Atlas / MCP servers / tacosyhorchata / Pilot

PilotBLOCK

mcp/tacosyhorchata/pilot-1

Chrome extension + MCP server — AI agents control a tab in your real browser, already logged in

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
69 57r · 8w · 4d
Transport
stdio
License
MIT
Stars
32
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/pilot-mcp) [](https://github.com/TacosyHorchata/Pilot/blob/main/LICENSE) [](https://github.com/TacosyHorchata/Pilot)

Native Playwright-backed browser sessions by default. No Chrome extension required for QA automation.

Pilot has two browser backends:

  • Native mode (default): isolated Playwright browser contexts. This is the supported path for parallel QA automation and reliable screenshots.
  • Extension mode (legacy/opt-in): connects to your real Chrome profile when you need existing cookies and logged-in sessions.

Native mode avoids chrome.tabs.captureVisibleTab() entirely, so screenshots do not depend on Chrome being foregrounded, a tab being visibly active, or the extension service worker being fresh.

How it works

AI Agent → MCP Server → Broker on 127.0.0.1:3131 → Native browser session
(stdio)       (first process owns broker)  (Playwright context/page)
  1. Pilot runs as an MCP server — Claude Code, Cursor, or any MCP client connects via stdio
  2. The first Pilot process becomes the broker on localhost
  3. Later Pilot processes connect as broker clients
  4. Each session gets an isolated native browser context/page
  5. Screenshots come from Playwright, not the Chrome extension capture API

Quick Start

1. Add the MCP server

codex mcp add pilot \
--env PILOT_BROWSER_MODE=native \
--env PILOT_PROFILE=full \
-- npx -y pilot-mcp

For a local checkout:

npm install
npm run build
codex mcp add pilot \
--env PILOT_BROWSER_MODE=native \
--env PILOT_PROFILE=full \
-- node /absolute/path/to/pilot/dist/index.js

2. Use it

"Open https://example.com, take a screenshot, and su
Read from source at commit 33160f9f22eaOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add pilot-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "pilot-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (69)

57 read · 8 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
pilot_actreadPerform a high-level browser action by resolving a human target into the best available @ref, label, role, placeholder, text, or selector. Use when an agent knows the user
pilot_annotated_screenshotread
pilot_assertread
pilot_authread
pilot_backreadNavigate back to the previous page in browser history. Use when the user wants to go back to the prior page they visited. Parameters: (none) Returns: The URL of the page after navigating back. Errors: -
pilot_blockread
pilot_cdpreadConnect Pilot to a real Chrome browser already running on the user
pilot_clickread
pilot_clipboardwriteRead from or write to the browser clipboard. Use when the user wants to read content that an app copied to clipboard (share links, API keys, generated tokens), or pre-populate clipboard with text for paste operations. Parameters: - action:
pilot_closereadClose the browser instance and release all associated resources. Use when the user wants to end the browsing session, clean up after completing a task, or start fresh with a new browser session. Parameters: (none) Returns: Confirmation that the browser was closed. Errors: -
pilot_consolereadRetrieve browser console messages (console.log, console.warn, console.error) from a circular buffer. Use when the user wants to debug JavaScript errors, check application logs, inspect warnings, or see what the page is printing to the console. Parameters: - level: Filter messages by log level —
pilot_cookiesread
pilot_dialogread
pilot_doctorread
pilot_dragdestructiveDrag one element and drop it onto another element on the page. Use when the user wants to move an element, reorder items in a drag-and-drop list, or interact with a drag-and-drop UI. Parameters: - start_ref: The source element reference from snapshot (e.g.,
pilot_element_statereadCheck the current state of an element — whether it is visible, hidden, enabled, disabled, checked, editable, or focused. Use when the user wants to verify an element
pilot_evaluatewriteExecute a JavaScript expression or function in the browser page context and return the result. Use when the user wants to run custom JavaScript on the page, read or modify DOM elements, extract data, or perform calculations. Supports async/await — use
pilot_evidence_exportreadExport the active evidence bundle to JSON, Markdown, or both. Use when the agent is done reproducing, validating, or debugging and needs durable artifacts the user or another agent can inspect without replaying the browser session. Parameters: - format:
pilot_evidence_startwrite
pilot_evidence_stepread
pilot_extension_statusreadCheck if the Pilot Chrome extension is connected and routing commands through the user
pilot_file_uploadwriteUpload one or more files to a file input element on the page. Use when the user wants to attach files, upload images, or submit documents through a file input field. Parameters: - ref: The file input element reference from snapshot (e.g.,
pilot_fillread
pilot_findreadFind an element by visible text, label, placeholder, or role — without running a full snapshot. Use when you know what you want to click or fill but don
pilot_forwardreadNavigate forward to the next page in browser history. Use when the user wants to go forward after using pilot_back. Parameters: (none) Returns: The URL of the page after navigating forward. Errors: -
pilot_frame_resetdestructive
pilot_frame_selectread
pilot_framesread
pilot_geolocationdestructiveSet or clear the browser
pilot_getreadNavigate to a URL and return its full readable content + interactive elements in one call. Use this as the primary tool for
pilot_guidereadRead short just-in-time Pilot guidance for a specific agent workflow topic. Use when an agent needs to know the right Pilot pattern, recovery path, browser mode, evidence flow, or ref behavior without loading the README or asking the user for instructions. Parameters: - topic: One of
pilot_handle_dialogread
pilot_handoffread
pilot_hoverreadHover the mouse over an element, triggering hover states, tooltips, and dropdown menus. Use when the user wants to reveal hidden content, trigger a CSS :hover effect, or inspect tooltip text. Parameters: - ref: Element reference from snapshot (e.g.,
pilot_import_cookieswriteImport cookies from a real Chromium browser (Chrome, Arc, Brave, Edge, Comet) by decrypting the browser
pilot_interceptread
pilot_navigatereadNavigate the browser to a URL and wait for DOM content to load. Use when the user wants to go to a specific webpage, URL, or link. For read tasks (
pilot_networkread
pilot_page_attrsreadGet all HTML attributes of a specific element as a JSON object. Use when the user wants to inspect an element
pilot_page_cssread
pilot_page_diffread
pilot_page_formsread
pilot_page_htmlreadGet innerHTML of a selector/ref, or full page HTML if none provided.
pilot_page_linksreadGet all links on the page as text + href pairs.
pilot_page_textreadExtract clean text from the page (strips script/style/noscript/svg).
pilot_pdfread
pilot_perfread
pilot_press_keyreadPress a keyboard key or key combination on the page. Use when the user wants to press Enter to submit a form, Tab to move between fields, Escape to close a modal, ArrowDown to navigate a list, or use any keyboard shortcut. Parameters: - key: Key name or combination (e.g.,
pilot_reloadread
pilot_resetdestructive
pilot_resizeread
pilot_responsiveread
pilot_resumeread
pilot_screenshotreadTake a PNG screenshot of the current page or a specific element. Use when the user wants to capture what the page looks like visually, save a screenshot to disk, or capture a specific element
pilot_scrollread
pilot_select_optionread
pilot_set_cookiewriteSet a cookie on the current page
pilot_set_headerwrite
pilot_set_useragentwrite
pilot_snapshotread
pilot_snapshot_diffread
pilot_statusread
pilot_storageread
pilot_tab_closeread
pilot_tab_newreadOpen a new browser tab, optionally navigating to a URL. Use when the user wants to open a link in a new tab, create a blank tab, or work with multiple pages simultaneously. Parameters: - url: Optional URL to navigate to in the new tab (omit for a blank about:blank tab) Returns: The new tab
pilot_tab_selectread
pilot_tabsread
pilot_typeread
pilot_waitread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (7 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
extension/content.js:334
const result = eval(script);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/url-validation.ts:7
'169.254.169.254',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/url-validation.ts:9
'metadata.google.internal',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
pilot_drag, pilot_frame_reset, pilot_geolocation, pilot_reset
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
benchmark/playwright-compare.ts:246
console.log(`  [Image data — base64 chars shown, not token-comparable to ARIA text]`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmark/llm-compare.ts:392
const local = path.resolve(fileURLToPath(import.meta.url), '../../cli/SKILL.md');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmark/llm-compare.ts:399
const serverPath = path.resolve(fileURLToPath(import.meta.url), '../../dist/index.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmark/llm-compare.ts:421
const daemonBin = path.resolve(fileURLToPath(import.meta.url), '../../dist/cli/daemon.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmark/llm-compare.ts:428
const clientBin = path.resolve(fileURLToPath(import.meta.url), '../../dist/cli/client.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmark/llm-compare.ts:472
const jsonlPath = path.resolve(fileURLToPath(import.meta.url), '../../benchmark/results.jsonl');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @modelcontextprotocol/sdk, @types/ws, better-sqlite3, diff, playwright, ws, zod
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
pilot-demo.gif
pilot-demo.gif
Why it matters. 13280176 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 33160f9f22eafull audit observations/trust-audit/mcp-server/tacosyhorchata__pilot-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0833160f9f22eaBLOCKD69first audit
06

Questions

What is the Pilot MCP server?

Chrome extension + MCP server — AI agents control a tab in your real browser, already logged in

What tools does Pilot expose?

69 in total: 57 read-only, 8 that write, and 4 that can delete or overwrite (pilot_drag, pilot_frame_reset, pilot_geolocation, pilot_reset). Every one is listed on this page with its risk.

Is Pilot safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Pilot need?

No credential environment variables were found in its source, so it appears to need none.

How does Pilot run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as pilot-mcp at 0.4.2.

How current is this page?

The grade is for one exact copy of the source (33160f9f22ea), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement