Atlas / MCP servers / unmodeled-tyler / Vessel

VesselCAUTION

mcp/unmodeled-tyler/vessel-1

Built from the ground-up for agents, Vessel Browser is an open source AI browser for Linux/Mac/Windows that provides a durable state, MCP control, and BYOK with full autonomous browsing. Use with Hermes Agent, OpenClaw, or connect to your favorite API provider.

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
114 80r · 22w · 12d
Transport
streamable-http
License
MIT
Stars
137
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Vessel is a simple, clean web browser with an AI assistant built in. Browse the web normally, then ask Vessel to help research, navigate pages, summarize what you are reading, fill forms, or keep track of longer tasks.

Unlike invisible browser automation, Vessel shows you what the AI is doing in a real browser window. You can follow along, approve important actions, pause or redirect the work, and take over whenever you want.

  • A familiar browser, with AI help nearby — tabs, bookmarks, reader mode, downloads, and a sidebar assistant for web tasks
  • Great for longer browsing sessions — durable conversation threads, a cross-source run inbox, named sessions, checkpoints, notes, bookmarks, and page changes make interrupted work recoverable
  • You stay in control — review what the AI is doing, approve sensitive actions once or for a scoped run/domain, reject with steering, undo recent changes, and switch back to manual browsing at any time
  • Open source and extensible — built on Chromium, with advanced automation support for MCP clients and agent tools when you need it

Linux is the most mature install target today. mac

Read from source at commit c1fd8119a907OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add vessel-browser -- npx -y @quanta-intellect/[email protected]
03

Exposed tools (114)

80 read · 22 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
accept_cookiesread
archive_bookmarkreadArchive the current page, a URL, a link target, or an existing bookmark into the
assign_to_groupread
bookmark_archiveread
bookmark_listread
bookmark_openread
bookmark_organizeread
bookmark_removedestructive
bookmark_savewrite
bookmark_searchread
checkpoint_createwrite
checkpoint_restoreread
clear_highlightsdestructive
clear_overlaysdestructive
clear_transcriptdestructive
clickread
close_tabread
create_bookmark_folderwriteCreate a bookmark folder for organizing saved pages. Returns existing folder if the same name exists.
create_checkpointwriteCapture the current browser session as a named checkpoint for later recovery.
create_folderwrite
create_groupwrite
create_tabwrite
current_tabread
delete_sessiondestructive
dismiss_popupread
extract_contentread
extract_structured_dataread
extract_tableread
extract_textread
fill_formread
flow_advanceread
flow_endread
flow_startwrite
flow_statusread
focusread
folder_removedestructive
folder_renamewrite
go_backread
go_forwardread
highlightread
hoverread
human_vault_fillread
human_vault_listread
human_vault_removedestructive
inspect_elementread
list_bookmarksreadList bookmark folders and saved pages. Optionally filter by folder name or ID.
list_groupsread
list_highlightsread
list_sessionsread
list_tabsread
load_sessionread
loginread
memory_appendread
memory_link_bookmarkread
memory_listread
memory_note_createwrite
memory_page_captureread
memory_searchread
metricsread
navigateread
open_bookmarkreadOpen a saved bookmark by its bookmark ID. Optionally open it in a new tab.
organize_bookmarkwriteMove an existing bookmark or save the current page into a folder, creating the folder if needed.
paginateread
press_keyread
publish_transcriptwrite
read_pageread
reloadread
remove_from_groupdestructive
remove_highlightdestructive
restore_checkpointreadRestore a previously captured checkpoint by name or ID.
save_bookmarkwriteSave the current page, a specified URL, or a link target from the current page as a bookmark.
save_sessionwrite
screenshotread
scrollread
scroll_to_elementread
searchread
search_bookmarksreadSearch bookmarks by title, URL, note, folder name, or folder summary.
select_optionread
set_ad_blockingwrite
set_group_colorwrite
submit_formwrite
suggestread
switch_tabread
task_abandonread
task_blockerread
task_noteread
task_resolveread
task_startwrite
task_statusread
task_updatewrite
toggle_groupread
typeread
type_textread
undo_last_actionread
vault_loginread
vault_statusread
vault_totpread
vessel_devtools_clear_errorsdestructive
vessel_devtools_console_cleardestructive
vessel_devtools_console_logsread
vessel_devtools_execute_jswrite
vessel_devtools_get_errorsread
vessel_devtools_get_storageread
vessel_devtools_get_stylesread
vessel_devtools_modify_domwrite
vessel_devtools_network_cleardestructive
vessel_devtools_network_logread
vessel_devtools_network_response_bodyread
vessel_devtools_performanceread
vessel_devtools_query_domread
vessel_devtools_set_storagewrite
wait_forread
wait_for_navigationread
web_searchread
04

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (7 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
resources/vessel-icon.icns
vessel-icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/main/ai/openrouter-oauth.ts:63
callback_url: callbackUrl,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/main/network/ad-blocking-rules.ts:45
/\/beacon/i,
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/security-hardening.test.ts:420
getValue: () => ({ secret: "do-not-store-plaintext" }),
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
bookmark_remove, clear_highlights, clear_overlays, clear_transcript, delete_session, folder_remove, human_vault_remove, remove_from_group, remove_highlight, vessel_devtools_clear_errors, vessel_devtoo
Why it matters. 12 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.node-version
.node-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/security-hardening.test.ts:745
const resolved = await resolveDownloadPath(tempDir, "../../.ssh/authorized_keys");
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/security-hardening.test.ts:747
assert.equal(path.basename(resolved), "authorized_keys");
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/security-hardening.test.ts:749
fs.writeFileSync(path.join(tempDir, "authorized_keys"), "existing");
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/security-hardening.test.ts:750
const collision = await resolveDownloadPath(tempDir, "../../.ssh/authorized_keys");
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/security-hardening.test.ts:752
assert.equal(path.basename(collision), "authorized_keys (1)");
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/main/agent/research/export.ts:1
import type { ResearchReport, SubAgentTrace } from "../../../shared/research-types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/main/agent/research/orchestrator.ts:1
import { createLogger } from "../../../shared/logger";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/main/agent/research/orchestrator.ts:13
} from "../../../shared/research-types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/main/agent/research/orchestrator.ts:16
import type { AIProvider } from "../../ai/provider";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/main/agent/research/orchestrator.ts:17
import { AGENT_TOOLS } from "../../ai/tools";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:276
4. Start Hermes Agent or OpenClaw and point it at Vessel — the easiest way is `vessel-browser-mcp --stdio` as the MCP command (auth is resolved automatically), or connect directly to `http://127.0.0.1
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:434
"url": "http://127.0.0.1:3100/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:448
url: "http://127.0.0.1:3100/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/mcp.md:10
4. Start Hermes Agent, OpenClaw, Codex, or another MCP client and point it at Vessel — the easiest way is `vessel-browser-mcp --stdio` as the MCP command, or connect directly to `http://127.0.0.1:<mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/mcp.md:122
url = "http://127.0.0.1:3100/mcp"
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/cloudflare-worker/vessel-premium-api.js:495
const binary = atob(normalized + padding);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @modelcontextprotocol/client, @modelcontextprotocol/node, @modelcontextprotocol/server, @mozilla/readability, dompurify, linkedom, openai
Why it matters. 28 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:93
- **Chat Assistant** — built-in conversational AI in the sidebar Chat tab; supports Anthropic, OpenAI, Ollama, llama.cpp, Mistral, xAI, Google Gemini, OpenRouter, and any OpenAI-compatible endpoint; r
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:58
curl -fsSL https://raw.githubusercontent.com/unmodeled-tyler/vessel-browser/main/scripts/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c1fd8119a907full audit observations/trust-audit/mcp-server/unmodeled-tyler__vessel-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c1fd8119a907CAUTIONB81first audit
06

Questions

What is the Vessel MCP server?

Built from the ground-up for agents, Vessel Browser is an open source AI browser for Linux/Mac/Windows that provides a durable state, MCP control, and BYOK with full autonomous browsing. Use with Hermes Agent, OpenClaw, or connect to your favorite API provider.

What tools does Vessel expose?

114 in total: 80 read-only, 22 that write, and 12 that can delete or overwrite (bookmark_remove, clear_highlights, clear_overlays, clear_transcript, delete_session). Every one is listed on this page with its risk.

Is Vessel safe to connect to an agent?

With care. The audit graded it B (81/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Vessel need?

It reads AUTH_PATH, POSTHOG_API_KEY and STATUS_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Vessel run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @quanta-intellect/vessel-browser at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (c1fd8119a907), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement