Inspiration

Prompt injection is now one of the dominant attacks against agent pipelines, yet most defenses run silently on the server. The human is cut out of the loop.

We wanted to make the near-miss visible: the moment an agent is about to follow a hidden instruction is the most important moment to show the user. WebMCP lets that happen directly inside a web page instead of disappearing into a hidden log.

What it does

Elcaro is a prompt-injection scanner that treats the web page as shared ground truth.

A human can paste an email, search result, document, or code snippet and immediately see a risk score and quarantine verdict. With WebMCP enabled, an agent can do the same thing on the same page: load a specimen, scan it, explain the verdict, and then declare what it was about to do.

The key interaction is that the page shows the agent's intended action next to the hidden instruction it found. This lets the human see the near-miss and understand exactly what the agent was about to do.

How we built it

The site is a Next.js frontend deployed on Netlify with a Python miner.

On /scan, we feature-detect document.modelContext and register five tools via registerTool:

  • scan_content
  • load_specimen
  • list_specimens
  • explain_verdict
  • contrast_intent

Each tool mutates the React form state and calls the same /api/scan endpoint that a human would use. This means the human and the agent are always looking at the same underlying results.

The contrast_intent tool computes a three-way contrast between the agent's intended action, the hidden instruction, and the safe remediation. Verdicts can also be Ed25519-signed for non-repudiation, and the repo already exposes a stdio MCP server for IDE-based workflows.

Challenges we ran into

WebMCP is a pre-standards draft, so the surface has shifted during development. The registration API moved from navigator.modelContext to document.modelContext, and ChatGPT's in-app browser behaves slightly differently from Chrome with chrome://flags/#enable-webmcp-testing.

We also had to separate in-page discovery from the actual tool surface. The home page advertises the site's WebMCP support through /.well-known/webmcp.json, but the tools only register on /scan, because that is where the shared UI lives.

The biggest design tension was keeping the page human-readable while making the tool schemas explicit enough for an agent to use reliably.

Accomplishments that we're proud of

The contrast_intent tool is the core win. Having an agent declare what it was about to do and showing that declaration next to the quarantined content creates a genuinely new human-agent interaction.

We're also proud that the WebMCP implementation is not a fake API. The same tools update the same React state that the human sees, and the same scanner endpoint backs both the form and the tools.

The signed verdicts, llms.txt agent instructions, and overall "agents as first-class users" design all reinforce the same idea: agent activity should be visible, understandable, and accountable.

What we learned

WebMCP is not just a way to expose actions; it is a way to make an agent's behavior legible to the human.

If a tool does not update the page visibly, the human has no reason to trust it. We also learned that tool descriptions are load-bearing: an agent needs to know when to call each tool, not just what the tool does.

We also confirmed that a /.well-known/webmcp.json manifest plus <meta name="webmcp"> helps agentic browsers and challenge evaluators discover the site before navigating to the tool page.

What's next for elcaro

Next, we want to expand WebMCP to the home page with a lightweight wayfinding tool, add a review_history tool, and ship a browser extension that automatically scans content retrieved by an agent and calls the WebMCP tools on the user's behalf.

We also want to expose an organization dashboard for audit trails of agent-declared intent and integrate Elcaro with agent platforms beyond ChatGPT and Chrome.

Built With

  • ed25519
  • fastapi
  • framer-motion
  • mcp
  • netlify
  • next.js
  • pydantic
  • python
  • react
  • tailwind-css
  • telegraph-protocol
  • typescript
  • uv
  • uvicorn
  • webmcp
Share this project:

Updates

Submission history