Web Debug MCP 0.7.0
0.7.0 adds a bounded direct-only Chrome WebMCP path and hybrid native-test authoring while keeping the public MCP catalog at 13 tools.
Highlights
- Adds direct WebMCP actions with bounded JSON arguments, opaque string/null results, fixed same-origin tool identity, and truthful
webmcp-page-apiprovenance. - Keeps WebMCP out of reproduction scenarios, retries, replay restoration, and server reset; every attempted call suppresses later screenshots and makes the replay generation non-restorable.
- Adds discover-only untrusted WebMCP capture metadata and the corresponding final wire-version cascade.
- Adds
webmcp-tool-authoringalongside strengthenedmanual-parity-qualificationandweb-debug-workflowskills. - Preserves repository-native UI/API/domain verdict authority and requires independent mutation evidence.
- Retains Safari WebDriver/BiDi after Safari 27 MCP failed the strict full-cutover gate; the workflow may use only the separately configured handle-scoped Safari MCP console/network diagnostic subset.
Compatibility and safety
Chrome WebMCP requires explicit browser support/activation and is reported as page-provided untrusted API, not native-browser attestation. Safari MCP diagnostics never merge with the authoritative Safari WebDriver session or award qualification PASS. Targets remain loopback-first, evidence remains bounded/redacted, and the package adds no hosted or production authority.
Verification
Final acceptance requires deterministic tests, typecheck/build, native harness, three skill validators, plugin validation, exact-archive Node 20/22/24 handshakes, live Chrome/WebMCP/framework/Safari WebDriver smokes, public fresh-cache install, exact source/tag/npm/GitHub identity, and one installed released Codex plugin with three skills and no duplicate MCP registration.