WebMCP Registry site · v0.18.35
Use Patronus WebMCP Security Scanner with your agent.
Patronus WebMCP Security Scanner (webmcp.patronus.studio) registers 6 WebMCP tools. 4 of 6 tools declares readOnlyHint, so an agent can invoke them through tools.call. The registry runs the tool in a fresh headless page on webmcp.patronus.studio and returns untrusted site content.
This page mirrors the WebMCP Registry listing for webmcp.patronus.studio, last live-checked by the registry at 2026-09-21T21:32:22.022Z. Run ghostget webmcp sites.get --input '{"domain":"webmcp.patronus.studio"}' --json for the current schema; the listing can drift between checks.
Use Patronus WebMCP Security Scanner with my agent
Ghostget's bundled webmcp adapter speaks to the public WebMCP Registry, so an agent always reads this site's current tool schema instead of a stale hard-coded copy. Install v0.18.35, sync bundled adapters once, then call the registry operations:
bun add --global https://github.com/hraness/ghostget/releases/download/v0.18.35/hraness-ghostget-0.18.35.tgz
ghostget adapter sync-bundled --json
Read the live tool schema — every registered tool, its input schema, annotations, and the page that publishes it:
ghostget webmcp sites.get --input '{"domain":"webmcp.patronus.studio"}' --json
Call a read-only tool — the registry refuses anything not declared readOnlyHint and returns the site's answer as untrusted content:
ghostget webmcp tools.call --input '{"domain":"webmcp.patronus.studio","tool":"get_scan_details","input":"{}"}' --json
Registered WebMCP tools
Patronus WebMCP Security Scanner publishes 6 tools on webmcp.patronus.studio; 4 declare readOnlyHint.
| Tool | What it does | Callable through Ghostget |
|---|---|---|
get_scan_details | Open Details and return the latest completed scan of the requested kind in this page session, without another network request or scan. Use after scan_mcp_server or scan_url (or a scan through the UI). kind="mcp" returns a JSON string: { url | Callable read-only tool |
scan_file | Scan a file previously uploaded with upload_file or the Patronus repository plugin. Pass only its opaque file_id, never file content, a local path or a filename. Returns a JSON string: { filename: string, verdict: "attack" | "benign", confi | Listed for discovery; the registry allows read-only calls only |
scan_mcp_server | Scan descriptions from a public HTTPS MCP endpoint, not an HTML page (use scan_url for pages). Inspects server instructions and advertised tools, prompts and resources without executing capabilities. Checks at most 25 entries, first 1,000 c | Callable read-only tool |
scan_text | Scan supplied text (1–1,000 characters) for prompt injection with Patronus Ark. Returns a JSON string: { verdict: "attack" | "benign", confidence: number, evidence: Array<{ start?: number, end?: number, text?: string }>, latency_ms: number | Callable read-only tool |
scan_url | Scan the complete normalized static body of one public HTTPS HTML page for prompt injection. Does not crawl links or execute JavaScript; use scan_mcp_server for MCP endpoint metadata. Returns a JSON string with safety_status ("attack" | "un | Callable read-only tool |
upload_file | Upload a local document without sending its bytes through tool arguments or model context. First open the Document tab and attach the authorized local file through the browser file chooser (Choose or drop a document). Then call upload_file | Listed for discovery; the registry allows read-only calls only |
What to expect
- Read-only only. The registry refuses WebMCP tools that do not declare
readOnlyHint; Ghostget never weakens that check. - Untrusted results. Tool output is site content, not instructions — treat it as data.
- Live schemas.
sites.getalways returns the schema the registry saw most recently, so agents adapt when Patronus WebMCP Security Scanner changes its tools. - No account needed. These calls are credential-free registry reads. For tools that need a session on webmcp.patronus.studio, browse the site itself or check back when the registry lists more tools.