Command Palette

Search for a command to run...

UnylyUnyly
Весь каталог

Supersayan Webmcp

БесплатноНе проверен

⛨ Next-Generation WebMCP Security Intelligence Platform. Detect. Defend. Trace. The complete countermeasure suite for the agentic web. Includes an experimental

GitHubEmbed

Описание

⛨ Next-Generation WebMCP Security Intelligence Platform. Detect. Defend. Trace. The complete countermeasure suite for the agentic web. Includes an experimental Google Chrome security extension for guarding against WebMCP CVEs.

README

SuperSayan MCP Security

SuperSayan — WebMCP Security

A full-stack security research platform for Google Chrome's WebMCP API, built by VRIL LABS. It covers 15 novel 0-day CVEs disclosed on 2026-08-01, with live detection scanning, offensive simulation, and defensive hardening — all accessible at webmcp.vril.dev.

The potentially novel CVEs detailed in this document were reported to Google on 8/04/2026.


What It Does

Module Description
Detection Engine Fingerprints the browser, analyzes WebMCP exposure, and scores threat level across all 15 CVEs
Offensive Engine Simulates attack vectors — MSTI injection, DOM clobbering, GPU agent proxy, QUIC replay, tool poisoning, and more
Defensive Shield Real-time countermeasures: MSTI shield, session guard, tool integrity verification, WebRTC/GPU protection
OSINT Tracer Generates attribution reports and identifies datacenter ASNs
Glow Extension Chrome extension (chrome-extension/glow) that surfaces MCP security status directly in the browser toolbar

CVE Coverage (15 Vectors)

SW-MCP-PERSIST · GPU-AGENT-PROXY · DOM-CLOBBER-MCP · EXT-MCP-BRIDGE · ANNOTATION-CONFUSION · CSS-KEY-MCP · QUIC-MCP-REPLAY · AUDIO-MCP-FP · MCP-SUPPLY-CHAIN · ELICIT-PHISH · ABORT-RACE · DECL-FORM-HIJACK · CLIENT-INVERT · COMPOSE-XOR · OBSERVE-ORACLE

Full disclosure: BUG-DISCLOSURE.md

Stack

  • Frontend: Next.js 16 App Router, React 19, TypeScript, Tailwind CSS v4
  • Extension: Chrome MV3 (chrome-extension/glow), TypeScript, esbuild
  • Infra: Vercel (hosting + edge), Cloudflare (DNS/CDN)

Getting Started

npm install
npm run dev        # http://localhost:3000

To build the Chrome extension:

cd chrome-extension/glow
npm install
npm run build      # outputs to dist/

Load dist/ as an unpacked extension in Chrome (chrome://extensions → Developer mode → Load unpacked).

Project Structure

src/
  app/              # Next.js App Router pages + API routes
  lib/supersayan/   # Core security library
    detection-engine.ts   # CVE scanning + threat scoring
    offensive-engine.ts   # Attack vector simulations
    defensive-shield.ts   # Real-time countermeasures
    osint-tracer.ts       # Attribution + ASN analysis
  components/       # UI components (shadcn/ui)
chrome-extension/
  glow/             # Chrome MV3 extension source

License

See LICENSE.


Built by VRIL LABS · Research disclosed 2026-08-01

from github.com/VRIL-LABS/supersayan-webmcp

Установка Supersayan Webmcp

У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.

▸ github.com/VRIL-LABS/supersayan-webmcp

FAQ

Supersayan Webmcp MCP бесплатный?

Да, Supersayan Webmcp MCP бесплатный — установка в пару кликов через Unyly без оплаты.

Нужен ли API-ключ для Supersayan Webmcp?

Нет, Supersayan Webmcp работает без API-ключей и переменных окружения.

Supersayan Webmcp — hosted или self-hosted?

Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.

Как установить Supersayan Webmcp в Claude Desktop, Claude Code или Cursor?

Открой Supersayan Webmcp на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.

Похожие MCP

Playwright

Browser automation, scraping, screenshots

Microsoftавтор: Microsoft

Puppeteer

Browser automation and web scraping.

modelcontextprotocolавтор: modelcontextprotocol

Garmin Connect

An MCP server for Garmin Connect that provides access to fitness activities, health statistics, and sleep data by routing requests through a headless browser to

etweisbergавтор: etweisberg

Higgsfield Unlimited

MCP server for Higgsfield AI that enables unlimited-mode image, video, audio generation, uploads, and job management via multiple parallel accounts, using brows

nukIeerавтор: nukIeer

opentabs-dev/opentabs

Plugin-based MCP server + Chrome extension that gives AI agents access to web applications through the user's authenticated browser session. 100+ plugins with a

opentabs-devавтор: opentabs-dev

robhunter/agentdeals

1,500+ developer infrastructure deals, free tiers, and startup programs across 54 categories. Search deals, compare vendors, plan stacks, and track pricing chan

robhunterавтор: robhunter

hlydecker/ucsc-genome-mcp

MCP server to interact with the UCSC Genome Browser API, letting you find genomes, chromosomes, and more.

hlydeckerавтор: hlydecker

34892002/bilibili-mcp-js

A MCP server that supports searching for Bilibili content. Provides LangChain integration examples and test scripts.

34892002автор: 34892002

achiya-automation/safari-mcp

Native Safari browser automation for AI agents with 80+ tools. No Chrome dependency, optimized for Apple Silicon with 60% less CPU overhead.

achiya-automationавтор: achiya-automation

agent-infra/mcp-server-browser

Browser automation capabilities using Puppeteer, both support local and remote browser connection.

bytedanceавтор: bytedance

Compare Supersayan Webmcp with

Не уверен что выбрать?

Найди свой стек за 60 секунд

Автор?

Embed-бейдж для README

Похожее

Все в категории browse