@webmcp-today/mcp-bridge

MCPattestiert
v0.3.1io.github.robertn702UnknownAktualisiert vor 1 Mon.npmGitHub

Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.

Läuft in
ClaudeCursorCopilotGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Attestierter Build
Eine verifizierte Herkunfts-Attestation bindet dieses Artefakt an das gelistete Repository. Den Eintrag hat noch niemand beansprucht — das belegt, wo der Code gebaut wurde, nicht, wer dahintersteht.
vor 1 Mon.Letzte Aktualisierung
Liest diese Zugangsdaten
  • WEBMCP_TODAY_API_KEYAPI-Schlüsseloptional

    Optional WebMCP Today API key for publishing and package pins

Vom Autor in der offiziellen MCP-Registry angegeben. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paket
Autorio.github.robertn702
LizenzUnknown
Version0.3.1
Quellenpm+mcp-registry
Trust-Status
A
85/100Vertrauenswürdig
✓Im Forge-Index gelistet+10/10
✓Identität verifiziert · attestierter Build+20/20
—Ed25519-Publish-Signatur+0/5
→ Wird automatisch ergänzt, wenn der Publisher `forge publish` ausführt
—Domain-Verifizierung+0/5
→ Publisher: hinterlege /.well-known/forge.json auf der Paket-Homepage mit { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm-Maintainer-Übereinstimmung+0/5
→ Publisher: trage den verifizierten GitHub-Login als Maintainer des npm-Pakets ein (npm owner add <login>)
✓CVE-Scan · sauber+30/30
✓Statische Analyse · sauber+20/20
Füge das in Claude Code, Cursor oder einen beliebigen KI-Assistenten ein, um alle Lücken zu schließen
StatusIdentität verifiziert
PublisherNicht verifiziert
SignaturNicht signiert
Domain—
Herkunft✓ Sigstore-verifiziert · 60e3660
Abhängigkeiten✓ 60 aufgelöst+ · keine verwundbar
Tool-Oberfläche17 Tools · 1 privilegiert
Sicherheits-Scan✓ Sauberv0.3.1 · vor 8 TWie gut funktioniert dieser Scan?
EvaluierungenKeine
Indexiert28. Aug. 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

17 Tools · 1 privilegiert
Statisch aus dem veröffentlichten Paket extrahiertv0.3.1 · 8d ago

Aus dem Quellcode gelesen, den npm tatsächlich ausliefert, zum Zeitpunkt des Scans. Das Paket wurde nie ausgeführt. Tools, die zur Laufzeit dynamisch registriert werden oder in gebündeltem beziehungsweise minifiziertem Code stecken, können übersehen werden — das hier ist also eine Untergrenze der Tool-Oberfläche, keine vollständige Erhebung.

list_connected_webmcp_tabsList all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.

List all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

focus_webmcp_tabFocus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.

Focus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

list_webmcp_toolsList live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.

List live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

execute_webmcp_toolKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

lookup_packageLook up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.

Look up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

list_packagesBrowse registry packages with pagination and optional domain filter (each at its latest version).

Browse registry packages with pagination and optional domain filter (each at its latest version).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_packageGet a single package by id, at its latest version.

Get a single package by id, at its latest version.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

list_installsList the caller's installed packages, each pinned to its installed version. Requires an API key.

List the caller's installed packages, each pinned to its installed version. Requires an API key.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_statsRegistry stats: total packages, domains covered, top domains.

Registry stats: total packages, domains covered, top domains.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

setup_webmcp_bridgeInstall the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.

Install the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_webmcp_bridge_statusInspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.

Inspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

uninstall_webmcp_bridgeRemove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.

Remove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

publish_packagePublish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.

Publish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

update_package_metaUpdate a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.

Update a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

publish_package_versionPublish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…

Publish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

install_packageprivilegiertPin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…

Pin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

uninstall_packageRemove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.

Remove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

16 von 17 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.

Schlagwörter
mcp
Alternativen
Tool-Oberflächen werden verglichen…

Abhängigkeitsbaum

Was ein Forge-Scan am 2026-09-26 aus den npm-Metadaten aufgelöst hat — beobachtete Auflösung, keine Angabe des Herausgebers.

60 Pakete aufgelöst · 3 direkt · keines mit Sicherheitshinweisen Die Auflösung endet bei Tiefe 4 und 60 Paketen.

Der Durchlauf endete an der Grenze von 60 Paketen. Der Rest des Baums wurde nie aufgelöst.

36 weitere aufgelöste Pakete werden hier nicht gezeichnet (Anzeigegrenze: 24). Jede Abhängigkeit mit einem Sicherheitshinweis wird unabhängig von der Grenze gezeichnet. Vollständiges Inventar (CycloneDX-SBOM)

Deklariert, aber nicht aufgelöst

57 deklarierte Abhängigkeiten sind nie im Baum gelandet. Sie fehlen in Forges Auflösung, nicht im Paket.

+45 weitere nicht aufgeführt. Die Zählungen nach Grund oben erfassen sie alle.

Nicht verfolgt: peerDependencies. Dieser Baum erfasst nur Laufzeitabhängigkeiten; was jene mitbringen, wurde nie aufgelöst.