PromptArmor 解析 WebMCP 的工作机制与安全风险
What is WebMCP, and why does it matter?
PromptArmor 发布 WebMCP 解析文章,介绍这项让网站直接向 AI 智能体提供工具的技术的机制与采用情况。
原文系统拆解 WebMCP 的机制、厂商采用现状和治理、提示词注入等新增风险,可作为评估供应商 WebMCP 暴露面的参考框架。
See all sites with WebMCP
WebMCP adoption
WebMCP has seen substantial early adoption, led by major browser providers offering support, including Chrome, Edge, and Brave.
Agentic-browsing providers like ChatGPT and Cloudflare have added support as well, and vendors (like Shopify) who aim to improve their accessibility to AI agents are beginning to offer WebMCP tools.
As of October 6, 2026, webmcp.com (a registry that documents WebMCP use) listed 2,959 sites with WebMCP tools.
| Vendor | Adoption |
|---|---|
| Shopify | Tools automatically added to all Liquid storefronts; additional tools available for checkout. |
| ChatGPT | ChatGPT's built-in browser supports WebMCP, referred to as 'Site tools' |
| Chrome | Available in Origin trials (developers can sign up to add WebMCP to their sites) |
| Edge | Available in Origin trials (developers can sign up to add WebMCP to their sites) |
| Cloudflare | WebMCP is supported for Browser Run (agentic browsing) |
| Brave | WebMCP is supported |
What is WebMCP?
WebMCP tools, similar to traditional MCP tools, define attributes like a name, description, expected inputs, and capability hints (e.g., whether a tool is read-only or write-capable). Each WebMCP is backed by code on the site, which defines what the site does when the agent calls the tool.
For example, a commerce site may offer tools like search_products and update_cart while a SaaS application could provide tools like create_ticket, or update_record.
Here is how it works:
The user asks the agent to perform a task (in this case, buy a product)
The agent opens the vendor's site in the user's signed-in browser
The page offers tools to the agent which it can see as part of the page
The agent calls
update_cartinstead of clicking through the pageThe site runs the add-to-cart tool in the user's session and returns the result
Assess WebMCP risks in your vendorsAssess WebMCP risks in your vendors
What risks does WebMCP introduce?
WebMCP introduces a number of net-new considerations for organizations to address. Below is a breakdown of the top risks to be aware of:
Governance: A vendor or its platform can add or change tools in frontend code, with no OAuth app, MCP server, or integration request for security teams to review.
Prompt injection: An untrusted site can use tool descriptions and results to steer the agent without changing the visible site, including convincing it to call tools that submit data to the site.
Web application security: Tools are page JavaScript, so a cross-site scripting flaw, a compromised third-party script, or a malicious extension can register, rewrite, or call them under the user's session.
Misconfiguration: As in traditional MCP, tools labeled as 'read-only' may actually perform write actions. AI clients often rely on these declarations of write/read to determine the default setting for whether human-in-the-loop approval is required before a tool is called.
Operational drift: WebMCP tools and the human UI can become disjoint, so a human's request based on the visible page can lead the agent to take an action via a tool that the user did not intend.
Need the full-detail threat model?
How is WebMCP different from regular MCP, or browser use?
WebMCP vs. traditional MCP
A traditional MCP server is an integration that an AI client connects to, which defines tools the agent can see and use in its session. WebMCP does not register tools in an agent's session; instead, its tools are part of websites the agent is currently visiting, and the agent can call them through the website.
WebMCP vs. browser use
Traditional browser agents use websites like humans do: inspect the page, find a button, click it, see what happened, and repeat. WebMCP lets the page offer agents a way to perform the key tasks on a page without figuring out how to use the user interface.
Get alerted when a vendor adds or changes the tools it exposes to agents
PromptArmor Threat Intelligence
Is your organization protected from AI in vendors?
PromptArmor continuously monitors across your portfolio of third party AI in vendors, skills, plugins, connectors, MCP servers, models and more.
We detect vulnerabilities and changes like this, surfacing risk before it becomes an incident.
来源:PromptArmor:Threat Intelligence · promptarmor.com