Atlas / MCP servers / aaronjmars / OpenDia

OpenDiaBLOCK

mcp/aaronjmars/opendia

Connect your browser to AI models. Just use Dia on Chrome, Arc or Firefox.

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
18 15r · 3w · 0d
Transport
—
License
MIT
Stars
1,923
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Star us ❤️ →

The open alternative to Dia / Perplexity Comet. Connect your browser to AI models — no browser switching needed. Works seamlessly with Chrome, Firefox, and any Chromium browser. Private, local-first & MCP focused.

[](https://github.com/aeonfun/opendia/stargazers) [](https://github.com/aeonfun/opendia/network/members) [](https://www.npmjs.com/package/opendia) [](../LIC

Read from source at commit 389190ac165eOBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add opendia -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "opendia": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (18)

15 read · 3 write · 0 destructive.

ToolRiskDescription
add_bookmarkwriteAdd a new bookmark
element_clickread🖱️ BACKGROUND TAB READY: Click elements in any tab without switching! Perform actions on background tabs while staying on current page. Use tab_id to target specific tabs.
element_fillread✏️ BACKGROUND TAB READY: Fill forms in any tab without switching! Enhanced focus and event simulation for modern web apps. Use tab_id to fill forms in background tabs.
element_get_statereadGet detailed state information for a specific element (disabled, clickable, etc.)
get_bookmarksreadGet all bookmarks or search for specific bookmarks
get_historyreadSearch browser history with comprehensive filters for finding previous work by date/keywords
get_page_linksreadGet all hyperlinks on the current page with filtering options
get_selected_textread📝 BACKGROUND TAB READY: Get selected text from any tab without switching! Perfect for collecting quotes, citations, or highlighted content from multiple research tabs simultaneously.
page_analyzeread🔍 BACKGROUND TAB READY: Analyze any tab without switching to it! Two-phase intelligent page analysis with token efficiency optimization. Use tab_id parameter to analyze background tabs while staying on current page.
page_extract_contentread📄 BACKGROUND TAB READY: Extract content from any tab without switching! Perfect for analyzing multiple research tabs, articles, or pages simultaneously. Use tab_id to target specific background tabs.
page_navigatereadNavigate CURRENT tab to a new URL. Use tab_create instead if you want to open a NEW tab with a URL.
page_scrollread📜 BACKGROUND TAB READY: Scroll any tab without switching! Critical for long pages. Navigate through content in background tabs while staying on current page. Use tab_id to target specific tabs.
page_stylewrite🎨 Transform page appearance with themes, colors, fonts, and fun effects! Apply preset themes like
page_wait_forreadWait for specific element or condition on current page
tab_closereadClose specific tab(s) by ID or close current tab
tab_createwriteCreates tabs. CRITICAL: For multiple identical tabs, ALWAYS use
tab_listread📋 TAB DISCOVERY: Get list of all open tabs with IDs for background tab targeting! Shows content script readiness status and tab details. Essential for multi-tab workflows - use tab IDs with other tools to work on background tabs.
tab_switchreadSwitch to a specific tab by ID
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
opendia-mcp/server.js:91
exec(`lsof -ti:${port}`, (error, stdout) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
opendia-mcp/server.js:98
exec(`ps -p ${pid} -o command=`, (psError, psOutput) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
opendia-mcp/server.js:122
exec(`lsof -ti:${port}`, async (error, stdout) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
opendia-mcp/server.js:134
exec(`kill ${pid}`, (killError) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
opendia-mcp/test-connection.js:40
httpUrl: `http://127.0.0.1:${httpPort}`,
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
opendia-extension/package.json
webextension-polyfill, fs-extra, web-ext
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
opendia-mcp/package.json
cors, express, ws
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.github/README.md:44
- ✅ **Browser data**: Access your bookmarks, history, and saved passwords
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
opendia-mcp/README.md:19
- ✅ **Browser data**: Access your bookmarks, history, and saved passwords
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
opendia-extension/logo.mp4
opendia-extension/logo.mp4
Why it matters. 11607966 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
opendia.dxt
opendia.dxt
Why it matters. 12711024 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
preview.gif
preview.gif
Why it matters. 3008902 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha 389190ac165efull audit observations/trust-audit/mcp-server/aaronjmars__opendia.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-23389190ac165eBLOCKD66source changed, verdict held
2026-09-1928affbefb7a7BLOCKD66first audit
06

Questions

What is the OpenDia MCP server?

Connect your browser to AI models. Just use Dia on Chrome, Arc or Firefox.

What tools does OpenDia expose?

18 in total: 15 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is OpenDia safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does OpenDia need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (389190ac165e), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement