REPOSITORY EVIDENCE / INDEXABLE REPORT

ChromeDevTools/chrome-devtools-mcp — MCP & Agent Security Evidence Report

MCP configuration, child-process execution, CI/CD and dependency evidence were observed in this selected bounded review. Evidence observations are review signals, not a safe/unsafe verdict.

Is ChromeDevTools/chrome-devtools-mcp safe to run?

ShadowMCP does not issue a safe/unsafe verdict. This report records bounded evidence tied to a specific commit so reviewers can identify what deserves inspection before use.

Scan identity

Report schemashadowmcp.repo-evidence.v9
Scannershadowmcp.web-repo-scan.v22 semantics
Scan completed2026-09-24T08:16:00.000Z
Repository branchmain
Scanned commit6a7e51fecaaefbea46b89e68892d42c175ee9163
Indexation gateIndexable quality gate passed.

Evidence summary

Review priority
Priority review

This is a triage priority, not a repository risk rating.

The repository is the Chrome DevTools MCP server for coding agents and has substantial current developer interest. The bounded review observed MCP client configuration, multiple child-process execution paths in tooling and runtime utilities, GitHub automation and explicit MCP/automation dependency declarations.

Evidence categories

MCP configuration

Found

Selected configuration evidence was observed. This does not establish how any user's client is configured.

  • README.mdmcpServers configuration examples
  • mcp.jsonstdio server definition using npx
  • docs/configuration.mdadditional client configuration examples

Shell / command execution

Found

Selected process-execution evidence was observed. This does not prove a vulnerability or malicious behavior.

  • src/daemon/client.tsspawn imported from node:child_process
  • src/telemetry/WatchdogClient.tschild process spawn used by watchdog client
  • scripts/prepare.tsexecSync used in repository preparation tooling

CI/CD automation

Found

Repository-level GitHub workflow and dependency automation are present in the selected scope.

  • .github/workflows/GitHub Actions workflow directory observed
  • .github/dependabot.ymldependency update automation configuration

Supply-chain / dependencies

Found

Selected package dependency declarations were observed; this is not a complete dependency audit.

  • package.jsonMCP v2 client/core/server packages, Puppeteer, Lighthouse and build dependencies declared
  • package.jsonallowScripts policy explicitly controls selected install scripts

Scope and limitations

Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.

  • Public, selected and bounded repository evidence only.
  • FOUND means evidence observed, not risk or malicious behavior proven.
  • Search matches were reviewed against immutable commit 6a7e51fecaaefbea46b89e68892d42c175ee9163.
  • No repository clone or target-code execution.
  • No secret/token values are included.
  • No CVE or package-reputation lookup.
  • No numeric security score and no safe/unsafe verdict.

Repository context

Trust/community metadata is descriptive context only; it is not a security guarantee.

Repository age / activitycreated 2025-09-11 · active through 2026-09-24
Community signalsstars 52,548 · forks 4,486 · open issues 111
OwnershipOrganization · ChromeDevTools
LicenseApache-2.0
Repository statearchived NO · fork NO · default branch main

Continue the review