Observed arrival · 2026-08-28
WebMCP Audit: security audits for the agentic web
An early-access scanner for auditing WebMCP tool registrations against the draft specification’s security threat model.
Field notes
The proposed audit begins by loading pages with a headless agent and cataloguing registered tools, their schemas, annotations, and allowed origins. It then applies six checks, including metadata-based prompt injection, privilege hidden behind read-only descriptions, unnecessary personal-data requests, and missing readOnlyHint or untrustedContentHint annotations. The page presents a scored report with specification-linked fixes as the intended output, but labels the scanner early access and does not show a completed audit.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue