# WebMCP Evals

> WebMCP Evals is an officially published WebMCP tool from GoogleChromeLabs. Anomity scores its risk at 20 out of 100 (low).

- **Canonical URL:** https://catalog.anomity.ai/webmcp/webmcp-evals
- **Kind:** WebMCP tool
- **Publisher:** GoogleChromeLabs
- **Trust level:** official
- **Risk score:** 20/100 (low)
- **Website:** https://github.com/GoogleChromeLabs/webmcp-evals
- **Repository:** https://github.com/GoogleChromeLabs/webmcp-evals
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/webmcp/webmcp-evals

## Description

A CLI evaluation harness for WebMCP tool surfaces. It drives an agent against a page's registered tools and checks whether the agent selects the right tool and supplies valid arguments — the two failure modes that make an otherwise correct tool surface useless in practice.

It runs locally, driving a browser and writing result files, so it declares browser control, filesystem writes, and outbound network access for the model calls. Treat its reports as a design signal rather than a security control: an eval suite tells you agents can use your tools correctly, not that a hostile agent cannot use them harmfully. Those are different questions, and only the first one has a harness.

## Why it scored 20

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Published by the vendor | -40 | trust offset |  |
| 1 high-risk capability: filesystem:write | +10 | high |  |

Clamped result: **20/100**, band **low**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `browser:control` | Browser control | Drives a browser session. Combined with credential access can impersonate the user on web services. |
| `filesystem:write` | Filesystem write | Can create, edit, or delete files on the host system. High-impact capability — anything from helpful edits to planting persistence. |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |

## Related WebMCP tools

- [webmcpify](https://catalog.anomity.ai/webmcp/webmcpify) — risk 100 (critical)
- [Latch](https://catalog.anomity.ai/webmcp/latch-webmcp) — risk 40 (medium)
- [Model Context Tool Inspector](https://catalog.anomity.ai/webmcp/model-context-tool-inspector) — risk 40 (medium)
- [nekuda WebMCP Workbench](https://catalog.anomity.ai/webmcp/nekuda-webmcp-workbench) — risk 40 (medium)
- [WebMCP Bridge](https://catalog.anomity.ai/webmcp/webmcp-bridge) — risk 40 (medium)
- [WordLift AI Audit](https://catalog.anomity.ai/webmcp/wordlift-ai-audit) — risk 40 (medium)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
