Atlas / MCP servers / ofershap / Real Browser

Real BrowserSAFE

mcp/ofershap/real-browser

MCP server + Chrome extension that gives AI agents control of your real browser with existing sessions and logins

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
22 17r · 5w · 0d
Transport
stdio
License
MIT
Stars
54
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

real-browser-mcp

Agentic browsers give agents a new browser. Coding agents need yours.

MCP + Chrome extension for the Chrome you already have open: cookies, SSO, staging sessions, the bug you already reproduced.

Read from source at commit 0aa29fcfb6d0OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add real-browser-mcp -- npx -y [email protected]
03

Exposed tools (22)

17 read · 5 write · 0 destructive.

ToolRiskDescription
browser_clickreadClick an element on the page using a ref from snapshot or a CSS selector
browser_click_textreadClick an element by its visible text content. Works on React dropdowns, portals, and overlays that may not appear in snapshots. CSP-safe (no eval). Prefers deepest matching element.
browser_consolereadRead console messages (log, warn, error) from the browser
browser_dragreadDrag from one element or position to another. Uses CDP mouse events for reliable drag-and-drop. Provide either refs/selectors or explicit x,y coordinates.
browser_evaluatewriteExecute JavaScript in the page and return the result. Use for DOM queries, reading page state, or any operation not covered by other tools.
browser_fill_formreadFill multiple form fields in a single call. Supports text inputs, selects, checkboxes, and contentEditable elements. Reduces round-trips compared to calling browser_type for each field individually. Optionally submit the form after filling.
browser_findreadFind elements on the page using natural language (e.g.
browser_handle_dialogreadHandle JavaScript dialogs (alert, confirm, prompt). Dialogs block page interaction until handled.
browser_hoverwriteHover over an element to trigger tooltips, dropdown menus, or hover states
browser_navigatereadNavigate to a URL in the active browser tab
browser_networkreadRead network requests made by the page. Filter by URL pattern.
browser_press_keyreadPress a keyboard key or combination (Enter, Escape, Tab, ArrowDown, etc). Supports modifiers like Ctrl+A, Cmd+C.
browser_run_actionwriteRun a self-contained JavaScript action object in the page context via CDP. The code must be an expression that evaluates to an object with an execute(params) method. Returns the action result directly. Bypasses CSP restrictions.
browser_screenshotreadCapture a screenshot of the visible page area
browser_scrollreadScroll the page or an element. Supports pixel offsets, scrolling to elements, and named positions (top/bottom). Works with virtual scroll containers used by social media sites.
browser_selectreadSelect an option from a dropdown/select element
browser_snapshotreadGet an accessibility tree snapshot of the page. Returns element refs you can use with click, type, and other tools. Use compact mode (default) for smaller output - only interactive elements.
browser_tabswriteManage browser tabs: list, create, close, or focus
browser_textreadExtract raw text content from the page or a specific element
browser_typereadType text into an input element
browser_upload_filewriteUpload a file through a file input element. Uses CDP DOM.setFileInputFiles — works even on strict-CSP pages. Provide the local file path and either a ref from snapshot, a CSS selector targeting the file input, or omit both to auto-find the first input[type=
browser_waitreadWait for a condition: element to appear, element to disappear, or a fixed delay. Useful for SPAs and dynamic content.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/registry.test.ts:2
import { allTools, toolMap } from '../../mcp-server/src/tools/index.js';
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:21
<a href="cursor://anysphere.cursor-deeplink/mcp/install?name=real-browser&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsInJlYWwtYnJvd3Nlci1tY3AiXX0="><img src="https://img.shields.io/badge/Add_to_Cur
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, ws, zod, @types/node, @types/ws, ai-context-kit, typescript, vitest
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0aa29fcfb6d0full audit observations/trust-audit/mcp-server/ofershap__real-browser.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-080aa29fcfb6d0SAFEB89first audit
06

Questions

What is the Real Browser MCP server?

MCP server + Chrome extension that gives AI agents control of your real browser with existing sessions and logins

What tools does Real Browser expose?

22 in total: 17 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Real Browser safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Real Browser need?

No credential environment variables were found in its source, so it appears to need none.

How does Real Browser run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as real-browser-mcp at 1.3.0.

How current is this page?

The grade is for one exact copy of the source (0aa29fcfb6d0), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement