Atlas / MCP servers / debugbase / Glance

GlanceCAUTION

mcp/debugbase/glance

AI-powered browser automation MCP server for Claude Code. Navigate, click, screenshot, test — all from your terminal.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
32 29r · 3w · 0d
Transport
stdio
License
MIT
Stars
156
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Glance

AI-powered browser automation for Claude Code by DebugBase

Navigate, click, screenshot, test — all from your terminal.

What is Glance?

Glance is an MCP server that gives Claude Code a real browser. Instead of guessing what your web app looks like, Claude can actually see it, interact with it, and test it.

You: "Test the login flow on localhost:3000"

Claude: *opens browser* *navigates* *fills form* *clicks submit*
*takes screenshot* *verifies redirect* *checks for errors*
"Login flow works. Found 1 console warning about..."

Features

  • 30 MCP tools for complete browser control
  • Inline screenshots — Claude sees what the browser sees
  • Accessibility snapshots — full page structure as text
  • Test scenario runner — define multi-step tests in JSON
  • 12 assertion types — exists, textContains, urlEquals, and more
  • Session recording — record and replay browser sessions
  • Visual regression — pixel-level screenshot comparison
  • Network & console monitoring — catch errors and failed requests
Read from source at commit 08792fa352acOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add glance-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "glance-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (32)

29 read · 3 write · 0 destructive.

ToolRiskDescription
browser_clickread
browser_closeread
browser_console_messagesread
browser_dragread
browser_evaluateread
browser_go_backread
browser_go_forwardread
browser_hoverread
browser_navigateread
browser_network_requestsread
browser_press_keyread
browser_screenshotread
browser_scrollread
browser_select_optionread
browser_snapshotread
browser_tab_listread
browser_tab_newread
browser_tab_selectread
browser_typeread
session_endread
session_listread
session_replayread
session_startwrite
test_assertread
test_auth_flowread
test_fill_formread
test_scenario_runwrite
test_scenario_statusread
test_stop_watchwrite
test_watch_eventsread
visual_baselineread
visual_compareread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/config.ts:6
urlAllowlist: ['http://localhost:*', 'http://127.0.0.1:*', 'https://localhost:*', 'https://127.0.0.1:*', 'http://*', 'https://*'],
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/config.ts:12
urlAllowlist: ['http://localhost:*', 'http://127.0.0.1:*'],
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, pixelmatch, playwright-core, pngjs, uuid, zod, @types/node, @types/uuid
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
skills/glance-test/SKILL.md:3
description: Run E2E browser tests on any web application using Glance MCP. Use when the user says "test this page," "check this URL," "run E2E tests," "browser test," "test the login flow," "check if

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 08792fa352acfull audit observations/trust-audit/mcp-server/debugbase__glance.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0708792fa352acCAUTIONB89first audit
06

Questions

What is the Glance MCP server?

AI-powered browser automation MCP server for Claude Code. Navigate, click, screenshot, test — all from your terminal.

What tools does Glance expose?

32 in total: 29 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Glance safe to connect to an agent?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Glance need?

No credential environment variables were found in its source, so it appears to need none.

How does Glance run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as glance-mcp at 1.1.0.

How current is this page?

The grade is for one exact copy of the source (08792fa352ac), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement