
This working paper examines a narrow but consequential WebMCP question: what happens between an AI agent proposing a state-changing action and a provider executing it? Across a controlled 576-run study spanning Claude, Gemini, and GPT, the baseline condition produced 165 unauthorized provider executions among 175 attempted state-changing calls. With a transaction-specific pre-provider authorization intervention enabled, 200 unauthorized attempts were blocked, 35 authorized attempts executed, and no unauthorized execution was observed across 235 attempts. In this frozen experimental environment, execution-boundary controls changed whether unauthorized model-generated transactions reached the provider. The study does not test Chrome’s origin-trial implementation, live commerce, prompt-injection resistance, semantic alignment with user intent, or universal WebMCP compatibility. Outcomes were determined from preserved execution records and provider-side evidence rather than model narration. The paper includes the experimental matrix, model and family level results, integrity checks, invalid-study disclosure, limitations, and claim boundaries. Proprietary implementation details and nonpublic study materials are not included.
exact-term authorization, agentic web, transaction assurance, provider-boundary enforcement, WebMCP, AI agents, Web Model Context Protocol, execution-boundary enforcement, tool execution, structured web tools, state-changing tool actions, pre-commit verification, large language models, browser agents
exact-term authorization, agentic web, transaction assurance, provider-boundary enforcement, WebMCP, AI agents, Web Model Context Protocol, execution-boundary enforcement, tool execution, structured web tools, state-changing tool actions, pre-commit verification, large language models, browser agents
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
