Skip to content

■ SIGNALS // RADAR SIGNAL

the config is already an access policy

Three small projects circle the same unglamorous problem: an agent is handed browser control, a server config, or a friendly training app, and the permission story gets buried in the setup.

■ [!] ON THIS PAGE ▼

self.md radar — 2026-10-01

the config is already an access policy

Three small projects circle the same unglamorous problem: an agent is handed browser control, a server config, or a friendly training app, and the permission story gets buried in the setup.

1. An MCP config can hide the real permission model

mcp-surface-scan starts from a question that should come before mounting another server: what did the configuration just hand over? The new tool reads common MCP client configs and turns their package names, arguments, URLs and environment values into findings. It calls out launch-time package resolution, plaintext remote endpoints, credentials passed in the environment, privileged containers and broad filesystem paths.

The useful restraint is in the project’s own description of source mode. It is regex-based and points at capability families; it does not announce that a call is exploitable. That is enough for a first review. A config is often one tidy JSON blob. It can still decide whether an agent starts with a drive root, a token, a Docker socket, or an upstream package that changes on the next launch.

reading: DeviosLang/mcp-surface-scan

2. Chrome’s agent bridge has its own telemetry settings

Chrome DevTools MCP gives coding agents a direct line into a live browser: network requests, console output, performance traces, screenshots, debugging and automation. Its documentation is unusually plain about the scope. MCP clients can inspect, debug and modify data in the browser or DevTools instance. That is not a tiny local helper once the browser holds sessions, test accounts or customer tabs.

The same README says its usage statistics are enabled by default, controlled by --no-usage-statistics, and separate from Chrome’s own metrics preference. Its performance tools can also send trace URLs to the Chrome UX Report API unless --no-performance-crux is set. None of that proves private page content is shipped as telemetry. It does make the settings review less optional: browser access and service reporting are two switches, not one.

reading: ChromeDevTools/chrome-devtools-mcp

3. WattzGOAT makes the AI assistant one flaw among many

WattzGOAT is an intentionally insecure fake electricity company: customer accounts, meter readings, top-ups, bills, support tickets and an admin side. It is built as a lab, not a product. The repository lists 48 hidden weaknesses to find, including five bonus flags around a simulated AI assistant.

That placement is the good bit. The assistant is rule-based rather than a real model, and the project warns that AI-assisted code may contain bugs beyond the planned exercises. Still, it refuses the tidy split between “AI security” and ordinary web security. In a customer portal, an assistant sits beside identity checks, support work, billing data and broken access control. The boring flaws are still in the room.

reading: wattzgoat/wattzgoat-web

  • Personal AI OS tools — the control-plane map for personal agents, receipts, memory, and tools
  • AI coding assistants — compare coding workbenches by review surface, permissions, cost, logs, and escape hatches
  • Best MCP servers — connect files, browsers, memory, search, and workflow tools without turning the stack into soup