WebMCP for cybersecurity workflows

BubbleSurface

A dynamic WebMCP surface for cybersecurity applications

BubbleSurface lets a cybersecurity product expose the right agent capabilities at the right moment—while keeping sensitive actions under human and server-side control.

Human
· · ·
AI agent
· · ·
Security page
Live capability surfaceCurrent state
InvestigateStructured tools
ApproveHuman decision
ExecuteAfter approval
VerifyFresh result
Current tools exposed
inspect_incidentget_active_sessionsreview_evidence_timeline remove_approved_privilege

Sensitive capabilities remain unavailable until state and approval allow them.

What BubbleSurface gives a security product

Browser surface

Registers, refreshes and removes WebMCP tools on the live page.

Server enforcement

Reloads authoritative state and revalidates permissions, versions, approvals and applicability.

Human control

Keeps consequential actions gated behind explicit review and approval.

How humans and agents use it

Human

  • Uses the normal security application
  • Reviews important context
  • Approves, rejects or modifies consequential actions
  • Sees execution and verification results

Agent

  • Discovers tools through WebMCP
  • Investigates using structured capabilities
  • Prepares and proposes actions
  • Executes only when the capability becomes valid

Both act against the same live page, state and workflow.

How BubbleSurface works

Investigate → Propose → Approve → Execute → Verify

  1. 1

    Security application loads BubbleSurface

  2. 2

    BubbleSurface derives current WebMCP capabilities

  3. 3

    Agent discovers investigation tools

  4. 4

    Agent investigates and prepares a consequential action

  5. 5

    Human reviews the exact proposal

  6. 6

    BubbleSurface exposes the exact approved execution capability

  7. 7

    Agent executes; the server revalidates authority

  8. 8

    Execution disappears, verification appears, and the result is verified

See the surface change live

Watch an external agent investigate, request a sensitive action, wait for human approval, execute through the newly exposed capability, and verify the result.

Launch live demo →