CamoFoxSAFE
Anti-detection browser MCP server for AI agents — navigate, interact, and automate the web without getting blocked
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
AI-powered anti-detection browser automation for MCP-compatible AI agents.
CamoFox MCP connects MCP clients such as Claude Desktop, VS Code, Cursor, and OpenClaw to the CamoFox browser server. It gives agents a practical browser toolset for navigation, interaction, search, extraction, downloads, and session reuse while relying on Camoufox-based anti-detection behavior underneath.
Key Features
- 47 browser automation tools across navigation, interaction, observation, search, downloads, sessions, and batch workflows.
- Anti-detection browser automation built on top of the CamoFox browser server and Camoufox.
- Multi-tab workflows with tracked state, history, and cleanup.
- Session persistence with cookie import, saved profiles, and optional auto-save.
- Token-efficient accessibility snapshots with CSS-selector fallbacks for difficult SPA flows.
- OpenClaw-compatible HTTP transport, plus standard stdio support for desktop MCP clients.
Quick Install
You need both components running:
camofox-browserhandles the anti-detection browser.camofox-mcpexposes that browser to your MCP client.
Option A: npx + stdio
Start the browser server:
npx camofox-browser@latest
Add CamoFox MCP to your MCP client:
{
"servers": {
"camofox": {
"type": "stdio",
"command": "npx",
"args": ["-y", "camofox-mcp@latest"],
"env": {
"CAMOFOX_URL": "http://localhost:9377"
}
}
}
}Option B: Docker
Start the browser server:
docker run -d -p 9377:9377 --name camofox-browser ghcr.io/redf0x1/camofox-browser:latest
Run CamoFox MCP in HTTP mode for remote MCP clients such as OpenClaw:
docker run -p 3000:8080 --rm \ -e CAMOFOX_TRANSPORT=http \ -e CAMOFOX_HTTP_HOST=0.0.0.0 \ -e CAMOFOX_HTTP_API_KEY=replace-with-32-plus-random-chars \ -e CAMOFOX_URL=http://host.docker.internal:9377 \ ghcr.io/redf0x1/camofox-mcp:latest node dist/http.js
Configure yo
54441b502ba6OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add camofox-mcp -- npx -y [email protected]
{
"mcpServers": {
"camofox-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (47)
38 read · 7 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
batch_click | read | Click multiple elements sequentially. Continues on error (clicks are independent). Returns per-click results. |
batch_download | read | Extract resources from a DOM container and download them all. Combines extract_resources + download in one call. Useful for downloading all images from a chat, all PDFs from a table, etc. |
camofox_close_session | read | Close all browser tabs for a user session. Use for complete cleanup when done with a browsing session. |
camofox_evaluate_js | read | |
camofox_get_page_html | read | Get rendered HTML from the live DOM. Use when snapshot refs are incomplete on SPA/custom-component sites or when you need the final DOM state rather than the accessibility tree. Optionally pass a CSS selector to return only that element |
camofox_hover | write | Hover over an element to trigger tooltips, dropdown menus, or hover states. Use ref from snapshot or CSS selector. |
camofox_press_key | write | Press a keyboard key. Use after type_text to submit forms (Enter), navigate between elements (Tab), move through suggestions (ArrowDown/ArrowUp), or dismiss dialogs (Escape). Common keys: Enter, Tab, Escape, ArrowDown, ArrowUp, Backspace, Space. |
camofox_query_selector | read | Query a CSS selector in the live DOM and return its element details or a specific attribute. Use this for targeted inspection without writing raw evaluate_js. Requires CAMOFOX_API_KEY only when browser-server authentication is enabled. |
camofox_scroll_element | read | Scroll a specific container element (modal dialog, scrollable div, sidebar). Use when page-level scroll doesn |
camofox_scroll_element_and_snapshot | read | Scroll a container element AND take a snapshot. Combines scroll_element + snapshot in one call. Perfect for incrementally loading lazy content in modals (e.g. Facebook group post comments). Returns both scroll position and page snapshot. |
camofox_wait_for | read | Wait for page to be fully ready (DOM loaded, network idle, framework hydration complete). Use after navigation or actions that trigger page changes. |
camofox_wait_for_selector | read | Wait for a CSS selector to appear in the live DOM. Use for SPA hydration and async content when snapshot refs are incomplete or stale. Once found, prefer snapshot refs for interaction when available. Requires CAMOFOX_API_KEY only when browser-server authentication is enabled. |
camofox_wait_for_text | read | Wait for specific text to appear on the page. Useful for waiting for search results, form submissions, or dynamic content loading. |
click | read | Click an element. Provide either ref (from snapshot) or CSS selector. Use snapshot first to discover element refs. |
close_tab | read | Close a browser tab and release resources. Always close tabs when done to free memory. |
create_tab | write | Create a new browser tab with anti-detection fingerprinting. Each tab gets a unique fingerprint. Optionally provide a URL, userId, sessionKey, and viewport. To share the camofox CLI default browser profile/context, pass userId \ |
delete_download | destructive | Delete a downloaded file from disk and registry |
delete_profile | destructive | Delete a saved browser profile from disk. Removes the profile |
extract_resources | read | Extract resources (images, links, media, documents) from a specific DOM container. Use a CSS selector or element ref from snapshot to scope extraction to a particular section of the page. This is useful for extracting all images from a specific post, all links from a table, etc. |
extract_structured | read | Extract deterministic structured JSON from a page using the camofox-browser structured extraction schema. |
fill_form | read | Fill multiple form fields in one call. Provide an array of field entries, each with a ref or CSS selector and the text to type. Optionally specify a submit button to click after filling. |
get_download | read | Get a downloaded file. Images are always returned as viewable images. Recommended for AI agents: set includeContent=true to get non-image file content as base64 inline (max 256KB). Otherwise returns metadata only (including contentUrl). |
get_links | read | Get all hyperlinks on page with URLs and text. Useful for navigation discovery and site mapping. |
get_stats | read | Get session statistics: request counts, active tabs, uptime, performance metrics. |
go_back | read | Navigate backward in browser history (Back button). Returns new page URL. |
go_forward | read | Navigate forward in browser history (Forward button). Returns new page URL. |
import_cookies | write | Import cookies for authenticated sessions. Provide cookies in a JSON string array. Restores login sessions without re-auth. Requires userId. |
list_downloads | read | List downloaded files with optional filtering by tab, status, extension, MIME type, and size range. Each download includes contentUrl for direct file retrieval. |
list_presets | read | List all available geo presets supported by the CamoFox server. Presets include locale, timezone, and optional geolocation. |
list_profiles | read | List all saved browser profiles with metadata. Shows profile names, cookie counts, save dates, and descriptions. |
list_tabs | read | List all open browser tabs with URLs and titles. Use to discover available tabs or verify tab state. |
load_profile | read | Load a saved profile |
navigate | read | Navigate a tab to a URL. Waits for page load. Use create_tab first, then navigate. Returns final URL (may differ due to redirects). |
navigate_and_snapshot | read | Navigate to a URL and return the page snapshot. Combines navigate + wait + snapshot into one call. |
refresh | read | Reload the current page. Useful when page state is stale or after changes. |
resolve_blobs | read | Resolve blob: URLs to downloadable base64 data. Blob URLs are temporary browser objects (common in Telegram, WhatsApp, Discord) that cannot be downloaded directly. This tool converts them to base64 data URIs. |
save_profile | write | Save browser cookies from an active tab to a named profile on disk. Enables session persistence across restarts. Use after login to save authenticated state. |
screenshot | write | Take a viewport or full-page visual screenshot in base64 PNG. Set fullPage to capture the entire scrollable page. Use ONLY for visual verification (CSS, layout, proof). Prefer snapshot for most tasks — much more token-efficient. |
scroll | read | Scroll page up or down by pixel amount. Use to reveal content below the fold or navigate long pages. |
scroll_and_snapshot | read | Scroll the page and take a snapshot. Useful for revealing content below the fold. |
server_status | read | Check CamoFox server health and browser connection. Call first to verify server is running. Returns version, browser status, and active tab count. |
snapshot | read | |
toggle_display | read | |
type_and_submit | write | Type text into a field and press a key (default: Enter). Useful for search boxes and single-field forms. |
type_text | read | Type text into an input field. Provide either a ref (from snapshot) or a CSS selector. Use ref when available; otherwise use selector when snapshot doesn |
web_search | read | Search via the 14 macros supported by camofox-browser 2.4.7: google, youtube, amazon, reddit, reddit_subreddit, wikipedia, twitter, yelp, spotify, netflix, linkedin, instagram, tiktok, twitch. Call snapshot after to read results. |
youtube_transcript | read | Extract transcript from a YouTube video. Returns timestamped text. No tab required. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
delete_download, delete_profile
return `http://127.0.0.1:${address.port}`;return `http://127.0.0.1:${address.port}`;vncUrl: "http://127.0.0.1:59077"
@modelcontextprotocol/sdk, express-rate-limit, @types/express, @types/node, tsx, typescript, vitest
For trusted private agent networks where clients cannot send browser bearer tokens, run the browser server with `CAMOFOX_AUTH_MODE=disabled` and leave `CAMOFOX_API_KEY` unset in CamoFox MCP. CamoFox M
A cold server can report no active browser session before the first tab is created.
Do not open a public issue with exploit details, credentials, tokens, private data, or weaponized proof-of-concept code.
Gates applied: no_behavioural_pass.
54441b502ba6full audit observations/trust-audit/mcp-server/redf0x1__camofox.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 54441b502ba6 | SAFE | B | 89 | first audit |
Questions
What is the CamoFox MCP server?
Anti-detection browser MCP server for AI agents — navigate, interact, and automate the web without getting blocked
What tools does CamoFox expose?
47 in total: 38 read-only, 7 that write, and 2 that can delete or overwrite (delete_download, delete_profile). Every one is listed on this page with its risk.
Is CamoFox safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does CamoFox need?
No credential environment variables were found in its source, so it appears to need none.
How does CamoFox run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as camofox-mcp at 1.15.0.
How current is this page?
The grade is for one exact copy of the source (54441b502ba6), read on 2026-10-07. The repository is watched and re-audited when it changes.