Skip to main content
Glama

webability

Scan an HTML snippet

scan_html
Read-onlyIdempotent

Scan a raw HTML snippet or component markup without serving it — IN-PROCESS by default (jsdom + WebAbility detectors + axe-core): milliseconds, no browser, no network, so it fits inside a tight edit loop. Fragments are auto-wrapped into a document. Returns scan_page's three-tier shape (issues / incomplete / summary) with fix.op + fixability on every finding. jsdom has no layout, so visual-tier rules (contrast, target size, focus ring) are NOT evaluated — the dropped count is reported as skippedVisual; pass engine: "browser" to run the axe-core headless-browser path for those (slower, axe rules only, returns axe violations).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
htmlYesHTML content to test — a full document or a fragment
tagsNoWCAG tags to check (default ["wcag2a","wcag2aa","wcag21aa","wcag22aa"])
wcagNoOnly these WCAG criteria. A prefix selects the whole guideline ("1.4") or principle ("2").
rulesNoOnly these rule ids (WebAbility type such as "missing_alt" or axe rule id such as "image-alt"). See get_rules.
widthNoViewport width (browser engine only, default 1280)
engineNo"in-process" (default): jsdom, ms, structural rules. "browser": headless Chromium + axe-core, includes contrast.
formatNo"compact" prints one line per element with rule metadata once — far fewer tokens than the default JSON. Default json.
heightNoViewport height (browser engine only, default 800)
contextYesExplain in 15-25 words, in third person, why this tool is called and how it supports the user's goal. For analytics only. You MUST describe only the abstract purpose of the tool call. NEVER include, repeat, paraphrase, or infer personal, sensitive, or identifying information from the user request or tool results, including names, emails, phone numbers, IPs, IDs, or credentials. You MUST generalize specific entities into roles such as "a user", "the customer", or "an account". Example: "Retrieving a customer's recent orders to investigate a billing issue and help support determine the appropriate resolution."
llm_modelYesThe exact model identifier you (the assistant) are running as, taken from your system prompt or environment (e.g. "claude-opus-4-8", "gpt-5.2"). Used for analytics only. If you do not know your model identifier with certainty, pass "unknown" — never guess.
minImpactNoOnly findings at this severity or above (critical > serious > moderate > minor)
conversation_idNoEcho the conversation_id from the server's previous response. The server provides it on the first call — never invent one, and do not issue parallel tool calls until you have it.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Far exceeds the annotations, which only cover read-only/idempotent safety. The description discloses the execution engine (jsdom + WebAbility + axe-core), latency, no-network behavior, automatic fragment wrapping, the three-tier return shape with fix.op/fixability, the skippedVisual dropped count, and what the browser path changes. This is exactly the behavioral context an agent needs to pick an engine.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the key differentiator (in-process, no serving) and stays dense with information; every clause carries load. It is a single long paragraph, which makes it slightly harder to scan than a structured form, but there is little filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, yet the description explains the return shape (issues/incomplete/summary), per-finding fields, and the skippedVisual count, so the agent knows what comes back. Combined with 100% schema coverage and rich engine semantics, an agent has everything needed to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds genuine meaning: the default and tradeoffs of engine (in-process structural vs browser contrast), and the browser-only nature of visual evaluation. It goes beyond restating the schema rather than simply duplicating it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (scan a raw HTML snippet/component markup) and immediately scopes it against the served-page alternative by noting it runs 'without serving it'. The agent can distinguish this from scan_page and visual_audit without opening a schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives a clear usage context ('fits inside a tight edit loop', milliseconds, no browser/network) and names the trigger for the alternative path (pass engine: "browser" for visual-tier rules). It references scan_page rather than explicitly telling the agent when to prefer it, so it stops short of full when-not guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.