What it does

WebMCPify Core Agent turns an existing web application into reviewed, secure, and browser-verified WebMCP capabilities.

A developer supplies a repository and running URL. A Strands agent coordinates WebMCPify Core through MCP to:

  1. discover routes, forms, handlers, APIs, authentication signals, state, and existing WebMCP tools;
  2. draft the smallest grounded capability set in a disposable workspace;
  3. audit access-control, origin, quota, privacy, and replay-protection declarations;
  4. surface the exact tools, tests, findings, and source patch for human review;
  5. apply only the approved patch and run the target's build checks; and
  6. exercise approved tools in a real browser and verify observable outcomes.

Why it matters

Developers preparing applications for AI agents must identify real actions, design grounded schemas, secure consequential operations, and prove the tools work. Doing that manually is repetitive and error-prone. Letting a coding agent edit a repository unchecked is not a safe substitute.

Core Agent automates the repetitive work while keeping consequential control with the developer. The agent cannot approve its own proposal: a separate local review interface creates an approval bound to the exact patch and task set.

Also, it is quite expensive(burning alot of tokens rather than picking the correct actions, insecure, no validation, no real browser testing and evaluation before and after the webmcp features are added, nothing like findind vunerabilities, audit, reporting issues that could allow rogue agent misuse the tools and many more when a neutral agent does it - the generation(only the generation). This helps fix that and more.

How we built it

Strands Agents SDK owns the planning and tool-use loop. It connects to Core's confined stdio MCP server, chooses among normalized workflow tools, maintains the conversation across the human-review boundary, and explains the resulting evidence.

Core uses a selected coding provider inside a disposable copy of the target repository. The target checkout remains unchanged until human approval. Core then validates the exact approved patch, runs the target build, exercises WebMCP capabilities through a real browser, and saves independent evidence.

Key features

  • Strands-powered interactive agent with native MCP integration
  • Source-grounded route and capability discovery
  • Disposable patch generation workspace
  • Security checkpoint for identity, authorization, origin, quota, privacy, and replay controls
  • Trusted human review outside model control
  • Exact-patch approval enforcement
  • Build validation and rollback
  • Chrome DevTools MCP and Playwright browser execution
  • Independent outcome verification
  • Optional durable Temporal workflows

Architecture

Developer intent → Strands Core Agent → confined Core MCP server → discovery and disposable draft → security audit → trusted human review → exact approved patch and build → isolated browser test → independent evidence

How we used Codex

Codex helped inspect the existing architecture, implement the Strands integration, strengthen the MCP review boundary, write focused tests, update documentation, create submission assets, and run the full verification suite. Core can also use an authenticated Codex CLI as one supported coding provider.

Testing

Automated verification requires no cloud credentials:

git clone https://github.com/improvisus-webmcp/webmcpify-core.git
cd webmcpify-core
git switch hackathon/agents-for-humans-strands
pnpm install
pnpm typecheck
pnpm test
npm pack --dry-run

A real agent run requires Node.js 22+, credentials for a Strands-supported model, an authenticated Core coding provider, and a running target application:

pnpm agent -- --path /path/to/web-app --url http://localhost:3000 --provider codex

Challenges and learning

The hardest part was preserving a real human authority boundary while adding an autonomous planning loop. We exposed review as a non-blocking MCP action and status query, but only the trusted local UI can persist approval. The agent receives no unrestricted shell or direct repository-editing tool, so it cannot bypass Core's patch identity checks.

Accomplishments

The complete Core and agent test suite passes locally. The public npm package stays small because the Node.js 22 Strands workspace is isolated from the Node.js 20 Core runtime.

What's next

Add more Strands model-provider examples, signed evidence exports, richer backend enforcement adapters, and reusable target fixtures.

Originality and third-party disclosure

The submitted Core repository began during the hackathon submission period. The Strands orchestration package was added specifically for this entry. The broader WebMCPify concept and website predate this agent integration. Third-party components include Strands Agents SDK, Model Context Protocol SDK, Chrome DevTools MCP, Playwright, Express, Commander, and optional Temporal libraries under their respective licenses.

Built With

  • chrome-devtools-mcp
  • model-context-protocol
  • node.js
  • playwright
  • strands-agents-sdk
  • typescript
  • webmcp
Share this project:

Updates

Submission history