SLOTH — DELEGATED OUTCOMES WITH SCOPED AUTHORITY
INSPIRATION WebMCP lets websites give AI agents native browser tools instead of guessing where to click. But the spec has a huge blind spot: zero concept of permissions or reversibility. If you register a refund tool on page load, the agent has permanent god-mode access. If you don't, it's useless. We built Sloth around one thesis: Delegate outcomes, not unlimited access.
WHAT IT DOES Sloth is an operations console for delegated outcomes with temporary capability boundaries:
- Zero Standing Privileges: Starts with 4 baseline tools (inspect issues, inspect transaction, retry payment, request capability). No refund tool exists.
- Autonomous Investigation: Agent investigates anomalies, retries pre-authorized failures, and confirms duplicate charges.
- Boundary Escalation: Agent hits a hard boundary and calls request_capability proposing a narrow scope.
- Human Negotiation: Operator can approve, deny (DO_NOT_RETRY), or adjust caps ($72 per item, $150 aggregate batch cap).
- Dynamic Tool Injection (4 -> 5 tools): Approval injects refund_scoped_transactions in real time with a 60-second TTL countdown.
- In-Tool Enforcement: Tool itself blocks unapproved IDs or amount breaches with structured SCOPE_VIOLATION errors.
- Single-Use Auto-Revocation (5 -> 4 tools): Executing refunds immediately revokes the tool to eliminate replay attacks.
- Compliance Audit: One-click export of a signed JSON audit ledger.
HOW WE BUILT IT
- Runtime: Next.js (Vinext engine) with native document.modelContext support for Chrome 149+ and ChatGPT desktop.
- Core Scope Engine: Pure, zero-dependency validation logic (scope.js) enforcing dual caps, backed by 17/17 automated unit tests.
- Dynamic Lifecycle: Browser AbortController signals and reactive state tracking to mount and unmount tools on the fly.
- Console UI: High-density dark mode console with monospace authority rail, live TTL countdown, and boundary test sandboxes.
CHALLENGES WE RAN INTO
- Dynamic WebMCP Registration: Most examples treat tools as static declarations. Mounting and unmounting tools dynamically without page reload required strict state isolation.
- Dual-Track Evaluation: Supporting live LLM tool calling in experimental browsers while providing an interactive simulation for standard browsers.
- Preventing Agent Loops: Implementing structured DO_NOT_RETRY machine contracts so models don't repeatedly beg for authority when denied.
ACCOMPLISHMENTS
- Proven 4 -> 5 -> 4 Capability Lifecycle: zero standing privileges -> JIT grant -> auto-revocation on execution.
- 100% In-Tool Security: Boundaries enforced inside the tool code, not just hidden UI buttons.
- Dual Blast Radius Protection: Combining unit limits ($72) with aggregate run limits ($150).
- 17/17 passing unit tests and <2s production build.
WHAT WE LEARNED
- WebMCP is a human-agent negotiation protocol, not just an API.
- Enterprise adoption requires verifiable blast radius limits and reversibility, not just smarter models.
- Temporary, single-use capabilities give humans the trust needed to delegate real outcomes.
WHAT'S NEXT FOR SLOTH
- Cryptographic Grant Attestation with WebCrypto.
- Universal open-source middleware (@sloth/webmcp-guard).
- Multi-agent capability hand-offs across agent swarms.
Built With
- javascript
- nextjs
- typescript
Log in or sign up for Devpost to join the conversation.