WebMCP Threat Atlas
BuildingHow WebMCP tools get attacked, and what correct defense looks like.
the lab
Every experiment, shippable or still on the bench. Filter by where it stands, what it's about, or whether it's a tool or a publication.
What the web actually deploys, not what the docs say should matter.
crawlspacelabs.dev/schema-watchHow WebMCP tools get attacked, and what correct defense looks like.
Finds product pages whose JSON-LD claims reviews the page never shows.
Some text on a blockchain can never be deleted. The question is who is reading it.
crawlspacelabs.dev/cold-storageIs that AI crawler who it says it is, checked against the operator's own published ranges.
bot-or-not.crawlspacelabs.dev