MCP server + Chrome extension for AI browser control with real sessions.
The missing piece in AI coding: your agent can now see your REAL browser. You ship a fix. Your agent says "done, please verify." You alt-tab to Chrome, navigate to the page, log in, click around, find the bug. Your agent just wrote the code. It could also verify it. It already has your browser open right there. It just can't see it. MCP server - runs on your machine, talks to your AI agent Chrome…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
browser_click_textNo description publishedThis tool published no description. Forge does not invent one.
browser_clickNo description publishedThis tool published no description. Forge does not invent one.
browser_consoleNo description publishedThis tool published no description. Forge does not invent one.
browser_handle_dialogNo description publishedThis tool published no description. Forge does not invent one.
browser_evaluateprivilegedNo description publishedThis tool published no description. Forge does not invent one.
browser_findNo description publishedThis tool published no description. Forge does not invent one.
browser_hoverNo description publishedThis tool published no description. Forge does not invent one.
browser_navigateNo description publishedThis tool published no description. Forge does not invent one.
browser_networkNo description publishedThis tool published no description. Forge does not invent one.
browser_press_keyNo description publishedThis tool published no description. Forge does not invent one.
browser_screenshotNo description publishedThis tool published no description. Forge does not invent one.
browser_scrollNo description publishedThis tool published no description. Forge does not invent one.
browser_selectNo description publishedThis tool published no description. Forge does not invent one.
browser_snapshotNo description publishedThis tool published no description. Forge does not invent one.
browser_tabsNo description publishedThis tool published no description. Forge does not invent one.
browser_textNo description publishedThis tool published no description. Forge does not invent one.
browser_typeNo description publishedThis tool published no description. Forge does not invent one.
browser_waitNo description publishedThis tool published no description. Forge does not invent one.
0 of 18 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
The missing piece in AI coding: your agent can now see your REAL browser. You ship a fix. Your agent says "done, please verify." You alt-tab to Chrome, navigate to the page, log in, click around, find the bug. Your agent just wrote the code. It could also verify it. It already has your browser open right there. It just can't see it. MCP server - runs on your machine, talks to your AI agent Chrome extension - sits in your browser, executes the commands…
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This package was last scanned before Forge began storing the resolved tree. The next scan will record it.