Aoai Web BrowsingSAFE
A minimal Model Context Protocol 🖥️ server/client🧑💻with OpenAI and 🌐 web browser control via Playwright.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Playwright browsing application with Azure OpenAI/OpenAI, plus focused examples of MCP v1/v2, OAuth, and interactive MCP Apps.
- Original browsing application — Azure OpenAI/OpenAI integration, setup and client connections.
- MCP v1 and v2 samples — browser tools and local OAuth flows.
- MCP Apps samples — interactive tool-response UIs built with Prefab.
1. Web browsing MCP application
A local browsing application with a Tkinter chat UI and an MCP-to-LLM bridge.
- The original server uses the standalone
fastmcppackage; Playwright controls
a visible Chromium browser and keeps the current page between tool calls.
- The local client_bridge implementation adapts MCP
tool definitions to OpenAI Chat Completions function calling. It supports an in-process FastMCP server or an external stdio server.
- The GUI uses Azure OpenAI. Python callers can configure the bridge for standard
OpenAI, but the original browser server separately initializes its own Azure client for the selector-extraction tool.
Setup and run
Requirements: Python 3.13 or newer, Tkinter, a graphical desktop session, and uv. The commands below use uv to manage this project's environment; MCP itself does not require a particular Python package manager. Run them from the repository root.
- Copy .env.template to a local
.envfile, keeping the
template intact. Configure an existing Azure OpenAI deployment that supports Chat Completions tool calling:
AZURE_OPEN_AI_ENDPOINT= AZURE_OPEN_AI_API_KEY= AZURE_OPEN_AI_DEPLOYMENT_MODEL= AZURE_OPEN_AI_API_VERSION=
The API version is needed for the legacy Azure endpoint, not the /openai/v1 path described below. Keep .env out of source control
8744c2d46d09OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-web-auto --env AZURE_OPENAI_AD_TOKEN=${AZURE_OPENAI_AD_TOKEN} --env AZURE_OPEN_AI_API_KEY=${AZURE_OPEN_AI_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENAI_TOKEN_LIMIT_PARAMETER=${OPENAI_TOKEN_LIMIT_PARAMETER} -- uvx mcp-web-auto{
"mcpServers": {
"mcp-web-auto": {
"command": "uvx",
"args": [
"mcp-web-auto"
],
"env": {
"AZURE_OPENAI_AD_TOKEN": "${AZURE_OPENAI_AD_TOKEN}",
"AZURE_OPEN_AI_API_KEY": "${AZURE_OPEN_AI_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"OPENAI_TOKEN_LIMIT_PARAMETER": "${OPENAI_TOKEN_LIMIT_PARAMETER}"
}
}
}
}Exposed tools (12)
11 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
browser_panel | read | Open the browser panel to read a demo page or example.com with Playwright. |
extract_selector_by_page_content | read | Try to find a css selector by current page content. |
playwright_click | read | Click an element on the page. |
playwright_evaluate | write | Execute JavaScript in the browser console. |
playwright_fill | read | Fill out an input field. |
playwright_hover | read | Hover over an element on the page. |
playwright_navigate | read | Open a URL in a fresh browser and return its title and visible text. |
playwright_screenshot | read | Open a URL in a fresh browser and return a viewport PNG. |
playwright_select | read | Select an element on the page with a Select tag. |
read_all_screenshots | read | Read all screenshots from a list of file names. |
read_demo_page | read | Read a local HTML page in Chromium, only after bearer authentication. |
reading_card | read | Open an interactive reading card. Editing it makes no further tool calls. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (7)
streamable_http_client("http://127.0.0.1:8011/mcp", http_client=http) as streams,.env.template
base = f"http://127.0.0.1:{server.server_port}"("https://127.0.0.1/", False),The client connects to `http://127.0.0.1:8011/mcp`, initializes, lists tools and
The intended endpoint is `http://127.0.0.1:8012/mcp`; inspect the printed protocol,
png = base64.b64decode(state["screenshot"].split(",", 1)[1])Gates applied: no_behavioural_pass.
8744c2d46d09full audit observations/trust-audit/mcp-server/kimtth__aoai-web-browsing.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 8744c2d46d09 | SAFE | B | 89 | first audit |
Questions
What is the Aoai Web Browsing MCP server?
A minimal Model Context Protocol 🖥️ server/client🧑💻with OpenAI and 🌐 web browser control via Playwright.
What tools does Aoai Web Browsing expose?
12 in total: 11 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Aoai Web Browsing safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Aoai Web Browsing need?
It reads AZURE_OPENAI_AD_TOKEN, AZURE_OPEN_AI_API_KEY, OPENAI_API_KEY and OPENAI_TOKEN_LIMIT_PARAMETER from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Aoai Web Browsing run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as mcp-web-auto.
How current is this page?
The grade is for one exact copy of the source (8744c2d46d09), read on 2026-10-08. The repository is watched and re-audited when it changes.