webmcp-chrome-devtools-quickstart
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches project templates and official libraries from the WebMCP organization's GitHub and npm registries.\n- [REMOTE_CODE_EXECUTION]: Instructs the user to run a browser automation server via npx and configures a remote transport for tool definitions hosted at docs.mcp-b.ai.\n- [COMMAND_EXECUTION]: Provides standard setup and development commands using npm for dependency management and local server execution.\n- [PROMPT_INJECTION]: Identifies an indirect prompt injection surface where the AI agent interacts with arbitrary web content using powerful tools like evaluate_script and click without explicit boundary markers.\n- [DATA_EXFILTRATION]: Includes an example tool demonstrating how to perform legitimate network requests to an external weather API from within a registered browser tool.
Audit Metadata