fury-antidetect-browserBLOCK
Free, open-source anti-detect browser. A Chromium 155 fork that spoofs the fingerprint in C++ rather than with injected JavaScript, with per-profile personas and proxies, a built-in MCP server for AI assistants, and a self-hostable team server with per-project access. No seats, no per-profile pricin
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A free, open-source anti-detect browser with real team collaboration. Own Chromium fork, works standalone with no server, self-hostable when you need a team. No seats, no per-profile pricing, no telemetry.
[furybrowser.dev](https://furybrowser.dev) · Русская версия
Status: in development, and now on both macOS and Windows. The core builds and spoofs; the agent launches profiles; the server and desktop shell work. Builds are on the Releases page, marked pre-release. macOS builds are signed and notarised since 21.09.2026; Windows is not — see below. Windows works, as of 16.08.2026. The Chromium core built (57 528 targets), the agent runs on it, andtools/verify-windows.ps1passes 30 claims on a real machine: the config reaches the browser as an inherited HANDLE, argv carries a slot number and nothing else, no process in the tree has a persona string in its command line, and the browser reports the persona's platform rather than the host's. The desktop shell builds to an NSIS installer. This paragraph used to say not yet, and it said so for as long as that was true. Getting there found eight defects that only running could find — a BSDdfflag, a bootstrap that returned success having done nothing, CRLF makinggit applyclaim a patch was stale, PowerShell reading UTF-8 as Windows-1252, a persona leaking through--user-data-dirinto every child process, and abeforeBuildCommandthat cmd.exe could not execute. They are in the history, one commit each, with what they cost. Team mode works end to end, as of 18.08.2026. Invite, enrol on a second machine, be let in with one button, send a profile to the server, open it there. Every stage of that path had a defe
32d4b350f9beOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add fury-desktop -- npx -y [email protected]
{
"mcpServers": {
"fury-desktop": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (17)
11 read · 6 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
fury_add_proxies | write | Save proxies from text, one per line, in any common format (host:port:user:pass, \ user:pass@host:port, scheme://...). Returns what was saved and which lines were not understood. |
fury_click | read | Click element N from the last fury_read_page, as a mouse click at its position. |
fury_create_profiles | write | Create one profile or a batch on this machine. Each gets its own fingerprint seed. \ Without a persona, machines are spread by how common they are (or restricted to |
fury_list_personas | read | The machines a profile can be: id, OS, GPU, screen, and how common each is among real users. \ Prefer common ones; the OS should usually match the person |
fury_list_profiles | read | The profiles on this machine: id, name, tags, stage, project, proxy and whether each is open. \ Filter by text, tag or project; with none, everything. |
fury_list_proxies | read | Saved proxies: name, type, host, port, last seen country and IP. Passwords are never returned. |
fury_move_to_trash | write | Move a profile to Fury |
fury_open_url | read | Go to an address in an open profile |
fury_read_page | read | The current page of an open profile: address, title, visible text, and a numbered list of \ links, buttons and fields. Use the numbers with fury_click and fury_type. |
fury_screenshot | read | A picture of what an open profile |
fury_start_profile | write | Open a profile |
fury_status | read | Fury |
fury_stop_profile | write | Close a profile |
fury_type | read | Type text into element N (it is clicked first), or into whatever has focus. \ submit presses Enter afterwards. |
fury_update_profile | write | Change a profile on this machine: name, tags, stage, proxy, start pages. \ Only the fields given change. The fingerprint is never changed here. |
fury_warm_status | read | Progress of warm-ups: which site each profile is on, cookies collected, finished or failed. |
fury_warm_up | read | Warm profiles: open each, visit sites with human-like pauses and scrolling so it collects \ ordinary cookies, optionally close it after. Runs in the background; see fury_warm_status. |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (14 observation(s))
- Network
- declared (15 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
KEY="${FURY_BUILD_KEY:-$HOME/.ssh/fury_winbuild}""10.0.0.5", "192.168.1.1", "172.16.0.1", "172.31.255.255", "169.254.169.254",
header.bmp
sidebar.bmp
predictable time is a beacon, and this is the same request the user
||beacon.example.org^
for host in ["ads.example.com", "trackers.example.net", "beacon.example.org", "plain.example.io"] {let url = format!("http://127.0.0.1:{port}/{token}/probe.html?auto=capture");let r = run(&format!("http://127.0.0.1:{port}"), None).await;"csv.columns": "Колонки (в любом порядке, лишние игнорируются): имя · прокси · метки · стадия · заметки · сайты · пояс · языки · персона\nАнглийские заголовки тоже работают: name · proxy · tags · stat
DATABASE_URL: postgres://fury:[email protected]:5432/fury
DATABASE_SUPERUSER_URL: postgres://postgres:[email protected]:5432/fury
DATABASE_URL=postgres://fury:ПАРОЛЬ@127.0.0.1:5432/fury BIND=127.0.0.1:8901 ./target/release/fury-server
DATABASE_URL=postgres://fury:ПАРОЛЬ@127.0.0.1:5432/fury \
password: "s3cr3t-proxy-password".into(),
const password = "correct-horse-battery-staple";
email = $email; password = 'correct-horse-battery-staple'; org_name = $org
key="${FURY_SSH_KEY:-$HOME/.ssh/fury_server}"for evil in ["../../../../tmp/pwned", "/etc/passwd", "a/../../b"] {"../../etc/hosts".to_string(),
"../../shared/personas/macos-15-m-series-1728x1117.json"
pub const SKILL: &str = include_str!("../../shared/mcp/SKILL.md");pub(crate) const PROBE_HTML: &str = include_str!("../../tools/detect-suite/probe.html");Open `http://127.0.0.1:8731/probe.html` in Chrome, then:
Open `http://127.0.0.1:8791/probe.html` in ordinary Chrome and in Fury, and
Gates applied: no_behavioural_pass.
32d4b350f9befull audit observations/trust-audit/mcp-server/furyteamtop__fury-antidetect-browser.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 32d4b350f9be | BLOCK | F | 54 | first audit |
Questions
What is the fury-antidetect-browser MCP server?
Free, open-source anti-detect browser. A Chromium 155 fork that spoofs the fingerprint in C++ rather than with injected JavaScript, with per-profile personas and proxies, a built-in MCP server for AI assistants, and a self-hostable team server with per-project access. No seats, no per-profile pricin
What tools does fury-antidetect-browser expose?
17 in total: 11 read-only, 6 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is fury-antidetect-browser safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does fury-antidetect-browser need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (32d4b350f9be), read on 2026-10-09. The repository is watched and re-audited when it changes.