Chromate — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Chromate (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Chromate MCP is a Model Context Protocol server for Chrome tab automation over the Chrome DevTools Protocol (CDP). It is designed for AI agents that work from screenshots: select a tab, inspect a coordinate grid, click CSS viewport coordinates, then receive an after screenshot.
Chromate controls the web page content area. It does not operate the Chrome address bar, native tab strip, extension popups, file pickers, or OS windows.
npm install
npm run buildChromate does not launch Chrome automatically. It can connect to an already-running Chrome in two ways.
For Chrome 144+, open chrome://inspect/#remote-debugging in Chrome and enable remote debugging. Chromate reads Chrome's DevToolsActivePort metadata by default and connects to the running browser after Chrome shows and you approve the permission dialog.
For older Chrome versions or sandbox/VM setups, start Chrome with a remote debugging port:
google-chrome-stable \
--remote-debugging-address=127.0.0.1 \
--remote-debugging-port=9222 \
--user-data-dir=/tmp/chromate-profileChromate auto-discovers local Chrome on ports 9222, 9223, 9224, and 9333 when CHROMATE_CDP_ENDPOINT is not set. Any Chromium-based browser that exposes CDP can work if it supports /json/version and a browser-level WebSocket endpoint.
Example client configuration:
{
"mcpServers": {
"chromate": {
"command": "node",
"args": ["/data0/chromate/dist/index.js"],
"env": {}
}
}
}Set CHROMATE_CDP_ENDPOINT only when you want to force a specific CDP HTTP or WebSocket endpoint.
During development, use:
npm run devCHROMATE_CDP_ENDPOINT: CDP HTTP or WebSocket endpoint. If omitted, Chromate auto-discovers local CDP.CHROMATE_AUTO_CONNECT: read Chrome 144+ DevToolsActivePort metadata before scanning ports. Default: trueCHROMATE_AUTO_CONNECT_CHANNEL: Chrome channel for default profile lookup: stable, beta, dev, or canary. Default: stableCHROMATE_AUTO_CONNECT_USER_DATA_DIR: explicit Chrome user data directory containing DevToolsActivePortCHROMATE_CDP_DISCOVERY_PORTS: comma-separated local ports to scan. Default: 9222,9223,9224,9333CHROMATE_DISCOVERY_TIMEOUT_MS: per-port discovery timeout. Default: 350CHROMATE_CONNECT_TIMEOUT_MS: connection timeout. Default: 10000CHROMATE_ACTION_TIMEOUT_MS: command timeout. Default: 30000CHROMATE_SETTLE_DELAY_MS: wait after auto actions. Default: 500CHROMATE_GRID_STEP: screenshot grid spacing. Default: 100CHROMATE_LOG_LEVEL: silent, error, info, or debug. Default: infolist_tabs.select_tab with the desired tabId.screenshot and inspect the grid.click with CSS viewport coordinates.See docs/tool-contract.md for the full tool contract.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.