Atlas / MCP servers / vpalmisano / WebRtcPerf

WebRtcPerfBLOCK

mcp/vpalmisano/webrtcperf

WebRTC performance and quality evaluation tool.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
AGPL-3.0
Stars
225
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

GitHub page | Documentation

[](https://github.com/vpalmisano/webrtcperf/actions/workflows/build.yaml)

[](https://cursor.com/en/install-mcp?name=webrtcperf&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkB2cGFsbWlzYW5vL3dlYnJ0Y3BlcmZAbGF0ZXN0IiwiLS1tY3AiXX0=) [](https://insiders.vscode.dev/redirect/mcp/install?name=webrtcperf&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40vpalmisano%2Fwebrtcperf%40latest%22%2C%22--mcp%22%5D%7D)

WebRtcPerf is an open-source tool designed for testing WebRTC services with multiple concurrent client connections, measuring the most important RTC statistics and collecting them in an easy way. This documentation will dive into its multiple features and configuration options, showing you how to leverage this tool to gain valuable insights into your real-time communication solutions.

Prerequisites and installation

The webrtcperf tool is a NodeJS application spawning multiple Puppeteer headless browsers that will actually start the WebRTC connections, so it could ideally run on every platform where NodeJS and Chromium browser could run. Anyway, to gain advantage of some specific features, using a Linux OS is the suggested way to use the tool. If you plan to run multiple concurrent connections to an external host running the WebRTC service, you need to make sure that your machine has enough network bandwidth to send and receive the audio/video streams without affecting the quality and an amount of CPU and memory proportional to the number of c

Read from source at commit 2a454852c189OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add webrtcperf --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GOOGLE_CREDENTIALS_PATH=${GOOGLE_CREDENTIALS_PATH} -- npx -y @vpalmisano/[email protected]
claude-desktop
{
  "mcpServers": {
    "webrtcperf": {
      "command": "npx",
      "args": [
        "-y",
        "@vpalmisano/[email protected]"
      ],
      "env": {
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "GOOGLE_CREDENTIALS_PATH": "${GOOGLE_CREDENTIALS_PATH}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
webrtcperfreadStarts a webrtcperf test.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (13 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/stats.ts:499
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/stats.ts:655
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/utils.ts:457
const httpsAgent = new Agent({ rejectUnauthorized: false })
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/utils.ts:567
const httpsAgent = new Agent({ rejectUnauthorized: false })
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintrc.js
.eslintrc.js
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/scenarios/variable-rate-loss-delay.mjs:5
import { twoParticipantsWithRateLossDelay, formatThrottleRule } from '../../build/src/index.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/utils.ts:51
__dirname + '/../../..',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:696
--prometheus-pushgateway=http://127.0.0.1:9091 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:710
--push-stats-url=https://192.168.0.1:5000 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:721
--push-stats-url=https://192.168.0.1:5000 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/config.md:536
If set, logs are sent to the specified Prometheus Pushgateway service (example: "http://127.0.0.1:9091").
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
prometheus-stack/README.md:25
WebRTCPerf dashboard (http://127.0.0.1:3001/d/webrtcperf/webrtcperf).
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google/genai, @modelcontextprotocol/sdk, @puppeteer/browsers, @vpalmisano/webrtcperf-js, chalk-template, change-case, compression, convict
Why it matters. 76 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
media/docs/image3.png
media/docs/image3.png
Why it matters. 1451272 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 2a454852c189full audit observations/trust-audit/mcp-server/vpalmisano__webrtcperf.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-062a454852c189BLOCKD69first audit
06

Questions

What is the WebRtcPerf MCP server?

WebRTC performance and quality evaluation tool.

What tools does WebRtcPerf expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is WebRtcPerf safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does WebRtcPerf need?

It reads GEMINI_API_KEY and GOOGLE_CREDENTIALS_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does WebRtcPerf run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @vpalmisano/webrtcperf at 4.9.3.

How current is this page?

The grade is for one exact copy of the source (2a454852c189), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement