← WebMCP KitCONTENT HISTORY

Update to WebMCP Kit

Snapshot Sep 30, 2026 · 23:14 UTC · version 0.4.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "description": "Check that a locally running site's WebMCP tools register and execute correctly. Use to verify WebMCP tools, confirm document.modelContext tools appear on the right pages and auth states, or test @nekuda/webmcp-sdk tools in a browser.",
  "included_files": [],
  "name": "verify",
  "skill_md_contents": "---\nname: verify\ndescription: Check that a locally running site's WebMCP tools register and execute correctly. Use to verify WebMCP tools, confirm document.modelContext tools appear on the right pages and auth states, or test @nekuda/webmcp-sdk tools in a browser.\nargument-hint: \"[base URL of the running site]\"\n---\n\n# WebMCP Kit — verify\n\nRuntime check that a site's WebMCP tools register and work. Runs standalone, and is the ladder the `implement` skill uses in its Phase F.\n\n## Before you start\n- The site must run locally. Use its own runbook (lifecycle commands, base URL, test identities) if it ships one; otherwise its own dev script. Never assume a harness exists.\n- WebMCP must be active in the browser: Chrome 150+ with the WebMCP flag (`chrome://flags`, enabled for localhost) — or load `@mcp-b/webmcp-polyfill` as backup. Confirm `document.modelContext` (or `navigator.modelContext` on Chrome 149) exists before testing.\n- Browser automation is tool-agnostic: a chrome-devtools MCP, a CLI driver, or a guided manual check all work.\n\n## Ladder\n1. **Boot.** Site starts; the baseline page renders; no *new* console errors versus a clean load.\n2. **Discover.** On each declared page and auth state — check anonymous **and** signed-in where relevant — list the registered tools. Confirm each tool appears where it should, is **absent** where it should not (logged-out account tools, wrong-role tools), and unregisters on its declared exits (empty cart, logout). Navigation is the expensive unit: visit each page × auth state **once** and settle every tool's expectations for that page in that single pass — never one navigation per tool.\n3. **Invoke read-only.** Call read-only tools with sample inputs; check the returned data **and** the visible ui_effect. Batch by page: invoke a page's tools in the visit that discovered them.\n4. **Invoke state-changing.** Only against local/dev/seeded data, with an explicit go-ahead. **Never** fire real POSTs at third-party or production services. No safe way to invoke → don't; report could-not-verify.\n\n## Report — one state per tool\n- **verified** — registered and invoked as declared (note the rung reached).\n- **failed** — did not register or errored; must be fixed or dropped, never shipped.\n- **could-not-verify** — plausible but unproven (no browser, or no safe way to invoke); ships flagged.\n\nPrint a per-tool table and restate any could-not-verify items.\n"
}

SHA-256 of public snapshot: 6048145f4e31c255bec1ab59d7e16c0740991682e0e9de7baa72f7c89b9f1718