Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.
Inferido de los transportes que declara este listado (stdio). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.
WEBMCP_TODAY_API_KEYClave de APIopcionalOptional WebMCP Today API key for publishing and package pins
Declarado por el autor en el registro oficial de MCP. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.
Leído del código que npm publica realmente, en el momento del análisis. El paquete nunca se ejecutó. Las herramientas registradas dinámicamente en tiempo de ejecución, o escondidas en código empaquetado o minificado, pueden pasarse por alto — así que esto es un mínimo de la superficie de herramientas, no un censo completo.
list_connected_webmcp_tabsList all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.List all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.
No se publicó ningún esquema de entrada para esta herramienta.
focus_webmcp_tabFocus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.Focus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.
No se publicó ningún esquema de entrada para esta herramienta.
list_webmcp_toolsList live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.List live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.
No se publicó ningún esquema de entrada para esta herramienta.
execute_webmcp_toolSin descripción publicadaEsta herramienta no publicó ninguna descripción. Forge no se la inventa.
lookup_packageLook up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.Look up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.
No se publicó ningún esquema de entrada para esta herramienta.
list_packagesBrowse registry packages with pagination and optional domain filter (each at its latest version).Browse registry packages with pagination and optional domain filter (each at its latest version).
No se publicó ningún esquema de entrada para esta herramienta.
get_packageGet a single package by id, at its latest version.Get a single package by id, at its latest version.
No se publicó ningún esquema de entrada para esta herramienta.
list_installsList the caller's installed packages, each pinned to its installed version. Requires an API key.List the caller's installed packages, each pinned to its installed version. Requires an API key.
No se publicó ningún esquema de entrada para esta herramienta.
get_statsRegistry stats: total packages, domains covered, top domains.Registry stats: total packages, domains covered, top domains.
No se publicó ningún esquema de entrada para esta herramienta.
setup_webmcp_bridgeInstall the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.Install the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.
No se publicó ningún esquema de entrada para esta herramienta.
get_webmcp_bridge_statusInspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.Inspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.
No se publicó ningún esquema de entrada para esta herramienta.
uninstall_webmcp_bridgeRemove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.Remove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.
No se publicó ningún esquema de entrada para esta herramienta.
publish_packagePublish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.Publish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.
No se publicó ningún esquema de entrada para esta herramienta.
update_package_metaUpdate a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.Update a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.
No se publicó ningún esquema de entrada para esta herramienta.
publish_package_versionPublish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…Publish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…
No se publicó ningún esquema de entrada para esta herramienta.
install_packageprivilegiadaPin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…Pin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…
No se publicó ningún esquema de entrada para esta herramienta.
uninstall_packageRemove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.Remove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.
No se publicó ningún esquema de entrada para esta herramienta.
16 de 17 herramientas publicaron una descripción.
Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.
Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.
Los nombres enlazados abren el índice de Forge con todas las entradas que se observó que exponen esa herramienta. Ver todas las herramientas indexadas.
El rastreo se detuvo en el límite de 60 paquetes. El resto del árbol nunca se resolvió.
Hay 36 paquetes resueltos más que no se dibujan aquí (límite de visualización: 24). Toda dependencia con avisos de seguridad se dibuja aunque se supere el límite. Inventario completo (SBOM CycloneDX)
57 dependencias declaradas nunca llegaron al árbol. Faltan en la resolución de Forge, no en el paquete.
+45 más sin listar. Los recuentos por motivo de arriba las incluyen todas.
No se siguen: peerDependencies. Este árbol cubre solo dependencias en tiempo de ejecución, así que lo que estas arrastren nunca se resolvió.