Public scan brief
BrowserMCP/mcp security scan
Partial no-execution triage for the public BrowserMCP repo. This is a heuristic scan of selected public text files, not a commissioned audit, vulnerability disclosure, or security certification.
RepoBrowserMCP/mcp
Score38/100 heuristic
Snapshot14 selected files scanned
Signals3 high / 0 medium / 2 low
Top findings
Browser-control MCPs sit at a sensitive trust boundary
The fetched slice produced high-priority review signals around remote listener exposure, write actions, and missing test visibility. A paid review would validate actual auth gates, local/remote mode defaults, browser session boundaries, and page-content injection handling.
HighRemote listener detected without nearby auth or permission signals.
HighWrite actions detected without obvious tool safety annotations.
HighNo obvious tests found in the fetched slice.
LowNo obvious CI workflow detected in the fetched slice.
Paid handoff
Convert this scan into a fixed-scope review
- Confirm local browser, extension, and MCP server trust boundaries.
- Review navigation, click, extraction, session, and download paths.
- Validate auth, allowlists, test coverage, and fail-closed behavior.
- Pay USD $1,000 only after written scope acceptance.