🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

tilion

Package Overview
Dependencies
Maintainers
1
Versions
14
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

tilion

Open stealth-browser framework — drive a real recompiled-Chromium (Fortress) that defeats bot-detection fingerprint suites. Drop-in stealth for browser-use, Playwright, Crawl4AI, with an MCP server for AI agents.

pipPyPI
Version
0.1.14
Weekly downloads
73
-59.67%
Maintainers
1
Weekly downloads
 
Created

Tilion — a stealth browser for AI agents

mcp-name: io.github.tiliondev/fortress

pip install tilion — drive a real, undetected Chromium that gets past Cloudflare, DataDome, and bot detection. No server, no account, no API key.

PyPI Python MCP engine

Framework & MCP: Beta · runs local & free · Tilion Cloud (residential egress) coming soon

Same site, same prompt: a vanilla browser is blocked by PerimeterX while an agent with the Tilion MCP returns clean JSON

Real, dated run against stockx.com (PerimeterX). A stock browser gets HTTP 403 — "Access denied"; an agent with the Tilion MCP returns clean JSON — same site, same prompt.

Tilion runs a recompiled-Chromium stealth engine (Fortress) locally, in-process, and gives you one clean API for fetching protected pages, extracting content, crawling sites, reconnaissance, and multi-step automation — plus a Model Context Protocol (MCP) server so AI agents can reach for it the moment they get blocked.

pip install tilion

Quickstart

import asyncio
from tilion import Tilion

async def main():
    async with Tilion() as t:                                 # boots Fortress locally
        page = await t.fetch("https://protected.example")     # past Cloudflare/DataDome/403
        print(page["title"], page["text"][:200])

        data = await t.extract("https://site/pricing")        # clean markdown + tables
        docs = await t.crawl("https://site", depth=2)         # whole-site crawl (auto-SPA)
        apis = await t.recon("https://site")                  # discover the site's private API
        hits = await t.search("undetected playwright")        # real-browser web search

asyncio.run(main())

No uvicorn, no Redis, no auth — local mode holds one real browser and drives it directly.

Drop-in stealth for your existing stack

Already on browser-use, Playwright, Puppeteer, or Crawl4AI? They connect to a browser by CDP URL. Point that at Tilion and your code runs through the stealth engine — one line, no rewrite:

t = await Tilion().start()
cdp_url = t.cdp_url                       # hand this to any CDP-speaking stack

from browser_use import Agent, BrowserSession
agent = Agent(task="...", browser_session=BrowserSession(cdp_url=cdp_url))

MCP server — stealth browsing for any AI agent

pip install "tilion[mcp]"
tilion-mcp                                # or:  npx -y tilion-mcp

Claude Desktop / Cursor / Cline / Windsurf — add to the MCP config:

{ "mcpServers": { "fortress": { "command": "tilion-mcp" } } }

Claude Code (CLI): claude mcp add fortress -- tilion-mcp

26 tools: fetch_protected_page, extract_page, crawl_site, recon_site_apis, search_web, run_browser_task, save_page, save_profile, get_stealth_cdp_endpoint, and more — pre-warmed (~100 ms first call), concurrency-safe, timeout- and SSRF-guarded. Full tool table →

What you get

fetchstealth GET past Cloudflare/DataDome/403 + auto challenge-resolve
extractpage → clean markdown + tables + metadata (or a schema-shaped record)
crawl / spa_crawlwhole-site crawl, auto-handles SPA/JS + lazy-load → sitemap
reconreverse-engineer a site's private XHR/JSON API (secret-scrubbed)
searchreal-browser web search (no SERP API)
agent20 multi-step flows: login, paginate, infinite-scroll, checkout, downloads…
screenshot / savePNG, or export as PDF / HTML / text
cdp_urlraw CDP endpoint for browser-use / Playwright / Puppeteer

How stealth works

The engine is a recompiled Chromium C++ fork (shipped as the tilion-fortress dependency), not a JS patch or a stealth plugin. Persona, User-Agent, WebGL, and canvas fingerprints are applied natively with genuine binding returns (toString() === [native code]), so there are no JavaScript injection tells. In independent suites it runs Sannysoft-clean, CreepJS 0% headless, BrowserScan "Normal."

Honest note: a great fingerprint on a datacenter IP still gets blocked by the biggest sites — real anti-bot decisions weigh the egress IP heavily. For hostile targets, add a residential proxy or use hosted Tilion cloud egress (coming soon). Tilion does not claim to be "undetectable."

Install options

pip install tilion              # core: stealth browser + fetch/extract/crawl/recon/search
pip install "tilion[mcp]"       # + the MCP server
pip install "tilion[vision]"    # + LLM-driven agent (Claude/OpenAI/Gemini)

Open-core: the tilion facade + MCP are BSD-3; the engine (tilion.core driver + the Fortress binary) is proprietary. Requires Python 3.10–3.13 on Linux, macOS, or Windows.

Keywords

agent

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts