CRX aminer
Extension icon

Browser MCP - Automate your browser using VS Code, Cursor, Claude, and more

Version 1.3.4 View in Chrome Web Store

Last scanned: about 17 hours ago

Extension Details

Developer: browsermcp.io
Rating: 4.8 ★ (652 ratings)
Users: 100,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a strong user base with 100,000 users and an excellent 4.8-star rating from 652 reviews, suggesting legitimate functionality. The developer domain browsermcp.io appears to be purpose-built for this tool, and the description clearly states its automation capabilities for browser control via development tools like VS Code and Claude.

Concerns:

The extension requests an extremely powerful combination of permissions that essentially grants complete browser control. The debugger permission is particularly concerning as it can manipulate other extensions and browser internals. Combined with broad host permissions and content script injection across all websites, this creates a perfect storm for potential abuse. The webNavigation and tabs permissions enable comprehensive browsing surveillance. While these permissions align with the stated automation functionality, they represent maximum possible access to user data and browser activity.

Recommendations:

Given the critical risk level, run this extension in a completely isolated Chrome profile dedicated solely to development work. Never use this profile for personal browsing, banking, or accessing sensitive accounts. Only install when actively using the automation features, and consider disabling it when not needed. Ensure you fully trust the developer and understand that this extension has unprecedented access to your entire browsing session. Monitor for any unexpected behavior and regularly review what data the extension might be collecting.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: debugger
This extension has the debugger permission. Can debug and manipulate other extensions/apps. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.