{"_id":"@mindstone/mcp-server-browser-automation","_rev":"5-8f62724b05ed588832fc75753f588d9b","name":"@mindstone/mcp-server-browser-automation","dist-tags":{"latest":"0.2.2"},"versions":{"0.1.7":{"name":"@mindstone/mcp-server-browser-automation","version":"0.1.7","license":"FSL-1.1-MIT","_id":"@mindstone/mcp-server-browser-automation@0.1.7","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/browser-automation","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"bin":{"mcp-server-browser-automation":"dist/index.js"},"dist":{"shasum":"99ff2da8b3c509875de8683eda06f3e184ff34d1","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-browser-automation/-/mcp-server-browser-automation-0.1.7.tgz","fileCount":25,"integrity":"sha512-jRmTYcgiAiFW1kR6RTZPmlKH/id5wfgqYVuvZ0iOvprm1Jf7vqAURe8a9RBi2aye9J0XrehvnOAxrtDi3Xinlg==","signatures":[{"sig":"MEUCIGoGFuqocbdZ6hJjE7swiElM5Otjsinxinxa9BIggkT1AiEAlEqTrHHUShGLPX46ukChUtLm4uFD14TP5+zpWu04jJA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":51085},"type":"module","engines":{"node":">=20"},"gitHead":"83878671b322434710c729d19cd790301bc68369","mcpName":"io.github.mindstone/mcp-server-browser-automation","scripts":{"test":"vitest run","build":"tsc && shx chmod +x dist/index.js","start":"node dist/index.js","watch":"tsc --watch","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"mindstone-engineering","email":"engineering@mindstone.com"},"overrides":{"hono":"^4.12.18","fast-uri":"^3.1.2","ip-address":"^10.2.0"},"repository":{"url":"git+https://github.com/mindstone/mcp-servers.git","type":"git","directory":"connectors/browser-automation"},"_npmVersion":"11.11.1","description":"Browser automation MCP server — visible-by-default browser control via accessibility snapshots, navigation, form filling, screenshots, and tab management. Set AGENT_BROWSER_SHOW_WINDOW=false to run quietly.","directories":{},"_nodeVersion":"25.8.2","dependencies":{"zod":"^3.23.0","graceful-fs":"^4.2.11","@modelcontextprotocol/sdk":"^1.26.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"msw":"^2.13.2","shx":"^0.3.4","vitest":"^4.1.3","typescript":"^5.8.2","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","@mindstone/mcp-test-harness":"file:../../test-harness"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-browser-automation_0.1.7_1779089017991_0.2893005989507762","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@mindstone/mcp-server-browser-automation","version":"0.1.8","license":"FSL-1.1-MIT","_id":"@mindstone/mcp-server-browser-automation@0.1.8","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/browser-automation","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"bin":{"mcp-server-browser-automation":"dist/index.js"},"dist":{"shasum":"bbc68d3ab5aed6582664bcd8b95688ecd6de94f4","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-browser-automation/-/mcp-server-browser-automation-0.1.8.tgz","fileCount":25,"integrity":"sha512-F8UWFiWGk1fI86LbqBwI8ij2av1SIulHSVhrBlrMulK6XQ3mzBd6MYm/oXDCeA5/F0jYFcZN7jDajVRTcx3Rww==","signatures":[{"sig":"MEYCIQCVRR+piTlKKaYSO0AlOdJbR3VizE4rL6oy8ZqHaWM+ZQIhANbPt8C0vq8/+WIUmgwbCT4cLS301/HDXeUh2d4top6Z","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@mindstone%2fmcp-server-browser-automation@0.1.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":55013},"type":"module","_from":"file:mindstone-mcp-server-browser-automation-0.1.8.tgz","engines":{"node":">=20"},"mcpName":"io.github.mindstone/mcp-server-browser-automation","scripts":{"test":"vitest run","build":"tsc && shx chmod +x dist/index.js","start":"node dist/index.js","watch":"tsc --watch","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:461d9770-da23-4570-a03f-318a17589fa1"}},"_resolved":"/home/runner/work/mcp-servers/mcp-servers/mindstone-mcp-server-browser-automation-0.1.8.tgz","overrides":{"hono":"^4.12.18","fast-uri":"^3.1.2","ip-address":"^10.2.0"},"_integrity":"sha512-F8UWFiWGk1fI86LbqBwI8ij2av1SIulHSVhrBlrMulK6XQ3mzBd6MYm/oXDCeA5/F0jYFcZN7jDajVRTcx3Rww==","repository":{"url":"git+https://github.com/mindstone/mcp-servers.git","type":"git","directory":"connectors/browser-automation"},"_npmVersion":"11.13.0","description":"Browser automation MCP server — visible-by-default browser control via accessibility snapshots, navigation, form filling, screenshots, and tab management. Set AGENT_BROWSER_SHOW_WINDOW=false to run quietly.","directories":{},"_nodeVersion":"24.17.0","dependencies":{"zod":"^3.23.0","graceful-fs":"^4.2.11","@modelcontextprotocol/sdk":"^1.26.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"msw":"^2.13.2","shx":"^0.3.4","vitest":"^4.1.3","typescript":"^5.8.2","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","@mindstone/mcp-test-harness":"file:../../test-harness"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-browser-automation_0.1.8_1782898153684_0.2127698586175355","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@mindstone/mcp-server-browser-automation","version":"0.2.0","license":"FSL-1.1-MIT","_id":"@mindstone/mcp-server-browser-automation@0.2.0","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/browser-automation","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"bin":{"mcp-server-browser-automation":"dist/index.js"},"dist":{"shasum":"59910bab87bed00926514de80b7efc7a5be30bf1","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-browser-automation/-/mcp-server-browser-automation-0.2.0.tgz","fileCount":31,"integrity":"sha512-ouzSjQuACcYM+vVxyU+g0LbSlTPA5DeH5b6DcZrUTCnfjdu99rNfiU/cHRsp5t5myDI7h86DcjA8x+0Myqcy2g==","signatures":[{"sig":"MEUCIQDoYRRWEuIwSx/gul2aGl5N6wCU0AughRZFfFICb/9aWwIgKUSAjaoQjFHZkkzi7zZzmA7tJcNT0HkiopVxvLEa2/0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@mindstone%2fmcp-server-browser-automation@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":86783},"type":"module","_from":"file:mindstone-mcp-server-browser-automation-0.2.0.tgz","engines":{"node":">=20"},"mcpName":"io.github.mindstone/mcp-server-browser-automation","scripts":{"test":"vitest run","build":"tsc && shx chmod +x dist/index.js","start":"node dist/index.js","watch":"tsc --watch","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:461d9770-da23-4570-a03f-318a17589fa1"}},"_resolved":"/home/runner/work/mcp-servers/mcp-servers/mindstone-mcp-server-browser-automation-0.2.0.tgz","overrides":{"hono":"^4.12.18","fast-uri":"^3.1.2","ip-address":"^10.2.0"},"_integrity":"sha512-ouzSjQuACcYM+vVxyU+g0LbSlTPA5DeH5b6DcZrUTCnfjdu99rNfiU/cHRsp5t5myDI7h86DcjA8x+0Myqcy2g==","repository":{"url":"git+https://github.com/mindstone/mcp-servers.git","type":"git","directory":"connectors/browser-automation"},"_npmVersion":"11.16.0","description":"Browser automation MCP server — visible-by-default browser control via accessibility snapshots, navigation, form filling, screenshots, and tab management. Set AGENT_BROWSER_SHOW_WINDOW=false to run quietly.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.23.0","graceful-fs":"^4.2.11","@modelcontextprotocol/sdk":"^1.26.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"msw":"^2.13.2","shx":"^0.3.4","vitest":"^4.1.3","typescript":"^5.8.2","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","@mindstone/mcp-test-harness":"file:../../test-harness"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-browser-automation_0.2.0_1786130168913_0.7135708069134776","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@mindstone/mcp-server-browser-automation","version":"0.2.1","license":"FSL-1.1-MIT","_id":"@mindstone/mcp-server-browser-automation@0.2.1","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/browser-automation","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"bin":{"mcp-server-browser-automation":"dist/index.js"},"dist":{"shasum":"aab81c22d39874f65f86572896c2ce8cc6cddcc3","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-browser-automation/-/mcp-server-browser-automation-0.2.1.tgz","fileCount":31,"integrity":"sha512-eSDlx9biVdGJSTArqpx0M8aI9XkcAFZcYa/g36RCdnEF904uC3h2I4VDBh/5DzxO3R3FTl+CDKkXjIvPwyFGlg==","signatures":[{"sig":"MEQCIECUbJcfMB6Ldy6lTuVe9JRj+K4oLcoJaXle25ak66ZZAiAIrOi/t5B0rTKDF94S2jJKJvDde0jPb68+UtOjpRbgCQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@mindstone%2fmcp-server-browser-automation@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":89364},"type":"module","_from":"file:mindstone-mcp-server-browser-automation-0.2.1.tgz","engines":{"node":">=20"},"mcpName":"io.github.mindstone/mcp-server-browser-automation","scripts":{"test":"vitest run","build":"tsc && shx chmod +x dist/index.js","start":"node dist/index.js","watch":"tsc --watch","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:461d9770-da23-4570-a03f-318a17589fa1"}},"_resolved":"/home/runner/work/mcp-servers/mcp-servers/mindstone-mcp-server-browser-automation-0.2.1.tgz","overrides":{"hono":"^4.12.18","fast-uri":"^3.1.2","ip-address":"^10.2.0"},"_integrity":"sha512-eSDlx9biVdGJSTArqpx0M8aI9XkcAFZcYa/g36RCdnEF904uC3h2I4VDBh/5DzxO3R3FTl+CDKkXjIvPwyFGlg==","repository":{"url":"git+https://github.com/mindstone/mcp-servers.git","type":"git","directory":"connectors/browser-automation"},"_npmVersion":"11.16.0","description":"Browser automation MCP server — visible-by-default browser control via accessibility snapshots, navigation, form filling, screenshots, and tab management. Set AGENT_BROWSER_SHOW_WINDOW=false to run quietly.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.23.0","graceful-fs":"^4.2.11","@modelcontextprotocol/sdk":"^1.26.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"msw":"^2.13.2","shx":"^0.3.4","vitest":"^4.1.3","typescript":"^5.8.2","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","@mindstone/mcp-test-harness":"file:../../test-harness"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-browser-automation_0.2.1_1786186090794_0.31188623232670176","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@mindstone/mcp-server-browser-automation","version":"0.2.2","mcpName":"io.github.mindstone/mcp-server-browser-automation","description":"Browser automation MCP server — visible-by-default browser control via accessibility snapshots, navigation, form filling, screenshots, and tab management. Set AGENT_BROWSER_SHOW_WINDOW=false to run quietly.","license":"FSL-1.1-MIT","type":"module","bin":{"mcp-server-browser-automation":"dist/index.js"},"repository":{"type":"git","url":"git+https://github.com/mindstone/mcp-servers.git","directory":"connectors/browser-automation"},"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/browser-automation","publishConfig":{"access":"public"},"scripts":{"build":"tsc && shx chmod +x dist/index.js","prepare":"npm run build","watch":"tsc --watch","start":"node dist/index.js","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage"},"dependencies":{"@modelcontextprotocol/sdk":"^1.26.0","graceful-fs":"^4.2.11","zod":"^3.23.0"},"devDependencies":{"@mindstone/mcp-test-harness":"file:../../test-harness","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","msw":"^2.13.2","shx":"^0.3.4","typescript":"^5.8.2","vitest":"^4.1.3"},"engines":{"node":">=20"},"overrides":{"fast-uri":"^3.1.2","hono":"^4.12.18","ip-address":"^10.2.0"},"_id":"@mindstone/mcp-server-browser-automation@0.2.2","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"_integrity":"sha512-sw3CXvLiDBU3MvFlxkrNuDO5E6DzlfDYEGLeE/5L4zzM9hIpYaC3MxtFRzbWcaOj8iBm8l7aTqqsiQzit8rBEw==","_resolved":"/home/runner/work/mcp-servers/mcp-servers/mindstone-mcp-server-browser-automation-0.2.2.tgz","_from":"file:mindstone-mcp-server-browser-automation-0.2.2.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-sw3CXvLiDBU3MvFlxkrNuDO5E6DzlfDYEGLeE/5L4zzM9hIpYaC3MxtFRzbWcaOj8iBm8l7aTqqsiQzit8rBEw==","shasum":"d2bbd6a3d3fee4dd91cf20624470c947de194500","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-browser-automation/-/mcp-server-browser-automation-0.2.2.tgz","fileCount":31,"unpackedSize":95073,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@mindstone%2fmcp-server-browser-automation@0.2.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEy/2IkzWf2IRd+LCN2XAvWQ95iDhEUmk7WxcgqNdQidAiABFUfIAZS/zRh0pH707/BtAtUwVBusYfn0RO08xcu5lg=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:461d9770-da23-4570-a03f-318a17589fa1"}},"directories":{},"maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server-browser-automation_0.2.2_1786326654944_0.6000003270447081"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-18T07:23:37.880Z","modified":"2026-08-10T01:50:55.599Z","0.1.7":"2026-05-18T07:23:38.167Z","0.1.8":"2026-07-01T09:29:13.818Z","0.2.0":"2026-08-07T19:16:09.123Z","0.2.1":"2026-08-08T10:48:10.982Z","0.2.2":"2026-08-10T01:50:55.081Z"},"bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"license":"FSL-1.1-MIT","homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/browser-automation","repository":{"type":"git","url":"git+https://github.com/mindstone/mcp-servers.git","directory":"connectors/browser-automation"},"description":"Browser automation MCP server — visible-by-default browser control via accessibility snapshots, navigation, form filling, screenshots, and tab management. Set AGENT_BROWSER_SHOW_WINDOW=false to run quietly.","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"readme":"# @mindstone/mcp-server-browser-automation\n\n[![npm version](https://img.shields.io/npm/v/@mindstone/mcp-server-browser-automation.svg)](https://www.npmjs.com/package/@mindstone/mcp-server-browser-automation)\n[![License: FSL-1.1-MIT](https://img.shields.io/badge/License-FSL--1.1--MIT-blue.svg)](./LICENSE)\n\nBrowser control you can watch: open pages, sign in, click around, fill forms, take screenshots, and keep a reusable browser session.\n\n*Best for practical web tasks where the user needs to see, approve, or reuse browser state instead of running a full browser-testing stack.*\n\n## Status\n\n- **Version:** [0.2.2](./CHANGELOG.md) · [npm](https://www.npmjs.com/package/@mindstone/mcp-server-browser-automation)\n- **Auth:** None ([`server.json`](./server.json))\n- **Tools:** [21](./src/tools/) (navigation, observation, interaction, sessions, files)\n- **Surface:** browser-automation\n- **Machine-readable:** [`STATUS.json`](./STATUS.json)\n\n## Why this exists\n\nMicrosoft's Playwright MCP is a strong choice for broad browser automation and testing. This connector is deliberately smaller and more visible.\n\nUse it when an assistant needs to work through ordinary websites in a way a person can follow: open a real browser, let the user complete a login, click through admin screens, fill forms, take screenshots, and come back to the same session later. The point is trust and day-to-day usefulness, not exposing every browser-testing capability.\n\n## Example interaction\n\n> \"Open https://example.com, tell me the page title, and take a screenshot.\"\n\nTools the host calls:\n1. `browser_navigate` — opens the URL in the configured browser session.\n2. `browser_get_page_info` — returns the current URL and page title.\n3. `browser_screenshot` — captures a PNG screenshot.\n\nResponse (trimmed):\n\n```json\n{\n  \"ok\": true,\n  \"url\": \"https://example.com/\",\n  \"title\": \"Example Domain\"\n}\n```\n\n## Requirements\n\n- Node.js 20+\n- npm\n- The `agent-browser` CLI on `PATH`, or `npx` available so the server can install it automatically.\n\n<!-- BEGIN INSTALL_LINKS: do not edit by hand; regenerated by scripts/gen-install-links.mjs -->\n## One-click install\n\n[![Add to Cursor](https://img.shields.io/badge/Add_to_Cursor-black?style=for-the-badge&logo=cursor&logoColor=white)](cursor://anysphere.cursor-deeplink/mcp/install?name=Browser%20Automation&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBtaW5kc3RvbmUvbWNwLXNlcnZlci1icm93c2VyLWF1dG9tYXRpb24iXSwiZW52Ijp7IkFHRU5UX0JST1dTRVJfU0VTU0lPTl9OQU1FIjoibWNwIiwiQUdFTlRfQlJPV1NFUl9TSE9XX1dJTkRPVyI6InRydWUifX0)\n[![Add to VS Code](https://img.shields.io/badge/Add_to_VS_Code-007ACC?style=for-the-badge&logo=visual-studio-code&logoColor=white)](vscode:mcp/install?%7B%22name%22%3A%22Browser%20Automation%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40mindstone%2Fmcp-server-browser-automation%22%5D%2C%22env%22%3A%7B%22AGENT_BROWSER_SESSION_NAME%22%3A%22mcp%22%2C%22AGENT_BROWSER_SHOW_WINDOW%22%3A%22true%22%7D%7D)\n[![Add to VS Code Insiders](https://img.shields.io/badge/Add_to_VS_Code_Insiders-24bfa5?style=for-the-badge&logo=visual-studio-code&logoColor=white)](vscode-insiders:mcp/install?%7B%22name%22%3A%22Browser%20Automation%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40mindstone%2Fmcp-server-browser-automation%22%5D%2C%22env%22%3A%7B%22AGENT_BROWSER_SESSION_NAME%22%3A%22mcp%22%2C%22AGENT_BROWSER_SHOW_WINDOW%22%3A%22true%22%7D%7D)\n\nAfter clicking the button, your host will prompt you to fill: `AGENT_BROWSER_SESSION_NAME`, `AGENT_BROWSER_SHOW_WINDOW`.\n\n<details>\n<summary>Manual config for Claude Desktop / Claude Code / Goose / Continue.dev (Browser Automation)</summary>\n\n```json\n{\n  \"mcpServers\": {\n    \"Browser Automation\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@mindstone/mcp-server-browser-automation\"\n      ],\n      \"env\": {\n        \"AGENT_BROWSER_SESSION_NAME\": \"mcp\",\n        \"AGENT_BROWSER_SHOW_WINDOW\": \"true\"\n      }\n    }\n  }\n}\n```\n\n</details>\n<!-- END INSTALL_LINKS -->\n\n## Quick Start\n\n### npx\n\n```bash\nnpx -y @mindstone/mcp-server-browser-automation\n```\n\nOr install globally:\n\n```bash\nnpm install -g @mindstone/mcp-server-browser-automation\nmcp-server-browser-automation\n```\n\nThis server requires the `agent-browser` CLI binary to control the browser.\n\n### Binary Resolution\n\n1. **PATH lookup** (preferred): If `agent-browser` is on your PATH, it is used directly.\n2. **npx fallback**: If the binary is not found, the server automatically falls back to `npx -y agent-browser@0.33.2`.\n\n### Installing agent-browser\n\n```bash\nnpm install -g agent-browser\n```\n\nOr let the npx fallback handle it automatically (slower on first use due to download).\n\n## Configuration\n\nNo API keys or credentials are required. The server communicates with the browser via the agent-browser CLI.\n\n| Variable | Required | Description |\n|---|---|---|\n| `AGENT_BROWSER_SESSION_NAME` | No | Session name for browser persistence (default: `mcp`) |\n| `AGENT_BROWSER_SHOW_WINDOW` | No | Set to `false` to run without a visible browser window. Default is visible (`true`). |\n| `MCP_WORKSPACE_PATH` | No | Workspace directory that `browser_pdf` writes into and `browser_upload` reads from. Defaults to the system temp directory. See [Security notes](#security-notes). |\n\n### MCP Host Configuration\n\n```json\n{\n  \"mcpServers\": {\n    \"browser-automation\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@mindstone/mcp-server-browser-automation\"]\n    }\n  }\n}\n```\n\n## Available Tools (21)\n\n### Navigation\n- **browser_navigate** — Navigate to a URL\n- **browser_back** — Navigate back in browser history\n- **browser_forward** — Navigate forward in browser history\n- **browser_wait** — Wait for an element to appear or a specified time\n\n### Observation\n- **browser_snapshot** — Get the page accessibility tree with interactive element references\n- **browser_screenshot** — Take a screenshot of the current page\n- **browser_get_page_info** — Get the current page URL and title\n- **browser_get_text** — Get the text content of the page or a single element\n- **browser_pdf** — Save the current page as a PDF inside the workspace directory (refuses to overwrite existing files unless `overwrite: true`)\n\n### Interaction\n- **browser_click** — Click an element using @ref or CSS selector\n- **browser_fill** — Clear a field and fill it with text\n- **browser_type** — Type text character by character (real keystrokes)\n- **browser_press_key** — Press a keyboard key\n- **browser_scroll** — Scroll the page in a direction\n- **browser_select** — Select an option from a dropdown\n- **browser_hover** — Hover over an element\n- **browser_upload** — Upload workspace files to a file input (regular files only, staged privately before upload)\n- **browser_evaluate** — Execute JavaScript in the page context (on by default; `destructiveHint: true` so hosts can require confirmation — see [Security notes](#security-notes))\n\n### Session Management\n- **browser_tabs** — List open tabs or switch to a tab\n- **browser_close** — Close the browser session\n- **browser_authenticate** — Open a visible browser for manual login\n\n## Workflow\n\nThe typical workflow uses accessibility snapshots for reliable element targeting:\n\n1. `browser_navigate` → open a page\n2. `browser_snapshot` → see interactive elements with @ref IDs\n3. `browser_click` / `browser_fill` → interact using @ref references\n4. `browser_screenshot` → visual verification\n\n## Security notes\n\nBrowser automation has a large attack surface: the agent-browser CLI controls a real headless browser that loads URLs you pass it, runs page-side JavaScript, and persists cookies and session state across runs. Read this section before deploying.\n\n### `browser_evaluate` runs by default — host confirmation is the gate\n\n`browser_evaluate` lets the model execute arbitrary JavaScript inside the page context — the security equivalent of giving the model a shell on whatever site it has just navigated to. The tool is registered **unconditionally** (capability-first); the safeguard is the host's tool-approval layer. The tool is marked `destructiveHint: true`, so MCP hosts SHOULD require explicit user confirmation before each invocation. Do not configure a host to auto-approve this tool.\n\n### URL scheme deny-list\n\n`browser_navigate` and `browser_authenticate` accept only `http:` and `https:` URLs (plus the special `about:blank`). Other URL schemes are refused before the underlying `agent-browser` CLI is invoked:\n\n- `file:` — would let pages read local filesystem paths\n- `chrome:` and `chrome-extension:` — internal browser pages and installed extensions\n- `javascript:` — equivalent to `eval()` against the current document\n- `data:` — inlined attacker-controlled HTML/JS payloads\n- `view-source:` — defeats the same-origin policy on rendered content\n- `about:` — privileged internal pages (`about:config`, `about:cache`, `about:debugging`, …); only `about:blank` is permitted\n\n### Cookie and session persistence\n\nThe connector tells `agent-browser` to use a **named, persistent session** via `AGENT_BROWSER_SESSION_NAME` (default value: `mcp`). All cookies, `localStorage` data, and any logins performed via `browser_authenticate` are stored on disk under that session name and reused across runs. Anyone who can read the session storage — the local user, other tools running as the same user, or backups — can also use those logged-in sessions.\n\nTo override the session name (for example, to keep separate profiles per project) set `AGENT_BROWSER_SESSION_NAME` explicitly in the host's MCP server config. To wipe state, close the browser via `browser_close` and remove the session directory managed by `agent-browser`.\n\n### Recommended deployment posture\n\n- **Run the connector against a separate browser profile** — a dedicated `AGENT_BROWSER_SESSION_NAME` per MCP host. Do not reuse your daily browser profile: the connector reads and overwrites cookies in whichever profile it is pointed at, and a malicious page can ride the existing session of any site you are logged into.\n- **Require host confirmation for `browser_evaluate`** — it runs by default; every call executes arbitrary JavaScript in the page context.\n- **Require host confirmation** for `browser_authenticate` and any flow that may navigate to authenticated sites — otherwise prompt injection in fetched content can drive the browser at sites the user is logged into.\n- **Returned page content is enveloped as untrusted** — accessibility snapshots, page text, titles, URLs, tab lists, and `browser_evaluate` outputs come from arbitrary websites and may contain prompt-injection attempts. The connector wraps them in `<untrusted-content source=\"…\">` envelopes (with close-tag breakout escaping) so hosts and models treat them as data, not instructions. Keep that treatment on your side: don't strip the envelopes, and don't let page text alone trigger irreversible actions.\n\n### Workspace sandbox for file tools\n\n`browser_pdf` writes PDF files and `browser_upload` reads files, and both are constrained to a workspace directory: `MCP_WORKSPACE_PATH` when set, otherwise the system temp directory. Paths are canonicalised before use, so `..` traversal, absolute paths outside the workspace, and in-workspace symlinks pointing outside it are all refused before the `agent-browser` CLI runs. Set `MCP_WORKSPACE_PATH` explicitly to control exactly where page captures land and which files the model can attach to a page. A `MCP_WORKSPACE_PATH` that cannot be resolved fails closed: file tools refuse to run rather than fall back to weaker checks.\n\nBoth tools are marked `destructiveHint: true`, so hosts can require user confirmation: `browser_upload` can trigger an immediate remote upload on pages that submit when the file input changes, and `browser_pdf` writes a local file.\n\nAdditional hardening:\n\n- **Staged file hand-off.** Validated files are never re-opened by pathname. `browser_upload` sources are opened once (`O_NOFOLLOW` + `O_NONBLOCK`, so a post-validation leaf-symlink swap fails and a planted FIFO cannot wedge the open), verified to be regular files (directories, devices, and FIFOs are refused), bound to a fresh confined resolution by device+inode (an intermediate-directory swap after validation redirects the resolution and is refused with `UPLOAD_SOURCE_CHANGED`), and copied into a fresh private staging directory that the CLI consumes. `browser_pdf` has the CLI write into a fresh private staging directory, then installs the PDF at the requested path: the destination directory's canonical identity is pinned before the CLI runs and re-verified before installing, so an intermediate directory swapped to a symlink mid-call is refused, and exclusive-create semantics refuse a file or symlink planted at the destination leaf instead of writing through it.\n- **No silent overwrite.** `browser_pdf` refuses an existing `file_path` with a `FILE_EXISTS` error unless the caller explicitly passes `overwrite: true`. Even then, a destination that is a directory is refused (`DESTINATION_IS_DIRECTORY`) — the overwrite delete is a bare unlink and never recurses.\n- **Enveloped errors.** Error output from the `agent-browser` CLI can contain page-authored text; it is wrapped in `<untrusted-content>` envelopes (with close-tag breakout escaping) before reaching the model, and timeout errors do not echo the command's argument values.\n\n## Licence\n\n[FSL-1.1-MIT](./LICENSE) — Functional Source License, Version 1.1, with MIT future licence. The software converts to MIT licence on 2030-04-08.\n","readmeFilename":"README.md"}