Skip to the card

Card 513 of 10002026-08-28 issue

Observed arrival · 2026-08-28

WebMCP Audit: security audits for the agentic web

mcpaudit.online Observed source
Editorial interest 78/100 Selection signal · not a rating of the site

An early-access scanner for auditing WebMCP tool registrations against the draft specification’s security threat model.

Landing page captured for the 2026-08-28 issue.

Field notes

The proposed audit begins by loading pages with a headless agent and cataloguing registered tools, their schemas, annotations, and allowed origins. It then applies six checks, including metadata-based prompt injection, privilege hidden behind read-only descriptions, unnecessary personal-data requests, and missing readOnlyHint or untrustedContentHint annotations. The page presents a scored report with specification-linked fixes as the intended output, but labels the scanner early access and does not show a completed audit.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

OpenPublic substance visible
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use

One card from the complete issue

Porion Gets More Tolerance

315,344 arrived 1,000 judged 1000 catalogued Enter the complete issue
mcpaudit.online

Landing page observed 2026-08-28. The live site may have changed.