KogiQA BrowserSAFE
This web browser has been designed to help your agent debug and develop complex web applications. (MCP Server)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
kogiQA MCP Web Browser
A Model Context Protocol (MCP) server that provides browser automation capabilities using kogiQA. This server enables LLMs to interact with web pages through natural language, bypassing the need for screenshots or visually-tuned models.
For what to use:
- Debug style issues on your page
- Automatically fix console errors.
- Map and document the functionality of your web app
- Automatically write end-to-end tests
- Automate exploratory testing of your application
See example prompts Usage Examples
kogiQA MCP vs Playwright MCP
The kogiQA MCP Server provides a browser which incorporates the capabilities of the kogiQA browser control algorithm. This enables agents to interact with pages without a selector, saving time and tokens.
Installation
Auto install:
npx kogiqa-mcp@latest
Claude Code
claude mcp add kogiqa-browser npx kogiqa-mcp@latest
VS Code
Click one of the buttons below to install directly in vs code:
[](https://insiders.vscode.dev/redirect?url=vscode-insiders%3Amcp%2Finstall%3F%7B%22name%22%3A%22kogiqa-browser%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22kogiqa-mcp%40latest%22%5D%7D) [](https://insiders.vscode.dev/redirect?url=vscode-insiders%3Amcp%2Finstall%3F%7B%22name%22%3A%22kogiqa-browser%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22kogiqa-mcp%40latest%22%5D%7D)
Alternatively, install via the VS Code CLI:
code --add-mcp '{"name":"kogiqa-browser","command":"npx","args":["kogiqa-mcp@latest"]}'Cursor
[](https://cursor.com/en/install-mcp?nam
18f8d15137f3OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add kogiqa-mcp -- npx -y [email protected]
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
fs.rmSync(extractedPath, {cwd: path.resolve(baseDirname, "../../desktop-client"),
@modelcontextprotocol/sdk, add-mcp, axios, @types/node
Gates applied: no_behavioural_pass.
18f8d15137f3full audit observations/trust-audit/mcp-server/atagon-gmbh__kogiqa-browser.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 18f8d15137f3 | SAFE | B | 89 | first audit |
Questions
What is the KogiQA Browser MCP server?
This web browser has been designed to help your agent debug and develop complex web applications. (MCP Server)
Is KogiQA Browser safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does KogiQA Browser need?
No credential environment variables were found in its source, so it appears to need none.
How does KogiQA Browser run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as kogiqa-mcp at 1.3.128.
How current is this page?
The grade is for one exact copy of the source (18f8d15137f3), read on 2026-10-07. The repository is watched and re-audited when it changes.