NotteBLOCK
Cloud browser infrastructure and web automation platform for your AI and coding agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The web agent framework built for speed, cost-efficiency, scale, and reliability → Read more at: open-operator-evals • X • LinkedIn • Landing • Console
[](https://github.com/nottelabs/notte/stargazers) [](https://spdx.org/licenses/SSPL-1.0.html) [](https://www.python.org/downloads/) [](https://pypi.org/project/notte/) [](https://pepy.tech/projects/notte)
What is Notte?
Notte provides all the essential tools for building and deploying AI agents that interact seamlessly with the web. Our full-stack framework combines AI agents with traditional scripting for maximum efficiency - letting you script deterministic parts and use AI only when needed, cutting costs by 50%+ while improving reliability. We allow you to develop, deploy, and scale your own agents and web automations, all with a single API. Read more in our documentation here 🔥
Opensource Core:
8d1d53d4d1bfOBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add notte-sdk --env ANCHOR_API_KEY=${ANCHOR_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_KEY=${API_KEY} --env AUTO_ISSUES_GITHUB_MFA_SECRET=${AUTO_ISSUES_GITHUB_MFA_SECRET} -- npx -y [email protected]{
"mcpServers": {
"notte-sdk": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANCHOR_API_KEY": "${ANCHOR_API_KEY}",
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"API_KEY": "${API_KEY}",
"AUTO_ISSUES_GITHUB_MFA_SECRET": "${AUTO_ISSUES_GITHUB_MFA_SECRET}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Echo | read | Echoes its input |
Example | read | Test |
Trust audit
BLOCKgrade F · trust 33/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(parsed_info.code, execution_globals, result)
exec(parsed_info.code, execution_globals)
<!DOCTYPE html><html lang="en-US" dir="ltr"><head>
<!DOCTYPE html><html lang="en-US" dir="ltr" style="background-color: rgb(250, 250, 250);"><head>
<!DOCTYPE html><html lang="en" class="TridactylThemeDefault wf-interstate-n4-active wf-interstate-i4-active wf-interstate-i5-active wf-interstate-n5-active wf-adobehandwritingernie-n4-active wf-active
<!DOCTYPE html><html lang="en-US" dir="ltr" style="background-color: rgb(255, 255, 255);"><head>
<!DOCTYPE html><html lang="en"><head class="js-pwa-async-styles-container">
OpenSansEmoji.otf
return __import__(name, *args, **kwargs)
return __import__(name, *args, **kwargs)
_ = importlib.import_module(module)
emojis.append("👁️🗨️")token="xoxb-your-token-here",
token="your-discord-bot-token-here",
secret = "delivery-boundary-secret" # noqa: S105 # pragma: allowlist secret
token="xoxb-your-token-here",
.coderabbit.yaml
.gitmodules
.pre-commit-config.yaml
.mintignore
new Function('require', 'exports', js)(() => ({ sessionExample: async options => {cd ../../
const require = createRequire(new URL('../../../node-sdk/package.json', import.meta.url));return { url: new URL('../../../node-sdk/dist/index.mjs', import.meta.url).href, shortCircuit: true };parentURL: new URL('../../../node-sdk/package.json', import.meta.url).href,Gates applied: no_behavioural_pass.
8d1d53d4d1bffull audit observations/trust-audit/mcp-server/nottelabs__notte.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 8d1d53d4d1bf | BLOCK | F | 33 | source changed, verdict held |
| 2026-09-19 | 989164f6a0c8 | BLOCK | F | 33 | first audit |
Questions
What is the Notte MCP server?
Cloud browser infrastructure and web automation platform for your AI and coding agents
What tools does Notte expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Notte safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (33/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Notte need?
It reads ANCHOR_API_KEY, ANTHROPIC_API_KEY, API_KEY, AUTO_ISSUES_GITHUB_MFA_SECRET, AUTO_ISSUES_GITHUB_PASSWORD, BROWSERBASE_API_KEY, EMAIL_PASSWORD, GITHUB_COM_PASSWORD, GOOGLE_APPLICATION_CREDENTIALS, HYPERBROWSER_API_KEY, MASSIVE_PASSWORD and MY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Notte run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as notte-sdk at 0.0.0-dev.
How current is this page?
The grade is for one exact copy of the source (8d1d53d4d1bf), read on 2026-09-23. The repository is watched and re-audited when it changes.