Browser UseSAFE
Cline Browser-Use MCP
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@ztobs/cline-browser-use-mcp)
A Model Context Protocol server for browser automation using Python scripts. For use with Cline
Features
Browser Operations
screenshot: Capture a screenshot of a webpage (full page or viewport)get_html: Retrieve the HTML content of a webpageexecute_js: Execute JavaScript on a webpageget_console_logs: Get console logs from a webpage
All operations support custom interaction steps (e.g., clicking elements, scrolling) after page load.
Prerequisites
- (Optional but recommended) Install Xvfb for headless browser automation:
# Ubuntu/Debian sudo apt-get install xvfb # CentOS/RHEL sudo yum install xorg-x11-server-Xvfb # Arch Linux sudo pacman -S xorg-server-xvfb
Xvfb (X Virtual Frame Buffer) creates a virtual display, allowing browser automation without detection as a bot. Learn more about Xvfb here.
- Install Miniconda or Anaconda
- Create a Conda environment:
conda create -n browser-use python=3.11 conda activate browser-use pip install -r requirements.txt
- Set up LLM configuration:
The server supports multiple LLM providers. You can use any of the following API keys:
# Required: Set at least one of these API keys export GLHF_API_KEY=your_api_key export GROQ_API_KEY=your_api_key export OPENAI_API_KEY=your_api_key export OPENROUTER_API_KEY=your_api_key export GITHUB_API_KEY=your_api_key export DEEPSEEK_API_KEY=your_api_key export GEMINI_API_KEY=your_api_key export OLLAMA_API_KEY=your_api_key # Optional: Override default configuration export MODEL=your_preferred_model # Override the default model export BASE
1ef4b56f1008OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add browser-use-server --env DEEPSEEK_API_KEY=${DEEPSEEK_API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GITHUB_API_KEY=${GITHUB_API_KEY} --env GLHF_API_KEY=${GLHF_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"browser-use-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"DEEPSEEK_API_KEY": "${DEEPSEEK_API_KEY}",
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"GITHUB_API_KEY": "${GITHUB_API_KEY}",
"GLHF_API_KEY": "${GLHF_API_KEY}"
}
}
}
}Exposed tools (4)
3 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
execute_js | write | Execute JavaScript code on a webpage |
get_console_logs | read | Get the console logs of a webpage |
get_html | read | Get the HTML content of a webpage |
screenshot | read | Take a screenshot of a webpage |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
screenshot_bytes = base64.b64decode(screenshot_base64)
@modelcontextprotocol/sdk, @types/node, typescript
browser-use
Gates applied: no_behavioural_pass, no_license.
1ef4b56f1008full audit observations/trust-audit/mcp-server/ztobs__browser-use-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 1ef4b56f1008 | SAFE | B | 89 | first audit |
Questions
What is the Browser Use MCP server?
Cline Browser-Use MCP
What tools does Browser Use expose?
4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Browser Use safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Browser Use need?
It reads DEEPSEEK_API_KEY, GEMINI_API_KEY, GITHUB_API_KEY, GLHF_API_KEY, GROQ_API_KEY, OLLAMA_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY and XAUTHORITY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Browser Use run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as browser-use-server at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (1ef4b56f1008), read on 2026-10-09. The repository is watched and re-audited when it changes.