@webmcp-today/mcp-bridge

MCPcon attestation
v0.3.1io.github.robertn702UnknownActualizado hace 1 mnpmGitHub

Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.

Funciona en
ClaudeCursorCopilotGemini

Inferido de los transportes que declara este listado (stdio). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Build con attestation
Una attestation de procedencia verificada vincula este artefacto al repositorio listado. Nadie ha reclamado todavía el listado: esto demuestra dónde se construyó el código, no quién lo respalda.
hace 1 mÚltima actualización
Lee estas credenciales
  • WEBMCP_TODAY_API_KEYClave de APIopcional

    Optional WebMCP Today API key for publishing and package pins

Declarado por el autor en el registro oficial de MCP. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquete
Autorio.github.robertn702
LicenciaUnknown
Versión0.3.1
Fuentenpm+mcp-registry
Estado de confianza
A
85/100Fiable
✓Listado en el índice de Forge+10/10
✓Identidad verificada · build con attestation+20/20
—Firma de publicación Ed25519+0/5
→ Se incluye automáticamente cuando el publicador ejecuta `forge publish`
—Verificación de dominio+0/5
→ Publicador: aloja /.well-known/forge.json en la página del paquete con { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Coincidencia de maintainer en npm+0/5
→ Publicador: añade el login de GitHub verificado a los maintainers del paquete de npm (npm owner add <login>)
✓Análisis CVE · limpio+30/30
✓Análisis estático · limpio+20/20
Pégalo en Claude Code, Cursor o cualquier asistente de IA para corregir todas las carencias
EstadoIdentidad verificada
PublicadorSin verificar
FirmaSin firmar
Dominio—
Procedencia✓ Verificado con Sigstore · 60e3660
Dependencias✓ 60 resueltas+ · ninguna vulnerable
Superficie de herramientas17 herramientas · 1 privilegiadas
Análisis de seguridad✓ Limpiov0.3.1 · hace 8 d¿Qué tan bien funciona este análisis?
EvaluacionesNinguna
Indexado28 ago 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

17 herramientas · 1 privilegiadas
Extraído estáticamente del paquete publicadov0.3.1 · 8d ago

Leído del código que npm publica realmente, en el momento del análisis. El paquete nunca se ejecutó. Las herramientas registradas dinámicamente en tiempo de ejecución, o escondidas en código empaquetado o minificado, pueden pasarse por alto — así que esto es un mínimo de la superficie de herramientas, no un censo completo.

list_connected_webmcp_tabsList all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.

List all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.

No se publicó ningún esquema de entrada para esta herramienta.

focus_webmcp_tabFocus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.

Focus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.

No se publicó ningún esquema de entrada para esta herramienta.

list_webmcp_toolsList live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.

List live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.

No se publicó ningún esquema de entrada para esta herramienta.

execute_webmcp_toolSin descripción publicada

Esta herramienta no publicó ninguna descripción. Forge no se la inventa.

lookup_packageLook up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.

Look up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.

No se publicó ningún esquema de entrada para esta herramienta.

list_packagesBrowse registry packages with pagination and optional domain filter (each at its latest version).

Browse registry packages with pagination and optional domain filter (each at its latest version).

No se publicó ningún esquema de entrada para esta herramienta.

get_packageGet a single package by id, at its latest version.

Get a single package by id, at its latest version.

No se publicó ningún esquema de entrada para esta herramienta.

list_installsList the caller's installed packages, each pinned to its installed version. Requires an API key.

List the caller's installed packages, each pinned to its installed version. Requires an API key.

No se publicó ningún esquema de entrada para esta herramienta.

get_statsRegistry stats: total packages, domains covered, top domains.

Registry stats: total packages, domains covered, top domains.

No se publicó ningún esquema de entrada para esta herramienta.

setup_webmcp_bridgeInstall the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.

Install the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.

No se publicó ningún esquema de entrada para esta herramienta.

get_webmcp_bridge_statusInspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.

Inspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.

No se publicó ningún esquema de entrada para esta herramienta.

uninstall_webmcp_bridgeRemove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.

Remove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.

No se publicó ningún esquema de entrada para esta herramienta.

publish_packagePublish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.

Publish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.

No se publicó ningún esquema de entrada para esta herramienta.

update_package_metaUpdate a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.

Update a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.

No se publicó ningún esquema de entrada para esta herramienta.

publish_package_versionPublish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…

Publish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…

No se publicó ningún esquema de entrada para esta herramienta.

install_packageprivilegiadaPin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…

Pin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…

No se publicó ningún esquema de entrada para esta herramienta.

uninstall_packageRemove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.

Remove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.

No se publicó ningún esquema de entrada para esta herramienta.

16 de 17 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.

Palabras clave
mcp
Alternativas
Comparando superficies de herramientas…

Árbol de dependencias

Lo que un análisis de Forge resolvió a partir de los metadatos de npm el 2026-09-26: resolución observada, no una declaración del publicador.

60 paquetes resueltos · 3 directos · ninguno con avisos de seguridad La resolución se detiene en la profundidad 4 y en 60 paquetes.

El rastreo se detuvo en el límite de 60 paquetes. El resto del árbol nunca se resolvió.

Hay 36 paquetes resueltos más que no se dibujan aquí (límite de visualización: 24). Toda dependencia con avisos de seguridad se dibuja aunque se supere el límite. Inventario completo (SBOM CycloneDX)

Declaradas pero no resueltas

57 dependencias declaradas nunca llegaron al árbol. Faltan en la resolución de Forge, no en el paquete.

+45 más sin listar. Los recuentos por motivo de arriba las incluyen todas.

No se siguen: peerDependencies. Este árbol cubre solo dependencias en tiempo de ejecución, así que lo que estas arrastren nunca se resolvió.