Web Proxy TrickyBird Blocks WebMCP Tool Access Before Registering Its Own
TrickyBird, a web proxy, had to address a security gap in WebMCP before implementing the browser-agent tool feature. Because all frames on a proxied page share the same origin, the default Permissions Policy would have allowed any ad frame to register tools into a user's session. The team fixed this by sending a tools=() Permissions-Policy header on every served document and removing document.modelContext from proxied pages via an injected shim. After locking down third-party access, TrickyBird registered a single tool called open_site on its own homepage, which navigates users to a proxied page when given a valid address. The tool is verified in Chrome 152 and scores correctly in Lighthouse 13.4.1, though real-world usage remains minimal as no known agent traffic has appeared yet.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in