webmcp/analysis

FlightSweeper

A browser agent buys a sandbox flight within exact, revocable limits set by the traveler.

Aggregate 37
Leverage 10
Execution 9
Impact 9
Creativity 9

Each criterion 1–10, equally weighted; aggregate is their sum. Ranking is the pipeline's consolidated output.

01 Links & metadata

Category
travel-maps / travel-maps
Origin
origin unclear / built for the challenge
Access
no auth
Eligibility
LIKELY_ELIGIBLE / LIKELY_ELIGIBLE
Substitution
TRANSFORMATIVE / MAJOR_DELTA
Demo liveness
alive

Origin, access model, eligibility, and substitution are reviewer diagnostics, not judging criteria. Authentication requirements are not penalized.

02 The two blind reviews

Two independent reviewers scored this project blind, from a sanitized evidence packet. Scores are shown separately so the reasoning stays inspectable. A withheld score means the reviewers differed by more than two points.

Reviewer A (round 1)

confidence 70%
Leverage
9 /10

Structured mandates, trust annotations, independent policy evaluation, revocation, and idempotent execution address consequential-agent risks beyond generic browser control.

Evidence cited
  • About text describes untrusted supplier instruction rejection and exact stored mandate evaluation.
  • Repeated requests resolve to the original ticket rather than duplicate purchase.
Execution
7 /10

The single transaction story is coherent and covers adversarial content, denial, eligible purchase, refresh, and duplicate handling, though no video is supplied.

Evidence cited
  • Description gives a complete positive and negative transaction path.
  • Facts report demo alive and submitted frame sheets, but no video.
Impact
9 /10

Travelers have a clear desire to delegate tedious booking while retaining exact financial and policy authority; the safeguards directly address consequential failure modes.

Evidence cited
  • Traveler-set purchase cap, refundability, arrival, and connection rules.
  • Independent approval and revocation preserve human authority.
Creativity
8 /10

Combining agent purchasing with explicit authority boundaries, hostile supplier content, and idempotency is a strong original interaction design.

Evidence cited
  • Supplier prompt-injection example is handled as untrusted evidence.
  • Policy evidence and duplicate-safe ticket issuance are central mechanics.

Reviewer B (round 2)

confidence 87%
Leverage
8 /10

Structured mandate, trust annotations, policy evaluation, idempotency, revocation, and human-authorized consequential action address reliability and safety gaps that UI-driving agents handle poorly.

Evidence cited
  • Description specifies exact route/date/deadline/cabin/connection/refundability/cap/mode mandate.
  • Supplier prompt injection is treated as untrusted and cheaper ineligible quote is denied.
  • Repeated purchase returns original ticket; authority can be revoked without deleting evidence.
Execution
8 /10

The packet describes a complete transaction flow with denied and authorized states, and frames show flight search, evidence/activity, purchase denial, and later authorization; no real purchase occurs by design.

Evidence cited
  • Frames show LAX-to-JFK offers, eligibility/policy states, Activity and Evidence, and purchase denied/authorized banners.
  • Devpost packaging visibly shows ELIGIBLE, FAILS REFUNDABILITY, FAILS PRICE, sandbox-only, and revoke authority.
  • Description gives a specific adversarial supplier and idempotent ticket scenario.
Impact
9 /10

Travelers have a concrete desire to delegate booking while retaining exact constraints; safe sandbox execution and auditable denial/approval directly address trust and financial risk.

Evidence cited
  • Specific traveler mandate and booking flow.
  • Human can revoke future authority and inspect evidence.
  • Sandbox prevents card charge or airline order while demonstrating consequential-workflow controls.
Creativity
8 /10

The combination of browser-agent booking, policy authority, adversarial supplier content, idempotency, and evidence is an ambitious and memorable safety-oriented interaction model.

Evidence cited
  • Agent cannot authorize itself.
  • Trust annotations and policy evaluation are first-class.
  • Denied then eligible purchase states demonstrate nuanced control.

03 Review highlights

Standouts across reviewers

  • Strong authority model.
  • Prompt-injection resistance and idempotent transaction handling in one concise demo concept.
  • Excellent prompt-injection/trust-boundary demonstration.
  • Idempotent transaction and revocation are unusually concrete.

Red flags

  • Sandbox nature limits evidence of real booking integrations; frame details were not fully viewable due to vision rate limiting.
  • Frames do not show raw tool names or protocol payloads.
  • Sandbox behavior does not establish production airline integration.

04 Evidence

What each artifact proves is labeled on the artifact itself. A Devpost page capture is packaging evidence, not proof the product runs; video frames are evidence from the submitted demo, not live verification.

Devpost page capture for FlightSweeper
EX-01 Devpost page capture · packaging evidence, not runtime proof · source

EX-V Submitted demo video

Contact sheets from the ?s video the team submitted. This is what reviewers were shown; it demonstrates the product in motion but is not independent verification. · watch the original

Contact sheet 1 from the FlightSweeper demo video
EX-V1 Sheet 1 of 3 · reported video evidence
Contact sheet 2 from the FlightSweeper demo video
EX-V2 Sheet 2 of 3 · reported video evidence
Contact sheet 3 from the FlightSweeper demo video
EX-V3 Sheet 3 of 3 · reported video evidence