SLOTH — DELEGATED OUTCOMES WITH SCOPED AUTHORITY

INSPIRATION WebMCP lets websites give AI agents native browser tools instead of guessing where to click. But the spec has a huge blind spot: zero concept of permissions or reversibility. If you register a refund tool on page load, the agent has permanent god-mode access. If you don't, it's useless. We built Sloth around one thesis: Delegate outcomes, not unlimited access.

WHAT IT DOES Sloth is an operations console for delegated outcomes with temporary capability boundaries:

  1. Zero Standing Privileges: Starts with 4 baseline tools (inspect issues, inspect transaction, retry payment, request capability). No refund tool exists.
  2. Autonomous Investigation: Agent investigates anomalies, retries pre-authorized failures, and confirms duplicate charges.
  3. Boundary Escalation: Agent hits a hard boundary and calls request_capability proposing a narrow scope.
  4. Human Negotiation: Operator can approve, deny (DO_NOT_RETRY), or adjust caps ($72 per item, $150 aggregate batch cap).
  5. Dynamic Tool Injection (4 -> 5 tools): Approval injects refund_scoped_transactions in real time with a 60-second TTL countdown.
  6. In-Tool Enforcement: Tool itself blocks unapproved IDs or amount breaches with structured SCOPE_VIOLATION errors.
  7. Single-Use Auto-Revocation (5 -> 4 tools): Executing refunds immediately revokes the tool to eliminate replay attacks.
  8. Compliance Audit: One-click export of a signed JSON audit ledger.

HOW WE BUILT IT

  • Runtime: Next.js (Vinext engine) with native document.modelContext support for Chrome 149+ and ChatGPT desktop.
  • Core Scope Engine: Pure, zero-dependency validation logic (scope.js) enforcing dual caps, backed by 17/17 automated unit tests.
  • Dynamic Lifecycle: Browser AbortController signals and reactive state tracking to mount and unmount tools on the fly.
  • Console UI: High-density dark mode console with monospace authority rail, live TTL countdown, and boundary test sandboxes.

CHALLENGES WE RAN INTO

  • Dynamic WebMCP Registration: Most examples treat tools as static declarations. Mounting and unmounting tools dynamically without page reload required strict state isolation.
  • Dual-Track Evaluation: Supporting live LLM tool calling in experimental browsers while providing an interactive simulation for standard browsers.
  • Preventing Agent Loops: Implementing structured DO_NOT_RETRY machine contracts so models don't repeatedly beg for authority when denied.

ACCOMPLISHMENTS

  • Proven 4 -> 5 -> 4 Capability Lifecycle: zero standing privileges -> JIT grant -> auto-revocation on execution.
  • 100% In-Tool Security: Boundaries enforced inside the tool code, not just hidden UI buttons.
  • Dual Blast Radius Protection: Combining unit limits ($72) with aggregate run limits ($150).
  • 17/17 passing unit tests and <2s production build.

WHAT WE LEARNED

  • WebMCP is a human-agent negotiation protocol, not just an API.
  • Enterprise adoption requires verifiable blast radius limits and reversibility, not just smarter models.
  • Temporary, single-use capabilities give humans the trust needed to delegate real outcomes.

WHAT'S NEXT FOR SLOTH

  • Cryptographic Grant Attestation with WebCrypto.
  • Universal open-source middleware (@sloth/webmcp-guard).
  • Multi-agent capability hand-offs across agent swarms.

Built With

Share this project:

Updates

Submission history