browser-mcpBLOCK
The browser tool that can stop and ask you. A 2FA code, a CAPTCHA, a choice only you can make: it asks on your screen, then carries on in the same signed-in Chrome. 40 tools, MCP clients that run local servers, MIT.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The browser tool that can stop and ask you. A 2FA code, a CAPTCHA, a choice only you can make: it asks on your own screen, then carries on in the same signed-in Chrome.
It drives the Chrome you are already signed into: no login step to fail, no API key to wire up, no fresh profile that is a stranger to every account you have. Up to 20 agents at once, each in its own colour-coded tab group. 40 tools, MIT, runs on your machine.
→ [What it can and cannot get past](https://browsermcp.dev/docs/capability-matrix/) - every wall, marked measured, by design, not yet, or won't. Including the ones we have not fixed.
[](https://www.npmjs.com/package/@agent360/browser-mcp) [](https://www.npmjs.com/package/@agent360/browser-mcp) [](https://github.com/Agent360dk/browser-mcp) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io) [](https://chromewebstore.google.com/detail/agent360-browser-mcp/jdehgalffmffhfhmmhaokfbfnafnmgcl)
[](https://cursor.com/install-mcp?name=browser-mcp&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBhZ2VudDM2MC9icm93c2VyLW1jcEBsYXRlc3QiXX0%3D) [](https://vscode.dev/redirect/mcp/install?name=browser-mcp&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40agent360%2Fbrowser-mcp%40latest%22%5D%7D) [
25 read · 9 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
browser_about | write | Returns Browser MCP info and pre-filled URLs the user can click to submit feature wishes, share use-cases, or report bugs. Call this PROACTIVELY whenever the user (a) mentions a feature they wish existed ( |
browser_ask_user | read | Show an overlay dialog asking the user to perform an action or provide information (credentials, 2FA, CAPTCHA, OAuth consent). Can include input fields for the user to fill in. Returns user responses. |
browser_click | read | Click an element on the page. Supports CSS selectors AND text-based selectors. Auto-scrolls element into view. Uses real mouse events (works on Angular/React SPAs and CSP-strict sites like Google, Stripe). Examples: |
browser_click_xy | read | ESCAPE HATCH: Click at raw viewport coordinates (CSS pixels) with fully trusted mouse events. Use when a visible button resists every selector strategy (Azure portal dialogs, Knockout-bound divs, canvas UIs): take a screenshot, read the button\ |
browser_close_tab | read | Close a browser tab by ID. Only tabs owned by the current session can be closed. |
browser_console_logs | read | Get recent console.log/warn/error messages from the page. Installs a lightweight interceptor on first call. Returns the last N console messages. |
browser_dismiss_overlays | read | Dismiss visible popups, modals, tooltips, banners, and |
browser_double_click | read | True double-click on an element (two trusted press/release pairs with escalating clickCount). Use for open-item actions (calendar events, file lists) where two single clicks would trigger inline-rename instead (e.g. OWA month view). |
browser_drop_file | destructive | Upload a file when browser_upload_file fails. Two strategies: (1) finds a hidden <input type= |
browser_execute_script | write | Execute JavaScript in the current page. IMPORTANT: the parameter is |
browser_extract_token | read | Navigate to a provider\ |
browser_fetch | read | Make an HTTP request from the extension background (NOT subject to CORS). Use this when page-context fetch would be blocked by CORS or CSP. Useful for API calls to Google, Stripe, Slack APIs while on their pages. |
browser_fill | read | Fill a form input field with a value. Supports CSS selectors AND text-based selectors. Auto-scrolls and focuses the element. Works on CSP-strict sites via Chrome Debugger API. For date inputs use browser_set_date, for autocomplete/combobox use browser_set_combobox. |
browser_get_cookies | read | Get cookies for a site this session has open in one of its tabs (the site itself, a parent domain or a subdomain). Navigate to the site first - cookies for sites the session is not working on are refused. |
browser_get_local_storage | read | Read localStorage from the current page. Pass key for a specific value, or omit for all. |
browser_get_new_tab | read | Get the most recently opened tab (useful after clicking links that open new tabs, OAuth popups, etc.). |
browser_get_page_content | read | Get the content of the current page as text or HTML. Pass |
browser_handle_dialog | read | Arm automatic handling of the next JavaScript alert/confirm/prompt on the active tab, then return immediately. Call this BEFORE the click that opens the dialog - a dialog freezes the tab, so nothing can be clicked once it is on screen. Pass wait=true only when the dialog is already opening. |
browser_hover | write | Hover over an element to trigger tooltips, dropdown menus, or hover states. Supports CSS and text selectors. |
browser_list_frames | read | List all frames (iframes) in the current page with their URLs and indices. |
browser_list_tabs | read | List all open browser tabs with their URLs and titles. |
browser_navigate | read | Navigate the active browser tab to a URL. Reuses the current tab by default (no tab spam). Pass new_tab=true only when you need to keep the current page open. |
browser_press_key | read | Press a keyboard key (Enter, Tab, Escape, ArrowDown, etc.). Useful for submitting forms, navigating dropdowns, closing dialogs. Supports modifier keys (ctrl, alt, shift, meta). |
browser_reattach_debugger | destructive | RECOVERY: Force-detach and re-attach the Chrome debugger on the current tab. Use when interactive tools (click/fill/press_key) start timing out or reporting ghost-attach ( |
browser_right_click | read | Right-click an element (trusted CDP mouse events) to open page-level context menus (web apps like OWA/Google Docs render their own). Note: Chrome\ |
browser_screenshot | read | Take a screenshot of the visible area of the current tab. Returns base64 PNG, or saves to disk if path is provided. |
browser_scroll | read | Scroll the page to an element or by pixel amount. Useful for reaching elements below the fold. |
browser_select_frame | write | Execute JavaScript in a specific iframe by frame index. Use browser_list_frames first to find the right index. |
browser_set_combobox | write | Set value(s) on an autocomplete/combobox input. Handles the click → type query → wait for filtered listbox → click option flow as one MCP call. Supports multi-select (e.g., Languages on Meta Ads). Use when browser_select_option fails because options render lazily after typing. |
browser_set_cookies | write | Set one or more cookies for a domain. |
browser_set_date | write | Robustly set a date input - handles native <input type= |
browser_set_local_storage | write | Set a localStorage key-value pair on the current page. |
browser_switch_tab | read | Switch to a specific browser tab by ID. Get tab IDs from browser_list_tabs or browser_get_new_tab. |
browser_upload_file | write | Upload a file to a <input type= |
browser_wait | read | Wait for an element to appear on the page. Supports CSS and text-based selectors. |
browser_wait_for_network | read | Wait for a network request to complete. Useful after clicking buttons that trigger API calls - ensures data is loaded before reading the page. Monitors real network traffic via Chrome DevTools Protocol. |
Trust audit
BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (12 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
try { fn = new Function('return (' + codeStr + ')'); }try { fn = new Function('return (' + codeStr + ')'); }return { __ok: true, value: new Function('return (' + codeStr + ')')() };try { fn = new Function('return (' + codeStr + ')'); }try { fn = new Function('return (' + codeStr + ')'); }/.env" ... curl
: 30 + Math.random() * 90; // normal keystroke
: 30 + Math.random() * 90; // normal keystroke
let mål; for (let i = 0; i < 50 && !mål; i++) { try { mål = (await (await fetch(`http://127.0.0.1:${PORT}/json`)).json()).find((t) => t.type === 'page'); } catch {} if (!mål) await vent(200); }const svar = await fetch(`http://127.0.0.1:${port}/`, {const svar = await fetch(`http://127.0.0.1:${port}/`, {const r = await fetch(`http://127.0.0.1:${CDP_PORT}/json/list`);try { egen = (await (await fetch(`http://127.0.0.1:${CDP_PORT}/json/version`)).json()) != null; } catch { /* ikke oppe endnu */ }browser_drop_file, browser_reattach_debugger
assert.match(blok, /homedir\(\)/, '~ skal foldes ud, ellers slipper ~/.ssh/id_rsa forbi som relativ sti');
const svar = await kald(['../../etc/hosts']);
@modelcontextprotocol/sdk, ws
Yes - MIT-licensed, open source, no paywall, no account, no API key. Built by [Agent360](https://agent360.dk) as part of its developer-tools work.
<script type="application/ld+json">{"@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "Is this an official OpenAI integration?", "acceptedAnswer": {"@t<p><b>Is it really free?</b> Yes - MIT-licensed, open source, no paywall, no account, no API key. Built by <a href="https://agent360.dk">Agent360</a> as part of its developer-tools work.</p>
> Set up Browser MCP for me. Read https://browsermcp.dev/llms-install.md and follow it for whichever AI client you are running in. One step only I can do - tell me which one, and wait for me. When I c
> Set up Browser MCP for me. Read https://browsermcp.dev/llms-install.md and follow it for whichever AI client you are running in. One step only I can do - tell me which one, and wait for me. When I c
- `browser_upload_file` and `browser_drop_file` accepted any path on disk, so an agent could upload `~/.ssh/id_rsa`. Paths are now resolved (symlinks, `~`, `..`) and must stay inside the working direc
This is the reason people install Browser MCP: Claude Code hits a login wall, needs a verification code, and - because it's driving your actual logged-in Chrome rather than a fresh headless session -
This is the reason people install Browser MCP: Cursor's agent hits a login wall, needs a verification code, and - because it's driving your actual logged-in Chrome rather than a fresh headless session
Gates applied: no_behavioural_pass.
e4e8ba3234affull audit observations/trust-audit/mcp-server/agent360dk__browser-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e4e8ba3234af | BLOCK | F | 49 | first audit |
Questions
What is the browser-mcp MCP server?
The browser tool that can stop and ask you. A 2FA code, a CAPTCHA, a choice only you can make: it asks on your screen, then carries on in the same signed-in Chrome. 40 tools, MCP clients that run local servers, MIT.
What tools does browser-mcp expose?
36 in total: 25 read-only, 9 that write, and 2 that can delete or overwrite (browser_drop_file, browser_reattach_debugger). Every one is listed on this page with its risk.
Is browser-mcp safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (49/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does browser-mcp need?
It reads ACTIONS_ID_TOKEN_REQUEST_TOKEN, ACTIONS_ID_TOKEN_REQUEST_URL, BROWSER_MCP_TOKEN, GH_TOKEN and GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does browser-mcp run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @agent360/browser-mcp at 1.30.1.
How current is this page?
The grade is for one exact copy of the source (e4e8ba3234af), read on 2026-10-08. The repository is watched and re-audited when it changes.