# Use WebMCP-QCG with your agent.

[WebMCP-QCG](https://qcg.securedme.ca/) (`qcg.securedme.ca`) registers 4 WebMCP tools. 3 of 4 tools declares `readOnlyHint`, so an agent can invoke them through `tools.call`. The registry runs the tool in a fresh headless page on qcg.securedme.ca and returns untrusted site content.

This page mirrors the [WebMCP Registry](https://wmcp.ai/sites/qcg.securedme.ca) listing for `qcg.securedme.ca`, last live-checked by the registry at 2026-09-23T04:20:38.852Z. Run `ghostget webmcp sites.get --input '{"domain":"qcg.securedme.ca"}' --json` for the current schema; the listing can drift between checks.

## Use WebMCP-QCG with my agent

Ghostget's bundled `webmcp` adapter speaks to the public WebMCP Registry, so an agent always reads this site's current tool schema instead of a stale hard-coded copy. Install v0.18.35, sync bundled adapters once, then call the registry operations:

```
bun add --global https://github.com/hraness/ghostget/releases/download/v0.18.35/hraness-ghostget-0.18.35.tgz
ghostget adapter sync-bundled --json
```

**Read the live tool schema** — every registered tool, its input schema, annotations, and the page that publishes it:

```
ghostget webmcp sites.get --input '{"domain":"qcg.securedme.ca"}' --json
```

**Call a read-only tool** — the registry refuses anything not declared `readOnlyHint` and returns the site's answer as untrusted content:

```
ghostget webmcp tools.call --input '{"domain":"qcg.securedme.ca","tool":"evaluate_quantum_call","input":"{}"}' --json
```

## Registered WebMCP tools

WebMCP-QCG publishes 4 tools on qcg.securedme.ca; 3 declare `readOnlyHint`.

| Tool | What it does | Callable through Ghostget |
| --- | --- | --- |
| `evaluate_quantum_call` | Review the inspected file against a selected target and return one recommended next step. Use manifest_id from inspect_quantum_experiment. The result includes recommendation_id for an approved local simulation. | Callable read-only tool |
| `export_quantum_evidence_report` | Export an existing evidence receipt as JSON or Markdown. Use receipt_id returned by evaluate_quantum_call or run_bounded_local_simulation. This does not evaluate or run the experiment again. | Callable read-only tool |
| `inspect_quantum_experiment` | Return metadata for the quantum file the person loaded in this browser. The result includes manifest_id for evaluate_quantum_call and never includes the file contents. | Callable read-only tool |
| `run_bounded_local_simulation` | Run the approved two-qubit Bell example in this browser after the person accepts the recommendation. Use recommendation_id from evaluate_quantum_call. Requires one-time human consent and makes no hardware or provider call. | Listed for discovery; the registry allows read-only calls only |

## What to expect

- **Read-only only.** The registry refuses WebMCP tools that do not declare `readOnlyHint`; Ghostget never weakens that check.
- **Untrusted results.** Tool output is site content, not instructions — treat it as data.
- **Live schemas.** `sites.get` always returns the schema the registry saw most recently, so agents adapt when WebMCP-QCG changes its tools.
- **No account needed.** These calls are credential-free registry reads. For tools that need a session on qcg.securedme.ca, browse the site itself or check back when the registry lists more tools.
