# nekuda WebMCP Workbench

> nekuda WebMCP Workbench is a community-maintained WebMCP tool from Nekuda. Anomity scores its risk at 40 out of 100 (medium).

- **Canonical URL:** https://catalog.anomity.ai/webmcp/nekuda-webmcp-workbench
- **Kind:** WebMCP tool
- **Publisher:** Nekuda
- **Trust level:** community
- **Risk score:** 40/100 (medium)
- **Website:** https://nekuda.ai
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/webmcp/nekuda-webmcp-workbench

## Description

A Chrome side-panel workbench for working with WebMCP tools end to end: inspect the tools a page registers, invoke them with structured arguments, test sequences, and audit what was called. It targets developers building agent-native pages who need to see their own tool surface the way an agent sees it.

Because it both reads and invokes, it inherits the full risk of the page it is pointed at. Its declared capabilities are browser control and outbound network access. The audit trail is the part worth adopting as practice: if you are shipping WebMCP tools, the record of which tools were invoked with which arguments is the difference between debugging an agent's behaviour and guessing at it.

## Why it scored 40

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Established community project | -10 | trust offset |  |

Clamped result: **40/100**, band **medium**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `browser:control` | Browser control | Drives a browser session. Combined with credential access can impersonate the user on web services. |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |

## Related WebMCP tools

- [Latch](https://catalog.anomity.ai/webmcp/latch-webmcp) — risk 40 (medium)
- [Model Context Tool Inspector](https://catalog.anomity.ai/webmcp/model-context-tool-inspector) — risk 40 (medium)
- [WebMCP Bridge](https://catalog.anomity.ai/webmcp/webmcp-bridge) — risk 40 (medium)
- [WordLift AI Audit](https://catalog.anomity.ai/webmcp/wordlift-ai-audit) — risk 40 (medium)
- [WebMCP Evals](https://catalog.anomity.ai/webmcp/webmcp-evals) — risk 20 (low)
- [Codex Modeling Studio](https://catalog.anomity.ai/webmcp/codex-modeling-studio) — risk 10 (low)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
