WebMCP Smart Home ↗
WebMCP Smart Home is an officially published WebMCP tool from GoogleChromeLabs. Anomity scores its risk at 10 out of 100 (low).
Analysis summary
WebMCP Smart Home is an officially published WebMCP tool from GoogleChromeLabs. Anomity scores its risk at 10 out of 100 (low).
A smart-home dashboard that reveals camera, climate, and energy controls as WebMCP tools, and lets an agent rearrange the dashboard as well as operate it. The demonstration extends past reading state into changing the physical environment.
This is the high-consequence end of the reference set, and worth catalogued attention for that reason alone. Tools that unlock, disarm, or view cameras are not recoverable the way a shopping cart is, and the agent invoking them is reading a page whose content may not be fully trusted. It declares browser control and outbound network access. Any real deployment of this shape needs per-tool authorization that is independent of the agent's context — the model should be able to request the action and still not be able to perform it unattended.
Why this entry scored 10 out of 100
This profile starts at the catalog's neutral base of 50. Because the entry is officially published, trust adjusts the score by -40. The entry declares no high-risk capabilities on its own, so capabilities add nothing. It matches no dangerous capability combinations. The clamped result is 10, placing it in the low band.
Findings
-
Published by the vendor Trust offset
Capabilities
Every capability the entry declares, with the security implication of each.
-
browser:controlBrowser controlDrives a browser session. Combined with credential access can impersonate the user on web services. -
network:outboundOutbound networkCan make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access.