
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
MCP server for web intelligence extraction — design systems, accessibility audits, competitive analysis, and migration prep
Web intelligence toolkit — an MCP server + CLI built with Node.js and Playwright. Designed for authenticated dashboard inspection, design system extraction, and UI analysis. Reuses browser sessions across tool calls so MFA-protected sites only need one manual login.
# Quick start (no install required)
npx tapsite-mcp
# Or install globally
npm install -g tapsite-mcp
npx playwright install chromium
npx playwright install-deps chromium
Add to your Claude config (~/.claude/.mcp.json):
{
"mcpServers": {
"tapsite": {
"command": "npx",
"args": ["tapsite-mcp"]
}
}
}
First run: Playwright will install the Chromium browser automatically if not already present. This is a one-time ~150MB download.
Click any image to see the full interactive page:
37 MCP tools for authenticated web intelligence extraction — colors, fonts, performance, accessibility, content, forms, assets, and more.
Four real-world scenarios — design system reverse-engineering, competitive intelligence, accessibility auditing, and asset migration prep.
git clone https://github.com/mgriffen/tapsite
cd tapsite
npm install
npx playwright install chromium
npx playwright install-deps chromium
MCP config pointing to local source:
{
"mcpServers": {
"tapsite": {
"command": "node",
"args": ["/absolute/path/to/tapsite/src/server.js"]
}
}
}
Recommended — set transcript cleanup to prevent credentials lingering on disk:
"cleanupPeriodDays": 1
| Tool | Description |
|---|---|
tapsite_login | Automated login (username + password, no MFA) |
tapsite_login_manual | Open headed browser for manual login + MFA |
tapsite_login_check | Verify authenticated session state |
tapsite_navigate | Navigate to a URL, returns indexed interactive elements |
tapsite_inspect | Full DOM inspection (nav, headings, buttons, forms, tables, links) |
tapsite_screenshot | Take a screenshot of the current page |
tapsite_act | Click or fill an indexed element from the last inspect/navigate |
tapsite_scroll | Scroll the page |
tapsite_run_js | Execute arbitrary JavaScript and return the result |
tapsite_close | Close the browser session |
| Tool | Description |
|---|---|
tapsite_extract_table | Extract a specific table as structured data |
tapsite_extract_links | Extract all links with text and href |
tapsite_extract_metadata | Extract page metadata (title, description, OG tags, etc.) |
tapsite_extract_content | Extract main readable content (article body, headings, paragraphs) |
tapsite_extract_forms | Extract all forms with fields, labels, and actions |
| Tool | Description |
|---|---|
tapsite_extract_colors | Extract color palette (hex values + usage counts) |
tapsite_extract_fonts | Extract font families, sizes, weights |
tapsite_extract_css_vars | Extract CSS custom properties |
tapsite_extract_spacing | Extract spacing scale values |
| Tool | Description |
|---|---|
tapsite_extract_images | Extract all images with src, alt, dimensions |
tapsite_download_images | Download images to local output directory |
tapsite_extract_svgs | Extract inline SVGs |
tapsite_extract_favicon | Extract favicon URLs and sizes |
| Tool | Description |
|---|---|
tapsite_extract_layout | Extract layout tree (inline text representation) |
tapsite_extract_components | Detect repeated UI components and patterns |
tapsite_extract_breakpoints | Extract responsive breakpoints from CSS media queries |
| Tool | Description |
|---|---|
tapsite_capture_network | Capture network requests during a page load |
tapsite_extract_api_schema | Infer API schema from observed network traffic |
tapsite_detect_stack | Detect frontend framework, libraries, and tech stack |
| Tool | Description |
|---|---|
tapsite_crawl | Crawl multiple pages from a start URL |
tapsite_diff_pages | Compare two pages and report differences |
| Tool | Description |
|---|---|
tapsite_extract_animations | Extract CSS animations and transitions |
tapsite_extract_a11y | Accessibility audit (ARIA, roles, contrast issues) |
tapsite_detect_darkmode | Detect dark mode support and extract dark palette |
tapsite_extract_perf | Extract performance metrics (Core Web Vitals, resource sizes) |
| Tool | Description |
|---|---|
tapsite_export | Export inspection results as JSON + Markdown + HTML report + CSV tables + screenshots |
tapsite_export_design_report | Full design system report: report.html (visual), design-tokens.json (W3C format), design-tokens.css (copy-pasteable :root vars) |
When extracting content from untrusted web pages, tapsite applies two layers of protection:
Hidden element filtering — Extractors skip elements with display:none, visibility:hidden, opacity:0, zero-size, and clip-hidden styling. This prevents invisible text (a common prompt injection vector) from entering extraction results. Applied to content, links, forms, and accessibility extractors.
Output sanitization — All text returned to the LLM is scanned for prompt injection patterns: instruction overrides, role hijacking, exfiltration attempts, and tool manipulation. Matches are flagged inline as [INJECTION_DETECTED] rather than silently dropped, so both the LLM and user can see what was caught.
Never pass credentials through the chat. Use tapsite_login_manual to open a headed browser, log in manually (including MFA), then tapsite_login_check to confirm. Credentials never touch Anthropic's servers or local transcripts.
MIT
src/
server.js — MCP server entry point
browser.js — shared Chromium context (ensureBrowser, closeBrowser)
helpers.js — shared helpers (navigateIfNeeded, summarizeResult, indexPage)
sanitizer.js — prompt injection detection
extractors.js — browser-context extraction functions (page.evaluate())
exporter.js — file export: JSON, Markdown, HTML, CSV
inspector.js — DOM extraction for inspect/navigate tools
cli.js — standalone CLI (login, inspect, session)
config.js — paths and defaults
tools/
session.js — login, navigate, inspect, screenshot, act, scroll, run_js, close
extraction.js — all extract_* and detect_* tools
network.js — capture_network, extract_api_schema, detect_stack
multipage.js — crawl, diff_pages
export.js — export, export_design_report
profiles/ — browser state / session cookies (gitignored)
output/ — export results (gitignored)
output/run-{timestamp}/ — tapsite_export runs: JSON, Markdown, HTML, screenshots, CSV tablesoutput/design-report-{timestamp}/ — tapsite_export_design_report runs: report.html, design-tokens.json, design-tokens.cssFAQs
MCP server for web intelligence extraction — design systems, accessibility audits, competitive analysis, and migration prep
The npm package tapsite receives a total of 38 weekly downloads. As such, tapsite popularity was classified as not popular.
We found that tapsite demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.