Atlas / MCP servers / ota-tech-ai / Web Agent Protocol

Web Agent ProtocolSAFE

mcp/ota-tech-ai/web-agent-protocol

🌐Web Agent Protocol (WAP) - Record and replay user interactions in the browser with MCP support

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MIT
Stars
508
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

<img alt="Homepage" src="https://img.shields.io/badge/Visit-otatech.ai-blue"/> <img alt="Hugging Face" src="https://img.shields.io/badge/%F0%9F%A4%97%20Hugging%20Face-OTA%20AI-ffc107?color=ffc107&logoColor=white"/> <img alt="Code License" src="https://img.shields.io/badge/Code_License-MIT-f5de53?&color=f5deff"/>

Overview

The Web Agent Protocol (WAP) is a standardized framework designed to enable seamless interaction between users, web agents, and browsers by recording and replaying browser actions. It separates the concerns of action recording and execution, allowing for efficient automation and reusability. The Python SDK for WAP implements the full specification, making it easy to:

  1. Collect user‐interaction data with the OTA‐WAP Chrome extension.
  2. Convert the raw event stream into either _exact‐replay_ or _smart‐replay_ action lists.
  3. Convert recorded actions into _MCP_ servers for reuse by any agent or user
  4. Replay those lists using the _WAP-Replay_ protocol to ensure accurate browser operations.

WAP FULL DEMO

[](https://www.youtube.com/watch?v=joh9FXJfnwk)

Without WAP

WAP Record

![image](https://github.com/user-attachments/as

Read from source at commit e8d4cd5f4258OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add WAP-Browser-Action-Capturer --env AZURE_OPENAI_API_KEY_EAST_US=${AZURE_OPENAI_API_KEY_EAST_US} --env AZURE_OPENAI_API_KEY_EAST_US_2=${AZURE_OPENAI_API_KEY_EAST_US_2} --env AZURE_OPENAI_API_KEY_WEST_EU=${AZURE_OPENAI_API_KEY_WEST_EU} --env AZURE_OPENAI_API_KEY_WEST_US=${AZURE_OPENAI_API_KEY_WEST_US} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "WAP-Browser-Action-Capturer": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AZURE_OPENAI_API_KEY_EAST_US": "${AZURE_OPENAI_API_KEY_EAST_US}",
        "AZURE_OPENAI_API_KEY_EAST_US_2": "${AZURE_OPENAI_API_KEY_EAST_US_2}",
        "AZURE_OPENAI_API_KEY_WEST_EU": "${AZURE_OPENAI_API_KEY_WEST_EU}",
        "AZURE_OPENAI_API_KEY_WEST_US": "${AZURE_OPENAI_API_KEY_WEST_US}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
find_top_rated_keyboard_amazon_ca_exact_replayreadexact replay: find a top rated keyboard on amazon.ca
find_top_rated_keyboard_amazon_ca_smart_replayreadsmart replay: find a top rated keyboard on amazon.ca
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
browser_use/browser/context.py:543
'beacon',
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
browser_use/agent/gif.py:108
img_data = base64.b64decode(item.state.screenshot)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
browser_use/agent/gif.py:150
img_data = base64.b64decode(first_screenshot)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
browser_use/browser/tests/screenshot_test.py:28
base64.b64decode(screenshot_b64)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
chrome-extension/package.json
grunt, grunt-contrib-csslint, grunt-contrib-jshint, grunt-contrib-watch, grunt-zip
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
langchain-core, flask
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
chrome-extension/assets/pause.gif
chrome-extension/assets/pause.gif
Why it matters. 1689871 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
chrome-extension/assets/recording.gif
chrome-extension/assets/recording.gif
Why it matters. 1604476 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha e8d4cd5f4258full audit observations/trust-audit/mcp-server/ota-tech-ai__web-agent-protocol.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-30e8d4cd5f4258SAFEB89first audit
06

Questions

What is the Web Agent Protocol MCP server?

🌐Web Agent Protocol (WAP) - Record and replay user interactions in the browser with MCP support

What tools does Web Agent Protocol expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Web Agent Protocol safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Web Agent Protocol need?

It reads AZURE_OPENAI_API_KEY_EAST_US, AZURE_OPENAI_API_KEY_EAST_US_2, AZURE_OPENAI_API_KEY_WEST_EU, AZURE_OPENAI_API_KEY_WEST_US, DOLPHIN_API_TOKEN, LLM_API_KEY and SKIP_LLM_API_KEY_VERIFICATION from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Web Agent Protocol run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as WAP-Browser-Action-Capturer at 1.3.0.

How current is this page?

The grade is for one exact copy of the source (e8d4cd5f4258), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement