10 ms·
Show HN: Browser MCP – Automate your browser using Cursor, Claude, VS Code
- deleted 1y ago[deleted]
- amendegree 1y agoSo is MCP the new RPA (Robotics Process Automation)? Like generic yahoo pipes?
- ajcp 1y agoNo, since MCP is just an interface layer it is to AI what REST API is to DPA and COM/App DLLs are to RPA. APA (Agentic Process Automation) is the new RPA, and this is definitely one example of it.
- XCSme 1y agoBut AI already supported function calling, and you could describe them in various ways. Isn't this just a different way to define function calling?
- spmurrayzzz 1y agoI just view it as a relative minor convenience, but it's not some game-changer IMO. The tool use / function calling thing far predates Anthropic releasing the MCP specification and it really wasn't that onerous to do before either. You could provide a json schema spec and tell the model to generate compliant json to pass to the API in question. MCP doesn't inherently solve any of the problems that come up in that sort of workflow, but it does provide an idiomatic approach for it (so there's a non-zero value there, but not much).
- PantaloonFlames 1y agoIt seems the benefit of MCP is for Anthropic to enlist the community in building integrations for Claude desktop, no? And if other vendors sign on to support MCP, then it becomes a self reinforcing cycle of adoption.
- JackYoustra 1y agoMCP is useful because anthropic has a disproportionate share of API traffic relative to its valuation and a tiny share of first-party client traffic. The best way around this is to shift as much traffic to API as possible.
- PantaloonFlames 1y agoFirst party client , meaning browser? User agent or … Electron app, or , any mobile app?
- JackYoustra 1y agofirst party client as in a claude subscription will give you access (mostly app + web)
- spmurrayzzz 1y agoYea it certainly does benefit Claude Desktop to some degree, but most MCP servers are a few hundred SLOC and the protocol schema itself is only ~400 SLOC. If that was the only major obstacle standing in the way of adoption, I'd be very surprised. Coupled with the fact that any LLM trained for tool use can utilize the protocol, it doesn't feel like much of a moat that uniquely positions Claude Desktop in a meaningful way.
- asabla 1y ago> And if other vendors sign on to support MCP, then it becomes a self reinforcing cycle of adoption This is exactly what's happening now. A good portion of applications, frameworks and actors are starting to support it. I've been reluctant on adopting MCP in applications until there was enough adoption. However, depending on your use case it may also be too complex for your use case.
- kmangutov 1y agoThe interesting thing about MCP as a tool use protocol is the traction that it has garnered in terms of clients and servers supporting it.
- wonderwhyer 1y agoI would probably call it shipping containers for LLM tool integrations. Containers are not a big deal when viewed in isolation. But when its common size/standard for all kinds of ships, cranes and trucks, it is a big deal then. In that sense its more about gathering community around one way to do things. In theory there are REST APIs and OpenAPI standard, but those were not made for LLMs but code. So you usually need some kind of friendly wrapper(like for candy) on top of REST API. It really starts to feel like a a big deal when you work in integrating LLMs with tools.
- tmvphil 1y agoI'm a bit stuck on this, maybe you can explain why an LLM would have any difficulty writing REST API calls? Seems like it should be no problem.
- buttofthejoke 1y agoWhy use this over Puppeteer or Playwright extensions?
- namuorg 1y agoThe Puppeteer MCP server doesn't work well because it requires CSS selectors to interact with elements. It makes up CSS selectors rather than reading the page and generating working selectors. The Playwright MCP server is great! Currently Browser MCP is largely an adaptation of the Playwright MCP server to use with your actual browser rather than creating a new one each time. This allows you to reuse your existing Chrome profile so that you don't need to log in to each service all over again and avoids bot detection which often triggers when using the fresh browser instances created by Playwright. I also plan to add other useful tools (e.g. Browser MCP currently supports a tool to get the console logs which is useful for automated debugging) which will likely diverge from the Playwright MCP server features.
- buttofthejoke 1y agoOoo, i like that. one of the most annoying points has been 'not sharing' the browser context. i'll def check it out
- cAtte_ 1y agoby the way, you can indeed access your personal context with Playwright. just `launchPersistentContext()` and set the userDataDir to that of your existing Chrome install: https://playwright.dev/docs/api/class-browsertype#browser-type-launch-persistent-context-option-user-data-dir https://playwright.dev/docs/api/class-browsertype#browser-ty...
- rahimnathwani 1y agoThis is cool. I'm curious why you chose to use an extension, rather than getting the user to run Chrome with remote debugging turned on?
- hannofcart 1y agoNot OP but I suspect it is because of this (mentioned on their page): 'Avoids bot detection and CAPTCHAs by using your real browser fingerprint.'
- tylergetsay 1y agoI don't think remote debugging by itself on a normal chrome profile is detectable
- parhamn 1y agoI'm sure its about the cookies/sessions but I do recall you can load cookies from another browser?
- omneity 1y agoExposing Chrome CDP is a terrible idea from a security and privacy perspective. You get the keys to the whole kingdom (and expose them on a standard port with a well documented API). All security features of the web can be bypassed, and then some, as CDP exposes even more capabilities than chrome extensions and without any form of supervision.
- redblacktree 1y agoYou're talking about exposing Chrome CDP to the wider internet, right? Or are you highlighting these dangers in the local context?
- omneity 1y agoIn the local context as well. Unlike say the docker socket which is protected by default using unix permissions, the CDP protocol has no authorization, authentication or permission mechanism. Anything on your machine (such as a rogue browser extension or a malicious npm/pypi package) could scan for this and just get all your cookies - and that's only the beginning of your problems. CDP can access any origin, any data stored (localStorage, indexedDB ...), any javascript heap, cross iframe and origin boundaries, run almost undetectable code that uses your sessions without you knowing, and the list is very long. CDP was never meant to expose a real browser in an untrusted context.
- neilellis 1y agoWell done, just tested on Claude Desktop and it worked smoothly and a lot less clunky than playwright. This is the right direction to go in. I don't know if you've done it already, but it would be great to pause automation when you detect a captcha on the page and then notify the user that the automation needs attention. Playwright keeps trying to plough through captchas.
- johnpaulkiser 1y ago> Private > Since automation happens locally, your browser activity stays on your device and isn't sent to remote servers. I think this is bullshit. Isn't the dom or whatever sent to the model api?
- namuorg 1y agoOf course, you're sending data to the AI model, but the "private" aspect is contrasting automating using a local browser vs. automating using a remote browser. When you automate using a remote browser, another service (not the AI model) gets all of the browsing activity and any information you send (e.g. usernames and passwords) that's required for the automation. With Browser MCP, since you're automating locally, your sensitive data and browser activity (apart from the results of MCP tool calls that's sent to the AI model) stay on your device.
- johnpaulkiser 1y agoI think we need to be very careful & intentional about the language we use with these kinds of tools, especially now that the MCP floodgates have been opened. You aren't just exposing the users browsing data to which ever model they are using, you are also exposing it any tools they may be allowing as well. A lot of non technical people are using these tools to "vibe" their way to productivity. I would explicitly tell them that potentially "all" of their browsing data is going to be exposed to their LLM client and they need to use this at their own risk.
- Fernicia 1y agoAny plans to make a Firefox version?
- namuorg 1y agoBrowser MCP uses the Chrome DevTools Protocol (CDP) to automate the browser so it currently only works for Chromium-based browsers. Unfortunately, Firefox doesn't expose WebDriver BiDi (the standardized version of CDP) to browser extensions AFAIK (someone please correct me if I'm mistaken!), so I don't think I can support it even if I tried.
- krono 1y agoJust found this[0] implementation roadmap on Mozilla's wiki, recently updated too! At least it's actively being worked on. Not going to lie, this makes me happy. [0]: https://wiki.mozilla.org/WebDriver/RemoteProtocol/WebDriver_BiDi https://wiki.mozilla.org/WebDriver/RemoteProtocol/WebDriver_...
- 101008 1y agoGood, just what we needed. More bots browsing the internet. Somedays I think I am not 100% against of every website having a captcha...
- mgraczyk 1y agoIt's a developer tool
- 101008 1y agoThen it should be limited to localhost or something similar.
- mgraczyk 1y agoIt can be, just do that when you install it
- dalemhurley 1y agoWhat if you are using domain names for your local environment or a cloud environment like IDX or you want to automate the testing of the UAT environment?
- handfuloflight 1y agoNot out of the realm of possibility that this very comment was written by a bot prompted to write a negative response to a given piece of content.
- 101008 1y agoNot, human tired of creating content to put online and being consumed not by people but by bots or any other form of mechanical consumption that I don't like. As the owner of the content I think I have the right to set that preference, don't you think?
- brandensilva 1y ago
- DebtDeflation 1y agoIn the Task Automation demo, how does it know all of the attributes of the motorcycle he is trying to sell? Is it relying on the underlying LLM's embedded knowledge? But then how would it know the price and mileage? Is there some underlying document not referenced in the demo? Because that information is not in the prompt.
- behnamoh 1y agoWhat I don't like about LLMs is that people keep re-inventing the wheel over and over. For example, we've been able to control browsers using GPT for about 2 years now: - https://github.com/mayt/BrowserGPT https://github.com/mayt/BrowserGPT - https://github.com/TaxyAI/browser-extension https://github.com/TaxyAI/browser-extension - https://github.com/browser-use/browser-use https://github.com/browser-use/browser-use - https://github.com/Skyvern-AI/skyvern https://github.com/Skyvern-AI/skyvern - https://github.com/m1guelpf/browser-agent https://github.com/m1guelpf/browser-agent - https://github.com/richardyc/Chrome-GPT https://github.com/richardyc/Chrome-GPT - https://github.com/handrew/browserpilot https://github.com/handrew/browserpilot - https://github.com/ishan0102/vimGPT https://github.com/ishan0102/vimGPT - https://github.com/Jiayi-Pan/GPT-V-on-Web https://github.com/Jiayi-Pan/GPT-V-on-Web
- ajcp 1y agoI think this is noteworthy in that it is using what is increasingly becoming the dominant API protocol for LLM. Just because the wheel exists doesn't mean we shouldn't strive to make it better by applying new knowledge and technologies to it.
- betasleep 1y ago[dead]
- darepublic 1y agonone of these have stuck right. And none of them work well enough that all web dev agencies no longer have to worry about e2e testing. (or do some of them? Maybe the market is simply that inefficient).
- dvngnt_ 1y agoI don't see this being a solution for full e2e regression testing. Having to run inference for each command/test seems expensive. I do think there's room for self-healing tests after failure.
- 1y ago
- BrandiATMuhkuh 1y agoThis is really well done! Very cool. I wonder if it's possible to add such plugins to election apps (e.g.: Slack). It would be such a nice experience if I could just connect my AI of choice to a local app.
- decayiscreation 1y agoGood idea! I'm sure this is possible since it looks like playwright can control electron apps. https://playwright.dev/docs/api/class-electronapplication https://playwright.dev/docs/api/class-electronapplication
- chrisweekly 1y agoelection -> Electron
- icelancer 1y agoI just run into a bunch of errors on my Windows machine + Chrome when connected over remote-ssh. Extension installed, tab enabled, npx updated/installed, etc. 2025-04-07 10:57:11.606 [info] rmcp: Starting new stdio process with command: npx @browsermcp/mcp@latest 2025-04-07 10:57:11.606 [error] rmcp: Client error for command spawn npx ENOENT 2025-04-07 10:57:11.606 [error] rmcp: Error in MCP: spawn npx ENOENT 2025-04-07 10:57:11.606 [info] rmcp: Client closed for command 2025-04-07 10:57:11.606 [error] rmcp: Error in MCP: Client closed 2025-04-07 10:57:11.606 [info] rmcp: Handling ListOfferings action 2025-04-07 10:57:11.606 [error] rmcp: No server info found --- EDIT: Ended up fixing it by patching index.js. killProcessOnPort() was the problem. Can hit me up if you have questions, I cannot figure out how to put readable code in HN after all these years with the fake markdown syntax they use.
- namuorg 1y agoThanks for the report and the update! I'd love to hear about what you changed — how can I get in touch? I didn't see anything in your HN profile. Feel free to email me at admin@browsermcp.io
- deathanatos 1y ago> I cannot figure out how to put readable code in HN after all these years with the fake markdown syntax they use. Not that HN supports much in the way of markup, but code blocks are actually the same as Markdown: indent (by 2 spaces or more, in HN's syntax; Markdown calls for 4 or more, so they're compatible). print("Hello, world.")
- serverlessmania 1y agoDid something similar but controls a hardware synth, allowing me to do sound design without touching the physical knobs: https://github.com/zerubeus/elektron-mcp https://github.com/zerubeus/elektron-mcp
- dmix 1y agoOh good idea. Imagine it controlling plugins remotely, have an LLM do mastering and sound shaping with existing tools. The complex overly-graphical UIs of VSTs might be a barrier to performance there, but you could hook into those labeled midi mapping interfaces to control the knobs and levels.
- picardo 1y agoI like this. It would be interesting to use it for when I need to use authenticated browser sessions.
- washedDeveloper 1y agoCan you add a license to your code along with open sourcing the chrome extension?
- jngiam1 1y agoPretty cool, do you know of a version of this that supports the new remote MCP protocol
- omneity 1y agoWe work on something similar and aim to be the huggingface hub for automations you can run in your browser[0], with built-in support for MCP SSE. Use the pre-built Trails[1][2] as MCP servers or create and publish your own with a familiar puppeteer-like API, powered by your or your friends browsers. 0: https://herd.garden https://herd.garden 1: https://herd.garden/trails/@herd/browser https://herd.garden/trails/@herd/browser 2: https://herd.garden/trails/@omneity/serp https://herd.garden/trails/@omneity/serp
- qwertox 1y agoMCP seems to be JavaScript's trojan horse into AI.
- deleted 1y ago[deleted]
- ketzo 1y ago"Trojan horse"? 95% of people currently access AI via web or mobile app; those are pretty JS-dominated, no?
- tigrezno 1y agothis is the way
- tntpreneur 1y agoThanks but idea is ok but it is not working smoothly.
- nonethewiser 1y agoStuff like this makes me giddy for manual tasks like reimbursement requests. Its such a chore (and it doesnt help our process isnt great). Every month, go to service providers, log in, find and download statement, create google doc with details filled in, download it, write new email and upload all the files. Maybe double chek the attachments are right but that requires downloading them again instead of being able to view in email). Automating this is already possible (and a real expense tracking app can eliminate about half of this work) but I think AI tools have the potential to elminate a lot of the nittier-grittier specification of it. This is especially important because these sorts of workflows are often subject to little changes.
- bhouston 1y agoSo the website claims: "Avoids bot detection and CAPTCHAs by using your real browser fingerprint." Yeah, not really. I've used a similar system a few weeks back (one I wrote myself), having AI control my browser using my logged in session, and I started to get Captcha's during my human sessions in the browser and eventually I got blocked from a bunch of websites. Now that I've stopped using my browser session in that way, the blocks eventually went away, but be warned, you'll lose access yourself to websites doing this, it isn't a silver bullet.
- DeathArrow 1y agoIt might depend on the speed with which you click on the elements on the website.
- SSLy 1y agoit does, CF bans my own honest to God clicks if I do them too fast.
- omgwtfbyobbq 1y agoAbout five years ago, maybe more, Google started sending me captchas if I ran too many repetitive searches. I could be wrong, but it feel like most large platforms have fairly sophisticated anti-bot/scraping stuff in place.
- SubiculumCode 1y agoGoogle does the same to me: Don't they know, I keep modifying my searches because their results sucked so bad I had to try 30 times to find the piece of information I needed?
- clown_strike 1y agoYandex does the same.
- what 1y ago
- cadence- 1y agoDoesn't work on Windows: 2025-04-07T18:43:26.537Z [browsermcp] [info] Initializing server... 2025-04-07T18:43:26.603Z [browsermcp] [info] Server started and connected successfully 2025-04-07T18:43:26.610Z [browsermcp] [info] Message from client: {"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"claude-ai","version":"0.1.0"}},"jsonrpc":"2.0","id":0} node:internal/errors:983 const err = new Error(message); ^ Error: Command failed: FOR /F "tokens=5" %a in ('netstat -ano ^| findstr :9009') do taskkill /F /PID %a at genericNodeError (node:internal/errors:983:15) at wrappedFn (node:internal/errors:537:14) at checkExecSyncError (node:child_process:882:11) at execSync (node:child_process:954:15)
- cadence- 1y agoI was able to make it work like this: 1. Kill your Claude Desktop app 2. Click "Connect" in the browser extension. 3. Quickly start your Calude Desktop app. It will work 50% of the time - I guess the timing must be just right for it to work. Hopefully, the developers can improve this. Now on to testing :)
- namuorg 1y agoCan you try again? There was another comment that mentioned that there's an issue with port killing code on Windows: https://news.ycombinator.com/item?id=43614145 https://news.ycombinator.com/item?id=43614145 I just published a new version of the @browsermcp/mcp library (version 0.1.1) that handles the error better until I can investigate further so it should hopefully work now if you're using @browsermcp/mcp@latest. FWIW, Claude Desktop currently has a bug where it tries to start the server twice, which is why the MCP server tries to kill the process from a previous invocation: https://github.com/modelcontextprotocol/servers/issues/812 https://github.com/modelcontextprotocol/servers/issues/812
- cadence- 1y agoIt's working now with the 0.1.0 for me. But I will let you know if I experience any issues once I get updated to 0.1.1. Thanks, great job! I like it overall, but I noticed it has some issues entering text in forms, even on google.com. It's able to find a workaround and insert the searched text in the URL, but it would be nice if the entry into forms worked well for UI testing.
- graiz 1y agoworks better than puppet mcp for me but having issues with keyboard events and actions on some websites.
- xena 1y agoDo you respect robots.txt so administrators can block this tool?
- randunel 1y agoDo user agents doing work for users need to respect robots.txt? If yes, does chrome?
- what 1y agoAny scraper is also a “user agent doing work for users”. Which ones should respect robots.tx?
- randunel 1y agoDoes the user agent fit the definition of a web crawler? If so, then observe robots.txt. This one does not, see https://en.m.wikipedia.org/wiki/Web_crawler https://en.m.wikipedia.org/wiki/Web_crawler
- canogat 1y agoShould I be blocked if I ask Claude Desktop to lower the prices in all of my Craigslist ads by 10%?
- wifipunk 1y agoSetting this up for claude desktop and cursor was alright. Works well out of the box with little setup, and I like that it attached to my active browser tab. Keep up the good work.
- ndr 1y agoWARNING for Cursor users: Cursor is currently stuck using an outdated snapshot of the VSCode Marketplace, meaning several extensions within Cursor remain affected by high-severity CVEs that have already been patched upstream in VSCode. As a result, Cursor users unknowingly remain vulnerable to known security issues. This issue has been acknowledged but remains unresolved: https://github.com/getcursor/cursor/issues/1602#issuecomment-2654870021 https://github.com/getcursor/cursor/issues/1602#issuecomment... Given Cursor's rising popularity, users should be aware of this gap in security updates. Until the Cursor team resolves the marketplace sync issue, caution is advised when using certain extensions. I've flagged it here, apologies for the repost: https://news.ycombinator.com/item?id=43609572 https://news.ycombinator.com/item?id=43609572
- rs186 1y agoI am surprised that the VSCode team hasn't gone after them for mirroring the marketplace, as the Visual Studio team made it very clear that they don't want anybody to do that -- it is their marketplace.
- SSLy 1y agoIt seems that there is one sane PM left at VScode who knows that such move would only lead to MSFT losing more PR. And anti-trust scrutiny?
- JackYoustra 1y agoWhy? This seems fine.
- deleted 1y ago[deleted]
- pknerd 1y agoSo why do I need an editor(Cusror)? How does a non-coder use it?
- rahimnathwani 1y agoIf you're a non-coder, use it with Claude Desktop.
- cadence- 1y agoHow does this compare to Anthropic's Computer Use?
- thenaturalist 1y agoCrazy, in looking up some info on the web and creating a Spreadsheet on Google Sheets to insert the results, it worked almost perfectly the first time and completely failed subsequently on 8-10 different tries. Is there an issue with the lag between what is happening in the browser and the MCP app (in my case Claude Desktop)? I have a feeling the first time I tried it, I was fast enough clicking the "Allow for this chat" permissions, whereas by the time I clicked the permission on subsequent chats, the LLM just reports "It seems we had an issue with the click. Let me try again with a different reference.". Actions which worked flawlessly the first time (rename a Google spreadsheet by clicking on the title and inputting the name) fail 100% of subsequent attempts. Same with identifying cells A1, B1, etc. and inserting into the rows. Almost perfect on 1st try, not reproducible in 100% of attempts afterwards. Kudos to how smooth this experience is though, very nice setup & execution! EDIT 2: The lag & speed to click the allow action make it seemingly unusable in Claude Desktop. :(
- otherayden 1y agoSuch a rich UI like google sheets seems like a bad use case for such a general "browser automation" MCP server. Would be cool to see an MCP server like this, but with specific tools that let the LLM read and write to google sheets cells. I'm sure it would knock these tasks out of the park if it had a more specific abstraction instead of generally interacting with a webpage
- mkummer 1y agoAgreed, I'd been working on a Google Sheets specific MCP last week – just got it published here: https://github.com/mkummer225/google-sheets-mcp https://github.com/mkummer225/google-sheets-mcp
- rahimnathwani 1y agoThis is cool. You should submit this as a 'Show HN'. Also consider publishing it so people can use it without having to use git.
- Gehinnn 1y agoWould be nice if it could use the Accessibility Tree from chrome dev tools to navigate the page instead of relying on screenshots (https://developer.chrome.com/blog/full-accessibility-tree https://developer.chrome.com/blog/full-accessibility-tree)
- mgraczyk 1y agoIn fact you have it backwards. It has no screenshots at the moment, only the accessibility tree
- throwaway81523 1y agoCan these things automatically solve recaptcha? That's the only AI browser feature that I have a real use for.
- SparkyMcUnicorn 1y agohttps://github.com/dessant/buster https://github.com/dessant/buster
- jayunit 1y agoawesome! For the Cursor / React / Click to Add 2 example, can we also have it write a unit/e2e regression test?
- jayunit 1y agoauthor replied on Twitter: > that's a great use case! the aria snapshot that browser mcp generates is enough to write tests for playwright using its role-based locators, but i may add a get_page_html tool in the same way that they're considering: https://github.com/microsoft/playwright-mcp/issues/103 https://github.com/microsoft/playwright-mcp/issues/103 https://x.com/roadtoramen/status/1909356255866733044 https://x.com/roadtoramen/status/1909356255866733044
- otherayden 1y agoI literally started working on the same exact idea last night haha. Great work OP. I'm curious, how are you feeding the web data to the LLM? Are you just passing the entire page contents to it and then having it interact with the page based on CSS selectors/xpath? Also, what are your thoughts on letting it do its own scripting to automate certain tasks?
- andy_ppp 1y agoWhen I go to a shopping website I want to be able to tell my browser "hey please go through all the sideboards on this list and filter out for the ones that are larger than 155cm and smaller than 100cm, prioritise the ones with dark wood and space for vinyl records which are 31.43cm tall" for example. Is there any browser that can do this yet as it seems extremely useful to be able to extract details from the page!
- mfkhalil 1y agoHey, we’re working on MatterRank which is pretty similar to this but currently works on web search. (e.g. I want to prioritize results that talk about X and have Y bias and I want to deprioritize those that are trying to sell me something). Feel free to try it out at https://matterrank.ai https://matterrank.ai Would also be interested in hearing more about what you’re envisioning for your use case. Are you thinking a browser extension that acts on sites you’re already on, or some sort of shopping aggregator that lets you do this, or something else entirely?
- Niksko 1y agoNot OP but I definitely sympathise with them. I don't know how practical it is to implement or how profitable it would be, but the problem I often have is this: * I have something I want to buy and have specific needs for it (height, color, shape, other properties) * I know that there's a good chance the website I'm on sells a product that meets those needs (or possibly several such that I'd want to choose from) * my criteria are more specific than the filters available on the site e.g. I want a specific length down to a few cm because I want the biggest thing that will fit in a fixed space * crucially for an AI use case: the information exists on the individual product pages. They all list dimensions and specifications. I just don't want to have to go through them all. Example: find me all of the desks on IKEA that come in light coloured wood, are 55 inches wide, and rank them from deepest to shallowest. Oh, and make sure they're in stock at my nearest IKEA, or are delivering within the next week.
- bravura 1y agoWhen doing interior decoration, I am definitely interested in finding objects that fit very specific prompts.
- justanotheratom 1y agoneat, but instead of asking me to install browser extension, can you just bundle a browser in the MCP server?
- StevenNunez 1y agoI feel like I slept for a day and now MCPs are everywhere... I don't know what MCPs are and at this point I'm too afraid to ask.
- jastuk 1y agoAnd the worst part is that it opens a pandora's box of potential exploits; https://elenacross7.medium.com/%EF%B8%8F-the-s-in-mcp-stands-for-security-91407b33ed6b https://elenacross7.medium.com/%EF%B8%8F-the-s-in-mcp-stands...
- halJordan 1y agoAt the risk of it sounding like i support theft; the automobile, you know, enabled the likes of Bonnie and Clyde and that whole era of lawlessness. Until the fbi and crossing county lines became a thing. So im not sure id give up the sum total progress of the automobile just because the first decade was a bad one
- joshwarwick15 1y agoMost of these are not a real concern with remote servers with Oauth. If you install the PayPal MCP MCP server from im-deffo-not-hacking-you.com than https://mcp.paypal.com/sse https://mcp.paypal.com/sse its the same sec model as anything else online... The article also reeks of LLM ironically
- tuananh 1y agoit still is. if user has 1 bad tool, it's done! https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks https://invariantlabs.ai/blog/mcp-security-notification-tool...
- joshwarwick15 1y agoIts the same security model as NPM/left pad yep, but consumers still use electron apps? It's a novel attack method, but its not a novel attack surface
- sdotdev 1y agoStill slightly confused on what MCPs are but looking at this it does look useful
- esafak 1y agoA protocol (the P in MCP) for LLMs to use tools.
- aryehof 1y agoA plugin protocol that allows “applications” to interact with LLMs.
- darepublic 1y agowouldn't it be for LLMs to interact with applications?
- aryehof 1y agoWell they do work two ways. Extend an application to access an LLM, and allow an LLM to get context from an application. For LLMs to interact with applications (without a two way protocol) is achievable just with tools/functions.
- therealesxi2i 1y ago[dead]
- lxe 1y agoThis one also uses aria snapshots formatted as yaml. This will quickly exceed context limits.
- revskill 1y agoCan u expose the sdk as a react component to be used inside an app ?
- mvdtnz 1y agoIs anyone successfully running MCPs / Claude Desktop on Linux?
- iDon 1y agoI am running this OK in Ubuntu 2404 : https://github.com/aaddrick/claude-desktop-debian https://github.com/aaddrick/claude-desktop-debian Claude Desktop for Debian-based Linux distributions From Claude I have connected to these MCP servers OK : @modelcontextprotocol/server-filesystem, @executeautomation/playwright-mcp-server. I have connected to OP's extension (browsermcp.io) from vsCode (and clicked 1 tab button OK), but not from Claude desktop so far (I get Cannot find module 'node:path'; which is require-d in npm/lib/cli.js; tried node 18,20,22; some suggestions here : https://medium.com/@aleksej.gudkov/error-cannot-find-module-node-path-causes-and-solutions-76683c6a6dd2 https://medium.com/@aleksej.gudkov/error-cannot-find-module-... ).
- pavelfeldman 1y agoI mean no disrespect, but this looks like an outdated clone of https://github.com/microsoft/playwright-mcp https://github.com/microsoft/playwright-mcp https://github.com/microsoft/playwright-mcp/blob/main/src/tools/tool.ts https://github.com/microsoft/playwright-mcp/blob/main/src/to... https://github.com/BrowserMCP/mcp/blob/main/src/tools/tool.ts https://github.com/BrowserMCP/mcp/blob/main/src/tools/tool.t...
- marifjeren 1y agoFrom the Browser MCP README.md: > Credits: Browser MCP was adapted from the Playwright MCP server
- namuorg 1y agoHey Pavel, this is Namu, the creator of Browser MCP. You’re right, this is an adaptation of Playwright MCP to automate the user’s local browser as mentioned in the GitHub README and here: - https://github.com/BrowserMCP/mcp/blob/3e6824de6f36eba7d2d3b15f76b768f0ddf0f03b/README.md#credits https://github.com/BrowserMCP/mcp/blob/3e6824de6f36eba7d2d3b... - https://news.ycombinator.com/item?id=43613905 https://news.ycombinator.com/item?id=43613905 Thanks for all your work to Playwright and Playwright MCP. I’m a big fan! (For those not familiar, Pavel is the largest contributor to both Playwright and Playwright MCP: https://github.com/microsoft/playwright/graphs/contributors https://github.com/microsoft/playwright/graphs/contributors, https://github.com/microsoft/playwright-mcp/graphs/contributors https://github.com/microsoft/playwright-mcp/graphs/contribut...)
- pavelfeldman 1y agoHi Namu, all good! Feel free to send us the patches and work upstream, would be happy to see you on board!
- doug_life 1y agoThis may be obvious to most here, but you need Node.js installed for the MCP server to run. This critical detail is not in the set up instructions.
- hliyan 1y agoIdeally, shouldn't this be the native experience of most "sites" on the internet? We've built an entire user experience around serving users rich, two dimensional visual content that is not machine-readable and are now building a natural language command line layer on top of it. Why not get rid of the middleware and present users a direct natural language interface to the application layer?
- tuananh 1y agoi want to add this for my project (which use wasm) but rustlang/socket2 WASI support is not merged yet. after that rust CDP will work.
- toutiao6 1y ago[dead]
- tuananh 1y ago> The moment tools like socket2 or HTTP clients land with Preview2 i'm waiting for that as well. my other options are - either bind a host function to manage wss connection to wasm. fork a CDP lib to use that. - create a proxy between http/wss maybe. And then fork a CDP lib to use http proxy i think.
- toutiao6 1y ago[dead]
- webprofusion 1y agoOr just use Playwright MCP: https://github.com/microsoft/playwright-mcp https://github.com/microsoft/playwright-mcp
- knes 1y agoThis is great. Especially debugging frontend issue on localhost or staging. Also works flawlessly with augment code.com too!
- makingstuffs 1y agoI don't see how an MCP can be useful for browsing the net and doing things like shopping as has been suggested. Large companies such as CloudFlare have spent millions on, and made a business from, bot detection and blocking. Do we suppose they will just create a backdoor to allow _some_ bots in? If they do that how long will it be before other bots impersonate them? It seems like a bit of a fad from my small mind. Suppose it does become a thing, what then? We end up with an internet which is heavily optimised for bots (arguably it already is to an extent) and unusable for humans? Wild.
- kraftman 1y agoThere are already plenty of services that provide residential proxies and captcha bypass pretty cheaply. https://brightdata.com/pricing/web-unlocker https://brightdata.com/pricing/web-unlocker https://2captcha.com/pricing https://2captcha.com/pricing
- TeMPOraL 1y ago> Suppose it does become a thing, what then? We end up with an internet which is heavily optimised for bots (arguably it already is to an extent) and unusable for humans? As opposed to the Web we now have, which is heavily optimized for... wasting human life. What you're asking for, what "large companies such as CloudFlare have spent millions on", is verifying that on the other end of the connection is a web browser, and behind that web browser there is a human being that's being made to needlessly suffer and waste their limited lifespans, as they tediously work their way through the UI maze like a good little lab rat, watching ads at every turn of the corridor, while being constantly surveilled. Or do you believe there is some other reason why you should care about whether you're interacting with a "human" (really: an user agent called "web browser") vs. "not human" (really: any other user agent)? The relationship between the commercial web and its users is antagonistic - businesses make money through friction, by making it more difficult for users to accomplish their goals. That's why we never got the era of APIs and web automation for users. That's why we're dealing with tons of bespoke shitty SPAs instead of consistent interfaces - because no store wants to make it easy for you to comparison-shop, or skip their upsells, or efficiently search through the stock; no news service wants you to skip ads or make focused searches, etc. As users, we've lost the battle for APIs and continue to be forced to use the "manual web" (with active cooperation of the browser vendors, too). MCP feels promising because we're in a moment in time, however brief, where LLMs can navigate the "manual web" for us, shielding us from all the malicious bullshit (ads, marketing copy, funneling, call to actions, confusing design, dark patterns, less dark patterns, the fact that your store is a bloated SPA instead of an endpoint for a generic database querying frontend, and so on) while remaining mostly impervious to it. This will not last long - the vendors de-facto ruling the web have every reason to shut it down (or turn it around and use LLMs against us). But for now, it works. Adversarial interoperability is the name of the game. LLMs, especially combined with tool use (and right tools), make it much easier and much more accessible than ever before. For however brief a moment.
- rmac 1y ago[!warning!] 1) this projects' chrome extension sends detailed telemetry to posthog and amplitude: - https://storage.googleapis.com/cobrowser-images/telemetry.png https://storage.googleapis.com/cobrowser-images/telemetry.pn... - https://storage.googleapis.com/cobrowser-images/pings.png https://storage.googleapis.com/cobrowser-images/pings.png 2) this project includes source for the local mcp server, but not for its chrome extension, which is likely bundling https://github.com/ruifigueira/playwright-crx https://github.com/ruifigueira/playwright-crx without attribution super suss
- arresin 1y agoThe only chrome extensions you should install are ones you can build yourself from source.
- neycoda 1y ago... And have reviewed and understand completely
- EGreg 1y agoSo ... pretty much none Keep in mind, extensions can update themselves at any time, including when they're bought out by someone else. In fact, I bet that's a huge draw... imagine buying an extension that "can read and modify data on all your websites" and then pushing an update that, oh I dunno, exfiltrates everyone's passwords from their gmail. How would most people even catch that? DO NOT have any extensions running by default except "on click". There should be at least some kind of static checker of extensions for their calls to fetch or other network APIs. The Web is just too permissive with updating code, you've got eval and much more. It would be great if browsers had only a narrow bottleneck through which code could be updated, and would ask the user first. (That wouldn't really solve everything since there can be sleeper code that is "switched on" with certain data coming over the wire, but better than what we have now.)
- metadat 1y ago
- mrwww 1y agoHow does it compare to playwright mcp?
- deleted 1y ago[deleted]
- metadat 1y agoBot Detection Evasion is becoming an increasingly relevant topic. Even for non-abusive automation, it's now a necessary consideration. Interesting research and reading via the HN search portal: https://hn.algolia.com/?q=bot+detection https://hn.algolia.com/?q=bot+detection
- josefrichter 1y agoWhat I used this for: "Go to https://news.ycombinator.com/upvoted?id=josefrichter https://news.ycombinator.com/upvoted?id=josefrichter, summarize what topics I am interested in, and then from the homepage pick articles I might be interested in." Works like a charm.
- khana 1y ago[dead]
- plessas 1y agothank you for this. Using my own browser helps me automate tasks on sites I 'd typically get detected using automation. Works like a charm! Hope you continue to work on the repo.