
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@mindstone/mcp-server-browser-automation
Advanced tools
Browser automation MCP server — visible-by-default browser control via accessibility snapshots, navigation, form filling, screenshots, and tab management. Set AGENT_BROWSER_SHOW_WINDOW=false to run quietly.
Browser control you can watch: open pages, sign in, click around, fill forms, take screenshots, and keep a reusable browser session.
Best for practical web tasks where the user needs to see, approve, or reuse browser state instead of running a full browser-testing stack.
server.json)STATUS.jsonMicrosoft's Playwright MCP is a strong choice for broad browser automation and testing. This connector is deliberately smaller and more visible.
Use it when an assistant needs to work through ordinary websites in a way a person can follow: open a real browser, let the user complete a login, click through admin screens, fill forms, take screenshots, and come back to the same session later. The point is trust and day-to-day usefulness, not exposing every browser-testing capability.
"Open https://example.com, tell me the page title, and take a screenshot."
Tools the host calls:
browser_navigate — opens the URL in the configured browser session.browser_get_page_info — returns the current URL and page title.browser_screenshot — captures a PNG screenshot.Response (trimmed):
{
"ok": true,
"url": "https://example.com/",
"title": "Example Domain"
}
agent-browser CLI on PATH, or npx available so the server can install it automatically.After clicking the button, your host will prompt you to fill: AGENT_BROWSER_SESSION_NAME, AGENT_BROWSER_SHOW_WINDOW.
{
"mcpServers": {
"Browser Automation": {
"command": "npx",
"args": [
"-y",
"@mindstone/mcp-server-browser-automation"
],
"env": {
"AGENT_BROWSER_SESSION_NAME": "mcp",
"AGENT_BROWSER_SHOW_WINDOW": "true"
}
}
}
}
npx -y @mindstone/mcp-server-browser-automation
Or install globally:
npm install -g @mindstone/mcp-server-browser-automation
mcp-server-browser-automation
This server requires the agent-browser CLI binary to control the browser.
agent-browser is on your PATH, it is used directly.npx -y agent-browser@0.26.0.npm install -g agent-browser
Or let the npx fallback handle it automatically (slower on first use due to download).
No API keys or credentials are required. The server communicates with the browser via the agent-browser CLI.
| Variable | Required | Description |
|---|---|---|
AGENT_BROWSER_SESSION_NAME | No | Session name for browser persistence (default: mcp) |
AGENT_BROWSER_SHOW_WINDOW | No | Set to false to run without a visible browser window. Default is visible (true). |
BROWSER_AUTOMATION_ALLOW_EVAL | No | Set to 1 to register the browser_evaluate tool. Off by default. See Security notes. |
{
"mcpServers": {
"browser-automation": {
"command": "npx",
"args": ["-y", "@mindstone/mcp-server-browser-automation"]
}
}
}
BROWSER_AUTOMATION_ALLOW_EVAL=1)The typical workflow uses accessibility snapshots for reliable element targeting:
browser_navigate → open a pagebrowser_snapshot → see interactive elements with @ref IDsbrowser_click / browser_fill → interact using @ref referencesbrowser_screenshot → visual verificationBrowser automation has a large attack surface: the agent-browser CLI controls a real headless browser that loads URLs you pass it, runs page-side JavaScript, and persists cookies and session state across runs. Read this section before deploying.
browser_evaluate is gated behind BROWSER_AUTOMATION_ALLOW_EVALbrowser_evaluate lets the model execute arbitrary JavaScript inside the page context — the security equivalent of giving the model a shell on whatever site it has just navigated to. To prevent prompt-injected content from doing this silently, the tool is only registered when the host explicitly opts in:
BROWSER_AUTOMATION_ALLOW_EVAL=1 mcp-server-browser-automation
Without this env var, browser_evaluate is not in the tools list at all — the LLM cannot even see it. When enabled, the tool is marked so MCP hosts can require explicit user confirmation before each invocation.
browser_navigate and browser_authenticate accept only http: and https: URLs (plus the special about:blank). Other URL schemes are refused before the underlying agent-browser CLI is invoked:
file: — would let pages read local filesystem pathschrome: and chrome-extension: — internal browser pages and installed extensionsjavascript: — equivalent to eval() against the current documentdata: — inlined attacker-controlled HTML/JS payloadsview-source: — defeats the same-origin policy on rendered contentabout: — privileged internal pages (about:config, about:cache, about:debugging, …); only about:blank is permittedThe connector tells agent-browser to use a named, persistent session via AGENT_BROWSER_SESSION_NAME (default value: mcp). All cookies, localStorage data, and any logins performed via browser_authenticate are stored on disk under that session name and reused across runs. Anyone who can read the session storage — the local user, other tools running as the same user, or backups — can also use those logged-in sessions.
To override the session name (for example, to keep separate profiles per project) set AGENT_BROWSER_SESSION_NAME explicitly in the host's MCP server config. To wipe state, close the browser via browser_close and remove the session directory managed by agent-browser.
AGENT_BROWSER_SESSION_NAME per MCP host. Do not reuse your daily browser profile: the connector reads and overwrites cookies in whichever profile it is pointed at, and a malicious page can ride the existing session of any site you are logged into.browser_evaluate disabled unless the host implements user confirmation for every call. The default (off) is the safe choice.browser_authenticate and any flow that may navigate to authenticated sites — otherwise prompt injection in fetched content can drive the browser at sites the user is logged into.FSL-1.1-MIT — Functional Source License, Version 1.1, with MIT future licence. The software converts to MIT licence on 2030-04-08.
FAQs
Browser automation MCP server — visible-by-default browser control via accessibility snapshots, navigation, form filling, screenshots, and tab management. Set AGENT_BROWSER_SHOW_WINDOW=false to run quietly.
The npm package @mindstone/mcp-server-browser-automation receives a total of 269 weekly downloads. As such, @mindstone/mcp-server-browser-automation popularity was classified as not popular.
We found that @mindstone/mcp-server-browser-automation demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.