputSchema: {
    type: "object",
    properties: {
      query: { type: "string", description: "What to search for" }
    },
    required: ["query"]
  }
}
passStub detection
5 / 5
All 2 tools declare an execute handler.
failAnnotations present
0 / 4
2 of 2 tools declare no readOnlyHint, so an agent cannot tell a read from a write without guessing from the name.
toolsearch_docs
search_docs, book_demo
fix
{
  name: "search_docs",
  annotations: { readOnlyHint: true, destructiveHint: false, idempotentHint: true }
}
not applicableAnnotation mismatch
0 / 3
No tool declares a readOnlyHint, so there is no safety claim to contradict.
not applicableUntrusted content hint
0 / 2
No tool's contract suggests it returns text written by somebody other than the site, so there is nothing to flag as untrusted.
passRegistration errors
2 / 2
No tool registration threw during the capture.
warningToolchange coherence
1 / 2
2 tools were registered but the page never dispatched a toolchange event, so an agent subscribed to registry updates never learns they exist.
fix
document.modelContext.dispatchEvent(new Event("toolchange"));
not applicableInjection surface
0 / 3
The injection-surface model hop returned no usable result, so tool contracts were not reviewed for injection surface.

Usefulness

73 / 100 · weight 30
passNaming quality
2 / 2
All 2 tool names are consistent, verb-led, and within Chrome's size guidance.
not applicableDescription quality
0 / 6
The description-quality model hop returned no usable result, so descriptions were not rated.
not applicableTool selection
0 / 14
The tool-selection model hop returned no usable result.
warningCoverage vs. site type
5.3 / 8
The tool set covers 2 of the 3 things an agent needs on a docs site; it cannot navigate the documentation tree.

Human experience

0 / 100 · weight 20
warningHuman parity
0 / 8
2 of 2 tools run through the JavaScript API with no visible counterpart, so the person co-browsing cannot see what the agent is offered. Declarative forms (or at least a title annotation) close the gap.
toolsearch_docs
search_docs, book_demo
fix
<!-- Give the tool a visible counterpart: a declarative form is one the person can see and use too. -->
<form toolname="search_docs" tooldescription="...">
  <!-- the same action, as UI -->
</form>
not applicablePage experience
0 / 12
The page-experience model hop returned no usable result, so the page was not graded.

Tool selection

The tool-selection model hop returned no usable result.
how this was captured
chrome
148.0.7778.96
capture shim
v1
spec snapshot
2026-08
mode
fast
pages
1
tools
2
run time
4s
finished
Aug 28, 2026