High-risk tools in Concurrent Browser MCP
12 of the 20 tools in Concurrent Browser MCP are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
browser_evaluateExecuteExecute JavaScript code in the page context
-
browser_navigateExecuteNavigate to a specified URL
-
browser_wait_for_elementExecuteWait for an element to appear
-
browser_wait_for_navigationExecuteWait for page navigation to complete
-
browser_clickExecuteClick on a page element
-
browser_create_instanceExecuteCreate a new browser instance
-
browser_fillExecuteFill a form field
-
browser_go_backExecuteGo back to the previous page
-
browser_go_forwardExecuteGo forward to the next page
-
browser_refreshExecuteRefresh the current page
-
browser_select_optionExecuteSelect an option from a dropdown
-
browser_typeExecuteType text into an element
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.