Skip to content

Document cross-origin tool exposure and two-sided opt-in in Section 6.3.4 - #326

Open
jpagnucco wants to merge 2 commits into
webmachinelearning:mainfrom
jpagnucco:update-section-6-3-4
Open

jpagnucco wants to merge 2 commits into
webmachinelearning:mainfrom
jpagnucco:update-section-6-3-4

Conversation

@jpagnucco

@jpagnucco jpagnucco commented Sep 28, 2026 •

Copy link
Copy Markdown

Summary

Replaces the TODO placeholder in Section 6.3.4 (Violation of Same-Origin Boundaries) (#violation-same-origin-boundaries) with documentation covering:

  1. Pathways for Same-Origin Boundary Risks:
    • Direct cross-document / cross-origin tool exposure via getTools() and executeTool().
    • Agent-mediated cross-origin state transfer (noting that this is a general agentic browsing consideration rather than a WebMCP-specific threat).
  2. In-Page Cross-Origin Tool Exposure and the Two-Sided Opt-In Model:
    • Embedder Delegation via Permissions Policy (allow="tools"): Gated behind the "tools" policy-controlled feature ('self' default allowlist).
    • Tool Provider Opt-In (exposedTo): Explicit allowlisting of potentially trustworthy origins in ModelContextRegisterToolOptions.exposedTo.
    • Tool Consumer Opt-In (fromOrigins): Explicit opt-in by the caller via ModelContextGetToolOptions.fromOrigins.
    • Rationale and code example illustrating how mutual consent prevents unsolicited tool-list pollution and unauthorized cross-origin tool invocation.

Preview | Diff

@anssiko

anssiko commented Sep 29, 2026

Copy link
Copy Markdown
Member

@jpagnucco to clear the automated ipr check for this and any future contributions, please check that your W3C account is associated with your GH account. That'll fix it.

@victorhuangwq

victorhuangwq commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Hey! Thanks for getting the draft started on this @jpagnucco, been left for a TODO for a while. I like the content here, but now that I'm reading the whole section together, the title and framing feel a bit off. Titling it "violation" feels wrong when most of what's described is the careful design that prevents cross-document exposure without permission.

I would prefer to retitle this section to something like "Cross-origin tool exposure" and reorder what you currently slightly have so it leads with the consideration and ends with the residual risk. Roughly:

  • Your consideration about same origin policy and the one right after it about what a cross-origin exposure means in the context of webmcp

  • How WebMCP helps enforce it, and why that matters: your paragraph on why both sides have to agree, and the code sample.

  • And then the residual risk: You already have the agent-mediated one (the non-WebMCP specific one) Is there anything else we should be calling out for the direct exposure path?

@victorhuangwq victorhuangwq left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update, this looks good to me! I cross-checked it against the current spec and I didn't spot any inconsistencies.

@domfarolino tagging you for review and merge.

Comment thread index.bs
</p>
<ul>
<li>
<strong>Direct Cross-Origin Exposure</strong>: Even when two [=origins=] mutually opt in via {{ModelContextRegisterToolOptions/exposedTo}} and {{ModelContextGetToolOptions/fromOrigins}}, they remain separate trust domains: tool providers must still treat caller-supplied arguments as untrusted input, and callers must treat cross-origin tool descriptions and return values as untrusted data (see [[#prompt-injection]]). Additionally, because {{ModelContext/getTools()}} aggregates tools across all descendant frames at the [=origin=] level, callers should inspect {{RegisteredTool/origin}} and {{RegisteredTool/window}} on each {{RegisteredTool}} to disambiguate tools when multiple subframes or [=origins=] expose tools with the same {{RegisteredTool/name}}.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good callout.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants