Inspiration

Technical SEO audits are good at producing findings, but the workflow after the audit is still fragmented: inspect an issue, decide what matters, remember what was supposed to change, implement the fix somewhere else, run another audit, and determine whether the original problem was actually resolved.

At the same time, many agent experiences treat the browser as something an AI operates around rather than a workspace a human and an agent can genuinely share.

Auvrora started from a simple question:

What if the audit page itself became the collaboration surface?

Instead of building another chatbot or giving an agent an opaque backend API, I wanted the human to keep the audit, selected fix scope, and verification result visible in the browser while an agent works against that exact same state through native WebMCP tools.

SEO became a useful test case because the loop is concrete and verifiable:

Audit → Inspect → Scope → Fix → Re-audit → Verify

The result is Auvrora WebMCP: a deliberately focused experiment in how humans and agents can collaborate on structured work directly through the open web.

What it does

Auvrora performs a bounded, deterministic technical SEO audit of a public page and exposes the remediation workflow through five native WebMCP tools:

  • run_audit — audits a public URL and establishes the active audit
  • list_findings — returns the current findings
  • inspect_finding — provides bounded evidence and guidance for one finding
  • set_fix_scope — selects the issues the human intends to address
  • verify_fix_scope — re-audits the same canonical URL and determines whether those selected findings were resolved

The important part is that these are not separate agent-only APIs.

The normal UI and the WebMCP tools operate through the same application controller and the same ephemeral browser state. If an agent changes the fix scope, the human sees that change immediately. If the human starts a new audit, the agent works against that new state.

That means a person can inspect and supervise the workflow visually while an agent uses structured tools against the exact same audit, finding IDs, selected scope, and verification result.

Auvrora currently checks 13 bounded technical SEO signals around titles, meta descriptions, H1s, canonical links, viewport metadata, document language, image alt text, and indexing directives.

It intentionally does not modify websites or deploy code. The agent helps investigate, scope, and verify; the human remains in control of implementation.

How we built it

Auvrora is built with Astro, TypeScript, native WebMCP, and Cloudflare Workers.

The browser owns the workflow state: the current audit, selected finding IDs, and verification results. Both the human UI and the WebMCP handlers delegate to a single AuvroraController, so there is no second hidden implementation for agents.

The agent-facing layer uses native:

document.modelContext.registerTool(...)

Each tool has a constrained JSON Schema, runtime validation, explicit lifecycle handling, and bounded outputs.

On the server side, a stateless Cloudflare Worker exposes a small audit endpoint. It validates the target URL, follows redirects manually with revalidation, bounds response size and execution time, accepts only appropriate HTML content, and runs deterministic source inspection.

Because an audit accepts an attacker-controlled URL, I treated retrieval as a security boundary rather than a normal fetch(). Private and reserved targets are blocked, redirects are revalidated, credentials and arbitrary headers are rejected, and Cloudflare's public-network fetch restrictions provide another layer of defense.

Target-derived content is also treated as untrusted when it crosses the WebMCP boundary. The agent receives compact findings rather than raw fetched HTML.

No database, account system, LLM backend, API key, or persistent user data is required by the Auvrora runtime.

Challenges we ran into

The hardest problem was not registering WebMCP tools. It was designing a coherent shared state machine for a human and an agent.

Actions have ordering and preconditions. You cannot inspect a finding that no longer belongs to the active audit. Verification must apply to the exact scope selected from the original audit. A stale network response must not overwrite a newer audit. Starting over must invalidate state that is no longer meaningful.

That forced the project to treat WebMCP as part of the application's interaction architecture rather than simply exposing five functions.

Another challenge was working against an emerging browser API. Tool descriptions, schemas, cancellation behavior, browser execution paths, and evaluation tooling all had to be tested rather than assumed.

Security also required substantial work because the input is a public URL. Redirect chains, private-network targets, oversized responses, malicious HTML, rate limiting, and untrusted tool output all needed explicit boundaries.

Finally, realistic end-to-end WebMCP evaluation exposed another constraint: the complete test journey triggered enough fresh audits to hit Auvrora's production rate limit. Rather than weakening that security control for the benchmark, I split the live evaluation across limiter windows.

Accomplishments that we're proud of

The part I am most proud of is that Auvrora became a complete product loop rather than a WebMCP proof of concept.

The same workflow works for both a person clicking through the interface and an agent calling native WebMCP tools.

The final application has:

  • five native WebMCP tools covering the complete remediation journey
  • shared human-agent browser state
  • a deterministic audit and verification model
  • a stateless production deployment on Cloudflare Workers
  • explicit public-URL and untrusted-content security boundaries
  • ten authored WebMCP evaluation scenarios
  • CI protection against tool-schema and evaluation drift
  • 108 passing automated tests across 20 test files
  • 29/29 required live WebMCP tool steps passed against the deployed application using pinned GoogleChromeLabs WebMCP evaluation tooling

That last result was especially important to me: the project is not just claiming that the tools exist. The actual multi-step WebMCP journeys were exercised against the production deployment.

What we learned

The biggest lesson was that good WebMCP design is not about exposing as many tools as possible.

A useful tool surface needs clear semantics, constrained inputs, predictable state transitions, useful outputs, and enough context for an agent to understand what can happen next.

I also learned that human-agent collaboration becomes much more interesting when the browser is the source of shared context. The agent does not need a separate hidden workspace; its actions can correspond directly to state the human can inspect and supervise.

Another lesson was that deterministic systems pair surprisingly well with agents. Auvrora does not use an LLM to generate audit findings. The audit engine provides stable evidence and identities, while the agent contributes reasoning about which tools to invoke, which findings to inspect, and how to navigate the workflow.

That separation makes the experience easier to test, easier to understand, and much harder to fake.

What's next for Auvrora WebMCP

The current version is intentionally narrow so the complete human-agent loop is reliable.

The next step is to deepen that loop rather than simply add more tools.

I want to explore:

  • additional deterministic audit signals
  • carefully bounded multi-page audit scopes
  • richer comparisons between previous and fresh audits
  • exportable remediation plans and verification reports
  • more adversarial and multi-step WebMCP evaluation cases
  • repeated model-driven tool-selection evaluations across different agents
  • better visual explanations of what the agent changed in shared browser state

Longer term, the interesting idea extends beyond SEO.

Auvrora is really an experiment in a broader pattern: a web application where humans and agents operate on the same visible, structured workflow rather than handing control back and forth between a website and a chat window.

Technical SEO is the first domain. The broader question is how far that interaction model can go.

Built With

Share this project:

Updates

Submission history