Scan identity
Evidence summary
The repository is the Chrome DevTools MCP server for coding agents and has substantial current developer interest. The bounded review observed MCP client configuration, multiple child-process execution paths in tooling and runtime utilities, GitHub automation and explicit MCP/automation dependency declarations.
Evidence categories
MCP configuration
FoundSelected configuration evidence was observed. This does not establish how any user's client is configured.
README.mdmcpServers configuration examplesmcp.jsonstdio server definition using npxdocs/configuration.mdadditional client configuration examples
Shell / command execution
FoundSelected process-execution evidence was observed. This does not prove a vulnerability or malicious behavior.
src/daemon/client.tsspawn imported from node:child_processsrc/telemetry/WatchdogClient.tschild process spawn used by watchdog clientscripts/prepare.tsexecSync used in repository preparation tooling
CI/CD automation
FoundRepository-level GitHub workflow and dependency automation are present in the selected scope.
.github/workflows/GitHub Actions workflow directory observed.github/dependabot.ymldependency update automation configuration
Supply-chain / dependencies
FoundSelected package dependency declarations were observed; this is not a complete dependency audit.
package.jsonMCP v2 client/core/server packages, Puppeteer, Lighthouse and build dependencies declaredpackage.jsonallowScripts policy explicitly controls selected install scripts
Scope and limitations
Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.
- Public, selected and bounded repository evidence only.
- FOUND means evidence observed, not risk or malicious behavior proven.
- Search matches were reviewed against immutable commit 6a7e51fecaaefbea46b89e68892d42c175ee9163.
- No repository clone or target-code execution.
- No secret/token values are included.
- No CVE or package-reputation lookup.
- No numeric security score and no safe/unsafe verdict.
Repository context
Trust/community metadata is descriptive context only; it is not a security guarantee.