DE EN
Back to MCP catalog

MCP Path

ContentScript Inventory

ContentScript Inventory is a public reference for extensions, external MCP sources, and bounded tool execution. It names the signal, policy, or flow an agent should understand before choosing a concrete tool.

Catalog path

Reference page for a documented MCP capability path.

Type
MCP path
Family
Plugins (AAP)
Effect
sensitive
Status
Reference
Path
15.19

Purpose

What this entry explains

What it does

This reference explains ContentScript Inventory for extensions, external MCP sources, and bounded tool execution. It is kept as a named reference so agents can cite the flow without inventing a tool name.

Use when

  • Use this entry when an agent needs to handle the sensitive path "ContentScript Inventory" for extensions, external MCP sources, and bounded tool execution.
  • Use it as a reference path when the catalog describes a capability but no single public tool name is explicit.
  • Use it before chaining follow-up tools so the next step is based on current evidence.

Reference Use

How agents should cite and apply this area

Examples are maintained at family level and use only public tool names or reference paths already present in the catalog.

Signal, gate, behavior, boundary

ContentScript Inventory describes a gate for extensions, external MCP sources, and bounded tool execution. The path shows which signal, gate, behavior, or boundary must be checked before choosing a concrete tool.

When agents cite it

An agent cites this path when it needs ContentScript Inventory as context for a decision, block, target check, or follow-up tool choice.

Why no callable name

The public source does not name one callable tool for this path. The documentation therefore keeps it as a reference path and does not invent a callable name.

Signals and rule

Relevant response signals: sessionId, documentId. Safety axes: Read current state, Sensitive, User confirmation. The reference path alone is not permission to execute. Before acting, check current MCP discovery, visible target, scope, and the actual response.

Family example

A task in extensions, external MCP sources, and bounded tool execution can trigger powerful execution and therefore needs target, approval, and result check before the step.

The agent starts with nova.plugin_create, reads the current response or reference, and only then chooses the concrete next tool.

Current discovery, target, user control, warning signals, and result check come before execution.

Contract

Inputs and important response fields

This page is a public reference. Agents and integrators should still read current MCP tool discovery before execution, because schemas can be gated by settings or version.

Inputs

No stable public input field is derived from the catalog source for this path. Read current MCP discovery before execution.

Response fieldExplanation
sessionIdReference to a session, recording, or resumable evidence context.
documentIdIdentifier or reference value. Do not guess it from memory; read it from the current response.

Safety

Boundary before execution

Effect

May touch sensitive data, permissions, credentials, identity, or external connection paths. Use only with explicit scope and visible user control.

Agent rule

Require explicit purpose and current context, avoid exposing secrets in prompts or logs, and stop when permission or identity state is unclear.

Human control

For humans, this entry marks the sensitive surface in extensions, external MCP sources, and bounded tool execution and keeps permission, credential, or external-connection handling explicit.

High-Impact Review

Execution boundary and recheck hints

Review category: Eval/CDP/diagnostics

Execution boundary

Run only on the currently confirmed target; expression, expected result, and visible context must be clear before the call.

Typical false assumption

False assumption: because a script is intended to read, the path is automatically harmless.

Visible user control

The user must be able to see which page is targeted and why code, CDP, or diagnostics are being run.

Agent rule

Before execution, check current discovery, target, expression, and stop signal; do not derive additional scripts from the result.

Abort or recheck

Abort or recheck if the target changed, the expression touches third-party data, or the response contains warnings.

Safety Axes

How this path can affect work

Axes are stable catalog signals for humans, agents, and LLM discovery. One path can carry several axes.

Read current state read_current_state

Reads current state, response signals, or evidence without treating that alone as permission for a follow-up action.

Use the signal as current evidence and re-check target, scope, and visible state before any follow-up action.
Sensitive sensitive_data

Touches cookies, storage, clipboard, credentials, tokens, user content, identity, or private data.

Use only with bounded purpose and visible user control; do not guess, log, or forward sensitive values.
User confirmation user_confirmation

Requires visible confirmation, target review, approval, or deliberate user control.

Do not proceed until the required confirmation is visible or unambiguous in the current context.