{"name":"io.github.triuzzi/brave-mcp","slug":"triuzzi-brave-mcp","title":"Brave DevTools MCP","description":"MCP server and CLI for Brave DevTools","url":"https://mcp.market/server/triuzzi-brave-mcp","rating":null,"grade":"C","score":58,"certified":false,"status":"active","category":"search","tags":["search"],"presence":{"score":44,"stars":34,"forks":3,"downloads_week":644,"last_push_at":"2026-09-14T07:38:42.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/triuzzi/brave-devtools-mcp","website":null,"version":"1.9.0","remotes":[],"packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"brave-mcp","version":"1.9.0","transport":{"type":"stdio"}}],"tools":[{"name":"execute_3p_developer_tool","description":"Executes a tool exposed by the page.","write_action":true,"price_micros":0,"input_schema":null},{"name":"list_3p_developer_tools","description":"Lists all third-party developer tools the page exposes for providing runtime information. Third-party developer tools can be called via the 'execute_3p_developer_tool()' MCP tool. Alternatively, third-party developer tools can be executed by calling 'evaluate_script' and adding the following command to the script: `window.__dtmcp.executeTool(toolName, params)` This might be helpful when the third-","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":58,"grade":"C","scanned_at":"2026-09-19T21:32:26.936Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-19T21:32:26.907Z","components":{"code":{"score":3,"max":25,"notes":["83 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 6 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[{"id":"exec.shell-concat","severity":"high","component":"code","title":"Shell command built from a string (injection risk)","evidence":"build/src/browser.js: … { const resolvedPath = execSync(`which ${candidate}`, { encod…"},{"id":"exec.eval","severity":"medium","component":"code","title":"eval / new Function used","evidence":"build/src/third_party/devtools-formatter-worker.js: …is.e = e; this.f = f; } eval(val) { const sign = val < 0 ? -1…"},{"id":"secret.google","severity":"medium","component":"code","title":"Google API key in source (often public by design; check its restrictions)","evidence":"build/src/tools/performance.js: …ogleapis.com/v1/records:queryRecord?key=AIza****'); const cruxSetting = DevTools.Com…"}],"inputs":{"packages":[{"registryType":"npm","identifier":"brave-mcp","version":"1.9.0","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":0,"publishedAt":"2026-09-14T07:36:58.859Z","repositoryUrl":"git+https://github.com/triuzzi/brave-devtools-mcp.git"}],"repo":{"found":true,"owner":"triuzzi","repo":"brave-devtools-mcp","archived":false,"pushedAt":"2026-09-14T07:38:42Z","stars":34,"forks":3,"openIssues":1,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/60050299?v=4","ownerCreatedAt":"2020-01-18T23:41:15Z","license":"Apache-2.0"},"icon":{"url":"https://avatars.githubusercontent.com/u/60050299?v=4&s=128","source":"registry"},"presence":{"stars":34,"forks":3,"downloadsWeek":644,"license":"Apache-2.0","lastPushAt":"2026-09-14T07:38:42.000Z","score":44}}}},"grade_history":[{"kind":"restore","fromGrade":"D","toGrade":"C","reason":"score 58: Shell command built from a string (injection risk); eval / new Function used; Google API key in source (often public by design; check its restrictions)","createdAt":"2026-09-19T20:35:28.029Z"}],"reviews":[]}