WebMCP: your website becomes a tool the browser agent calls — read the fine print
A Google/Microsoft-backed proposal lets your page hand an AI agent real callable tools instead of screenshot-and-guess. Chrome's already trialing it. But it's a W3C draft (not a standard), the API is churning, and the security fine print is stark: tools run with your logged-in auth and there's no mandated consent model. Clever, and a new attack surface — both at once.