schrute (sheeki03/schrute) is an MCP server listed on the M8ven Trust Index. It scores 48 out of 100, grade D. It declares 39 tools. No publisher has claimed this listing.
Universal Self-Learning Browser Agent. UI automation for the first run, API-level replay for the 100th run
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
sheeki03
Source: github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
schrute_exploreStart a browser session to explore a website
schrute_recordStart recording an action frame for skill generation
schrute_stopStop recording and return a pipeline job ID for background processing
schrute_pipeline_statusGet the status of a background recording pipeline job
schrute_sitesList all known sites
schrute_skillsList skills, optionally filtered by site
schrute_statusGet current session and engine status
schrute_dry_runPreview a request for a skill without executing it
schrute_set_transformSet or clear an output transform for a skill
schrute_export_skillExport a skill as standalone curl, fetch, Python, or Playwright code
schrute_create_workflowCreate a read-only linear workflow skill from existing active GET/HEAD skills
schrute_confirmConfirm or deny first-run of a newly-active skill
schrute_connect_cdpConnect to an Electron app or existing browser via Chrome DevTools Protocol. Domains are host-only (port-agnostic).
schrute_recover_exploreRecover an explore session blocked by Cloudflare by handing off to a real local Chrome session
schrute_sessionsList all named browser sessions
schrute_close_sessionClose a named browser session
schrute_switch_sessionSwitch active browser session for tool routing
schrute_import_cookiesImport cookies from a Netscape/Mozilla cookie file into a browser context
schrute_executeExecute any skill by ID (cross-site)
schrute_activateManually activate a DRAFT or BROKEN skill (first execution still requires confirmation)
schrute_doctorRun diagnostic checks on browser engine, config, database, etc.
schrute_export_cookiesExport cookies from a browser context
schrute_webmcp_callCall a WebMCP tool discovered on the current site. Use schrute_status to see available tools.
schrute_search_skillsSearch learned skills by keyword. Returns matching skill IDs, input guidance, and metadata. Use with schrute_execute to run a skill by ID.
schrute_revokeRevoke permanent approval for a skill (next execution will require confirmation again)
schrute_amendmentsList amendments for a skill
schrute_optimizeRun GEPA offline optimization on a broken or degraded skill
schrute_delete_skillPermanently delete a skill and its amendments/exemplars (admin only)
schrute_list_tabsList open tabs in a CDP-connected browser session
schrute_select_tabSwitch to a specific tab by URL or title in a CDP session
schrute_capture_recentCapture recent network activity and generate skills from it. Requires a CDP-connected session (schrute_connect_cdp). Does not work with schrute_explore sessions.
schrute_performance_traceStart/stop performance trace on the current browser session
schrute_test_webmcpTest a WebMCP tool with sample inputs and validate the response
schrute_batch_executeExecute multiple skill calls in sequence with batch confirmation
schrute_webmcp_directorySearch the local WebMCP tool directory across all known sites
schrute_api_coverageRun discovery on a URL and report API surface coverage against learned skills
schrute_workflow_suggestionsList pending workflow suggestions for a site
schrute_accept_suggestionAccept a workflow suggestion and create the workflow skill
LoginAuthenticate and get access token
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Fastify's Content-Type header tab character allows body validation bypass
AGENT_BROWSER_SOCKET_DIRProgramFilesProgramFiles(x86)SCHRUTE_DIRECT_TRANSPORTXDG_RUNTIME_DIRDependencies
17 runtime dependencies (9 dev), 2 flagged: playwright, playwright-core
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
39/39 tools missing one or more hints — schrute_explore (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); schrute_record (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); schrute_stop (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +36 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
27/39 tools referenced in tests (69%)
Write tests that reference each tool by name so every tool has at least one test.
No arbitrary install scripts
Has postinstall/preinstall script — runs arbitrary code on npm install
Remove postinstall/preinstall hooks unless they’re essential.
Production dependencies are patched
0 critical, 7 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
1 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Dependency freshness
1/17 production deps stale: pngjs@2023-02-20 (3.5y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/sheeki03/schrute)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check