CSS Noop CheckerCAUTION
Chrome DevTools extension that detects CSS properties with no effect
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/purupurupu/css-noop-checker/actions/workflows/ci.yml) [](./LICENSE)
Chrome DevTools (Elements sidebar) extension that detects CSS properties that currently have no effect on the selected element.
Features
- Selected-element mode — inspects the currently selected element in DevTools
- Full-page scan — scans all elements on a page for violations
- Detection rules — categorized by context (inline, block, container, item, static, positioned, overflow, etc.)
- MCP server — exposes rules as tools for AI-assisted analysis via Playwright
- Actionable warnings — each warning includes a title, explanation, and fix suggestion
Detected Patterns
CSS Noop Checker finds CSS properties that have no visible effect on the element they are applied to. These "no-op" declarations are not syntax errors — they are valid CSS that the browser silently ignores due to layout context. For example, width on an inline `, or gap` on a non-flex/grid container.
[!NOTE] Rule correctness in this project is based primarily on current Chromium behavior, not on spec interpretation alone. A declaration may be valid CSS, partially effective, or browser-dependent. For nuanced cases, the source of truth is the real-browser coverage in examples/test.html + Playwright, not unit tests alone.Inline
e7b5640db805OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add css-noop-checker -- npx -y [email protected]
{
"mcpServers": {
"css-noop-checker": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_element | read | Analyze a specific element on a page for CSS no-op violations |
list_rules | read | List all available CSS no-op detection rules |
scan_page | read | Scan all elements on a page for CSS no-op violations |
Trust audit
CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (16)
Produce your review in the output format from your system prompt.
.mise.toml
.oxfmtrc.jsonc
.oxlintrc.json
expect(() => new Function('$0', `return ${script}`)).not.toThrow();import '../../src/rules/engine.ts';
import type { ElementData } from '../../src/rules/types.ts';} from '../../src/rules/registry.ts';
import { isElementData } from '../../src/rules/validation.ts';import { MAX_SCAN_ELEMENTS, SKIP_TAGS } from '../../src/rules/scan-constants.ts';expect(() => validateUrl('http://127.0.0.1')).toThrow('private/internal address');expect(() => validateUrl('http://10.0.0.1')).toThrow('private/internal address');expect(() => validateUrl('http://100.64.0.1')).toThrow('private/internal address');@modelcontextprotocol/sdk, playwright, zod, @types/node, tsup, tsx, typescript
react, react-dom, @playwright/test, @testing-library/react, @types/chrome, @types/node, @types/react, @types/react-dom
docs/demo.gif
Gates applied: no_behavioural_pass.
e7b5640db805full audit observations/trust-audit/mcp-server/purupurupu__css-noop-checker.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | e7b5640db805 | CAUTION | B | 84 | first audit |
Questions
What is the CSS Noop Checker MCP server?
Chrome DevTools extension that detects CSS properties with no effect
What tools does CSS Noop Checker expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is CSS Noop Checker safe to connect to an agent?
With care. The audit graded it B (84/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does CSS Noop Checker need?
No credential environment variables were found in its source, so it appears to need none.
How does CSS Noop Checker run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as css-noop-checker at 0.1.1.
How current is this page?
The grade is for one exact copy of the source (e7b5640db805), read on 2026-10-09. The repository is watched and re-audited when it changes.