Skip to main content
Glama

cdp_command

Destructive

Send raw Chrome DevTools Protocol commands to a chosen browser tab, target, or extension, while blocking destructive calls to protect browser state.

Instructions

Raw CDP can cause side effects in a tab, extension target or the entire browser profile. Choose session_id (client:tabId), tab_id (number or composite), extension_id or target_id deliberately. A cross-process iframe can use target_id from DOM.describeNode.frameId of its exact parent-page element; verify the frame origin and control before input. Listed high-risk methods are blocked before dispatch unless mode=lab AND operator env BROWSERTAP_ALLOW_UNSAFE_CDP=1; safe always blocks them (raw_cdp_blocked, delivery_state=undelivered, retry_safe=false, retryable=false). This guard prevents common destructive calls; allowed CDP/JavaScript can still change pages or profile state. Inspect state after uncertain delivery before retrying.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
methodYes
tab_idNo
timeoutNo
target_idNo
session_idNo
params_jsonNo{}
extension_idNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description enriches the destructive/openWorld annotations with concrete guard behavior: high-risk methods are blocked unless mode=lab and BROWSERTAP_ALLOW_UNSAFE_CDP=1, with delivery_state=undelivered, retry_safe=false, and retryable=false. It also warns that even allowed CDP/JavaScript can mutate page or profile state and advises inspecting state after uncertain delivery. This goes well beyond the structured annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but efficient: the side-effect warning is front-loaded, followed by target selection, the iframe caveat, and the guard behavior. Every sentence carries a distinct safety or targeting fact, though the paragraph is longer than strictly necessary.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a dangerous raw-CDP tool, the description covers target selection, cross-process iframe handling, blocked-method guardrails, and retry behavior, while the output schema covers return details. Minor gaps remain around what a 'composite' tab_id means and how to structure params_json.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

With 0% schema description coverage, the description compensates partially by explaining the meanings of session_id, tab_id, extension_id, and target_id, and by explaining how to derive target_id for a cross-process iframe. It does not explain params_json formatting, timeout semantics, or valid method formats beyond the high-risk blocking note, so several parameters remain under-documented.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly centers on dispatching raw CDP commands to a target and warns about side effects, so an agent can infer the tool's purpose. However, it never states an explicit verb like 'sends a CDP command' and does not distinguish itself from the sibling cdp_batch or execute_js tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives meaningful targeting guidance: choose deliberately among session_id, tab_id, extension_id, and target_id, and use target_id from DOM.describeNode.frameId for cross-process iframes. It does not state when to prefer this tool over alternatives like execute_js, cdp_batch, or page_click, and it gives no explicit exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.