Robin Saige we check the tools AI agents call

WebRun Browser Automation

ai.webrun/webrun

Run multi-step tasks in a real Chrome browser: persistent environments, live view, human takeover.

— the operator's own registry description reported

Publisher ai.webrun · first seen 2026-08-12 · endpoint https://api.webrun.ai/mcp

allow
verdict
mid-solo
cluster
ok_tools
answers
21
tools served

Dependency rating derived

allow — mid-solo — safe to depend on

Cluster mid-solo · distinctiveness 0.202 (typical). Every figure is a percentile or class within the 11,094-server censussee the whole spectrum.

Reach — can an agent get to it?
answersalive_tools
latency117 ms
vs populationtypical
protocolcurrent
authopen
Use — can it use it?
tools21
vs populationmid
capabilities1
harnessA
Trust — can it rely on it?
identitysolo
servers on its host1
verifiabilityunassessed
duplicate inventoryno
drift events0
answers trueno primary

🔏 Signed receipt rr_2815579c1956917600c12d8a · ed25519 · key rs-rcpt-2026-08 — this rating is tamper-evident; an agent gets the full signature from check_server and can verify it against the published key.

What kind of tools these are derived

Verification only means something relative to a tool's NATURE — an email-sender has no "true answer", a generator has no answer key. Classification evidence: classified from tool names/descriptions/annotations WE OBSERVED. What checking applies to each kind (the full methodology →):

naturetoolsmeaning what checking applies
action14changes the worldno true answer exists; we check the CONTRACT (destructive/read-only/idempotent declarations, error legibility) and never fire real actions
retrieval-public6serves public factstruth-checkable against a public source — the V-ladder applies in full
orchestration1routes other toolsidentity + fronted-service disclosure checks (gateway vs costume)

Tools last seen

browser_task create_agent create_session create_workflow get_task_status get_workflow guardrail_response list_agents list_environments list_sessions list_workflows pause_agent pause_session_task resume_agent resume_session_task screenshot send_task stop_session_task terminate_session trigger_workflow update_workflow

Harness readiness observed

Can an agent's harness pick this tool and call it correctly? Graded on the three things an agent reads — name, description, typed parameters. Band A — an agent can pick and call these reliably.

legibility checktools passingok
name is clear & specific21/21
has a description21/21
description is substantive21/21
parameters are typed21/21
parameters are described21/21

21 of 21 tools graded · 21 with a captured input schema. RS-008, Tier-1 — no domain knowledge, applies to any tool. “Alive” is not the same as “usable”.

Truth checks observed

Not in the Tier-2 trade lane, or not yet checked. Tier-2 re-derives a server's answers against published primary sources — see truth checks.

Protocol conformance observed

2025-06-18
protocol version
session model
2.0.0
server version webrun-browser

Capabilities: tools

Drift

No confirmed drift on record. Baseline set 2026-08-14; changes appear here after human review.

History observed

Every probe we made, oldest → newest (2 shown, 2026-08-12 → 2026-08-14). Green answered · amber answered-but-walled · red no useful answer. A gap in our cadence is a gap in coverage, not evidence about the server.

changelog (2 events)
datetypewhat changed
2026-08-14inventorytools 12 → 21
2026-08-12outcomefirst probe: ok_tools
raw probe records
probed (UTC) outcomehttpmsprotocol
2026-08-14T19:57:43Zok_tools2001172025-06-18
2026-08-12T05:33:00Zok_tools2001862025-06-18

Watch or embed this verdict

verdict badge

Operators: put the live verdict in your README — it updates with every census, links back here, and is a dated observation, never a warranty:

[![Robin Saige verdict](https://robinsaige.com/badge/ai.webrun/webrun.svg)](https://robinsaige.com/s/ai.webrun/webrun)

Depend on it? Subscribe to its change feed — outcome changes and confirmed drift, no account needed. Building on it? The full dossier as JSON — verdict, rating, truth checks, history — stable enough to gate CI on.

← overview