Model Context Protocol server for Amazon Nova Act browser automation
Single tool 'browse' with basic schema and description. Tool is well-named (verb-first: browse), has a reasonable description (81 chars), and includes input parameters with types and descriptions. However, the tool combines multiple responsibilities (start browser, execute instructions, close session) into one call, output schema is not documented, error handling is absent, and there is no guidance for recovery or retry logic. The schema is present but incomplete, lacks detailed constraints, validation rules, and output format documentation. Security concern: the tool executes arbitrary instructions in a browser with write access (WRITE risk), but there is no documentation of rate limits, permission checks, or audit trails.
Execute a sequence of instructions in a single browser session. This endpoint handles the entire workflow: starting a browser, executing instructions, and closing the session.
Output schema not documented. The tool accepts a 'schema' parameter for structured output, but the tool definition itself does not declare what fields the response contains or what format results are returned in. LLMs cannot plan downstream tool calls without knowing the response structure.
No error handling or recovery guidance. The tool description does not explain what errors might occur (network failure, timeout, invalid instruction), how to classify them (retryable vs. fatal), or what the agent should do next. A raw 500 or timeout gives the LLM no direction.
Tool combines multiple concerns (start session, execute, close session). Per single-responsibility principle, this should be split into separate tools or the unified behavior should be justified in the tool composition pattern. Currently, an agent cannot start a browser without executing instructions, or execute without closing, limiting flexibility.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 65 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 33 | - | v1 |
No pagination or result limit documented. The 'instructions' array is unbounded, 'results' array size is unconstrained, and there is no guidance on token cost or context window impact. Agents could pass 1000 instructions and receive massive responses.
Security: Tool marked as WRITE risk but has no documented permission checks, rate limits, or audit trail requirements. Browser automation is powerful, instructions could extract data, modify state, or launch attacks. No guidance on scope restrictions or how to verify authorization.
Parameter 'schema' expects a JSON schema object but is typed as Dict[str, Any] with no description of format, required fields, or what happens if it is invalid. This is error-prone, the LLM could pass malformed schemas and receive a cryptic error.
Missing parameter descriptions for 'timeout_per_instruction' (null default is ambiguous, does it mean no timeout, or inherit a server default?) and no documentation of time unit (seconds is stated but not enforced). 'max_steps_per_instruction' default of 30 is not justified.