Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
WEBMCP_TODAY_API_KEYAPI keyoptionalOptional WebMCP Today API key for publishing and package pins
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
list_connected_webmcp_tabsList all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.List all Chrome/Brave tabs with reachable WebMCP tools: the user's selected tab plus tabs matching installed packages. Use focus_webmcp_tab with a tabId from this list to switch targets.
No input schema was published for this tool.
focus_webmcp_tabFocus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.Focus a connected tab, making it the selected target for list_webmcp_tools and execute_webmcp_tool. Use a tabId from list_connected_webmcp_tabs.
No input schema was published for this tool.
list_webmcp_toolsList live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.List live WebMCP tools in the user-selected active visible Chrome/Brave tab. Returns a document and tool-list generation required by execute_webmcp_tool. If the tab is not eligible or available, call focus_webmcp_tab with the target tabId, then retry.
No input schema was published for this tool.
execute_webmcp_toolNo description publishedThis tool published no description. Forge does not invent one.
lookup_packageLook up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.Look up WebMCP packages for a page URL, at each package's latest version. Returns matches most-specific-pattern first.
No input schema was published for this tool.
list_packagesBrowse registry packages with pagination and optional domain filter (each at its latest version).Browse registry packages with pagination and optional domain filter (each at its latest version).
No input schema was published for this tool.
get_packageGet a single package by id, at its latest version.Get a single package by id, at its latest version.
No input schema was published for this tool.
list_installsList the caller's installed packages, each pinned to its installed version. Requires an API key.List the caller's installed packages, each pinned to its installed version. Requires an API key.
No input schema was published for this tool.
get_statsRegistry stats: total packages, domains covered, top domains.Registry stats: total packages, domains covered, top domains.
No input schema was published for this tool.
setup_webmcp_bridgeInstall the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.Install the first-party WebMCP Today native bridge for macOS Chrome or Brave. This copies a fixed bundled host to ~/.config/webmcp-today and writes only this bridge's native-messaging manifest under ~/Library/Application Support. Set confirm to true to approve these writes.
No input schema was published for this tool.
get_webmcp_bridge_statusInspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.Inspect the macOS Chrome or Brave WebMCP Today bridge installation without changing files. Reports bridge-owned paths and permissions but never returns the bridge secret.
No input schema was published for this tool.
uninstall_webmcp_bridgeRemove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.Remove WebMCP Today's macOS native-messaging bridge artifacts for Chrome or Brave. Brave retains Chrome's compatibility manifest because Brave may use it; the result reports that residual and the required follow-up Chrome uninstall. Set confirm to true to approve removal.
No input schema was published for this tool.
publish_packagePublish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.Publish a new WebMCP package to the registry as a fresh package whose version field must declare 1 (validated against @webmcp-today/schema). Requires an API key.
No input schema was published for this tool.
update_package_metaUpdate a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.Update a package's metadata (title, description) — owner only. Domain is immutable and never touches urlPatterns/tools/minEngine; use publish_package_version for that. Requires an API key.
No input schema was published for this tool.
publish_package_versionPublish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…Publish the next version of a package you contributed (urlPatterns, tools, required api and minEngine, optional changelog) — owner only, append-only. The version field is author-declared and must equal the current latest version + 1 exactly (query the package first to see it); a 409 response return…
No input schema was published for this tool.
install_packageprivilegedPin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…Pin a package to its latest version, or a given versionId, on your webmcp.today account — creates the pin if absent, moves it if present (also how rollback works: pass an older versionId). This does not install into your browser; the extension's installs are local to the browser. Returns a link tha…
No input schema was published for this tool.
uninstall_packageRemove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.Remove the caller's install pin on your webmcp.today account. This does not affect the extension's local install in your browser. Requires an API key.
No input schema was published for this tool.
16 of 17 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Your agent gets trustworthy tools on sites without WebMCP — data-only packages you approve.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
The crawl stopped at the 60-package limit. The rest of the tree was never resolved.
36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)
57 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.
+45 more not listed. The counts by reason above cover all of them.
Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.