BrowserSAFE
Cloud Browser MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that provides browser automation capabilities using Anchor Browser's remote browser service with Playwright. This server enables LLMs to interact with web pages through Anchor's cloud-based browsers with built-in proxies, stealth features, and advanced capabilities.
Key Features
- Remote Browser Execution: Uses Anchor Browser's cloud infrastructure instead of local browsers
- Built-in Proxies: Automatic residential proxy rotation and geo-targeting
- Stealth & Anti-Detection: Advanced browser fingerprinting and anti-bot detection
- Fast and lightweight: Uses Playwright's accessibility tree, not pixel-based input
- LLM-friendly: No vision models needed, operates purely on structured data
- Deterministic tool application: Avoids ambiguity common with screenshot-based approaches
Requirements
- Node.js 18 or newer
- Anchor Browser API Key (Get one here)
- VS Code, Cursor, Windsurf, Claude Desktop, Goose or any other MCP client
Getting Started
1. Clone and Build
Since this is a custom Browser MCP server, you need to build it locally:
# Clone the repository git clone https://github.com/anchorbrowser/anchor-mcp.git cd anchor-mcp # Install dependencies and build npm install npm run build
2. Get Your Anchor API Key
- Sign up at anchorbrowser.io
- Get your API key from the dashboard
- Copy your API key (starts with
sk-)
3. Configure MCP Client
Cursor
Add to your ~/.cursor/mcp.json:
{
"mcpServers": {
"anchor-browser": {
"command": "node",
"args": [
"/path/to/anchor-mcp/cli.js"
],
"env": {
"ANCHOR_API_KEY": "sk-your-api-key-here"
}
}
}
}VS Code
Add to your MCP confi
ee02362053e5OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add browser-mcp --env ANCHOR_API_KEY=${ANCHOR_API_KEY} --env PLAYWRIGHT_MCP_PROXY_BYPASS=${PLAYWRIGHT_MCP_PROXY_BYPASS} -- npx -y [email protected]{
"mcpServers": {
"browser-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANCHOR_API_KEY": "${ANCHOR_API_KEY}",
"PLAYWRIGHT_MCP_PROXY_BYPASS": "${PLAYWRIGHT_MCP_PROXY_BYPASS}"
}
}
}
}Exposed tools (29)
25 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
anchor_click | read | Perform click on a web page |
anchor_close | read | Close the page |
anchor_console_messages | read | Returns all console messages |
anchor_drag | destructive | Perform drag and drop between two elements |
anchor_file_upload | write | Upload one or multiple files |
anchor_handle_dialog | read | Handle a dialog |
anchor_hover | read | Hover over element on page |
anchor_navigate | read | Navigate to a URL |
anchor_navigate_back | read | Go back to the previous page |
anchor_navigate_forward | read | Go forward to the next page |
anchor_network_requests | read | Returns all network requests since loading the page |
anchor_pdf_save | write | Save page as PDF |
anchor_press_key | read | Press a key on the keyboard |
anchor_resize | read | Resize the browser window |
anchor_select_option | read | Select an option in a dropdown |
anchor_snapshot | read | Capture accessibility snapshot of the current page, this is better than screenshot |
anchor_tab_close | read | Close a tab |
anchor_tab_list | read | List browser tabs |
anchor_tab_new | read | Open a new tab |
anchor_tab_select | read | Select a tab by index |
anchor_take_screenshot | read | Take a screenshot of the current page. You can |
anchor_wait_for | read | Wait for text to appear or disappear or a specified time to pass |
browser | read | Perform a task with the browser. It can click, type, export, capture screenshot, drag, hover, select options, etc. |
browser_evaluate | read | Evaluate JavaScript expression on page or element |
browser_mouse_click_xy | read | Click left mouse button at a given position |
browser_mouse_drag_xy | read | Drag left mouse button to a given position |
browser_mouse_move_xy | write | Move mouse to a given position |
browser_type | read | Type text into editable element |
done | read | Call this tool when the task is complete. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
anchor_drag
path.resolve(__filename, '../../../cli.js'),
'--output-dir', path.resolve(__filename, '../../../sessions')
path.resolve(__filename, '../../../cli.js'),
import type { ToolCapability } from '../../config.js';@modelcontextprotocol/sdk, axios, commander, debug, mime, ws, zod-to-json-schema, @anthropic-ai/sdk
Gates applied: no_behavioural_pass.
ee02362053e5full audit observations/trust-audit/mcp-server/browsermcp-com__browser-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ee02362053e5 | SAFE | B | 89 | first audit |
Questions
What is the Browser MCP server?
Cloud Browser MCP server
What tools does Browser expose?
29 in total: 25 read-only, 3 that write, and 1 that can delete or overwrite (anchor_drag). Every one is listed on this page with its risk.
Is Browser safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Browser need?
It reads ANCHOR_API_KEY and PLAYWRIGHT_MCP_PROXY_BYPASS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Browser run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as browser-mcp at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (ee02362053e5), read on 2026-10-08. The repository is watched and re-audited when it changes.