Atlas / MCP servers / redf0x1 / CamoFox

CamoFoxSAFE

mcp/redf0x1/camofox

Anti-detection browser MCP server for AI agents — navigate, interact, and automate the web without getting blocked

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
47 38r · 7w · 2d
Transport
stdio · streamable-http
License
MIT
Stars
117
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI-powered anti-detection browser automation for MCP-compatible AI agents.

CamoFox MCP connects MCP clients such as Claude Desktop, VS Code, Cursor, and OpenClaw to the CamoFox browser server. It gives agents a practical browser toolset for navigation, interaction, search, extraction, downloads, and session reuse while relying on Camoufox-based anti-detection behavior underneath.

Key Features

  • 47 browser automation tools across navigation, interaction, observation, search, downloads, sessions, and batch workflows.
  • Anti-detection browser automation built on top of the CamoFox browser server and Camoufox.
  • Multi-tab workflows with tracked state, history, and cleanup.
  • Session persistence with cookie import, saved profiles, and optional auto-save.
  • Token-efficient accessibility snapshots with CSS-selector fallbacks for difficult SPA flows.
  • OpenClaw-compatible HTTP transport, plus standard stdio support for desktop MCP clients.

Quick Install

You need both components running:

  1. camofox-browser handles the anti-detection browser.
  2. camofox-mcp exposes that browser to your MCP client.

Option A: npx + stdio

Start the browser server:

npx camofox-browser@latest

Add CamoFox MCP to your MCP client:

{
"servers": {
"camofox": {
"type": "stdio",
"command": "npx",
"args": ["-y", "camofox-mcp@latest"],
"env": {
"CAMOFOX_URL": "http://localhost:9377"
}
}
}
}

Option B: Docker

Start the browser server:

docker run -d -p 9377:9377 --name camofox-browser ghcr.io/redf0x1/camofox-browser:latest

Run CamoFox MCP in HTTP mode for remote MCP clients such as OpenClaw:

docker run -p 3000:8080 --rm \
-e CAMOFOX_TRANSPORT=http \
-e CAMOFOX_HTTP_HOST=0.0.0.0 \
-e CAMOFOX_HTTP_API_KEY=replace-with-32-plus-random-chars \
-e CAMOFOX_URL=http://host.docker.internal:9377 \
ghcr.io/redf0x1/camofox-mcp:latest node dist/http.js

Configure yo

Read from source at commit 54441b502ba6OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add camofox-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "camofox-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (47)

38 read · 7 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
batch_clickreadClick multiple elements sequentially. Continues on error (clicks are independent). Returns per-click results.
batch_downloadreadExtract resources from a DOM container and download them all. Combines extract_resources + download in one call. Useful for downloading all images from a chat, all PDFs from a table, etc.
camofox_close_sessionreadClose all browser tabs for a user session. Use for complete cleanup when done with a browsing session.
camofox_evaluate_jsread
camofox_get_page_htmlreadGet rendered HTML from the live DOM. Use when snapshot refs are incomplete on SPA/custom-component sites or when you need the final DOM state rather than the accessibility tree. Optionally pass a CSS selector to return only that element
camofox_hoverwriteHover over an element to trigger tooltips, dropdown menus, or hover states. Use ref from snapshot or CSS selector.
camofox_press_keywritePress a keyboard key. Use after type_text to submit forms (Enter), navigate between elements (Tab), move through suggestions (ArrowDown/ArrowUp), or dismiss dialogs (Escape). Common keys: Enter, Tab, Escape, ArrowDown, ArrowUp, Backspace, Space.
camofox_query_selectorreadQuery a CSS selector in the live DOM and return its element details or a specific attribute. Use this for targeted inspection without writing raw evaluate_js. Requires CAMOFOX_API_KEY only when browser-server authentication is enabled.
camofox_scroll_elementreadScroll a specific container element (modal dialog, scrollable div, sidebar). Use when page-level scroll doesn
camofox_scroll_element_and_snapshotreadScroll a container element AND take a snapshot. Combines scroll_element + snapshot in one call. Perfect for incrementally loading lazy content in modals (e.g. Facebook group post comments). Returns both scroll position and page snapshot.
camofox_wait_forreadWait for page to be fully ready (DOM loaded, network idle, framework hydration complete). Use after navigation or actions that trigger page changes.
camofox_wait_for_selectorreadWait for a CSS selector to appear in the live DOM. Use for SPA hydration and async content when snapshot refs are incomplete or stale. Once found, prefer snapshot refs for interaction when available. Requires CAMOFOX_API_KEY only when browser-server authentication is enabled.
camofox_wait_for_textreadWait for specific text to appear on the page. Useful for waiting for search results, form submissions, or dynamic content loading.
clickreadClick an element. Provide either ref (from snapshot) or CSS selector. Use snapshot first to discover element refs.
close_tabreadClose a browser tab and release resources. Always close tabs when done to free memory.
create_tabwriteCreate a new browser tab with anti-detection fingerprinting. Each tab gets a unique fingerprint. Optionally provide a URL, userId, sessionKey, and viewport. To share the camofox CLI default browser profile/context, pass userId \
delete_downloaddestructiveDelete a downloaded file from disk and registry
delete_profiledestructiveDelete a saved browser profile from disk. Removes the profile
extract_resourcesreadExtract resources (images, links, media, documents) from a specific DOM container. Use a CSS selector or element ref from snapshot to scope extraction to a particular section of the page. This is useful for extracting all images from a specific post, all links from a table, etc.
extract_structuredreadExtract deterministic structured JSON from a page using the camofox-browser structured extraction schema.
fill_formreadFill multiple form fields in one call. Provide an array of field entries, each with a ref or CSS selector and the text to type. Optionally specify a submit button to click after filling.
get_downloadreadGet a downloaded file. Images are always returned as viewable images. Recommended for AI agents: set includeContent=true to get non-image file content as base64 inline (max 256KB). Otherwise returns metadata only (including contentUrl).
get_linksreadGet all hyperlinks on page with URLs and text. Useful for navigation discovery and site mapping.
get_statsreadGet session statistics: request counts, active tabs, uptime, performance metrics.
go_backreadNavigate backward in browser history (Back button). Returns new page URL.
go_forwardreadNavigate forward in browser history (Forward button). Returns new page URL.
import_cookieswriteImport cookies for authenticated sessions. Provide cookies in a JSON string array. Restores login sessions without re-auth. Requires userId.
list_downloadsreadList downloaded files with optional filtering by tab, status, extension, MIME type, and size range. Each download includes contentUrl for direct file retrieval.
list_presetsreadList all available geo presets supported by the CamoFox server. Presets include locale, timezone, and optional geolocation.
list_profilesreadList all saved browser profiles with metadata. Shows profile names, cookie counts, save dates, and descriptions.
list_tabsreadList all open browser tabs with URLs and titles. Use to discover available tabs or verify tab state.
load_profilereadLoad a saved profile
navigatereadNavigate a tab to a URL. Waits for page load. Use create_tab first, then navigate. Returns final URL (may differ due to redirects).
navigate_and_snapshotreadNavigate to a URL and return the page snapshot. Combines navigate + wait + snapshot into one call.
refreshreadReload the current page. Useful when page state is stale or after changes.
resolve_blobsreadResolve blob: URLs to downloadable base64 data. Blob URLs are temporary browser objects (common in Telegram, WhatsApp, Discord) that cannot be downloaded directly. This tool converts them to base64 data URIs.
save_profilewriteSave browser cookies from an active tab to a named profile on disk. Enables session persistence across restarts. Use after login to save authenticated state.
screenshotwriteTake a viewport or full-page visual screenshot in base64 PNG. Set fullPage to capture the entire scrollable page. Use ONLY for visual verification (CSS, layout, proof). Prefer snapshot for most tasks — much more token-efficient.
scrollreadScroll page up or down by pixel amount. Use to reveal content below the fold or navigate long pages.
scroll_and_snapshotreadScroll the page and take a snapshot. Useful for revealing content below the fold.
server_statusreadCheck CamoFox server health and browser connection. Call first to verify server is running. Returns version, browser status, and active tab count.
snapshotread
toggle_displayread
type_and_submitwriteType text into a field and press a key (default: Enter). Useful for search boxes and single-field forms.
type_textreadType text into an input field. Provide either a ref (from snapshot) or a CSS selector. Use ref when available; otherwise use selector when snapshot doesn
web_searchreadSearch via the 14 macros supported by camofox-browser 2.4.7: google, youtube, amazon, reddit, reddit_subreddit, wikipedia, twitter, yelp, spotify, netflix, linkedin, instagram, tiktok, twitch. Call snapshot after to read results.
youtube_transcriptreadExtract transcript from a YouTube video. Returns timestamped text. No tab required.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_download, delete_profile
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/http-auth-boundary.test.ts:41
return `http://127.0.0.1:${address.port}`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/http.test.ts:34
return `http://127.0.0.1:${address.port}`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/session.test.ts:264
vncUrl: "http://127.0.0.1:59077"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, express-rate-limit, @types/express, @types/node, tsx, typescript, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/getting-started.md:169
For trusted private agent networks where clients cannot send browser bearer tokens, run the browser server with `CAMOFOX_AUTH_MODE=disabled` and leave `CAMOFOX_API_KEY` unset in CamoFox MCP. CamoFox M
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/getting-started.md:187
A cold server can report no active browser session before the first tab is created.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SECURITY.md:5
Do not open a public issue with exploit details, credentials, tokens, private data, or weaponized proof-of-concept code.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 54441b502ba6full audit observations/trust-audit/mcp-server/redf0x1__camofox.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0754441b502ba6SAFEB89first audit
06

Questions

What is the CamoFox MCP server?

Anti-detection browser MCP server for AI agents — navigate, interact, and automate the web without getting blocked

What tools does CamoFox expose?

47 in total: 38 read-only, 7 that write, and 2 that can delete or overwrite (delete_download, delete_profile). Every one is listed on this page with its risk.

Is CamoFox safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does CamoFox need?

No credential environment variables were found in its source, so it appears to need none.

How does CamoFox run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as camofox-mcp at 1.15.0.

How current is this page?

The grade is for one exact copy of the source (54441b502ba6), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement