Ghostget

WebMCP Registry site · v0.18.35

Use XXL with your agent.

XXL (xxl.fi) registers 2 WebMCP tools. 1 of 2 tools declares readOnlyHint, so an agent can invoke it through tools.call. The registry runs the tool in a fresh headless page on xxl.fi and returns untrusted site content.

This page mirrors the WebMCP Registry listing for xxl.fi, last live-checked by the registry at 2026-09-22T00:21:12.567Z. Run ghostget webmcp sites.get --input '{"domain":"xxl.fi"}' --json for the current schema; the listing can drift between checks.

Use XXL with my agent

Ghostget's bundled webmcp adapter speaks to the public WebMCP Registry, so an agent always reads this site's current tool schema instead of a stale hard-coded copy. Install v0.18.35, sync bundled adapters once, then call the registry operations:

bun add --global https://github.com/hraness/ghostget/releases/download/v0.18.35/hraness-ghostget-0.18.35.tgz
ghostget adapter sync-bundled --json

Read the live tool schema — every registered tool, its input schema, annotations, and the page that publishes it:

ghostget webmcp sites.get --input '{"domain":"xxl.fi"}' --json

Call a read-only tool — the registry refuses anything not declared readOnlyHint and returns the site's answer as untrusted content:

ghostget webmcp tools.call --input '{"domain":"xxl.fi","tool":"get_agent_authentication_status","input":"{}"}' --json

Registered WebMCP tools

XXL publishes 2 tools on xxl.fi; 1 declare readOnlyHint.

ToolWhat it doesCallable through Ghostget
get_agent_authentication_statusWhether this site publishes OAuth/OIDC discovery metadata for AI agents.Callable read-only tool
search.executeSearch the XXL storefront product catalog for a query string and open the search results page.Listed for discovery; the registry allows read-only calls only

What to expect

  • Read-only only. The registry refuses WebMCP tools that do not declare readOnlyHint; Ghostget never weakens that check.
  • Untrusted results. Tool output is site content, not instructions — treat it as data.
  • Live schemas. sites.get always returns the schema the registry saw most recently, so agents adapt when XXL changes its tools.
  • No account needed. These calls are credential-free registry reads. For tools that need a session on xxl.fi, browse the site itself or check back when the registry lists more tools.

Ghostget 0.18.35 · MIT · Source on GitHub · About · Contact · Privacy · llms.txt