01 · DISCOVER
Find every tool
registerTool on document or navigator, aliases included. nextjs-webmcp and webmcp-react definitions. Forms with toolname in JSX and plain HTML.
Scanning src/ · 6 tools · 3 flagged
A SECURITY LINTER FOR WEBMCP
Your site is starting to hand actions to AI agents. agentfrisk X-rays your source, finds every WebMCP tool you expose, works out what each one actually runs, and flags the dangerous ones before they ship.
$ npx agentfrisk scan
NEW TO WEBMCP?
A one-minute version for anyone who has not met WebMCP yet.
WebMCP is a new browser standard. A website registers tools, such as search_products or refund_order, on document.modelContext, and an AI agent in the browser can call them for the user.
A tool that deletes an account, moves money or returns a password hash can be called by an agent that misread the page or was steered by injected text. Nothing stops it unless the tool asks the user first.
Point it at your project. It finds every tool, works out what each one really does, and flags the risky ones with a fix. It runs in your terminal and in CI, and it never executes your code.
Agents will press every button your site hands them.
agentfrisk checks the buttons first.
rules, each with a fix you can paste
ways to define a tool, all understood: imperative, library, forms
lines of your code executed. It is pure static analysis
command to run. Exit code 1 fails the build
Static analysis on the TypeScript compiler API. It reads, it never executes.
01 · DISCOVER
registerTool on document or navigator, aliases included. nextjs-webmcp and webmcp-react definitions. Forms with toolname in JSX and plain HTML.
02 · CLASSIFY
DB deletes, raw SQL, POST and DELETE requests, Stripe refunds. Followed one call deep across imports. The handler body beats the name.
03 · CHECK
Seven focused rules. Readable report, JSON, or SARIF for GitHub code scanning. Exit code 1 when something crosses your line.
GET STARTED
Node.js 20.19 or later. Nothing to configure for a first run.
$ npx agentfrisk scanNo install needed. It scans the current folder, skipping node_modules, dist and build output.
Every tool is listed with what it does. Each finding names the rule, explains the risk and gives a fix. Exit code 1 means an error was found.
$ npx agentfrisk scan . --sarifApply the fix or suppress a finding on purpose. Then upload SARIF in CI so new risky tools show up on pull requests.
THE SCAN SHEET · 7 CHECKS
Grouped by file. Every tool, its effect, every finding, and the fix. Same data as JSON or SARIF.
CI
Upload SARIF and each dangerous tool lands as an annotation on the exact line. The job fails on errors; add --fail-on warning to be stricter.
Destructive tool "delete_account" runs without asking the user to confirm. Fix: set annotations: { consequentialHint: true }.