79OUT OF 100
CautionCautionStatic read

GabrielGargiuloDev/google-flow-mcp

The repository is a browser automation tool for Google Flow using Playwright and the Chrome DevTools Protocol (CDP). All flagged regions involve local loopback connections (127.0.0.1) to manage a local Chrome instance, which is explicitly documented in the README as the intended method for browser automation. No malicious behavior, credential theft, or unauthorized egress was observed in the static analysis. The project is transparent about its unofficial nature and the risks of violating Google's Terms of Service.

Repository size
57 KB
Packages
0
Stars
1
Created
5 yr 9 mo
Reputation signals
GabrielGargiuloDev avatar
GabrielGargiuloDev
@GabrielGargiuloDev
Account age5 yr 9 mo
Public repos2
Forks0
Community sentiment50

neutral

Code & behavior signals
Local Loopback Communication
LowCode

The code frequently connects to 127.0.0.1 via CDP to control a local Chrome instance. This is consistent with the declared intent of browser automation and does not involve external network egress.

Low Owner Reputation
LowReputation

The owner has limited public activity and low star counts, which is common for niche automation tools but warrants standard caution.

Per-package scoring
Final verdict

Static analysis flagged undisclosed install-time behavior. This is not confirmed malicious, but it is more than this tool needs, and runtime was not executed in a sandbox on this pass. Run it only inside a sandbox or throwaway environment.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Repository cloned successfully.
›Commit hash: aae58a79aecd640a00f853e454e16e101bb7a756
Static scan
›No obfuscation, hardcoded secrets, or unauthorized network calls detected.
›All flagged regions identified as local loopback (127.0.0.1) for CDP.
Read
›README confirms intent to use Playwright/CDP for browser automation.
›Flagged regions align perfectly with documented setup and operation.
Reputation
›Owner account is not established (low repo count, low stars).
›Project is a niche automation tool; low engagement is expected.
Score
›Score computed by formula: 79/100 (deterministic, code-driven)
›-3 [code] model_findings: 1 code/behavior finding(s) reported by the read model.
Auto-published at clauderabbit.in/GabrielGargiuloDev/google-flow-mcp · re-checked when the repo changes