# WebMCP Smart Home

> WebMCP Smart Home is an officially published WebMCP tool from GoogleChromeLabs. Anomity scores its risk at 10 out of 100 (low).

- **Canonical URL:** https://catalog.anomity.ai/webmcp/webmcp-smart-home
- **Kind:** WebMCP tool
- **Publisher:** GoogleChromeLabs
- **Trust level:** official
- **Risk score:** 10/100 (low)
- **Website:** https://github.com/GoogleChromeLabs/webmcp
- **Repository:** https://github.com/GoogleChromeLabs/webmcp
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/webmcp/webmcp-smart-home

## Description

A smart-home dashboard that reveals camera, climate, and energy controls as WebMCP tools, and lets an agent rearrange the dashboard as well as operate it. The demonstration extends past reading state into changing the physical environment.

This is the high-consequence end of the reference set, and worth catalogued attention for that reason alone. Tools that unlock, disarm, or view cameras are not recoverable the way a shopping cart is, and the agent invoking them is reading a page whose content may not be fully trusted. It declares browser control and outbound network access. Any real deployment of this shape needs per-tool authorization that is independent of the agent's context — the model should be able to request the action and still not be able to perform it unattended.

## Why it scored 10

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Published by the vendor | -40 | trust offset |  |

Clamped result: **10/100**, band **low**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `browser:control` | Browser control | Drives a browser session. Combined with credential access can impersonate the user on web services. |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |

## Related WebMCP tools

- [Latch](https://catalog.anomity.ai/webmcp/latch-webmcp) — risk 40 (medium)
- [Model Context Tool Inspector](https://catalog.anomity.ai/webmcp/model-context-tool-inspector) — risk 40 (medium)
- [nekuda WebMCP Workbench](https://catalog.anomity.ai/webmcp/nekuda-webmcp-workbench) — risk 40 (medium)
- [WebMCP Bridge](https://catalog.anomity.ai/webmcp/webmcp-bridge) — risk 40 (medium)
- [WordLift AI Audit](https://catalog.anomity.ai/webmcp/wordlift-ai-audit) — risk 40 (medium)
- [WebMCP Evals](https://catalog.anomity.ai/webmcp/webmcp-evals) — risk 20 (low)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
