Atlas / MCP servers / agent360dk / browser-mcp

browser-mcpBLOCK

mcp/agent360dk/browser-mcp

The browser tool that can stop and ask you. A 2FA code, a CAPTCHA, a choice only you can make: it asks on your screen, then carries on in the same signed-in Chrome. 40 tools, MCP clients that run local servers, MIT.

Verdict
BLOCK
Grade
F
Trust score
49 /100
Exposed tools
36 25r · 9w · 2d
Transport
stdio
License
MIT
Stars
53
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The browser tool that can stop and ask you. A 2FA code, a CAPTCHA, a choice only you can make: it asks on your own screen, then carries on in the same signed-in Chrome.

It drives the Chrome you are already signed into: no login step to fail, no API key to wire up, no fresh profile that is a stranger to every account you have. Up to 20 agents at once, each in its own colour-coded tab group. 40 tools, MIT, runs on your machine.

→ [What it can and cannot get past](https://browsermcp.dev/docs/capability-matrix/) - every wall, marked measured, by design, not yet, or won't. Including the ones we have not fixed.

[](https://www.npmjs.com/package/@agent360/browser-mcp) [](https://www.npmjs.com/package/@agent360/browser-mcp) [](https://github.com/Agent360dk/browser-mcp) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io) [](https://chromewebstore.google.com/detail/agent360-browser-mcp/jdehgalffmffhfhmmhaokfbfnafnmgcl)

[](https://cursor.com/install-mcp?name=browser-mcp&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBhZ2VudDM2MC9icm93c2VyLW1jcEBsYXRlc3QiXX0%3D) [](https://vscode.dev/redirect/mcp/install?name=browser-mcp&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40agent360%2Fbrowser-mcp%40latest%22%5D%7D) [![Glama quality](https://glama.ai/mcp/servers/Agent360dk/browser-mcp/badges/sco

Read from source at commit e4e8ba3234afOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add browser-mcp -- npx -y @agent360/[email protected]
03

Exposed tools (36)

25 read · 9 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
browser_aboutwriteReturns Browser MCP info and pre-filled URLs the user can click to submit feature wishes, share use-cases, or report bugs. Call this PROACTIVELY whenever the user (a) mentions a feature they wish existed (
browser_ask_userreadShow an overlay dialog asking the user to perform an action or provide information (credentials, 2FA, CAPTCHA, OAuth consent). Can include input fields for the user to fill in. Returns user responses.
browser_clickreadClick an element on the page. Supports CSS selectors AND text-based selectors. Auto-scrolls element into view. Uses real mouse events (works on Angular/React SPAs and CSP-strict sites like Google, Stripe). Examples:
browser_click_xyreadESCAPE HATCH: Click at raw viewport coordinates (CSS pixels) with fully trusted mouse events. Use when a visible button resists every selector strategy (Azure portal dialogs, Knockout-bound divs, canvas UIs): take a screenshot, read the button\
browser_close_tabreadClose a browser tab by ID. Only tabs owned by the current session can be closed.
browser_console_logsreadGet recent console.log/warn/error messages from the page. Installs a lightweight interceptor on first call. Returns the last N console messages.
browser_dismiss_overlaysreadDismiss visible popups, modals, tooltips, banners, and
browser_double_clickreadTrue double-click on an element (two trusted press/release pairs with escalating clickCount). Use for open-item actions (calendar events, file lists) where two single clicks would trigger inline-rename instead (e.g. OWA month view).
browser_drop_filedestructiveUpload a file when browser_upload_file fails. Two strategies: (1) finds a hidden <input type=
browser_execute_scriptwriteExecute JavaScript in the current page. IMPORTANT: the parameter is
browser_extract_tokenreadNavigate to a provider\
browser_fetchreadMake an HTTP request from the extension background (NOT subject to CORS). Use this when page-context fetch would be blocked by CORS or CSP. Useful for API calls to Google, Stripe, Slack APIs while on their pages.
browser_fillreadFill a form input field with a value. Supports CSS selectors AND text-based selectors. Auto-scrolls and focuses the element. Works on CSP-strict sites via Chrome Debugger API. For date inputs use browser_set_date, for autocomplete/combobox use browser_set_combobox.
browser_get_cookiesreadGet cookies for a site this session has open in one of its tabs (the site itself, a parent domain or a subdomain). Navigate to the site first - cookies for sites the session is not working on are refused.
browser_get_local_storagereadRead localStorage from the current page. Pass key for a specific value, or omit for all.
browser_get_new_tabreadGet the most recently opened tab (useful after clicking links that open new tabs, OAuth popups, etc.).
browser_get_page_contentreadGet the content of the current page as text or HTML. Pass
browser_handle_dialogreadArm automatic handling of the next JavaScript alert/confirm/prompt on the active tab, then return immediately. Call this BEFORE the click that opens the dialog - a dialog freezes the tab, so nothing can be clicked once it is on screen. Pass wait=true only when the dialog is already opening.
browser_hoverwriteHover over an element to trigger tooltips, dropdown menus, or hover states. Supports CSS and text selectors.
browser_list_framesreadList all frames (iframes) in the current page with their URLs and indices.
browser_list_tabsreadList all open browser tabs with their URLs and titles.
browser_navigatereadNavigate the active browser tab to a URL. Reuses the current tab by default (no tab spam). Pass new_tab=true only when you need to keep the current page open.
browser_press_keyreadPress a keyboard key (Enter, Tab, Escape, ArrowDown, etc.). Useful for submitting forms, navigating dropdowns, closing dialogs. Supports modifier keys (ctrl, alt, shift, meta).
browser_reattach_debuggerdestructiveRECOVERY: Force-detach and re-attach the Chrome debugger on the current tab. Use when interactive tools (click/fill/press_key) start timing out or reporting ghost-attach (
browser_right_clickreadRight-click an element (trusted CDP mouse events) to open page-level context menus (web apps like OWA/Google Docs render their own). Note: Chrome\
browser_screenshotreadTake a screenshot of the visible area of the current tab. Returns base64 PNG, or saves to disk if path is provided.
browser_scrollreadScroll the page to an element or by pixel amount. Useful for reaching elements below the fold.
browser_select_framewriteExecute JavaScript in a specific iframe by frame index. Use browser_list_frames first to find the right index.
browser_set_comboboxwriteSet value(s) on an autocomplete/combobox input. Handles the click → type query → wait for filtered listbox → click option flow as one MCP call. Supports multi-select (e.g., Languages on Meta Ads). Use when browser_select_option fails because options render lazily after typing.
browser_set_cookieswriteSet one or more cookies for a domain.
browser_set_datewriteRobustly set a date input - handles native <input type=
browser_set_local_storagewriteSet a localStorage key-value pair on the current page.
browser_switch_tabreadSwitch to a specific browser tab by ID. Get tab IDs from browser_list_tabs or browser_get_new_tab.
browser_upload_filewriteUpload a file to a <input type=
browser_waitreadWait for an element to appear on the page. Supports CSS and text-based selectors.
browser_wait_for_networkreadWait for a network request to complete. Useful after clicking buttons that trigger API calls - ensures data is loaded before reading the page. Monitors real network traffic via Chrome DevTools Protocol.
04

Trust audit

BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (12 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
extension/background.js:3629
try { fn = new Function('return (' + codeStr + ')'); }
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
extension/background.js:3661
try { fn = new Function('return (' + codeStr + ')'); }
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
extension/background.js:5223
return { __ok: true, value: new Function('return (' + codeStr + ')')() };
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp-server/extension/background.js:3629
try { fn = new Function('return (' + codeStr + ')'); }
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp-server/extension/background.js:3661
try { fn = new Function('return (' + codeStr + ')'); }
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
runbrowsermcpupdate.sh:407
/.env" ... curl
Why it matters. reads secrets in the same file that sends data out
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
extension/background.js:846
: 30 + Math.random() * 90;   // normal keystroke
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
mcp-server/extension/background.js:846
: 30 + Math.random() * 90;   // normal keystroke
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
demo-video-src/film/optag.mjs:21
let mål; for (let i = 0; i < 50 && !mål; i++) { try { mål = (await (await fetch(`http://127.0.0.1:${PORT}/json`)).json()).find((t) => t.type === 'page'); } catch {} if (!mål) await vent(200); }
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
extension/offscreen.js:111
const svar = await fetch(`http://127.0.0.1:${port}/`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/extension/offscreen.js:111
const svar = await fetch(`http://127.0.0.1:${port}/`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/flow-isoleret.mjs:104
const r = await fetch(`http://127.0.0.1:${CDP_PORT}/json/list`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/flow-isoleret.mjs:215
try { egen = (await (await fetch(`http://127.0.0.1:${CDP_PORT}/json/version`)).json()) != null; } catch { /* ikke oppe endnu */ }
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
browser_drop_file, browser_reattach_debugger
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
test/ejerskab.test.mjs:264
assert.match(blok, /homedir\(\)/, '~ skal foldes ud, ellers slipper ~/.ssh/id_rsa forbi som relativ sti');
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/upload-symlink.test.mjs:57
const svar = await kald(['../../etc/hosts']);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-server/package.json
@modelcontextprotocol/sdk, ws
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
content/browsermcp-docs-install-codex.md:139
Yes - MIT-licensed, open source, no paywall, no account, no API key. Built by [Agent360](https://agent360.dk) as part of its developer-tools work.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/docs/install-codex/index.html:22
<script type="application/ld+json">{"@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "Is this an official OpenAI integration?", "acceptedAnswer": {"@t
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/docs/install-codex/index.html:77
<p><b>Is it really free?</b> Yes - MIT-licensed, open source, no paywall, no account, no API key. Built by <a href="https://agent360.dk">Agent360</a> as part of its developer-tools work.</p>
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:39
> Set up Browser MCP for me. Read https://browsermcp.dev/llms-install.md and follow it for whichever AI client you are running in. One step only I can do - tell me which one, and wait for me. When I c
Why it matters. remote text is to be obeyed as instructions
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
mcp-server/README.md:39
> Set up Browser MCP for me. Read https://browsermcp.dev/llms-install.md and follow it for whichever AI client you are running in. One step only I can do - tell me which one, and wait for me. When I c
Why it matters. remote text is to be obeyed as instructions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:231
- `browser_upload_file` and `browser_drop_file` accepted any path on disk, so an agent could upload `~/.ssh/id_rsa`. Paths are now resolved (symlinks, `~`, `..`) and must stay inside the working direc
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
content/browsermcp-docs-install-claude-code.md:166
This is the reason people install Browser MCP: Claude Code hits a login wall, needs a verification code, and - because it's driving your actual logged-in Chrome rather than a fresh headless session -
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
content/browsermcp-docs-install-cursor.md:157
This is the reason people install Browser MCP: Cursor's agent hits a login wall, needs a verification code, and - because it's driving your actual logged-in Chrome rather than a fresh headless session
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e4e8ba3234affull audit observations/trust-audit/mcp-server/agent360dk__browser-mcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e4e8ba3234afBLOCKF49first audit
06

Questions

What is the browser-mcp MCP server?

The browser tool that can stop and ask you. A 2FA code, a CAPTCHA, a choice only you can make: it asks on your screen, then carries on in the same signed-in Chrome. 40 tools, MCP clients that run local servers, MIT.

What tools does browser-mcp expose?

36 in total: 25 read-only, 9 that write, and 2 that can delete or overwrite (browser_drop_file, browser_reattach_debugger). Every one is listed on this page with its risk.

Is browser-mcp safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (49/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does browser-mcp need?

It reads ACTIONS_ID_TOKEN_REQUEST_TOKEN, ACTIONS_ID_TOKEN_REQUEST_URL, BROWSER_MCP_TOKEN, GH_TOKEN and GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does browser-mcp run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @agent360/browser-mcp at 1.30.1.

How current is this page?

The grade is for one exact copy of the source (e4e8ba3234af), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement