Is Chrome DevTools MCP server safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
No critical or high findings in the latest scan.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
2 medium
- Code scan78 source files scanned15/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year9/10
Findings (2)
- mediumeval / new Function used
exec.evalbuild/src/third_party/devtools-formatter-worker.js: …is.e = e; this.f = f; } eval(val) { const sign = val < 0 ? -1… - mediumGoogle API key in source (often public by design; check its restrictions)
secret.googlebuild/src/tools/performance.js: …ogleapis.com/v1/records:queryRecord?key=AIza****'); const cruxSetting = DevTools.Com…
Overall 78/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON