Make any site agent-ready with WebMCP. One human click.
Live: https://chudi.dev/tools/toolsmith Code: https://github.com/Citability/toolsmith-webmcp
Inspiration
Agents keep guessing at forms that were built for people. Every wrong guess costs somebody a failed checkout or a broken signup. Toolsmith closes that gap without asking the site owner to write code, and without ever letting an agent approve its own work.
What it does
Paste a URL. Toolsmith reads the page, proposes one WebMCP tool per form, drafts a webmcp.js file, and waits. Nothing activates until a person clicks Approve. A receipt comes back, and the file downloads.
There is no language model anywhere in the loop. Every generated line traces to a real field on a real page.
The five tools, registered on document.modelContext:
profile_sitereads the public structure of one page: title, headings, forms and their fields, top-level navigation.propose_toolsturns the profile into candidate tools. GET forms become read-only tools. POST forms are marked consequential and get a confirm gate.draft_manifestemits thewebmcp.jssource for the chosen candidates, plus the SHA-256 of that exact text.activate_manifestshows the approval card and returns a pending request. This tool cannot approve anything on its own.verify_manifest_activationreads back the receipt and checks its digest against the manifest stored in the browser.
How we built it
The drafting logic is a deterministic template over detected forms, not a model call. The five tools are registered natively on document.modelContext with AbortSignal cleanup.
The only thing that can activate a manifest is a click on the Approve card. The page checks two properties of that event before it writes a receipt:
event.isTrustedmust be true, so a synthetic click from script does not count.navigator.userActivation.isActivemust be true, so the click happened inside a real user gesture.
The generated file carries the same discipline forward. Every consequential tool it registers wraps its submit in a browser confirm dialog, so an agent using the output still cannot post a form without a person in the loop.
Challenges we ran into
The hard part was proving the approval boundary still holds when the tool itself produces tools. It was not enough to gate Toolsmith's own Approve card. The output had to inherit the same rule, so every consequential tool in a generated file got its own confirm gate.
Accomplishments that we're proud of
A site owner can read the template and trace every output line to a form on their page. The approval boundary generalized from gating one action on one page to gating every action a generated file can take. And the whole loop runs with zero metered calls.
What we learned
A readable template earns more trust than a model nobody can inspect. One human click is enough to gate an entire generated interface, as long as the gate checks the properties of the click and not just its presence.
What's next for Toolsmith
Point it at a whole site and get one manifest back. Detect authentication-gated forms so owners can cover their dashboards, not only their public pages.
Try it in 60 seconds
- Open https://chudi.dev/tools/toolsmith in Chrome 152 for Testing with the WebMCP flag enabled.
- Ask the agent:
Make https://chudi.dev/toolsmith-fixtures/shop.html agent-ready. - Watch the activity strip fill with
profile_site,propose_tools, anddraft_manifest. - Click Approve.
- Download the receipt-backed
webmcp.js.
Three fixtures are available:
- https://chudi.dev/toolsmith-fixtures/shop.html has a single POST add-to-cart form, so the tool gets a confirm gate.
- https://chudi.dev/toolsmith-fixtures/newsletter.html has a GET search form beside a POST subscribe form, one read-only tool and one gated tool.
- https://chudi.dev/toolsmith-fixtures/empty.html has no forms at all, so the proposal step returns nothing.
Why not just ask a chatbot
A chat window returns text. Toolsmith returns a file that runs on your own domain, and only you hold the click that activates it. Anyone can verify the result independently by calling verify_manifest_activation and reading the four fields of the receipt.
Built With
- javascript
- webmcp
Log in or sign up for Devpost to join the conversation.