Google's WebMCP proposal replaces the screenshot-parse-click loop with structured tool contracts. Sites declare capabilities through the navigator.modelContext API, complete with schemas, parameters, and browser-enforced permissions. Agents stop guessing which button means "Buy Now" by squinting at raw HTML.
The fix is real where sites cooperate. Where they don't, where pages serve poisoned data to detected bots or embed hidden instructions targeting agent context windows, the old architecture persists untouched. WebMCP solves the tractable version of the problem. The intractable version doesn't notice.
