Atlas / MCP servers / kimtth / Aoai Web Browsing

Aoai Web BrowsingSAFE

mcp/kimtth/aoai-web-browsing

A minimal Model Context Protocol 🖥️ server/client🧑💻with OpenAI and 🌐 web browser control via Playwright.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 11r · 1w · 0d
Transport
streamable-http
License
MIT
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Playwright browsing application with Azure OpenAI/OpenAI, plus focused examples of MCP v1/v2, OAuth, and interactive MCP Apps.

  1. Original browsing application — Azure OpenAI/OpenAI integration, setup and client connections.
  2. MCP v1 and v2 samples — browser tools and local OAuth flows.
  3. MCP Apps samples — interactive tool-response UIs built with Prefab.

1. Web browsing MCP application

A local browsing application with a Tkinter chat UI and an MCP-to-LLM bridge.

  • The original server uses the standalone fastmcp package; Playwright controls

a visible Chromium browser and keeps the current page between tool calls.

  • The local client_bridge implementation adapts MCP

tool definitions to OpenAI Chat Completions function calling. It supports an in-process FastMCP server or an external stdio server.

  • The GUI uses Azure OpenAI. Python callers can configure the bridge for standard

OpenAI, but the original browser server separately initializes its own Azure client for the selector-extraction tool.

Setup and run

Requirements: Python 3.13 or newer, Tkinter, a graphical desktop session, and uv. The commands below use uv to manage this project's environment; MCP itself does not require a particular Python package manager. Run them from the repository root.

  1. Copy .env.template to a local .env file, keeping the

template intact. Configure an existing Azure OpenAI deployment that supports Chat Completions tool calling:

AZURE_OPEN_AI_ENDPOINT=
AZURE_OPEN_AI_API_KEY=
AZURE_OPEN_AI_DEPLOYMENT_MODEL=
AZURE_OPEN_AI_API_VERSION=

The API version is needed for the legacy Azure endpoint, not the /openai/v1 path described below. Keep .env out of source control

Read from source at commit 8744c2d46d09OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-web-auto --env AZURE_OPENAI_AD_TOKEN=${AZURE_OPENAI_AD_TOKEN} --env AZURE_OPEN_AI_API_KEY=${AZURE_OPEN_AI_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENAI_TOKEN_LIMIT_PARAMETER=${OPENAI_TOKEN_LIMIT_PARAMETER} -- uvx mcp-web-auto
claude-desktop
{
  "mcpServers": {
    "mcp-web-auto": {
      "command": "uvx",
      "args": [
        "mcp-web-auto"
      ],
      "env": {
        "AZURE_OPENAI_AD_TOKEN": "${AZURE_OPENAI_AD_TOKEN}",
        "AZURE_OPEN_AI_API_KEY": "${AZURE_OPEN_AI_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "OPENAI_TOKEN_LIMIT_PARAMETER": "${OPENAI_TOKEN_LIMIT_PARAMETER}"
      }
    }
  }
}
03

Exposed tools (12)

11 read · 1 write · 0 destructive.

ToolRiskDescription
browser_panelreadOpen the browser panel to read a demo page or example.com with Playwright.
extract_selector_by_page_contentreadTry to find a css selector by current page content.
playwright_clickreadClick an element on the page.
playwright_evaluatewriteExecute JavaScript in the browser console.
playwright_fillreadFill out an input field.
playwright_hoverreadHover over an element on the page.
playwright_navigatereadOpen a URL in a fresh browser and return its title and visible text.
playwright_screenshotreadOpen a URL in a fresh browser and return a viewport PNG.
playwright_selectreadSelect an element on the page with a Select tag.
read_all_screenshotsreadRead all screenshots from a list of file names.
read_demo_pagereadRead a local HTML page in Chromium, only after bearer authentication.
reading_cardreadOpen an interactive reading card. Editing it makes no further tool calls.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (7)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp_learning_samples/mcp_v1_browser_tools/client.py:22
streamable_http_client("http://127.0.0.1:8011/mcp", http_client=http) as streams,
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/capture_previews.py:57
base = f"http://127.0.0.1:{server.server_port}"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp_learning_samples/apps_browser/test_app.py:55
("https://127.0.0.1/", False),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp_learning_samples/mcp_v1_browser_tools/README.md:49
The client connects to `http://127.0.0.1:8011/mcp`, initializes, lists tools and
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp_learning_samples/mcp_v2_browser_tools/README.md:50
The intended endpoint is `http://127.0.0.1:8012/mcp`; inspect the printed protocol,
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp_learning_samples/apps_browser/test_app.py:40
png = base64.b64decode(state["screenshot"].split(",", 1)[1])

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 8744c2d46d09full audit observations/trust-audit/mcp-server/kimtth__aoai-web-browsing.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-088744c2d46d09SAFEB89first audit
06

Questions

What is the Aoai Web Browsing MCP server?

A minimal Model Context Protocol 🖥️ server/client🧑💻with OpenAI and 🌐 web browser control via Playwright.

What tools does Aoai Web Browsing expose?

12 in total: 11 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Aoai Web Browsing safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Aoai Web Browsing need?

It reads AZURE_OPENAI_AD_TOKEN, AZURE_OPEN_AI_API_KEY, OPENAI_API_KEY and OPENAI_TOKEN_LIMIT_PARAMETER from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Aoai Web Browsing run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as mcp-web-auto.

How current is this page?

The grade is for one exact copy of the source (8744c2d46d09), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement