Oya BrowserBLOCK
The browser control plane for AI agents. One API over Oya Cloud, Browserbase, Steel, Anchor, Browser Use and your own Chrome, with persistent personas, CAPTCHA and MFA handling, and live human takeover.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Everyone else drives Chrome from the outside. We built the browser.
The automation lives inside it, not attached over the debugging protocol, so your agents stop looking like a harness. Sign in once and every browser you start is already signed in. Do the task once and Oya replays it forever, with no model in the loop.
bf3c3cb35362OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ui --env ANCHOR_API_KEY=${ANCHOR_API_KEY} --env API_KEYS=${API_KEYS} --env AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} --env AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY} -- npx -y [email protected]{
"mcpServers": {
"ui": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANCHOR_API_KEY": "${ANCHOR_API_KEY}",
"API_KEYS": "${API_KEYS}",
"AWS_ACCESS_KEY_ID": "${AWS_ACCESS_KEY_ID}",
"AWS_SECRET_ACCESS_KEY": "${AWS_SECRET_ACCESS_KEY}"
}
}
}
}Exposed tools (33)
25 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
click | read | Click an interactive element by its ID number (from analyze_page results). |
click_coordinates | read | Click at specific x,y pixel coordinates on the page. |
close_tab | read | Close a tab. Closes active tab if no tab_id specified. |
double_click | read | Double-click an element by ID or at x,y coordinates. |
drag | destructive | Drag from one point to another. For sliders, drag-and-drop, or text selection. |
handle_dialog | read | Answer a native browser dialog (confirm or prompt) that is blocking the page. Alerts are answered for you. Accept only what the task actually asks for, a confirm may be guarding something destructive. |
internal-pdf-viewer | read | Portable Document Format |
keyboard_type | read | Type text into whatever is currently focused, without targeting a specific element. |
list_tabs | read | List all open tabs (ID, title, URL, which is active). |
mouse_move | write | Move mouse to x,y coordinates without clicking. Triggers hover states and tooltips. |
navigate | read | Navigate the browser to a URL. |
one | read | |
open_tab | read | Open a new browser tab, optionally navigating to a URL. |
pool_status | read | Show pool size and connected browsers. |
press_key | read | Press a safe navigation key. Allowed: Enter, Escape, Tab, ArrowDown, ArrowUp, ArrowLeft, ArrowRight, Backspace, Delete, Space, Home, End, PageUp, PageDown. Do NOT press F-keys, Meta, Control, Alt, or Shift. |
read_console | read | Read what the page logged: its own errors and warnings. Use this when a step failed, a page stalled, or the portal showed an error you cannot read on screen, it says what the page itself complained about. |
read_elements | read | List interactive elements on the page, with the same ids analyze_page gives. Lighter than analyze_page: no page text. |
remember | write | Keep a short note about how the site you are on works, for the next run that comes here: where a report lives, which menu hides a setting, a login or form quirk that cost you steps. Never task values, personal data or anything secret. Notes come back when a run reaches this site. |
request_human | read | Ask a person for help when you are stuck: a question only the user can answer, a login you cannot pass, or something the tools cannot do. Waits for their reply. |
restart_recording | write | Call this right before you start the whole task again from the beginning, after an attempt went wrong. The playbook then keeps only the attempt that worked, so its replay does the task once. Do not call it to fix one field or step; fix that in place. |
screenshot | read | See the visible browser tab as an image. Use it when layout, images, icons or a canvas matter, or when analyze_page does not explain what is on screen. Element ids still come from analyze_page. |
scroll | read | Scroll the page up or down. |
select_option | read | Choose an option in a native dropdown (a select element from analyze_page) by the option text you see. Accepts {{placeholders}} and filters. |
start_browser | write | |
stop_browser | write | |
switch_tab | read | Switch to a different tab by ID (from list_tabs). |
t | read | d |
type | read | Type text into an input element by its ID (from analyze_page). Clears existing content first. |
update_plan | write | Write or update your plan: the steps this task needs, each marked done or not. Call it first for any task of more than a few steps, and again as you finish each one. It does not touch the page. |
upload_file | write | Attach one of the task |
wait | read | Wait for an element matching a CSS selector to appear. |
wait_for | read | Wait until the page is ready: some text shows, the url contains something, and/or the network has gone quiet. With no text or url it waits for the network to settle. Use it after an action that loads results in the background, rather than analyzing again and again. |
x | read | y |
Trust audit
BLOCKgrade F · trust 37/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
webhook-payload.tsx
- 169.254.169.254/32 # cloud metadata
icon.icns
.claude/skills/browser-agent
.claude/skills/frontend-design
console.log(`\n ${style.bold('API key')} ${style.green(apiKey)}\n`);console.log(` oya login --url ${publicUrl} --key ${apiKey}`);console.log(`OYA_API_KEY=${apiKey}`);const res = await fetch(`http://127.0.0.1:${port}/json/version`);const res = await fetch(`http://127.0.0.1:${port}/json/version`);const endpoint = `http://127.0.0.1:${(this.server!.address() as AddressInfo).port}`;auth: { type: 'iam', accessKeyId: 'AKIAABCDEFGHIJKLMNOP', secretAccessKey: 'tenant-secret' },accessKeyId: 'AKIAABCDEFGHIJKLMNOP',
auth: { type: 'iam', accessKeyId: 'AKIAABCDEFGHIJKLMNOP', secretAccessKey: 'shh' },assert.deepEqual(view.auth, { type: 'iam', accessKeyId: 'AKIAABCDEFGHIJKLMNOP', secretAccessKey: '••3' });AWS_ACCESS_KEY_ID: 'AKIAABCDEFGHIJKLMNOP',
--database-url 'postgres://oya:[email protected]:5432/oya?sslmode=require' \
const env = { DATABASE_URL: 'postgres://u:p@db/x', BROWSERBASE_API_KEY: 'bb', OPENAI_API_KEY: 'sk' };DATABASE_URL: 'postgres://u:p@db/x',
const local = 'postgresql://postgres:[email protected]:54322/postgres';
verifyFull('postgres://u:p@h:5432/db?sslmode=require&uselibpqcompat=true&application_name=oya', ''),await mfa.set(persona, { type: 'totp', secret: 'GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ' });const SECRET = 'GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ';
const SECRET = 'GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ';
if (path === '/auth/projects/prj-two/access') body = { token: 'oya_research-credential' };Gates applied: no_behavioural_pass.
bf3c3cb35362full audit observations/trust-audit/mcp-server/oyadotai__oya-browser.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | bf3c3cb35362 | BLOCK | F | 37 | first audit |
Questions
What is the @oya-ai/browser MCP server?
The browser control plane for AI agents. One API over Oya Cloud, Browserbase, Steel, Anchor, Browser Use and your own Chrome, with persistent personas, CAPTCHA and MFA handling, and live human takeover.
What tools does @oya-ai/browser expose?
33 in total: 25 read-only, 7 that write, and 1 that can delete or overwrite (drag). Every one is listed on this page with its risk.
Is @oya-ai/browser safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (37/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does @oya-ai/browser need?
It reads ANCHOR_API_KEY, API_KEYS, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SSO_ACCESS_TOKEN, BROWSERBASE_API_KEY, BROWSERUSE_API_KEY, DAYTONA_API_KEY, FAKE_SECRET_FAILS, FLEET_TOKEN, GEMINI_API_KEY and LOGIN_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does @oya-ai/browser run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as ui at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (bf3c3cb35362), read on 2026-10-07. The repository is watched and re-audited when it changes.