Evaluator quick path · about 60 seconds
Test the WebMCP boundary, not just the interface
- Ask the agent to
summarize_metadata_risk. It receives counts and reason codes—not raw descriptions. - Ask it to
stage_metadata_reviewwith{"risk":"quarantine","maxRecords":3}. Three bounded records appear visibly below. - Ask it to
request_human_metadata_reviewforinstruction-001. The page opens raw text for the human, while the tool result still withholds it. - Ask it to
stage_safe_csv_exportwith{"risk":"quarantine"}. The agent can stage four safe structural rows; only the human can download.
What this proves: non-trivial WebMCP leverage · complete human/agent execution · a concrete prompt-injection boundary · a least-authority pattern that differs from generic click automation.
A safer human + agent boundary
Tool responses include IDs, lengths, risk labels, and reasons—never raw descriptions. An agent can open one record in the page for a human, but cannot approve, rewrite, publish, or silently download anything.
Risk summary
Human review queue
Eight synthetic records demonstrate clear, review, and prompt-injection quarantine paths.
| ID | Page | Risk | Description length | Reasons |
|---|
Human review
- URL
- Title
- Raw untrusted description (human-visible only)
- Scanner reasons
No approve/publish tool exists. The human decides what happens next.
Bounded export
Stage a CSV containing only safe structural fields. Download still requires a human click.