Inspiration
Designing a tabletop game means coordinating rules, card costs, timing, win conditions, play length, and balance. An agent that relies on pixels has to guess how those parts relate, while unrestricted mutation can remove the designer from the decision that matters most. Ruleloom explores a better agentic-web pattern: the page exposes semantic operations, and the person keeps authorship and final approval.
What it does
Ruleloom is a visual game-design studio where a person and a WebMCP agent work on the same versioned specification. An agent can inspect, validate, run deterministic seeded playtests, and stage a bounded patch. Staging is inert: Ruleloom shows every operation, path, and value while the game remains unchanged.
Only a direct human click creates a short-lived, proposal-bound, version-bound, one-use approval. That action dynamically registers apply_approved_patch. The agent can apply once; Ruleloom advances the version, consumes approval, removes the tool, and shows post-change evidence in the same workspace.
In the captured public flow, Lunar Orchard advanced from v1 to v2. Replay was unavailable because the dynamic tool disappeared. Validation returned 0 errors, 0 warnings, and 1 informational finding. A 200-game deterministic run with seed 42017 produced 78 Player 1 wins, 89 Player 2 wins, and 33 draws, averaging 15.835 turns.
Why WebMCP
WebMCP is the product architecture, not an add-on. Five stable native tools expose inspection, draft creation, proposal staging, validation, and seeded playtesting. A sixth tool exists only while a current direct human approval is valid. The React UI and every WebMCP call share one versioned store. Tool mutations update the visual workspace, and human actions change which tools exist.
Human authority and replay protection
Approve, Reject, Reset, and Undo are UI-only. The approval value stays in a private store closure and never appears in tool input, output, persistence, or the activity trace. Approval expires and is tied to one proposal and base version. Stale or mismatched work is rejected without partial mutation; one successful apply consumes and unregisters the capability.
How we built it
Ruleloom is a static React 19, TypeScript, Vite, and Zod app on Vercel. src/domain contains the strict schema, versioned store, allowlisted patch engine, validator, and seeded simulator. src/webmcp owns native document.modelContext registration, JSON Schemas, validation, bounded results, and registration lifetimes. src/App.tsx renders the human workspace from the same store.
There is no login, server, remote database, production API, private package, or required secret. The complete MIT-licensed source, tests, threat model, evaluation definition, judge guide, and reproducible video materials are public. OpenAI Codex helped scope, implement, test, verify, and prepare this new standalone project. The runtime does not call an LLM API.
Challenges
The hardest problem was useful agent mutation without a reusable bearer token. We solved it with a private approval closure and a dynamic tool bound to proposal, version, expiry, and one successful use. Native WebMCP support also varies by client, so Ruleloom feature-detects support and names only tested clients. Seeded simulation stays reproducible through strict schemas, workload limits, recorded seeds, and versioned reports.
Accomplishments
- Five stable WebMCP tools plus one state-dependent tool
- Direct human approval without agent-visible approval material
- Observed one-use apply and replay prevention
- 45 passing unit tests and 6 passing browser tests
- Public no-login deployment and MIT repository
- 2:44 public narrated demo with authored English captions
- Honest live-agent subset reporting without a fabricated full-suite rate
What we learned
Dynamic tool registration can express authority directly: if the person has not approved, the mutation capability does not exist. Strong human-agent interfaces need clear state, constrained mutations, version binding, and visible evidence.
What's next
We want to support more bounded tabletop systems, richer simulation distributions, side-by-side scenarios, opt-in collaboration, and the full frozen 27-task evaluation across more WebMCP clients.
Testing
Open https://ruleloom-nu.vercel.app in the Codex in-app browser or Chrome with WebMCP enabled. Confirm five tools, use the Judge Quickstart prompt, review the staged proposal, click Approve for agent, ask the agent to apply, then validate and run 200 playtests with seed 42017. Confirm v2 and that the apply tool disappears. No credentials are required.
Built With
- openai-codex
- playwright
- react
- typescript
- vercel
- vite
- vitest
- webmcp
- zod
Log in or sign up for Devpost to join the conversation.