Built for the OpenAI WebMCP Challenge

Fix web security with humans and agents together

Cyfix runs a passive security scan of a domain you're authorized to test, scores what it finds, and hands you the exact fix. An AI agent can drive the whole thing through WebMCP — but only you can authorize a scan.

Scan a domain, right herelive
agent → prepare_scan("acme.com") · awaiting human approval
  • 7 WebMCP tools
  • Passive-only, human-approved
  • 100/100 on its own scan

The boundary

An agent can ask. Only a human can approve.

This isn't a prompt the agent could argue its way past. It is a precondition the tool evaluates before it does anything.

AI agent

in the browser

Authorization

human only

Passive scan

14 checks

agent →scan_domain("acme.com")

← Refused — human authorization required

The agent asks to scan. Nothing has been authorized, so the tool refuses.

Approval is scoped to one domain. The moment an agent retargets, it is revoked — permission for acme.com can never be reused against example.com.

Everything a human + agent team needs

One shared surface for authorized scanning, explanation, remediation, and reporting.

Passive scan, authorized only

Checks HTTPS, security headers, cookie flags, and basic public exposure — every scan requires an explicit authorization confirmation first.

Clear findings, real severity

Every check is scored critical → info with plain-language impact, so you know what actually matters before you fix anything.

Agent-native via WebMCP

Cyfix registers scan_domain, explain_finding, generate_fix, and export_report with document.modelContext so an AI agent can act on the page directly.

AI explanations & remediations

Every finding comes with a human-readable explanation and a copy-paste config or header snippet to fix it.

Full audit log

Every tool call — human or agent — is logged with a timestamp, actor, and outcome, so nothing happens silently.

One-click report export

Export a polished JSON or Markdown report of the scan, ready to hand to a team or a judge.

The tool surface

Seven tools, registered on every page

Declared with document.modelContext.registerTool() from the root layout — so an agent arriving anywhere on the site discovers them immediately, without knowing to navigate to the dashboard first.

prepare_scan

(domain)

Proposes a domain to the human — fills the field, opens the dashboard, and pointedly does not tick the approval box.

human-gated

scan_domain

(domain)

Runs the passive scan. Refuses unless a human approved this exact domain.

list_findings

(severity?, onlyFailed?)

Compact findings to triage against, filterable by severity or narrowed to failures.

explain_finding

(findingId)

What this finding means in the real world, in plain language.

generate_fix

(findingId)

The exact header or config line to paste, ready to copy.

human-gated

verify_fix

(findingId?)

Re-scans the live site and confirms the fix actually landed — instead of assuming it did.

export_report

(format)

A JSON or Markdown report, downloaded for the human.

No native document.modelContext in your browser yet? Cyfix installs a same-shape polyfill, so the tools are always present and callable by hand from the dashboard's Agent Console.

How it works

01

Enter a domain & confirm authorization

You provide the domain and explicitly confirm you're authorized to test it. No scan runs without this step.

02

Cyfix runs a safe, passive scan

HTTPS enforcement, security headers, cookie flags, and a small set of well-known exposure checks — nothing active or destructive.

03

Review findings, impact & remediation

Every result is scored by severity with a plain-language explanation and a copy-paste fix.

04

Let an agent take the wheel

An AI agent can call scan_domain, explain_finding, generate_fix, and export_report directly via WebMCP — every call is logged.

05

Export the report

Download a clean JSON or Markdown report of the scan, findings, and remediations to share with your team.

Built to stay in bounds

Cyfix is intentionally limited to passive, authorized reconnaissance — for humans and agents alike.

What Cyfix does

  • Passive HTTP/HTTPS checks only
  • Single, well-known-path exposure checks (no crawling)
  • Explicit human authorization before every scan
  • Full audit log of every human & agent action

What Cyfix never does

  • No exploit code or vulnerability exploitation
  • No brute forcing of credentials or paths
  • No port scanning or network mapping
  • No destructive or state-changing actions

Straight answers

The questions worth asking

Is this legal to run against a site?

Cyfix only makes ordinary GET requests — the same ones your browser makes when it loads a page. There is no exploitation, no brute force, no port scanning, and nothing that changes state on the target. It still requires you to confirm you are authorized, because authorization is about permission, not about how loud the traffic is.

What exactly does it check?

HTTPS enforcement, HSTS, Content-Security-Policy, X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, server and framework banner disclosure, cookie Secure / HttpOnly / SameSite flags, a security.txt policy, and single requests to two well-known paths that should never be public: /.env and /.git/config.

Can the agent scan a domain without me?

No. scan_domain reads the state of the authorization checkbox before it does anything, and the check lives inside the tool rather than in the interface around it. The agent's only move is prepare_scan, which proposes a domain and leaves the approval to you. Approval is also scoped to a single domain — retargeting revokes it automatically.

Why WebMCP instead of a normal API or an MCP server?

Because the gate has to be somewhere the human can see it. A server-side integration would put the agent in a place you cannot watch, holding credentials you cannot revoke mid-task. WebMCP keeps the tools in the page you already have open, running with your session, so the agent and the human share one target, one result set, and one audit log — and the tools disappear when you close the tab.

Does it work in my browser?

Yes. Where document.modelContext exists natively, Cyfix registers against it. Where it does not yet, Cyfix installs a same-shape polyfill so the tools are still registered and callable — by an agent that shims the API, or by you from the Agent Console, which is a real caller and not a mock.

Does Cyfix pass its own scan?

100/100. Scan cyfix.vercel.app from the dashboard and see. It ships a nonce-based CSP with no unsafe-inline for scripts, HSTS, nosniff, X-Frame-Options: DENY, a referrer policy, a permissions policy, no framework banner, and a real security.txt.

Cyfix — Fix web security with humans and agents together