V0 CaptureSAFE
MCP Server to connect your MCP host to V0.dev directly
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A tool that connects to your browser, navigates to v0.dev, submits prompts, and captures all network responses - including the streamed AI responses. This allows you to save the complete output from v0.dev for further analysis or use.
Features
- Connects to your existing Chrome browser with all your accounts/cookies
- Navigates to v0.dev and submits your prompt
- Captures all network activity, focusing on streamed AI responses
- Decodes the Vercel AI SDK streaming format to extract complete responses
- Saves responses to files for later reference
- Provides tools to extract and view responses from saved files
Prerequisites
- Python 3.8+
- Google Chrome browser
Installation
- Clone this repository
- Install dependencies:
# Using pip pip install -r requirements.txt # OR using uv uv pip install -r requirements.txt # Install Playwright browsers python -m playwright install chromium
Usage
Capturing a v0.dev response
Run the script with a prompt to capture the response:
# Use the default prompt (calendar app) python main.py # Specify a custom prompt python main.py monitor --prompt "Build a landing page for a coffee shop with a menu section and contact form"
The script will:
- Connect to your Chrome browser (or launch a new instance)
- Navigate to v0.dev
- Submit your prompt
- Capture all network activity, including the streaming responses
- Save the responses to the
capturesdirectory
Listing captured files
List all the files in your captures directory:
python main.py list
Extracting responses from captured files
Extract and display the complete response from a captured file:
python main.py extract captures/full_response_1234567890.txt
This will:
- Parse and decode the captured file
- Extract the complete text response
- Display it in the terminal
- Save a clean version to a new file
How It Works
Vercel AI SDK Streaming Format
ac6c736c7771OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add v0-mcp -- uvx v0-mcp
{
"mcpServers": {
"v0-mcp": {
"command": "uvx",
"args": [
"v0-mcp"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
monitor_v0_interactions | read | Monitor v0.dev interactions and return the AI generated content |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
body_bytes = base64.b64decode(body)
body_bytes = base64.b64decode(body)
body_bytes = base64.b64decode(body)
playwright, asyncio, typing-extensions, json5, mcp
Gates applied: no_behavioural_pass, no_license.
ac6c736c7771full audit observations/trust-audit/mcp-server/m2rads__v0-capture.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ac6c736c7771 | SAFE | B | 89 | first audit |
Questions
What is the V0 Capture MCP server?
MCP Server to connect your MCP host to V0.dev directly
What tools does V0 Capture expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is V0 Capture safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does V0 Capture need?
No credential environment variables were found in its source, so it appears to need none.
How does V0 Capture run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as v0-mcp.
How current is this page?
The grade is for one exact copy of the source (ac6c736c7771), read on 2026-10-08. The repository is watched and re-audited when it changes.