WebMCP · Surface scan

Scan your WebMCP tool surface.

If your product exposes tools to AI agents via WebMCP (document.modelContext), MCP Sentinel can scan what that surface declares - tool descriptions, parameter schemas, annotations, and any resources, prompts or roots you expose - with the real deterministic engine. No fetch, no socket, nothing executed. A surface scan is not listed in the public registry.

Scan in one click

Drag this to your bookmarks bar once. Then, on your own WebMCP page, click it - it reads your tool surface (getTools() or listTools() on document.modelContext or navigator.modelContext, whichever your build exposes), submits it to the scanner, and opens your scored report in a new tab. Same-origin rules mean the read must run on your page, so that single click is all it takes.

Scan my WebMCP page← drag me to your bookmarks bar (one-time)
Or copy the bookmarklet source

Create a new bookmark and paste this as its URL. When you click it on your page it reads your declared tools and submits them to MCP Sentinel's scanner (a surface scan, not listed in the public registry), then opens the report - nothing else on your page is touched.

Or paste your tools manually

The declared surface is analyzed as pasted - no fetch, no socket, nothing is executed. A surface scan is not listed in the public registry.

Runs the real engine over the declared surface. Rate-limited (5 / hour); can take up to ~60s.