Browser MCP: the app under test egresses via the real ISP while the agent stays on the VPN.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Browser MCP: the app under test egresses via the real ISP while the agent stays on the VPN.