Implementation audit methodology
Your WebMCP implementation grade summarizes the tool definitions and registration details reviewed in your audit. The report shows what we inspected, the issues we found, and suggested fixes.
The scan checks your starting page and up to five additional pages. If only one page is checked, pages fail to load, or page suggestions cannot all be checked, the report shows a limited coverage notice. Its grade reflects the pages actually checked, not a complete inventory of your website.
Add an optional pages array to your existing /.well-known/webmcp.json, such as "pages": ["/products", "/products/example"]. Put a representative page of each type first. These pages must be on the same origin as your homepage after redirects.
This hint is a webmcp.com extension, not a WebMCP standard field. The scanner checks these suggestions first, then pages found in previous scans, sitemaps and homepage links. It still inspects each page for live tools.
We grade the issues found during the audit, then use the lowest grade as the overall result. For example, a missing tool description gives a B. Fixing it lets the next audit reflect the remaining findings.
We review both tools registered in JavaScript and tools defined through HTML forms. We look for clear descriptions and inputs that match the tool's purpose. Tools that take no inputs can omit an input schema, and output schemas are optional.
Our review follows Chrome's WebMCP best practices: explain actions and results clearly, define meaningful input types, and validate inputs in your application. WebMCP.com defines the grades below.
| Grade | What the audit found |
|---|---|
| A+ | The reviewed definitions and registration details passed the audit with no suggested changes. |
| A | Small, optional improvements to the tool definitions. |
| A- | A tool's description or expected result needs clarification, or its purpose overlaps with another tool. |
| B+ | Inputs need clearer types, units, or accepted values, or require avoidable conversions. |
| B | A tool is missing its description, or gives unclear or conflicting instructions about what it does. |
| B- | The scan captured an invalid schema or an invalid function for executing a tool. |
| C | A tool is missing its name, or the browser rejected its registration. |
Use the report to fix the issues found, then request another audit. Live definition grades currently use webmcp-implementation-v4. A fresh audit applies the current grading rules; older grades are not reused as current results.
Every tool is sorted into one of three categories — a trust ladder for how freely an agent can call it. The category is assigned automatically by classifying each tool's name, description, and input schema during the scan, so it's inferred, not declared by the site.