VesselCAUTION
Built from the ground-up for agents, Vessel Browser is an open source AI browser for Linux/Mac/Windows that provides a durable state, MCP control, and BYOK with full autonomous browsing. Use with Hermes Agent, OpenClaw, or connect to your favorite API provider.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Vessel is a simple, clean web browser with an AI assistant built in. Browse the web normally, then ask Vessel to help research, navigate pages, summarize what you are reading, fill forms, or keep track of longer tasks.
Unlike invisible browser automation, Vessel shows you what the AI is doing in a real browser window. You can follow along, approve important actions, pause or redirect the work, and take over whenever you want.
- A familiar browser, with AI help nearby — tabs, bookmarks, reader mode, downloads, and a sidebar assistant for web tasks
- Great for longer browsing sessions — durable conversation threads, a cross-source run inbox, named sessions, checkpoints, notes, bookmarks, and page changes make interrupted work recoverable
- You stay in control — review what the AI is doing, approve sensitive actions once or for a scoped run/domain, reject with steering, undo recent changes, and switch back to manual browsing at any time
- Open source and extensible — built on Chromium, with advanced automation support for MCP clients and agent tools when you need it
Linux is the most mature install target today. mac
c1fd8119a907OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add vessel-browser -- npx -y @quanta-intellect/[email protected]
Exposed tools (114)
80 read · 22 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
accept_cookies | read | |
archive_bookmark | read | Archive the current page, a URL, a link target, or an existing bookmark into the |
assign_to_group | read | |
bookmark_archive | read | |
bookmark_list | read | |
bookmark_open | read | |
bookmark_organize | read | |
bookmark_remove | destructive | |
bookmark_save | write | |
bookmark_search | read | |
checkpoint_create | write | |
checkpoint_restore | read | |
clear_highlights | destructive | |
clear_overlays | destructive | |
clear_transcript | destructive | |
click | read | |
close_tab | read | |
create_bookmark_folder | write | Create a bookmark folder for organizing saved pages. Returns existing folder if the same name exists. |
create_checkpoint | write | Capture the current browser session as a named checkpoint for later recovery. |
create_folder | write | |
create_group | write | |
create_tab | write | |
current_tab | read | |
delete_session | destructive | |
dismiss_popup | read | |
extract_content | read | |
extract_structured_data | read | |
extract_table | read | |
extract_text | read | |
fill_form | read | |
flow_advance | read | |
flow_end | read | |
flow_start | write | |
flow_status | read | |
focus | read | |
folder_remove | destructive | |
folder_rename | write | |
go_back | read | |
go_forward | read | |
highlight | read | |
hover | read | |
human_vault_fill | read | |
human_vault_list | read | |
human_vault_remove | destructive | |
inspect_element | read | |
list_bookmarks | read | List bookmark folders and saved pages. Optionally filter by folder name or ID. |
list_groups | read | |
list_highlights | read | |
list_sessions | read | |
list_tabs | read | |
load_session | read | |
login | read | |
memory_append | read | |
memory_link_bookmark | read | |
memory_list | read | |
memory_note_create | write | |
memory_page_capture | read | |
memory_search | read | |
metrics | read | |
navigate | read | |
open_bookmark | read | Open a saved bookmark by its bookmark ID. Optionally open it in a new tab. |
organize_bookmark | write | Move an existing bookmark or save the current page into a folder, creating the folder if needed. |
paginate | read | |
press_key | read | |
publish_transcript | write | |
read_page | read | |
reload | read | |
remove_from_group | destructive | |
remove_highlight | destructive | |
restore_checkpoint | read | Restore a previously captured checkpoint by name or ID. |
save_bookmark | write | Save the current page, a specified URL, or a link target from the current page as a bookmark. |
save_session | write | |
screenshot | read | |
scroll | read | |
scroll_to_element | read | |
search | read | |
search_bookmarks | read | Search bookmarks by title, URL, note, folder name, or folder summary. |
select_option | read | |
set_ad_blocking | write | |
set_group_color | write | |
submit_form | write | |
suggest | read | |
switch_tab | read | |
task_abandon | read | |
task_blocker | read | |
task_note | read | |
task_resolve | read | |
task_start | write | |
task_status | read | |
task_update | write | |
toggle_group | read | |
type | read | |
type_text | read | |
undo_last_action | read | |
vault_login | read | |
vault_status | read | |
vault_totp | read | |
vessel_devtools_clear_errors | destructive | |
vessel_devtools_console_clear | destructive | |
vessel_devtools_console_logs | read | |
vessel_devtools_execute_js | write | |
vessel_devtools_get_errors | read | |
vessel_devtools_get_storage | read | |
vessel_devtools_get_styles | read | |
vessel_devtools_modify_dom | write | |
vessel_devtools_network_clear | destructive | |
vessel_devtools_network_log | read | |
vessel_devtools_network_response_body | read | |
vessel_devtools_performance | read | |
vessel_devtools_query_dom | read | |
vessel_devtools_set_storage | write | |
wait_for | read | |
wait_for_navigation | read | |
web_search | read |
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
vessel-icon.icns
callback_url: callbackUrl,
/\/beacon/i,
getValue: () => ({ secret: "do-not-store-plaintext" }),bookmark_remove, clear_highlights, clear_overlays, clear_transcript, delete_session, folder_remove, human_vault_remove, remove_from_group, remove_highlight, vessel_devtools_clear_errors, vessel_devtoo
.node-version
const resolved = await resolveDownloadPath(tempDir, "../../.ssh/authorized_keys");
assert.equal(path.basename(resolved), "authorized_keys");
fs.writeFileSync(path.join(tempDir, "authorized_keys"), "existing");
const collision = await resolveDownloadPath(tempDir, "../../.ssh/authorized_keys");
assert.equal(path.basename(collision), "authorized_keys (1)");
import type { ResearchReport, SubAgentTrace } from "../../../shared/research-types";import { createLogger } from "../../../shared/logger";} from "../../../shared/research-types";
import type { AIProvider } from "../../ai/provider";import { AGENT_TOOLS } from "../../ai/tools";4. Start Hermes Agent or OpenClaw and point it at Vessel — the easiest way is `vessel-browser-mcp --stdio` as the MCP command (auth is resolved automatically), or connect directly to `http://127.0.0.1
"url": "http://127.0.0.1:3100/mcp",
url: "http://127.0.0.1:3100/mcp"
4. Start Hermes Agent, OpenClaw, Codex, or another MCP client and point it at Vessel — the easiest way is `vessel-browser-mcp --stdio` as the MCP command, or connect directly to `http://127.0.0.1:<mcp
url = "http://127.0.0.1:3100/mcp"
const binary = atob(normalized + padding);
@anthropic-ai/sdk, @modelcontextprotocol/client, @modelcontextprotocol/node, @modelcontextprotocol/server, @mozilla/readability, dompurify, linkedom, openai
- **Chat Assistant** — built-in conversational AI in the sidebar Chat tab; supports Anthropic, OpenAI, Ollama, llama.cpp, Mistral, xAI, Google Gemini, OpenRouter, and any OpenAI-compatible endpoint; r
curl -fsSL https://raw.githubusercontent.com/unmodeled-tyler/vessel-browser/main/scripts/install.sh | bash
Gates applied: no_behavioural_pass.
c1fd8119a907full audit observations/trust-audit/mcp-server/unmodeled-tyler__vessel-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c1fd8119a907 | CAUTION | B | 81 | first audit |
Questions
What is the Vessel MCP server?
Built from the ground-up for agents, Vessel Browser is an open source AI browser for Linux/Mac/Windows that provides a durable state, MCP control, and BYOK with full autonomous browsing. Use with Hermes Agent, OpenClaw, or connect to your favorite API provider.
What tools does Vessel expose?
114 in total: 80 read-only, 22 that write, and 12 that can delete or overwrite (bookmark_remove, clear_highlights, clear_overlays, clear_transcript, delete_session). Every one is listed on this page with its risk.
Is Vessel safe to connect to an agent?
With care. The audit graded it B (81/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Vessel need?
It reads AUTH_PATH, POSTHOG_API_KEY and STATUS_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Vessel run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @quanta-intellect/vessel-browser at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (c1fd8119a907), read on 2026-10-07. The repository is watched and re-audited when it changes.