WebMCP Assurance for browser-native agent tools
LyraShield AI is the launch gate for WebMCP tools your app exposes. It discovers tool source in a repository, gates pull requests with SARIF and a fail-closed GitHub Action, keeps pasted code in the browser, and records bounded evidence receipts.
Our free browser-local WebMCP Security Lab evaluates fourteen deterministic controls across tool behavior and annotations, cross-origin exposure, origin isolation, confirmation boundaries, input and output bounds, cancellation, cleanup, runtime validation, embedded secrets, prompt-injection surface, spec drift, and contract budgets. Pasted or selected source remains in the browser; nothing is uploaded for the public check.
Humans and agents collaborate with clear boundaries
A supported browser agent can ask the Lab to analyze selected local source or prepare one narrow rewrite. It receives only bounded summaries and rewrite metadata. The human sees the visible result, reviews the diff, and must use the explicit Apply control. The agent cannot silently apply a change.
Inside the authenticated LyraShield dashboard, page-scoped WebMCP tools review launch readiness, filter and explain visible findings, and prepare valid scan-form inputs. Existing server authorization, workspace isolation, and the human Start control remain the authority for durable or resource-consuming work. A visible activity receipt records current-tab agent activity.
Implementation
The project uses feature-detected document.modelContext tools with strict schemas, bounded outputs, cancellation support, same-origin tools policy, and origin isolation. The shared analyzer powers the free Lab, repository scanning, CLI/SARIF output, a GitHub Action gate, and evidence-bound reports. Dynamic or unsupported source remains inconclusive rather than being labeled clean.
What this does not claim
A deterministic result is not a security guarantee or independent verification. WebMCP is experimental, and this project does not claim search ranking, indexing, or AEO/GEO citation outcomes.
Live demo: https://lyrashieldai.com/tools/webmcp-security-checker WebMCP overview: https://lyrashieldai.com/webmcp Source: https://github.com/ecryptoguru/lyrashield-ai
Built With
- astro
- azure
- cloudflare
- github-actions
- next.js
- node.js
- typescript
- webmcp