CloakBrowser-AgentCAUTION
Jev-powered stealth browser agent. TypeSafe Jev decides each step in ~0.3 s, CloakBrowser carries it out like a human. MCP server, CLI and Python API.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Give it a goal in plain language. [TypeSafe Jev](https://docs.typesafe.ai/introduction) decides every step in ~0.3 s, [CloakBrowser](https://github.com/CloakHQ/CloakBrowser) carries it out like a human, and you get the result back as markdown.
browse(goal="Find one-way flights from Zurich to London on October 20, 2026, for one adult in economy. Stop when matching flight options are visible.", url="https://www.google.com/travel/flights?hl=en") status: done tab_id: t1 (still open) url: https://www.google.com/travel/flights/search?tfs=... title: Zürich to London | Google Flights steps: 10 actions, 14 decisions, 22596 ms actions taken (p = Jev's probability for the chosen target; runner-ups in brackets): 1. click 'Change ticket type. Round trip' p=0.81 ['Open Where from?' p=0.15, 'Flights' p=0.01] 2. click 'One way' p=1.0 3. fill 'Where from?' = 'Zurich' p=0.93 ['Where to? ' p=0.04, 'Departure' p=0.03] 4. click 'Zürich, Switzerland' p=0.77 ['Zurich Airport (ZRH)' p=0.21, 'Open Where from? ' p=0.01] 5. fill 'Where to? ' = 'London' p=0.99 ['Departure' p=0.01] 6. click 'London, United Kingdom' p=0.95 ['Heathrow Airport (LHR)' p=0.02, ...] 7. click 'Open Departure' p=0.97 ['Search' p=0.03] 8. click 'Tuesday, October 20, 2026 , 48 euros, Cheapest price' p=0.98 ['Done. ' p=0.02] 9. click 'Done. Search for one-way flights, departing on October 20, 2' p=0.98 [...] 10. click 'Search' p=0.99 ['Open Where from?' p=0.01] ... # Flight search ... ## Search results ... from €48
A real run, trimmed.
It works as an MCP server (Claude Code, Cursor, Claude Desktop, any MCP client), a CLI, or a Python library. It runs on CloakBrowser, a stealth Chromium with human-like mouse and keyboard input.
Why Jev
Most browser agents ask a large language model to write the next action, wh
ea37455dbeeaOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cloakbrowser-agent --env TEXT_MODEL_API_KEY=${TEXT_MODEL_API_KEY} --env TYPESAFE_API_KEY=${TYPESAFE_API_KEY} -- uvx cloakbrowser-agent{
"mcpServers": {
"cloakbrowser-agent": {
"command": "uvx",
"args": [
"cloakbrowser-agent"
],
"env": {
"TEXT_MODEL_API_KEY": "${TEXT_MODEL_API_KEY}",
"TYPESAFE_API_KEY": "${TYPESAFE_API_KEY}"
}
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
act | read | Do one step in a tab yourself, e.g. to get browse past a page it is stuck on. |
browse | read | Complete a web task in a stealth browser and return the relevant page content as markdown. |
close_tab | read | Close a tab that browse left open. |
snapshot | read | Show a tab exactly as the agent sees it: url, title, scroll position, the numbered element table |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (6)
print(f"CloakBrowser running. Connect with: --cdp http://127.0.0.1:{args.port} (Ctrl-C to close)", flush=True)r.add_argument("--cdp", help="e.g. http://127.0.0.1:9222 (from `cloak-agent browser`)")| `CLOAK_AGENT_CDP` | unset | attach to an already running browser, e.g. `http://127.0.0.1:9222` |
cloak-agent run --cdp http://127.0.0.1:9222 --url https://www.google.com --goal "Search Google for 'CloakBrowser'"
session = await Session.launch(headless=False) # or: await Session.connect("http://127.0.0.1:9222")return base64.b64decode(shot["data"])
Gates applied: no_behavioural_pass.
ea37455dbeeafull audit observations/trust-audit/mcp-server/cloakhq__cloakbrowser-agent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | ea37455dbeea | CAUTION | B | 89 | first audit |
Questions
What is the CloakBrowser-Agent MCP server?
Jev-powered stealth browser agent. TypeSafe Jev decides each step in ~0.3 s, CloakBrowser carries it out like a human. MCP server, CLI and Python API.
What tools does CloakBrowser-Agent expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is CloakBrowser-Agent safe to connect to an agent?
With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does CloakBrowser-Agent need?
It reads TEXT_MODEL_API_KEY and TYPESAFE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (ea37455dbeea), read on 2026-10-09. The repository is watched and re-audited when it changes.