HTMLをレンダリングしてレイアウトの破綻を検出するMCPサーバー。ベースライン画像は不要。検査専用・自動修正なし。
Single tool 'layout_check' with well-structured Zod schema, comprehensive parameter definitions, and detailed descriptions. Tool exhibits excellent naming (verb_noun pattern: 'layout_check'), extensive parameter documentation with constraints, and structured output design. However, output schema is not formally documented in the source code, only mentioned in the description text. Error handling provides actionable guidance. Schema validation is thorough with min/max bounds on numeric parameters and enum constraints on check types. Description is LLM-optimized and detailed (470+ chars), exceeding baseline. One critical gap: tool accepts 'url' parameter without documented network restrictions beyond a boolean flag, and the description implies localhost-only restriction but the implementation allows arbitrary URLs if allowNetwork=true, a security concern that should be more explicitly gated.
HTMLをレンダリングしてレイアウトの破綻を検出する。検査専用でファイルは変更しない。 比較用のベースライン画像は不要。DOMの座標と文字の描画矩形を実測するため、 「どの要素が何ピクセルはみ出しているか」が数値で返る。 検出: 文字の重なり / 画面外や親からのはみ出し / overflow:hidden による切り捨て / 横スクロールの発生 / undefined・{{name}} 等の未展開 / 参照切れ / id重複 / 不可視テキスト 引数: - html | path | url のいずれか1つ(必須) - viewport (必須): { width, height }。幅で結果が変わるため既定値なし - checks (任意): 検査の絞り込み。既定は element-collision 以外すべて - format (任意): "text"(既定)または "json" その他: minOverlapPx, minOverlapArea, allowNetwork, executablePath, settleMs 戻り値: summary(pass, errors, warnings, infos)と findings の配列。 各所見は check / severity / verdict / elements(selector, text, rect)/ evidence / suggest を持つ。 verdict は "static"(確定)か "candidate"(座標上は検出、可視性は未判定)。 対象外: デザインの評価、コントラスト比などのアクセシビリティ検査、前回との差分比較。
Output schema not formally documented in source code. The description text describes the output structure (summary with pass/errors/warnings/infos, findings array with check/severity/verdict/elements/evidence/suggest fields), but there is no structured JSON Schema definition visible for the return type. This forces LLMs to infer the response structure from prose alone, risking misalignment.
URL parameter lacks explicit security gate. The tool accepts 'url' with optional allowNetwork flag, but the description states 'localhost のみ' (localhost only by default) without enforcing this. If allowNetwork=false and a non-localhost URL is passed, error handling is not visible in code. This could allow confused agents to attempt restricted network access.
Parameter relationships underdocumented. The 'checks' parameter is optional and defaults to 'element-collision 以外すべて' (all except element-collision), but the dependency between checks and minOverlapPx/minOverlapArea is not explicitly stated. The description hints these thresholds apply to overlap detection, but the relationship is implicit, not explicit.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 76 | 2025-06-18+ | v2 |
Secrets / executable paths in parameters. The 'executablePath' parameter allows agents to specify a Chromium binary path. If an agent is compromised or tricked via prompt injection, it could point to a malicious binary. No validation or allowlist is visible in the code snippet.