@webmcp-today/mcp-bridge

MCPattesté
v0.3.1io.github.robertn702UnknownMis à jour il y a 1 moisnpmGitHub

Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Build attesté
Une attestation de provenance vérifiée lie cet artefact au dépôt indiqué. Personne n’a encore revendiqué l’annonce — cela prouve où le code a été construit, pas qui le soutient.
il y a 1 moisDernière mise à jour
Lit ces identifiants
  • WEBMCP_TODAY_API_KEYClé d’APIfacultatif

    Optional WebMCP Today API key for publishing and package pins

Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquet
Auteurio.github.robertn702
LicenceUnknown
Version0.3.1
Sourcenpm+mcp-registry
Statut de confiance
A
85/100Fiable
✓Listé dans l’index Forge+10/10
✓Identité vérifiée · build attesté+20/20
—Signature de publication Ed25519+0/5
→ Incluse automatiquement quand l’éditeur exécute `forge publish`
—Vérification de domaine+0/5
→ Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Correspondance de mainteneur npm+0/5
→ Éditeur : ajoutez le login GitHub vérifié aux mainteneurs du paquet npm (npm owner add <login>)
✓Analyse CVE · propre+30/30
✓Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIdentité vérifiée
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance✓ Vérifié par Sigstore · 60e3660
Dépendances✓ 60 résolues+ · aucune vulnérable
Surface d’outils17 outils · 1 privilégiés
Analyse de sécurité✓ Proprev0.3.1 · il y a 8 jQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé28 août 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

17 outils · 1 privilégiés
Extrait statiquement du paquet publiév0.3.1 · 8d ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

list_connected_webmcp_tabsList all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.

List all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.

Aucun schéma d’entrée n’a été publié pour cet outil.

focus_webmcp_tabFocus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.

Focus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_webmcp_toolsList live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.

List live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.

Aucun schéma d’entrée n’a été publié pour cet outil.

execute_webmcp_toolAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

lookup_packageLook up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.

Look up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_packagesBrowse registry packages with pagination and optional domain filter (each at its latest version).

Browse registry packages with pagination and optional domain filter (each at its latest version).

Aucun schéma d’entrée n’a été publié pour cet outil.

get_packageGet a single package by id, at its latest version.

Get a single package by id, at its latest version.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_installsList the caller's installed packages, each pinned to its installed version. Requires an API key.

List the caller's installed packages, each pinned to its installed version. Requires an API key.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_statsRegistry stats: total packages, domains covered, top domains.

Registry stats: total packages, domains covered, top domains.

Aucun schéma d’entrée n’a été publié pour cet outil.

setup_webmcp_bridgeInstall the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.

Install the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_webmcp_bridge_statusInspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.

Inspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.

Aucun schéma d’entrée n’a été publié pour cet outil.

uninstall_webmcp_bridgeRemove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.

Remove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.

Aucun schéma d’entrée n’a été publié pour cet outil.

publish_packagePublish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.

Publish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.

Aucun schéma d’entrée n’a été publié pour cet outil.

update_package_metaUpdate a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.

Update a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.

Aucun schéma d’entrée n’a été publié pour cet outil.

publish_package_versionPublish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…

Publish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…

Aucun schéma d’entrée n’a été publié pour cet outil.

install_packageprivilégiéPin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…

Pin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…

Aucun schéma d’entrée n’a été publié pour cet outil.

uninstall_packageRemove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.

Remove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.

Aucun schéma d’entrée n’a été publié pour cet outil.

16 outils sur 17 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-09-26 — résolution observée, et non une déclaration de l'éditeur.

60 paquets résolus · 3 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.

36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)

Déclarées mais non résolues

57 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.

+45 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.