A decoy tool tells the model browser tools already exist, only active in a specific remote session profile.
A new tool, enable__mcp__claude-in-chrome (with a generic Browser variant), does nothing but tell the model that browser tools are already available under names containing Claude_Browser, or to use claude-in-chrome/Claude_in_Chrome tools directly, so the model stops trying to invoke a non-existent "enable" step. It only registers when the session runs under a CCR session profile, requiring CCR_SESSION_PROFILE, a valid SESSION_INGRESS_URL, a CLAUDE_CODE_REMOTE_SESSION_ID matching the cse_... pattern, and a first-party check; outside that remote/cloud profile the tool is not registered at all.