# WebMCP Page Agent

> WebMCP Page Agent is an officially published WebMCP tool from GoogleChromeLabs. Anomity scores its risk at 10 out of 100 (low).

- **Canonical URL:** https://catalog.anomity.ai/webmcp/webmcp-page-agent
- **Kind:** WebMCP tool
- **Publisher:** GoogleChromeLabs
- **Trust level:** official
- **Risk score:** 10/100 (low)
- **Website:** https://github.com/GoogleChromeLabs/webmcp
- **Repository:** https://github.com/GoogleChromeLabs/webmcp
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/webmcp/webmcp-page-agent

## Description

A Gemini-powered controller that accepts natural language and drives whatever WebMCP tools the current page has registered. It is the reference demonstration of the full loop: a page publishes tools, a model reads them, the user types an intent, the model calls tools until the intent is satisfied.

This is the clearest illustration of why WebMCP belongs in a risk catalog. The agent's context includes page content, and page content is attacker-influenceable on any site that renders user input. The controller declares browser control and outbound network access. Anything that can get text in front of this agent is one injection away from calling the page's tools with arguments of its choosing — inside a session that is already authenticated.

## Why it scored 10

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Published by the vendor | -40 | trust offset |  |

Clamped result: **10/100**, band **low**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `browser:control` | Browser control | Drives a browser session. Combined with credential access can impersonate the user on web services. |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |

## Related WebMCP tools

- [Latch](https://catalog.anomity.ai/webmcp/latch-webmcp) — risk 40 (medium)
- [Model Context Tool Inspector](https://catalog.anomity.ai/webmcp/model-context-tool-inspector) — risk 40 (medium)
- [nekuda WebMCP Workbench](https://catalog.anomity.ai/webmcp/nekuda-webmcp-workbench) — risk 40 (medium)
- [WebMCP Bridge](https://catalog.anomity.ai/webmcp/webmcp-bridge) — risk 40 (medium)
- [WordLift AI Audit](https://catalog.anomity.ai/webmcp/wordlift-ai-audit) — risk 40 (medium)
- [WebMCP Evals](https://catalog.anomity.ai/webmcp/webmcp-evals) — risk 20 (low)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
