MCP servers › io.github.mrfentmen › firefox-addons-mcp
MCP server · registry snapshot 2026-10-04 · last tested 2026-10-09
io.github.mrfentmen/firefox-addons-mcp
Search Firefox browser extensions on AMO. No key required. — the publisher's description
Summary
io.github.mrfentmen/firefox-addons-mcp is a local MCP server listed in the official MCP registry at version 1.0.0. On 2026-10-09 its published package did not start, so no check could run. None of the 18 checks that apply to it could be exercised. Results of the checks are published only after we have verified them and told the publisher.
Package does not start
The published package does not install or start cleanly today, so no check could run. No security score is given; a check we did not run is never counted as passed.
Key facts
- Runs
- local package
- Transport
- standard input/output
- Package
- npm · listed version behind the latest release
- License
- MIT
- Dependencies
- no known high or critical advisories
- Repository
- link does not open publicly
- Topic
- search-and-web-dataAI-classified
- Last tested
- 2026-10-09
- Inventory: not run · package does not start
- Hidden instructions: not run · package does not start
- Real execution: not run · package does not start
- Secret leak: not run · package does not start
- Internal addresses: not run · package does not start
- Unconfirmed changes: not run · package does not start
- Bad input: not run · package does not start
- Model requests: not run · package does not start
- Sensitive questions: not run · package does not start
- Folder boundary: not run · package does not start
- Log leaks: not run · package does not start
- Hidden content: not run · package does not start
- Fake assistant turns: not run · package does not start
- Token passthrough: not run · package does not start
- Token audience: not run · package does not start
- Sign-in redirect: not run · package does not start
- Consent handling: not run · package does not start
- Sign-in metadata: not run · package does not start
0 exercised18 not run (reason given)0 not applicable
Worth knowing before you connect it
- The registry lists 1.0.0; 1.0.1 is newer (1 release).
- The linked repository does not open publicly, so the code cannot be reviewed through it.
Each line comes from a section below, with its source and date.
How fresh this is
- Live-tested
- attempted, see below
- Last tested
- 2026-10-09
- Registry data
- snapshot 2026-10-04
- Package and repository
- checked 2026-10-06
- Engine
- mcp-runtime-engine@0.1.0 · sdk@1.32.0
Security testing
What did we test, and what did we leave out?
18 checks · features #1, #2Each check ends in exactly one state: exercised, not run (with the reason), or not applicable (with the reason). None of the 18 checks that apply to it could be exercised. Results of the checks are published only after we have verified them and told the publisher.
- 1Inventory
tool-listReads the declared tools, resources and prompts.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 2Hidden instructions
description-poisoningLooks for hidden instructions in tool descriptions.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 3Real execution
real-executionCalls a tool and checks what really happens.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 4Secret leak
canary-leakPlants a fake secret and checks whether it leaks.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 5Internal addresses
ssrfChecks whether a tool can be steered to internal addresses.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 6Unconfirmed changes
write-without-confirmationChecks whether tools that change data act without asking.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 7Bad input
error-handlingSends bad input and watches how the server answers.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 8Model requests
samplingChecks whether the server asks the client's model to act for it.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 9Sensitive questions
elicitation-sensitive-dataChecks whether the server asks users for sensitive data.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 10Folder boundary
root-boundaryChecks whether the server reaches outside the folders it was given.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 11Log leaks
logging-side-channelChecks whether log messages carry data they should not.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 12Hidden content
audience-hidingChecks resources that hide content from the user.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 13Fake assistant turns
fake-assistant-turnChecks prompts that pose as the assistant's own words.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 14Token passthrough
token-passthroughChecks whether the server forwards a user's token to other services.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 15Token audience
token-audience-validationChecks whether tokens meant for another service are accepted.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 16Sign-in redirect
open-redirectChecks the sign-in redirect for abuse.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 17Consent handling
confused-deputyChecks consent handling when one service acts for another.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start - 18Sign-in metadata
oauth-url-schemeChecks the published sign-in metadata for unsafe URLs.The npm package's executable has no interpreter line, so the operating system cannot run it.not run · package does not start
Source: our own test in an isolated sandbox, 2026-10-09, mcp-runtime-engine@0.1.0. Which checks count and why follows our published scoring model.
What happened during the test?
Feature #8The steps in order, as the test record holds them.
- 0 msStarted the published package in an isolated sandbox
- The package did not start.
- 157 msFinished: 0 checks exercised.
What it is
Does the registry listing match what we found?
Feature #6The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.
| Registry says | We found | Result | Source · date |
|---|---|---|---|
| Published package can be started | Did not start | differs | our test · 2026-10-09 |
| Version 1.0.0 on npm | Exists and can be installed | matches | npm · 2026-10-06 |
| Repository github.com/mrfentmen/firefox-addons-mcp | Does not open (not found or private) | differs | api.github.com · 2026-10-06 |
Can it be installed, and is it up to date?
Version pin · advisories
Listed version
- Registry lists
- 1.0.0
- Latest stable
- 1.0.1
- Status
- behind the latest release (1 releases, 7 days)
- Withdrawn
- no
Source: registry.npmjs.org · 2026-10-06. About the version the registry lists; a manual install may resolve to a different one.
Dependency advisories
Counted in the full dependency tree as resolved on 2026-10-08 (npm audit). Bars share one scale. The package itself has no known vulnerability (OSV.dev).
Integrity, provenance, license
- Integrity
- sha512-Vs55zCN/fFYe2a1vs…
- Signature
- signed
- License
- MIT
Source: the package registry · 2026-10-06.
Usage
- Downloads
- 497 in the last month
Source: api.npmjs.org · 2026-10-06.
Who made it?
Feature #7 · lineage
Facts about the publisher. We do not turn them into a trust score.
- Namespace
- io.github.mrfentmen
- Repository
- github.com/mrfentmen/firefox-addons-mcp — does not open publicly
Source: the registry entry and api.github.com · 2026-10-06.
Choosing
Common questions about io.github.mrfentmen/firefox-addons-mcp
Answered from the data aboveHas io.github.mrfentmen/firefox-addons-mcp been security tested?
We tried, but no check could run. None of the 18 checks that apply to it could be exercised. The published package does not install or start cleanly today, so no check could run. No security verdict is published before verification.
Is the listed version current?
No. The registry lists 1.0.0; the latest stable release on npm is 1.0.1.
Where is the source code of io.github.mrfentmen/firefox-addons-mcp?
The registry links to github.com/mrfentmen/firefox-addons-mcp, but that link does not open publicly, so the code cannot be inspected through it.
Reference
How is it classified?
18 fields
One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.
“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.
Cite or correct this page
Sources and corrections
Suggested citation
ProtocolProbe. “io.github.mrfentmen/firefox-addons-mcp: MCP server record.” Data checked 2026-10-09. https://protocolprobe.com/mcp/servers/io.github.mrfentmen/firefox-addons-mcp
Figures are valid for the date shown. Our facts on this page are CC BY 4.0: reuse them with a link and the check date. Quoted text (the publisher’s descriptions, website quotes, tool names) is not ours to license.
As JSON: this record in the API · API documentation.
Something wrong, or is this yours?
If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.
Write to hello@protocolprobe.com · corrections log · methodology