MCP server for HTTP/HTTPS MITM proxy via mockttp with browser automation, interceptors, and session management
This MCP server exposes 4 browser automation tools with generally solid naming and comprehensive parameter schemas. All tools follow verb_noun naming conventions and include detailed descriptions. Parameter definitions use Zod for type safety with descriptive annotations. However, there are notable gaps: (1) output schemas are not formally documented, responses are serialized to JSON text rather than structured typed objects; (2) error handling provides basic error-to-string conversion but lacks recovery guidance or categorization; (3) security considerations around file path traversal in screenshot tool are not documented; (4) pagination/truncation strategies are applied but not uniformly described. The code shows good engineering practices (Zod validation, defensive limit normalization, value capping) but MCP-level documentation is incomplete. Tools are composition-friendly (each does one thing) and parameter naming is consistent.
List console messages buffered since the browser was launched. Types: log, info, warning, error, debug, etc.
List cookies from the browser context with pagination and truncated value previews.
Take a screenshot of the bound page. Saves to file_path if provided; otherwise reports byte count without embedding the image.
Take an ARIA accessibility snapshot of the bound page (YAML-formatted role tree). Great for LLM-driven page understanding without parsing HTML.
Output schemas not formally documented. Tools return JSON-serialized text responses rather than structured typed objects. LLMs must parse text to extract fields, risking interpretation errors and wasting tokens.
Error responses lack recovery guidance. errorToString() converts exceptions to plain strings (e.g., 'Page not found'), but does not categorize errors as retryable/user-fixable/fatal or suggest next steps. Agents cannot distinguish between a timeout and a permissions error.
File path parameter (file_path in interceptor_browser_screenshot) accepts arbitrary paths without validation. No documented protection against path traversal attacks (e.g., '../../etc/passwd'). Security risk if agent is compromised or prompt-injected.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 63 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 37 | - | v1 |
Pagination and truncation behavior not uniformly described. list_console and list_cookies implement limit/offset with defaults and caps (DEFAULT_LIST_LIMIT=50, MAX_LIST_LIMIT=500), but tool descriptions do not state these limits. LLMs may assume unbounded results.
JPEG quality parameter description says '0-100' but does not document default behavior or whether out-of-range values are clamped/rejected. Zod schema uses .optional() but does not constrain range.