Web BrowserSAFE
A Minimum Control Program (MCP) server implementation for web browsing capabilities using BeautifulSoup4
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://twitter.com/JoeBlazick) [](https://smithery.ai/server/web-browser-mcp-server) [](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT) [](https://pypi.org/project/web-browser-mcp-server/) [](https://pypi.org/project/web-browser-mcp-server/)
✨ Features
🌐 Enable AI assistants to browse and extract content from the web through a simple MCP interface.
The Web Browser MCP Server provides AI models with the ability to browse websites, extract content, and understand web pages through the Message Control Protocol (MCP). It enables smart content extraction with CSS selectors and robust error handling.
🤝 [Contribute](https://github.com/blazickjp/web-browser-mcp-server/blob/main/CONTRIBUTING.md) • 📝 [Report Bug](https://github.com/blazickjp/web-browser-mcp-server/issues)
✨ Core Features
- 🎯 Smart Content Extraction: Target exactly what you need with CSS selectors
- ⚡ Lightning Fast: Built with async processing for optimal performance
- 📊 Rich Metadata: Capture titles, links, and structured content
- 🛡️ Robust & Reliable: Built-in error handling and timeout management
- 🌍 Cross-Platform: Works everywhere Python runs
🚀 Quick Start
Installing via Smithery
To install Web Browser Server for Claude Desktop automatically via [Smithery](https://smithery.ai/server/web-
1e3dd5918a22OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add web-browser-mcp-server -- uvx web-browser-mcp-server
{
"mcpServers": {
"web-browser-mcp-server": {
"command": "uvx",
"args": [
"web-browser-mcp-server"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
browse_webpage | read | Extract content from a webpage with optional CSS selectors for specific elements |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
test_server.cpython-311-pytest-8.0.0.pyc
Gates applied: no_behavioural_pass.
1e3dd5918a22full audit observations/trust-audit/mcp-server/blazickjp__web-browser.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 1e3dd5918a22 | SAFE | B | 89 | first audit |
Questions
What is the Web Browser MCP server?
A Minimum Control Program (MCP) server implementation for web browsing capabilities using BeautifulSoup4
What tools does Web Browser expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Web Browser safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Web Browser need?
No credential environment variables were found in its source, so it appears to need none.
How does Web Browser run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as web-browser-mcp-server.
How current is this page?
The grade is for one exact copy of the source (1e3dd5918a22), read on 2026-10-08. The repository is watched and re-audited when it changes.