High Risk →

camofox_evaluate_js

Execute JavaScript in the browser page context. Runs in isolated scope (invisible to page scripts — safe for anti-detection). Use for: extracting data not visible in accessibility snapshot, checking element properties, reading computed styles, manipulating DOM elements. Requires CAMOFOX_API_KEY t...

How to control camofox_evaluate_js ↓

AI agents invoke camofox_evaluate_js to trigger actions in Camofox. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call — builds kicked off, notifications sent, workflows started.

High Risk

This tool runs arbitrary JavaScript in a live browser context, which is a classic Execute operation. While the description notes it runs in 'isolated scope' for anti-detection purposes, it still has the capability to execute arbitrary code and manipulate the DOM.

From the tool's definition Tool name 'camofox_evaluate_js' and description states it will 'Execute JavaScript in the browser page context' and enable 'manipulating DOM elements'. These are explicit indicators of code execution capabilities.

Documented attack patterns abuse exactly the kind of access camofox_evaluate_js gives an agent:

PolicyLayer is an MCP gateway — it sits between your AI agents and Camofox, and nothing reaches the server without passing your rules. This is the rule we recommend for camofox_evaluate_js:

policy.json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "camofox_evaluate_js": {
      "limits": [
        {
          "counter": "camofox_evaluate_js_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}

camofox_evaluate_js stays usable, but rate-capped — a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.

  1. Create a free account and register Camofox — nothing to install.
  2. Add this policy — paste it, or build it visually.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
RATE-LIMIT THIS TOOL →

Free to start. No card required.

Go deeper

What does the camofox_evaluate_js tool do? +

Execute JavaScript in the browser page context. Runs in isolated scope (invisible to page scripts — safe for anti-detection). Use for: extracting data not visible in accessibility snapshot, checking element properties, reading computed styles, manipulating DOM elements. Requires CAMOFOX_API_KEY to be configured. It is categorised as a Execute tool in the Camofox MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.

How do I enforce a policy on camofox_evaluate_js? +

Register the Camofox MCP server in PolicyLayer and add a rule for camofox_evaluate_js: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Camofox. Nothing to install.

What risk level is camofox_evaluate_js? +

camofox_evaluate_js is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.

Can I rate-limit camofox_evaluate_js? +

Yes. Add a rate_limit block to the camofox_evaluate_js rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block camofox_evaluate_js completely? +

Set action: deny in the PolicyLayer policy for camofox_evaluate_js. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides camofox_evaluate_js? +

camofox_evaluate_js is provided by the Camofox MCP server (redf0x1/camofox-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

Enforce policy on every Camofox tool call.

Deterministic rules across all 47 Camofox tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Free to start. No card required.

47 Camofox tools catalogued and risk-classified — across an index of 42,500+ MCP servers.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.