Atlas / MCP servers / furyteamtop / fury-antidetect-browser

fury-antidetect-browserBLOCK

mcp/furyteamtop/fury-antidetect-browser

Free, open-source anti-detect browser. A Chromium 155 fork that spoofs the fingerprint in C++ rather than with injected JavaScript, with per-profile personas and proxies, a built-in MCP server for AI assistants, and a self-hostable team server with per-project access. No seats, no per-profile pricin

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
17 11r · 6w · 0d
Transport
—
License
AGPL-3.0
Stars
53
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A free, open-source anti-detect browser with real team collaboration. Own Chromium fork, works standalone with no server, self-hostable when you need a team. No seats, no per-profile pricing, no telemetry.

[furybrowser.dev](https://furybrowser.dev) · Русская версия

Status: in development, and now on both macOS and Windows. The core builds and spoofs; the agent launches profiles; the server and desktop shell work. Builds are on the Releases page, marked pre-release. macOS builds are signed and notarised since 21.09.2026; Windows is not — see below. Windows works, as of 16.08.2026. The Chromium core built (57 528 targets), the agent runs on it, and tools/verify-windows.ps1 passes 30 claims on a real machine: the config reaches the browser as an inherited HANDLE, argv carries a slot number and nothing else, no process in the tree has a persona string in its command line, and the browser reports the persona's platform rather than the host's. The desktop shell builds to an NSIS installer. This paragraph used to say not yet, and it said so for as long as that was true. Getting there found eight defects that only running could find — a BSD df flag, a bootstrap that returned success having done nothing, CRLF making git apply claim a patch was stale, PowerShell reading UTF-8 as Windows-1252, a persona leaking through --user-data-dir into every child process, and a beforeBuildCommand that cmd.exe could not execute. They are in the history, one commit each, with what they cost. Team mode works end to end, as of 18.08.2026. Invite, enrol on a second machine, be let in with one button, send a profile to the server, open it there. Every stage of that path had a defe
Read from source at commit 32d4b350f9beOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add fury-desktop -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "fury-desktop": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (17)

11 read · 6 write · 0 destructive.

ToolRiskDescription
fury_add_proxieswriteSave proxies from text, one per line, in any common format (host:port:user:pass, \ user:pass@host:port, scheme://...). Returns what was saved and which lines were not understood.
fury_clickreadClick element N from the last fury_read_page, as a mouse click at its position.
fury_create_profileswriteCreate one profile or a batch on this machine. Each gets its own fingerprint seed. \ Without a persona, machines are spread by how common they are (or restricted to
fury_list_personasreadThe machines a profile can be: id, OS, GPU, screen, and how common each is among real users. \ Prefer common ones; the OS should usually match the person
fury_list_profilesreadThe profiles on this machine: id, name, tags, stage, project, proxy and whether each is open. \ Filter by text, tag or project; with none, everything.
fury_list_proxiesreadSaved proxies: name, type, host, port, last seen country and IP. Passwords are never returned.
fury_move_to_trashwriteMove a profile to Fury
fury_open_urlreadGo to an address in an open profile
fury_read_pagereadThe current page of an open profile: address, title, visible text, and a numbered list of \ links, buttons and fields. Use the numbers with fury_click and fury_type.
fury_screenshotreadA picture of what an open profile
fury_start_profilewriteOpen a profile
fury_statusreadFury
fury_stop_profilewriteClose a profile
fury_typereadType text into element N (it is clicked first), or into whatever has focus. \ submit presses Enter afterwards.
fury_update_profilewriteChange a profile on this machine: name, tags, stage, proxy, start pages. \ Only the fields given change. The fingerprint is never changed here.
fury_warm_statusreadProgress of warm-ups: which site each profile is on, cookies collected, finished or failed.
fury_warm_upreadWarm profiles: open each, visit sites with human-like pauses and scrolling so it collects \ ordinary cookies, optionally close it after. Runs in the background; see fury_warm_status.
04

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (14 observation(s))
Network
declared (15 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
tools/build-status.sh:34
KEY="${FURY_BUILD_KEY:-$HOME/.ssh/fury_winbuild}"
Why it matters. touches a credential store
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
agent/src/relay.rs:1364
"10.0.0.5", "192.168.1.1", "172.16.0.1", "172.31.255.255", "169.254.169.254",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMInventory / provenance · inv.binary · CWE-1104
desktop/src-tauri/installer/header.bmp
header.bmp
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
desktop/src-tauri/installer/sidebar.bmp
sidebar.bmp
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
desktop/src/App.tsx:816
predictable time is a beacon, and this is the same request the user
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
shared-rs/src/domains.rs:280
||beacon.example.org^
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
shared-rs/src/domains.rs:287
for host in ["ads.example.com", "trackers.example.net", "beacon.example.org", "plain.example.io"] {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
agent/src/capture.rs:93
let url = format!("http://127.0.0.1:{port}/{token}/probe.html?auto=capture");
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
agent/src/diagnose.rs:402
let r = run(&format!("http://127.0.0.1:{port}"), None).await;
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
desktop/src/i18n.ts:1641
"csv.columns": "Колонки (в любом порядке, лишние игнорируются): имя · прокси · метки · стадия · заметки · сайты · пояс · языки · персона\nАнглийские заголовки тоже работают: name · proxy · tags · stat
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci.yml:329
DATABASE_URL: postgres://fury:[email protected]:5432/fury
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci.yml:334
DATABASE_SUPERUSER_URL: postgres://postgres:[email protected]:5432/fury
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/13-self-hosting.md:113
DATABASE_URL=postgres://fury:ПАРОЛЬ@127.0.0.1:5432/fury BIND=127.0.0.1:8901 ./target/release/fury-server
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/13-self-hosting.md:266
DATABASE_URL=postgres://fury:ПАРОЛЬ@127.0.0.1:5432/fury \
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
agent/src/relay.rs:1383
password: "s3cr3t-proxy-password".into(),
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tools/team-e2e/run.mjs:380
const password = "correct-horse-battery-staple";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tools/verify-team.ps1:65
email = $email; password = 'correct-horse-battery-staple'; org_name = $org
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
site/deploy.sh:27
key="${FURY_SSH_KEY:-$HOME/.ssh/fury_server}"
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agent/src/ext.rs:683
for evil in ["../../../../tmp/pwned", "/etc/passwd", "a/../../b"] {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agent/src/ipc.rs:3138
"../../etc/hosts".to_string(),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agent/src/launcher.rs:328
"../../shared/personas/macos-15-m-series-1728x1117.json"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agent/src/mcp.rs:43
pub const SKILL: &str = include_str!("../../shared/mcp/SKILL.md");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agent/src/relay.rs:937
pub(crate) const PROBE_HTML: &str = include_str!("../../tools/detect-suite/probe.html");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONTRIBUTING.md:24
Open `http://127.0.0.1:8731/probe.html` in Chrome, then:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:255
Open `http://127.0.0.1:8791/probe.html` in ordinary Chrome and in Fury, and

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 32d4b350f9befull audit observations/trust-audit/mcp-server/furyteamtop__fury-antidetect-browser.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0932d4b350f9beBLOCKF54first audit
06

Questions

What is the fury-antidetect-browser MCP server?

Free, open-source anti-detect browser. A Chromium 155 fork that spoofs the fingerprint in C++ rather than with injected JavaScript, with per-profile personas and proxies, a built-in MCP server for AI assistants, and a self-hostable team server with per-project access. No seats, no per-profile pricin

What tools does fury-antidetect-browser expose?

17 in total: 11 read-only, 6 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is fury-antidetect-browser safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does fury-antidetect-browser need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (32d4b350f9be), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement