MCP server for Chrome DevTools Protocol integration - control Chrome tabs, execute JavaScript, capture screenshots, and monitor network traffic
Chrome Tools MCP has 7 well-named tools that follow verb_noun conventions (list_tabs, capture_screenshot, execute_script, load_url, capture_network_events, query_dom_elements, click_element). All tools have descriptions and input schemas with Zod validation visible in src/index.ts. However, definitions lack critical production-grade polish: output schemas are NOT documented (tools return plain text or JSON without field descriptions), parameter descriptions are present but inconsistent in depth and clarity, and error handling provides generic error messages without recovery guidance or error classification. Description lengths average ~60 chars, which is below the 194-char baseline for production tools. The code shows proper Zod schema registration (good), but MCP's structured output pattern (returning typed objects with described fields) is not applied, most tools return {content: [{type: 'text', text: ...}]} without documenting what fields the response contains. Naming is excellent (all verb-first, action-clear), but the definition completeness score is dragged down by missing output documentation and generic error handling.
Capture network events (XHR/Fetch) from a specific Chrome tab
Capture a screenshot of a specific Chrome tab
Click an element in a Chrome tab using CSS selector
Execute JavaScript code in a specific Chrome tab
List all available Chrome tabs
Load a URL in a specific Chrome tab
Query DOM elements in a Chrome tab using CSS selector
Output schemas are not documented. Tools return content arrays with type 'text' and unstructured JSON strings, but LLMs cannot parse what fields to expect from the response. capture_screenshot returns {status, path}, list_tabs returns tab objects, but these are never formally declared or constrained. LLMs must guess the response structure.
Error messages are generic and do not guide recovery. All tools return 'Error: <message>' without categorizing whether the error is retryable, user-fixable, or fatal. Example: 'Error: Tab not found' gives the LLM no actionable next step (should suggest: 'Try list_tabs() to find a valid tab ID').
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 48 | - | v1 |
Descriptions are too brief (avg 60 chars vs 194-char baseline). execute_script ('Execute JavaScript code in a specific Chrome tab') lacks context on when to use it vs query_dom_elements, and does not warn that arbitrary JS execution is powerful and may have side effects. load_url and query_dom_elements have similarly generic descriptions.
Parameter descriptions lack depth. 'tabId: ID of the Chrome tab...' is present but does not explain HOW to obtain a tab ID (call list_tabs first) or whether IDs are stable across connections. 'script' parameter in execute_script has no constraints or examples of valid JS patterns.
No input validation error messages. If an LLM passes an invalid URL format to load_url, a zod validation failure will occur but the tool does not provide a corrective error like 'Invalid URL format: must start with http:// or https://'.
Missing tool annotations (readOnlyHint/destructiveHint/idempotentHint). execute_script, load_url, and click_element are marked in the provided data as WRITE risk, but the tool registration in src/index.ts does not use MCP's tool annotation feature to declare this risk to the client. This prevents agents from understanding which tools modify state.
No dry-run or confirmation pattern for destructive operations. execute_script and click_element can modify page state, but agents cannot preview the effect or confirm before executing. This invites accidental side effects.
capture_network_events filters parameter structure is underspecified. The 'filters' object accepts 'types' (array of enum) and 'urlPattern' (string regex?), but there is no documentation of whether urlPattern is a regex, wildcard pattern, or substring match. This ambiguity invites incorrect usage.