SECURITY

Local-first is not risk-free.

What the bridge can do

A connected MCP client can inspect page content and interact with pages in the paired Chrome profile. Those pages may already be authenticated. In effect, the connected client has browser automation capability under your active identity.

Default controls

Operational guidance

Threat model

The primary threat is an untrusted or prompt-injected agent issuing browser commands. A malicious page can also try to influence an agent through page text. Treat retrieved page content as untrusted input, review actions that change data or send messages, and never allow arbitrary automation solely because text on a page requests it.

Reporting vulnerabilities

Use a private GitHub security advisory. Do not publish exploit details in an issue. See the repository security policy for details.