Static source inference · medium confidence · detected: Logging
Deprecated protocol patterns detected
Summary
camofox-browser-mcp demonstrates solid tool definition quality with consistent naming patterns, comprehensive schema definitions, and clear descriptions. All 11 tools follow verb_noun convention (camofox_web_search, camofox_navigate, etc.). Schemas are well-structured with proper JSON Schema types and descriptions for all parameters. However, several medium-severity gaps prevent a higher score: (1) Output schemas are not documented in the source, tool descriptions lack detail about return types and structure, which LLMs need for downstream chaining; (2) Error handling guidance is minimal, descriptions don't explain recovery paths or categorize failures; (3) Parameter descriptions, while present, are somewhat generic and lack format constraints (e.g., no regex patterns, character limits, or range boundaries stated explicitly); (4) No tool-level annotations (readOnlyHint/destructiveHint/idempotentHint) despite clear semantic differences in risk profiles (READ_ONLY vs WRITE tools exist but are not formally annotated in the schema).
Tools (11)
camofox_clear_cookieswriteauth50/100
Clears all cookies from the camofox-browser instance.
camofox_click_elementwriteauth50/100
Clicks an element on the current page in camofox-browser using a selector.
camofox_execute_scriptwriteauth50/100
Executes JavaScript code in the camofox-browser instance and returns the result.
camofox_fill_formwriteauth50/100
Fills form fields in camofox-browser with provided values.
camofox_get_contentread onlyauth50/100
Extracts the current page content from camofox-browser.
camofox_get_cookiesread onlyauth50/100
Retrieves all cookies from the camofox-browser instance.
camofox_navigateread onlyauth50/100
Navigates to a URL in the camofox-browser instance.
Output schemas are not documented. Tool descriptions lack return type specifications (e.g., what does camofox_web_search return? Array of results with which fields?). LLMs cannot plan downstream chaining without knowing what data is available after each call.
Error handling guidance is minimal or absent. Descriptions do not categorize failures as retryable, user-fixable, or fatal. No recovery hints provided (e.g., 'If element not found, try wait_for_element() first'). This forces LLMs to guess appropriate recovery steps.
Document return types for all tools in their descriptions. For camofox_web_search, specify: 'Returns an array of search results, each with: title (string), url (string), snippet (string), source_domain (string). Max 50 results per call.' For camofox_get_content, specify: 'Returns a single string containing the page content in the requested format (HTML, plain text, or Markdown).'
Add error handling guidance to every tool description. Example pattern: 'On failure, returns an error object with: code (string: NOT_FOUND|TIMEOUT|INVALID_INPUT|SERVER_ERROR), message (string), recovery_hint (string). Retryable: TIMEOUT and transient server errors. User-fixable: NOT_FOUND (element may have moved; try wait_for_element first). Fatal: INVALID_INPUT (selector syntax error).'
Implement tool annotations in schema. Add to each tool's definition: readOnlyHint (bool) for READ_ONLY risk tools, destructiveHint (bool) for WRITE risk tools. Example: camofox_clear_cookies should include destructiveHint=true and description note: 'WARNING: This clears all cookies. Irreversible without restore_cookies tool.'
Specify numeric parameter bounds. For timeoutMs, add: 'Must be between 100 and 300000 (5 minutes). Recommend <30000 for browser responsiveness.' For page/offset in future pagination: 'Page number must be ≥ 1; offset must be ≥ 0. Max limit per call: 100.'
Formalize camofox_fill_form field parameter. Replace generic object with structured schema: 'fields object where each key is a CSS selector and each value is a string (form data encoded as application/x-www-form-urlencoded or JSON). Example: {"input[name=email]": "user@example.com", "select[name=country]": "US"}. All values coerced to strings. Invalid selectors or missing fields return PARTIAL_FAILURE with details on which selectors matched/failed.'
Spec posture evidence
Inferred effective spec: 2026-07-28+.
Relies on Logging (deprecated) - log to stderr or use OpenTelemetry
Score history
Overall score trend
↑ 17 points across a rubric change (v1 → v2)
59/100
Scored
Grade
Overall
Spec posture
Rubric
2026-09-22
D
59
2026-07-28+
v2
2026-03-09
F
42
-
v1
auth
source verified
79/100
Takes a screenshot of the current page in camofox-browser.
camofox_set_cookieswriteauth50/100
Sets cookies in the camofox-browser instance for the current domain.
camofox_wait_for_elementread onlyauth50/100
Waits for an element matching the given selector to appear on the page in camofox-browser.
camofox_web_searchread onlyauth50/100
Performs a web search using camofox-browser with support for multiple search engines via macros.
Missing tool annotations (toolAnnotations feature is claimed but not visible in schema). WRITE tools (camofox_click_element, camofox_fill_form, camofox_set_cookies, camofox_clear_cookies, camofox_execute_script) should include destructiveHint=true where appropriate; READ_ONLY tools should include readOnlyHint=true. Risk field exists but is not formalized in MCP schema.
Parameter constraints are underspecified. Numeric params lack min/max bounds (e.g., timeoutMs has no stated limit; could be 1ms or 1 hour with equal validity). String params lack format patterns (CSS selectors, URLs). LLMs cannot validate inputs without explicit constraints.
camofox_execute_script has no security warnings in description. JavaScript execution in a browser context is high-risk (DOM access, storage, cookies, network requests). Description must explain data leakage risks, output size limits, and that arbitrary scripts run with page permissions.
camofox_fill_form uses generic object type for 'fields' parameter. No schema for field values (string vs number vs boolean), no documentation of required fields, no guidance on form validation or CSRF tokens. This invites invalid payloads.
camofox_fill_form
Add security note to camofox_execute_script. Description should state: 'WARNING: Arbitrary JavaScript runs in the page context with full access to DOM, localStorage, cookies, and network. Do not execute untrusted scripts. Output is limited to 1MB; large returns are truncated. Errors (syntax, runtime exceptions) return error code SCRIPT_ERROR with exception message.'
For camofox_navigate, clarify wait/timeout behavior: 'Waits up to 30 seconds for page load (until networkidle). Returns success immediately on redirect; subsequent get_content() call fetches the final destination. Timeouts return TIMEOUT error with partial page state available via get_content().'
For camofox_screenshot, document return format: 'Returns a base64-encoded PNG image of the viewport (1024x768 by default). Use data URL in markdown: . Large pages capture only visible viewport; not full-page scrolls.'
For camofox_click_element, add idempotency note: 'Idempotent if element state doesn't change. Clicking a toggle button twice may revert state. If repeatability matters, verify element state before and after via get_content().'
For camofox_get_cookies, clarify scope: 'Returns ALL cookies currently set in the browser for the loaded domain. Result is an array of cookie objects. To filter by name/domain/path, use camofox_execute_script with custom filtering logic.'