Atlas / MCP servers / onkernel / Kernel

KernelCAUTION

mcp/onkernel/kernel-1

Open-source MCP server for secure, low-latency cloud-browser automation on Kernel.

Verdict
CAUTION
Grade
C
Trust score
77 /100
Exposed tools
45 42r · 3w · 0d
Transport
streamable-http
License
MIT
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/MIT) [](https://nodejs.org/) [](https://nextjs.org/) [](https://smithery.ai/server/kernel)

A Model Context Protocol (MCP) server that provides AI assistants with secure access to Kernel platform tools and browser automation capabilities.

🌐 Use instantly at https://mcp.onkernel.com/mcp — no installation required!

What is this?

The Kernel MCP Server bridges AI assistants (like Claude, Cursor, fx, or other MCP-compatible tools) with the Kernel platform, enabling them to:

  • 🚀 Deploy and manage Kernel apps in the cloud
  • 🌐 Launch and control headless Chromium sessions for web automation
  • 📊 Monitor deployments and track invocations
  • 🔍 Search Kernel documentation and inject context
  • 💻 Execute arbitrary Playwright code against live browsers
  • 🧠 Run persistent JavaScript Browser REPL cells with native helpers, Patchright, Playwright, and raw CDP
  • 🎥 Record MP4 video replays of browser automation

Open-source & fully-managed — the complete codebase is available here, and we run the production instance so you don't need to deploy anything.

The server uses OAuth 2.0 authentication via Clerk to ensure secure access to your Kernel resources. During authorization, users can grant organization-wide access or restrict the resulting access and refresh tokens to one Kernel project. Project-scoped tokens cannot switch projects; organization-wide authorization remains available for existing workflows.

For a deeper dive into why and how we built this server, see our blog post: [Introducing Kernel MCP Server](https://blog.onkernel.

Read from source at commit 5447a4a5e217OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add kernel-mcp-server --env BRAINTRUST_API_KEY=${BRAINTRUST_API_KEY} --env CLERK_SECRET_KEY=${CLERK_SECRET_KEY} --env MANAGED_AUTH_APP_ORIGIN=${MANAGED_AUTH_APP_ORIGIN} --env MINTLIFY_ASSISTANT_API_TOKEN=${MINTLIFY_ASSISTANT_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "kernel-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "BRAINTRUST_API_KEY": "${BRAINTRUST_API_KEY}",
        "CLERK_SECRET_KEY": "${CLERK_SECRET_KEY}",
        "MANAGED_AUTH_APP_ORIGIN": "${MANAGED_AUTH_APP_ORIGIN}",
        "MINTLIFY_ASSISTANT_API_TOKEN": "${MINTLIFY_ASSISTANT_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (45)

42 read · 3 write · 0 destructive.

ToolRiskDescription
api_failureread
authorization_code_org_scoped_pkcereadPKCE authorization for an organization-wide scope: authorize stores the oauth-request context, the code exchange consumes it and persists jwt/refresh mappings.
authorization_code_project_scoped_pkcereadSame as above but the selected scope is a single project, so the persisted context carries project_id.
begin_auth_loginread
browser_curlread
browser_replread
coded_api_failureread
computer_actionread
custom_searchreadSearch via CDP
exec_commandwrite
execute_playwright_codewrite
get_connection_contextread
input_guardread
legacy_non_pkce_clientreadAn allowlisted legacy client without PKCE: authorize stores the context under the literal client:<client_id> key, which its exchanges read.
manage_api_keysread
manage_appsread
manage_auth_connectionsread
manage_browser_filesread
manage_browser_poolsread
manage_browsersread
manage_config_registryread
manage_credential_providersread
manage_credentialsread
manage_extensionsread
manage_playwright_executorsread
manage_profilesread
manage_projectsread
manage_proxiesread
manage_replaysread
manage_vault_cardsread
manage_vault_credentialsread
manage_vault_itemsread
manage_vault_provider_configsread
manage_vault_walletsread
manage_vaultsread
open_auth_loginread
pingread
refresh_backfills_clerk_user_id_from_id_tokenreadA pre-existing context without clerk_user_id (stored by older versions) is refreshed: the id_token subject is backfilled into the newly written contexts.
refresh_token_rotation_sliding_ttlreadAn initial org-scoped grant is followed by a refresh_token grant: the old refresh mapping is deleted, the rotated one is written with a fresh sliding TTL.
searchreadSearch
search_docsread
submitwriteSubmit
titlereadRead title
web_searchread
webmcpread
04

Trust audit

CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (21)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/lib/mcp/tools/vault-credential-flow.test.ts:485
const secret = "private-password-value";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/lib/mcp/tools/vault-credential-flow.test.ts:520
const secret = "private-duplicate-value";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/lib/mcp/tools/vault-provider-configs.test.ts:10
const secret = "secret-sentinel+/configuration";
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
.github/workflows/publish-mcp.yml:46
printf '%s\n' '-----BEGIN PRIVATE KEY-----'
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.semgrepignore
.semgrepignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
benchmarks/harbor/publish-braintrust.ts:109
const digest = createHash("sha1")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmarks/harbor/clawbench/run.sh:18
harness_root=$(cd "$(dirname "${BASH_SOURCE[0]}")/../../.." && pwd)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/app/[transport]/dual-era.test.ts:17
new URL("../../../fixtures/mcp-http-server.ts", import.meta.url).pathname,
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/app/[transport]/route.ts:33
import { name, version } from "../../../server.json";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/harbor/bin/kernel-mcp-local:17
http://127.0.0.1:3002/mcp \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/harbor/bin/start-kernel-mcp-server:31
if curl -fsS -X POST http://127.0.0.1:3002/mcp \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/app/register/route.test.ts:45
"http://127.0.0.1:58432/callback",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/lib/mcp/vault-schemas.test.ts:30
"http://127.0.0.1:3000",
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/app/managed-auth-proxy/auth/connections/[...path]/route.ts:56
return JSON.parse(atob(normalized + padding)) as Record<string, unknown>;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/app/token/route.ts:56
const decoded = atob(authHeader.slice(6));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@clerk/nextjs, @clerk/themes, @types/jsonwebtoken, @types/redis, builtin-modules, install, jose, jsonwebtoken
Why it matters. 28 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:348
- `manage_vault_items` - List, get, invoke advertised operations (including fill and `webmcp_invoke` with value-free bindings), observe events, and delete vault items. Read credential definitions, pre
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/vault-payments.md:34
`manage_vault_items` can read existing credential items and invoke advertised `collect`.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/vault-payments.md:209
the agent-controlled browser; they open it on a device with the 1Password app and
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/vault-payments.md:237
`1pw_update_access_token`, and never returns them. It can read such credentials,
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 5447a4a5e217full audit observations/trust-audit/mcp-server/onkernel__kernel-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-095447a4a5e217CAUTIONC77first audit
06

Questions

What is the Kernel MCP server?

Open-source MCP server for secure, low-latency cloud-browser automation on Kernel.

What tools does Kernel expose?

45 in total: 42 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kernel safe to connect to an agent?

With care. The audit graded it C (77/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Kernel need?

It reads BRAINTRUST_API_KEY, CLERK_SECRET_KEY, MANAGED_AUTH_APP_ORIGIN, MINTLIFY_ASSISTANT_API_TOKEN, NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY, OAUTH_LEGACY_NON_PKCE_CLIENT_IDS, OAUTH_RECORDING_ALLOW_REMOTE_REDIS, OAUTH_RECORDING_REDIS_URL, POSTHOG_PROJECT_TOKEN, TEST_API_KEY and TEST_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kernel run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as kernel-mcp-server at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (5447a4a5e217), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement