Skip to content
On this page

Tool risk matrix ​

Every tool the bridge exposes, with its risk level, what it reads and changes, whether it touches credentials, the Chrome permission it needs, and how the user is protected. This is the reference for security review: adding or changing a tool means updating this table, and the review bar says what else the change carries.

Risk levels: Low (read-only, no sensitive data), Medium (reads page content or navigates), High (writes to the page, or reads credentials), Critical (arbitrary code or maximal blast radius).

The protections listed are the defaults. The confirmation gates are host-owned policy fields (confirmHighRiskClick, confirmTabClose, confirmPageEval, presenceConfirm, confirmGraceMs), edited with genkan policy (set signs a grant, restrict is free); the extension's options page can only tighten them. Relaxing one is an explicit, signed choice whose residual is tabulated in the defaults table.

ToolRiskReadsWrites / effectCredentials?Chrome permUser protection
list_browsersLowconnected browser labels + open-tab counts-notabs (via a routed tab_list per browser)answered by the MCP server; no page access
tab_listLowtab titles/URLs-notabsallowlist not required (metadata only)
tab_focusLow-activates a tabnotabs-
tab_openMedium-opens a URL (navigation)notabsallowlist-gated origin
tab_closeHightab title/URLcloses a tab (data loss)notabsextension-window confirm
page_snapshotLowinteractive elements (a11y)-noscriptingallowlist-gated; content injected
page_clickHigh [1]element under refclicks (may submit/navigate)noscriptingextension-window confirm for submit/link
page_fillHigh-types into a fieldpossibly (into password fields)scriptingpassword value masked in the echo
page_textMediumvisible page text-maskedscriptingpasswords + long digit runs masked
page_screenshotMediumviewport pixels-possibly (whatever is on screen)tabs-
page_scrollLowscroll positionscrollsnoscripting-
page_wait_forLowselector/text presence-noscripting-
page_navigateMedium-loads an http(s) URL in the active tabnotabsallowlist-gated on the destination origin
page_backLow-steps the active tab back in historynotabsallowlist-gated on the current origin, not the destination (residual)
page_forwardLow-steps the active tab forward in historynotabsallowlist-gated on the current origin, not the destination (the same residual)
page_reloadLow-reloads the active tabnotabsallowlist-gated on the current origin
page_pressHigh-sends a synthetic key or combo to the page (may submit/navigate)noscriptingextension-window confirm, every call
page_hoverLow-moves the pointer over an elementnoscriptingallowlist-gated
page_selectHigh-chooses an option in a <select>noscriptingextension-window confirm, every call
console_getMediumrecent console output incl. network errors-maskeddebuggerallowlist-gated; output masked; "debugging" banner
page_handle_dialogHigh-accepts or dismisses a JS dialog (alert/confirm/prompt)nodebuggeroff by default (opt-in); allowlist-gated; "debugging" banner
page_uploadCriticalthe named local file's bytesattaches a local file to a file inputpossibly (any readable file)debuggeroff by default (opt-in); allowlist-gated; every-call extension-window confirm showing the exact path; the origin is rechecked after the confirm and the attach bound to the document node resolved then; see residual
page_evalCriticalanything the page canarbitrary JS in the pageyes (can read tokens/cookies)scripting (host)off by default under host-owned policy (pageEvalEnabled, granted with policy set); every-call extension-window confirm showing the full code; result masked
page_snapshot_preciseMediumauthoritative a11y tree (CDP)-nodebuggerpre-warn toast; "debugging" infobar flashes
cookie_getHighcookies incl. httpOnly- (read-only)yescookiesallowlist-scoped; values masked; no cookie_set by design
storage_getHighlocal/sessionStorage- (read-only)yes (tokens)scriptingsame-origin; values always masked

[1] page_click is Medium for ordinary elements; High when the target is a submit button or a navigating link (those trigger the confirmation window).

Cross-cutting protections ​

  • Browser routing never guesses: with several browsers connected, a tool call must name one via its browser argument or it fails (BROWSER_AMBIGUOUS); an unknown label fails (BROWSER_NOT_FOUND). Each browser's connection is independently authenticated, and a connection that answers another browser's request is dropped.
  • Allowlist: page-level tools run only on origins the user approved (a per-site prompt plus chrome.permissions.request). allowAllSites is an explicit opt-in.
  • Masking: page_text, cookie_get, storage_get, and page_eval output run through the mask (JWTs, long hex, long digit runs, token-like strings). storage_get masking is not user-toggleable.
  • Confirmation grace window: a repeated submit or link click under the per-tab key skips the prompt within confirmGraceMs; page_eval never skips, so an earlier approval never lets later, unrelated code run. The same section owns the default.
  • Read-only by design: no cookie_set or storage_set (writing httpOnly cookies is a session-fixation risk).
  • CDP mode (opt-in, off by default): the cdpMode policy field reroutes every page-level tool through chrome.debugger in the page's MAIN world instead of a content script. No tool's contract, permission, confirmation, or masking changes; the protections above still apply.
    • Its two costs: it bypasses page CSP, so page_eval runs on strict-CSP sites, and it holds a persistent debugger attach for the tab, so the "Started debugging this browser" banner stays up the whole time it is on.

When you add or change a tool ​

Update this table and follow the review bar. A change that raises a tool's blast radius (a new permission, a new sensitive read, a new write, a weaker confirmation, a wider masking bypass) also updates the trust boundaries ledger and takes a security-labeled review.

Built from main at 25ae5f4Source: docs/security/tool-risk-matrix.md