webmcp-register-tool

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill follows best practice guidelines for tool registration, emphasizing user interaction for sensitive operations and schema validation for inputs.
  • [EXTERNAL_DOWNLOADS]: Fetches technical specifications and documentation from the Web Machine Learning GitHub Pages repository, which is an established source for this technology.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an interface for processing agent-supplied data.
  • Ingestion points: execute(input, client) callback in navigator.modelContext.registerTool (SKILL.md).
  • Boundary markers: The API architecture uses inputSchema for JSON Schema validation of all inputs.
  • Capability inventory: Code examples demonstrate standard browser fetch usage for data retrieval and submission.
  • Sanitization: Recommends using inputSchema for validation and client.requestUserInteraction for human-in-the-loop authorization of destructive actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM