Real BrowserSAFE
MCP server + Chrome extension that gives AI agents control of your real browser with existing sessions and logins
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
real-browser-mcp
Agentic browsers give agents a new browser. Coding agents need yours.
MCP + Chrome extension for the Chrome you already have open: cookies, SSO, staging sessions, the bug you already reproduced.
0aa29fcfb6d0OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add real-browser-mcp -- npx -y [email protected]
Exposed tools (22)
17 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
browser_click | read | Click an element on the page using a ref from snapshot or a CSS selector |
browser_click_text | read | Click an element by its visible text content. Works on React dropdowns, portals, and overlays that may not appear in snapshots. CSP-safe (no eval). Prefers deepest matching element. |
browser_console | read | Read console messages (log, warn, error) from the browser |
browser_drag | read | Drag from one element or position to another. Uses CDP mouse events for reliable drag-and-drop. Provide either refs/selectors or explicit x,y coordinates. |
browser_evaluate | write | Execute JavaScript in the page and return the result. Use for DOM queries, reading page state, or any operation not covered by other tools. |
browser_fill_form | read | Fill multiple form fields in a single call. Supports text inputs, selects, checkboxes, and contentEditable elements. Reduces round-trips compared to calling browser_type for each field individually. Optionally submit the form after filling. |
browser_find | read | Find elements on the page using natural language (e.g. |
browser_handle_dialog | read | Handle JavaScript dialogs (alert, confirm, prompt). Dialogs block page interaction until handled. |
browser_hover | write | Hover over an element to trigger tooltips, dropdown menus, or hover states |
browser_navigate | read | Navigate to a URL in the active browser tab |
browser_network | read | Read network requests made by the page. Filter by URL pattern. |
browser_press_key | read | Press a keyboard key or combination (Enter, Escape, Tab, ArrowDown, etc). Supports modifiers like Ctrl+A, Cmd+C. |
browser_run_action | write | Run a self-contained JavaScript action object in the page context via CDP. The code must be an expression that evaluates to an object with an execute(params) method. Returns the action result directly. Bypasses CSP restrictions. |
browser_screenshot | read | Capture a screenshot of the visible page area |
browser_scroll | read | Scroll the page or an element. Supports pixel offsets, scrolling to elements, and named positions (top/bottom). Works with virtual scroll containers used by social media sites. |
browser_select | read | Select an option from a dropdown/select element |
browser_snapshot | read | Get an accessibility tree snapshot of the page. Returns element refs you can use with click, type, and other tools. Use compact mode (default) for smaller output - only interactive elements. |
browser_tabs | write | Manage browser tabs: list, create, close, or focus |
browser_text | read | Extract raw text content from the page or a specific element |
browser_type | read | Type text into an input element |
browser_upload_file | write | Upload a file through a file input element. Uses CDP DOM.setFileInputFiles — works even on strict-CSP pages. Provide the local file path and either a ref from snapshot, a CSS selector targeting the file input, or omit both to auto-find the first input[type= |
browser_wait | read | Wait for a condition: element to appear, element to disappear, or a fixed delay. Useful for SPAs and dynamic content. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
import { allTools, toolMap } from '../../mcp-server/src/tools/index.js';<a href="cursor://anysphere.cursor-deeplink/mcp/install?name=real-browser&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsInJlYWwtYnJvd3Nlci1tY3AiXX0="><img src="https://img.shields.io/badge/Add_to_Cur
@modelcontextprotocol/sdk, ws, zod, @types/node, @types/ws, ai-context-kit, typescript, vitest
Gates applied: no_behavioural_pass.
0aa29fcfb6d0full audit observations/trust-audit/mcp-server/ofershap__real-browser.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0aa29fcfb6d0 | SAFE | B | 89 | first audit |
Questions
What is the Real Browser MCP server?
MCP server + Chrome extension that gives AI agents control of your real browser with existing sessions and logins
What tools does Real Browser expose?
22 in total: 17 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Real Browser safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Real Browser need?
No credential environment variables were found in its source, so it appears to need none.
How does Real Browser run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as real-browser-mcp at 1.3.0.
How current is this page?
The grade is for one exact copy of the source (0aa29fcfb6d0), read on 2026-10-08. The repository is watched and re-audited when it changes.