Atlas / MCP servers / purupurupu / CSS Noop Checker

CSS Noop CheckerCAUTION

mcp/purupurupu/css-noop-checker

Chrome DevTools extension that detects CSS properties with no effect

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
MIT
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/purupurupu/css-noop-checker/actions/workflows/ci.yml) [](./LICENSE)

Chrome DevTools (Elements sidebar) extension that detects CSS properties that currently have no effect on the selected element.

Features

  • Selected-element mode — inspects the currently selected element in DevTools
  • Full-page scan — scans all elements on a page for violations
  • Detection rules — categorized by context (inline, block, container, item, static, positioned, overflow, etc.)
  • MCP server — exposes rules as tools for AI-assisted analysis via Playwright
  • Actionable warnings — each warning includes a title, explanation, and fix suggestion

Detected Patterns

CSS Noop Checker finds CSS properties that have no visible effect on the element they are applied to. These "no-op" declarations are not syntax errors — they are valid CSS that the browser silently ignores due to layout context. For example, width on an inline `, or gap` on a non-flex/grid container.

[!NOTE] Rule correctness in this project is based primarily on current Chromium behavior, not on spec interpretation alone. A declaration may be valid CSS, partially effective, or browser-dependent. For nuanced cases, the source of truth is the real-browser coverage in examples/test.html + Playwright, not unit tests alone.

Inline

Read from source at commit e7b5640db805OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add css-noop-checker -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "css-noop-checker": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_elementreadAnalyze a specific element on a page for CSS no-op violations
list_rulesreadList all available CSS no-op detection rules
scan_pagereadScan all elements on a page for CSS no-op violations
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (16)

HIGHPrompt injection · prompt.read_system · CWE-94, CWE-1427
.claude/skills/team-dev/SKILL.md:347
Produce your review in the output format from your system prompt.
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mise.toml
.mise.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxfmtrc.jsonc
.oxfmtrc.jsonc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
e2e/integration/eval-script.test.ts:40
expect(() => new Function('$0', `return ${script}`)).not.toThrow();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/helpers/extract-element-data.ts:2
import '../../src/rules/engine.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/helpers/extract-element-data.ts:5
import type { ElementData } from '../../src/rules/types.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/helpers/extract-element-data.ts:10
} from '../../src/rules/registry.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/helpers/extract-element-data.ts:11
import { isElementData } from '../../src/rules/validation.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/helpers/extract-element-data.ts:12
import { MAX_SCAN_ELEMENTS, SKIP_TAGS } from '../../src/rules/scan-constants.ts';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/src/__tests__/url-validation.test.ts:109
expect(() => validateUrl('http://127.0.0.1')).toThrow('private/internal address');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/src/__tests__/url-validation.test.ts:113
expect(() => validateUrl('http://10.0.0.1')).toThrow('private/internal address');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/src/__tests__/url-validation.test.ts:134
expect(() => validateUrl('http://100.64.0.1')).toThrow('private/internal address');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-server/package.json
@modelcontextprotocol/sdk, playwright, zod, @types/node, tsup, tsx, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
react, react-dom, @playwright/test, @testing-library/react, @types/chrome, @types/node, @types/react, @types/react-dom
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
docs/demo.gif
docs/demo.gif
Why it matters. 1149343 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha e7b5640db805full audit observations/trust-audit/mcp-server/purupurupu__css-noop-checker.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09e7b5640db805CAUTIONB84first audit
06

Questions

What is the CSS Noop Checker MCP server?

Chrome DevTools extension that detects CSS properties with no effect

What tools does CSS Noop Checker expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is CSS Noop Checker safe to connect to an agent?

With care. The audit graded it B (84/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does CSS Noop Checker need?

No credential environment variables were found in its source, so it appears to need none.

How does CSS Noop Checker run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as css-noop-checker at 0.1.1.

How current is this page?

The grade is for one exact copy of the source (e7b5640db805), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement