InspirationWebMCP lets a page hand tools to an agent. A tool can say it only reads. It has no way to say it destroys.

That is not something I found. It is in the spec. Section 6.3.2 admits there is no guarantee a tool's declared intent matches what it actually does, and the example they use is a checkout tool that says it finalises a cart and really buys. Only the site knows what an action will do, so the site has to be the one that says.

claustrum is a small library. Register a tool with c.read and it runs. Register it with c.propose and it changes nothing at all. It returns held, plus an id, and the page shows the before and after next to what that action costs right now.

In the video I ask an agent to cut my riskiest position in half. It reads the book, checks the price before committing, then proposes selling 90 billion BONK. Sounds sensible. Routing it returns 93,842 dollars on a position marked at 268,000. Two thirds gone to price impact. The same call on a deeper pair costs 0.08 percent. The agent cannot tell those two apart. Asking first can.

Refuse it and you type a reason. Ask the agent afterwards what happened and it reads your reason back in your own words.

ChatGPT's browser already asks before risky actions. That asks whether you want to proceed. It cannot tell you the number, because the number lives in the site.

There is also a button that strips the write tools out mid session. It uses the abort signal from registerTool, which is the only way to remove a tool, since unregisterTool does not exist.

Two apps run on the same library so it is not one clever page. A portfolio priced against live Jupiter routing, and a team access console with no money in it, where the cost is counted in what breaks instead of dollars.

Chrome 151 differs from the spec in three places I could reproduce. executeTool wants a JSON string where the spec says object. execute never gets the abort signal the spec makes required. getTools hands back inputSchema as a string instead of parsed, so anything reading it sees a tool with no parameters. All three belong in crbug 2021259. Separately, inputSchema is not enforced at execution at all, so every tool here checks its own arguments and refuses in a way an agent can act on.

62 tests. One suite pulls the real functions back out of the shipped HTML and runs them, so the tests cannot drift from what ships. The page checks itself on load and prints what it verified rather than what it assumes. Prices only appear after a round trip, 100 dollars out and back, and anything that drifts more than 15 percent is marked not measured instead of guessed at.

Registered for the WebMCP origin trial, so it works in Chrome 149 and up with no flag. I checked that in a clean Brave install with nothing turned on.

Built With

Share this project:

Updates

Submission history