The Standard Library for the Agentic Web — verified MCP tools for any AI Agent.
ProtocolBox provides 8 tools with complete input schemas and descriptions for all tools. Naming follows verb_noun conventions (heal_json, safe_math, remember, recall, scrape, web_search, get_time, get_transcript). However, descriptions are concise but lack LLM-optimized depth, they explain WHAT but not WHEN or WHY to use the tool. Parameter descriptions are present but minimal (typically 1 - 2 sentences). Output schemas are not documented in the source code. Error handling is basic, no recovery guidance or actionable error messages. The tools are well-composed and single-purpose, but descriptions fall short of production baselines (target 50 - 200 chars per description; these average ~80 chars, which is lean). No tool annotations (readOnlyHint, destructiveHint) despite clear read/write risk distinctions. The 'remember' tool has WRITE risk but no confirmation or dry-run pattern.
Get the current real-world time in a specified timezone. Returns the time in ISO 8601 format (YYYY-MM-DD HH:MM:SS TZ).
Fetch the English transcript of a YouTube video. Extracts the video ID from the URL, fetches the transcript, and returns it as a single clean block of text.
Attempt to repair malformed JSON and return a valid Python dict. Handles common LLM output issues: trailing commas, unquoted keys, single quotes, truncated output, and more.
Retrieve a value from persistent memory by key.
Store a key-value pair in persistent memory. Data is saved to ~/.protocolbox/memory.json and persists across sessions.
Safely evaluate a mathematical expression without using eval(). Supports basic arithmetic (+, -, *, /, **, %) and math functions (sqrt, floor, ceil, abs, sin, cos, tan, log).
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). The 'remember' tool is marked WRITE risk but the tool definition has no destructiveHint annotation to signal this to clients. Other tools are READ_ONLY but lack readOnlyHint.
Output schemas not documented. Tool descriptions do not specify what fields are returned. LLMs cannot infer output structure, heal_json returns dict, web_search returns formatted results, but the exact field names/types are not declared in tool metadata.
No error handling guidance. Tools return error dicts but do not guide the LLM on recovery. E.g. heal_json returns {'error': 'Failed', 'input_snippet': ...} but does not suggest next steps. No categorization of errors as retryable vs. user-fixable.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 66 | 2026-07-28+ | v2 |
Fetch a web page and return its content as clean Markdown. Strips scripts, styles, and footers for token-efficient reading.
Search the web using DuckDuckGo and return formatted results. Allows an Agent to query the live web for up-to-date information without tracking or ads.
Descriptions are lean on context. 'Store a key-value pair in persistent memory' lacks guidance on WHEN to use remember vs. other persistence patterns. Descriptions do not explain prerequisites or relationships to other tools (e.g., recall depends on prior remember calls).
No confirmation or dry-run pattern for destructive/persistent writes. The 'remember' tool modifies persistent state (~/.protocolbox/memory.json) with no confirmation step or ability to preview the change. Agents make mistakes, a dry-run would prevent data loss.
Parameter constraints not formalized. web_search has a 'max_results' parameter with no type bounds (min/max). get_time accepts arbitrary timezone strings with no enum or validation guidance. These open the door to invalid LLM inputs.