WebRtcPerfBLOCK
WebRTC performance and quality evaluation tool.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/vpalmisano/webrtcperf/actions/workflows/build.yaml)
[](https://cursor.com/en/install-mcp?name=webrtcperf&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkB2cGFsbWlzYW5vL3dlYnJ0Y3BlcmZAbGF0ZXN0IiwiLS1tY3AiXX0=) [](https://insiders.vscode.dev/redirect/mcp/install?name=webrtcperf&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40vpalmisano%2Fwebrtcperf%40latest%22%2C%22--mcp%22%5D%7D)
WebRtcPerf is an open-source tool designed for testing WebRTC services with multiple concurrent client connections, measuring the most important RTC statistics and collecting them in an easy way. This documentation will dive into its multiple features and configuration options, showing you how to leverage this tool to gain valuable insights into your real-time communication solutions.
Prerequisites and installation
The webrtcperf tool is a NodeJS application spawning multiple Puppeteer headless browsers that will actually start the WebRTC connections, so it could ideally run on every platform where NodeJS and Chromium browser could run. Anyway, to gain advantage of some specific features, using a Linux OS is the suggested way to use the tool. If you plan to run multiple concurrent connections to an external host running the WebRTC service, you need to make sure that your machine has enough network bandwidth to send and receive the audio/video streams without affecting the quality and an amount of CPU and memory proportional to the number of c
2a454852c189OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add webrtcperf --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GOOGLE_CREDENTIALS_PATH=${GOOGLE_CREDENTIALS_PATH} -- npx -y @vpalmisano/[email protected]{
"mcpServers": {
"webrtcperf": {
"command": "npx",
"args": [
"-y",
"@vpalmisano/[email protected]"
],
"env": {
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"GOOGLE_CREDENTIALS_PATH": "${GOOGLE_CREDENTIALS_PATH}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
webrtcperf | read | Starts a webrtcperf test. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (13 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
rejectUnauthorized: false,
rejectUnauthorized: false,
const httpsAgent = new Agent({ rejectUnauthorized: false })const httpsAgent = new Agent({ rejectUnauthorized: false }).eslintrc.js
import { twoParticipantsWithRateLossDelay, formatThrottleRule } from '../../build/src/index.js'__dirname + '/../../..',
--prometheus-pushgateway=http://127.0.0.1:9091 \
--push-stats-url=https://192.168.0.1:5000 \
--push-stats-url=https://192.168.0.1:5000 \
If set, logs are sent to the specified Prometheus Pushgateway service (example: "http://127.0.0.1:9091").
WebRTCPerf dashboard (http://127.0.0.1:3001/d/webrtcperf/webrtcperf).
@google/genai, @modelcontextprotocol/sdk, @puppeteer/browsers, @vpalmisano/webrtcperf-js, chalk-template, change-case, compression, convict
media/docs/image3.png
Gates applied: no_behavioural_pass.
2a454852c189full audit observations/trust-audit/mcp-server/vpalmisano__webrtcperf.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 2a454852c189 | BLOCK | D | 69 | first audit |
Questions
What is the WebRtcPerf MCP server?
WebRTC performance and quality evaluation tool.
What tools does WebRtcPerf expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is WebRtcPerf safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does WebRtcPerf need?
It reads GEMINI_API_KEY and GOOGLE_CREDENTIALS_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does WebRtcPerf run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @vpalmisano/webrtcperf at 4.9.3.
How current is this page?
The grade is for one exact copy of the source (2a454852c189), read on 2026-10-06. The repository is watched and re-audited when it changes.