npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@infra-tools/agentic-ui-webmcp

v1.2.3

Published

WebMCP adapter for @infra-tools/agentic-ui — exposes the host app's ToolRegistry to an in-browser agent via the navigator.modelContext proposal. Tools register/unregister reactively; every inbound call is scope- and approval-gated. Optional plugin; stays

Readme

@infra-tools/agentic-ui-webmcp

WebMCP adapter for @infra-tools/agentic-ui — exposes the host app's ToolRegistry to an in-browser agent via the WebMCP (navigator.modelContext) proposal.

The mirror image of @infra-tools/agentic-ui-mcp (a Node MCP server): same ToolRegistry source, different (browser) transport. Phase 2 of the MCP-UI + WebMCP plan. Security model in ADR-050.

navigator.modelContext is a draft proposal. This adapter feature-detects it and degrades to a no-op (with one telemetry signal) when the browser doesn't implement it. No errors, no crashes — your app runs unchanged.

Install

npm install @infra-tools/agentic-ui-webmcp

Quick start

import { provideWebMcp } from '@infra-tools/agentic-ui-webmcp';
import { inject } from '@angular/core';
import { AGENTIC_ACTIVE_PERSONA, provideAgenticUi } from '@infra-tools/agentic-ui';

export const appConfig = {
  providers: [
    provideAgenticUi({ tools, widgets }),
    provideWebMcp({
      // Read your active persona so approval policies gate correctly.
      persona: () => inject(AGENTIC_ACTIVE_PERSONA)(),
    }),
  ],
};

That's it. Every tool visible through the current scope policy is mirrored into navigator.modelContext. The mirror is reactive — register a tool, federate a remote, or change the scope policy, and the WebMCP tool list re-syncs on the next change.

What it does

  1. Reactive registration — subscribes to ToolRegistry.signal(); registers each scope-visible tool with navigator.modelContext.registerTool({ name, description, inputSchema, execute }). Re-syncs (register new, unregister vanished) whenever the visible set changes.
  2. Schema fidelity — each tool's Zod schema is converted to JSON Schema (zodToWebMcpSchema) so the in-browser agent sees the full argument shape, not just the name.
  3. Scope enforcement — only tools the active persona can see are exposed (ToolRegistry.list/get apply the scope policy on read). A tool hidden from the persona is never registered, and inbound calls re-check.
  4. Approval gating — a tool with an agenticApproval policy whose required(args, ctx) returns true is not auto-executed; the call queues an Approval and returns a pending result, mirroring the chat-shell HITL intercept.
  5. Telemetry — emits agentic.tool_call.start/end (with webmcp.origin), agentic.webmcp.call_blocked, agentic.webmcp.call_queued_for_approval, and agentic.webmcp.unavailable.

Security model (ADR-050)

| Concern | Behaviour | |---|---| | Tool visibility | Scope-policy gated. Hidden tools never registered; inbound calls re-check. | | Privileged actions | Approval-policy gated — queued, not auto-executed. | | Arg integrity | Validated against the tool's Zod schema before the handler runs. | | Defense in depth | Like all client-side gating, server-side enforcement is still required for HITL-critical tools (standard ADR-008 note). |

API

  • provideWebMcp(options?) — wires the adapter. options: persona (getter), source (telemetry tag), modelContext (override for tests).
  • WebMcpService — the DI service; start() returns a disposer.
  • zodToWebMcpSchema(schema) — Zod → WebMCP JSON Schema.
  • getModelContext(nav?) — feature-detect helper.

License

Apache 2.0