No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by opentiny · MCP Server · ★ 118
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is webmcp-sdk safe to install? View the security audit →
OpenTiny NEXT-SDKs: Built-in WebMCP & Polyfill + WebSkills + WebAgent English | 简体中文 A front-end intelligent application development and browser automation toolkit. It turns existing apps intelligent via WebMCP + WebSkills, and provides webmcp-cli to perceive and control any webpage with zero refactoring. 📖 Docs | 🚀 Quick Start | 🌐 WebMCP & Polyfill | 💡 Scenarios [!IMPORTANT] Next-Gen AI Protocol: OpenTiny NEXT-SDKs is built on the WebMCP (Model Context Protocol for Web). It is fully compatible with the native API (currently in experimental stage in browsers like Chrome), allowing your web apps to be controlled by AI via a standardized protocol. [!TIP] ✨ Command-line Automation & AI Skills: We now offer (browser control & polyfill auto-injection CLI) and (standard instructions and sub-skills like Excalidraw drawing for AI agents). Together, they enable AI agents to perform complex, fine-grained tasks and "remote-drive" any webpage out of the box. OpenTiny NEXT-SDKs is a front-end intelligent application development and browser automation toolkit. Beyond enabling the "WebMCP + WebSkills" model to expose page operations as standardized tools in j
| Stars | 118 |
| Forks | 21 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 67.0712616241469/100 |
| Open Issues | 17 |
| Last Updated | 2026-09-21 |
| Created | 2025-07-15 |
| Platforms | browser, cli, mcp, node |
| Est. Tokens | ~19k |
Looking for a webmcp-sdk alternative? If you're comparing webmcp-sdk with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
OpenClaw-inspired autonomous AI agent built entirely in n8n. Adaptive RAG-powered memory, Skills via MCP templ
Context-Engine MCP - Agentic Context Compression Suite
Daymon puts your favorite AI to work 24/7. It schedules, remembers, and orchestrates your own virtual team. Fr
DeepContext is an MCP server that adds symbol-aware semantic search to Claude Code, Codex CLI, and other agent
One-stop handbook for building, deploying, and understanding LLM agents with 60+ skeletons, tutorials, ecosyst
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 287 comman
Explore other popular mcp server tools:
webmcp-sdk is OpenTiny NEXT-SDKs is a front-end AI and browser automation toolkit. It implements WebMCP + WebSkills to build AI-native apps, and leverages webmcp-cli to enable LLM agents to remote-control any webpa. It is categorized as a MCP Server with 118 GitHub stars.
webmcp-sdk is primarily written in TypeScript. It covers topics such as ai, ai-agents, mcp.
You can find installation instructions and usage details in the webmcp-sdk GitHub repository at github.com/opentiny/webmcp-sdk. The project has 118 stars and 21 forks, indicating an active community.
webmcp-sdk is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to webmcp-sdk on Agent Skills Hub include n8n-claw, Context-Engine, daymon. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: