Web Agent ProtocolSAFE
🌐Web Agent Protocol (WAP) - Record and replay user interactions in the browser with MCP support
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
<img alt="Homepage" src="https://img.shields.io/badge/Visit-otatech.ai-blue"/> <img alt="Hugging Face" src="https://img.shields.io/badge/%F0%9F%A4%97%20Hugging%20Face-OTA%20AI-ffc107?color=ffc107&logoColor=white"/> <img alt="Code License" src="https://img.shields.io/badge/Code_License-MIT-f5de53?&color=f5deff"/>
Overview
The Web Agent Protocol (WAP) is a standardized framework designed to enable seamless interaction between users, web agents, and browsers by recording and replaying browser actions. It separates the concerns of action recording and execution, allowing for efficient automation and reusability. The Python SDK for WAP implements the full specification, making it easy to:
- Collect user‐interaction data with the OTA‐WAP Chrome extension.
- Convert the raw event stream into either _exact‐replay_ or _smart‐replay_ action lists.
- Convert recorded actions into _MCP_ servers for reuse by any agent or user
- Replay those lists using the _WAP-Replay_ protocol to ensure accurate browser operations.
WAP FULL DEMO
[](https://www.youtube.com/watch?v=joh9FXJfnwk)
Without WAP
WAP Record

2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
find_top_rated_keyboard_amazon_ca_exact_replay | read | exact replay: find a top rated keyboard on amazon.ca |
find_top_rated_keyboard_amazon_ca_smart_replay | read | smart replay: find a top rated keyboard on amazon.ca |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
'beacon',
img_data = base64.b64decode(item.state.screenshot)
img_data = base64.b64decode(first_screenshot)
base64.b64decode(screenshot_b64)
grunt, grunt-contrib-csslint, grunt-contrib-jshint, grunt-contrib-watch, grunt-zip
langchain-core, flask
chrome-extension/assets/pause.gif
chrome-extension/assets/recording.gif
Gates applied: no_behavioural_pass.
e8d4cd5f4258full audit observations/trust-audit/mcp-server/ota-tech-ai__web-agent-protocol.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | e8d4cd5f4258 | SAFE | B | 89 | first audit |
Questions
What is the Web Agent Protocol MCP server?
🌐Web Agent Protocol (WAP) - Record and replay user interactions in the browser with MCP support
What tools does Web Agent Protocol expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Web Agent Protocol safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Web Agent Protocol need?
It reads AZURE_OPENAI_API_KEY_EAST_US, AZURE_OPENAI_API_KEY_EAST_US_2, AZURE_OPENAI_API_KEY_WEST_EU, AZURE_OPENAI_API_KEY_WEST_US, DOLPHIN_API_TOKEN, LLM_API_KEY and SKIP_LLM_API_KEY_VERIFICATION from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Web Agent Protocol run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as WAP-Browser-Action-Capturer at 1.3.0.
How current is this page?
The grade is for one exact copy of the source (e8d4cd5f4258), read on 2026-09-30. The repository is watched and re-audited when it changes.