WebMCP tool community service
Risk level
medium
40/100

WordLift AI Audit

WordLift AI Audit is a community-maintained WebMCP tool from WordLift. Anomity scores its risk at 40 out of 100 (medium).

browser:control network:outbound

Analysis summary

WordLift AI Audit is a community-maintained WebMCP tool from WordLift. Anomity scores its risk at 40 out of 100 (medium).

A live service that runs an agent-readiness review of a site — checking structure, machine-readable metadata, and how legible the page is to an AI agent — and exposes that review itself as WebMCP tools, so an agent can request the audit and read the findings without a human in the loop.

It is one of the few production services in the WebMCP ecosystem rather than a demonstration, which is why it is catalogued. It declares outbound network access and browser control. The data-flow question to ask before pointing it at anything sensitive is the usual one for hosted analysis tools: the URLs you submit, and whatever the crawler can reach from them, leave your perimeter.

Why this entry scored 40 out of 100

This profile starts at the catalog's neutral base of 50. Because the entry is community-maintained, trust adjusts the score by -10. The entry declares no high-risk capabilities on its own, so capabilities add nothing. It matches no dangerous capability combinations. The clamped result is 40, placing it in the medium band.

See the full scoring formula →

Findings

  • Established community project Trust offset
    Contribution to score: -10

Capabilities

Every capability the entry declares, with the security implication of each.

  • browser:control Browser control
    Drives a browser session. Combined with credential access can impersonate the user on web services.
  • network:outbound Outbound network
    Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access.