Stealth Agent Browser
NPM · STEALTH-AGENT-BROWSER-MCP · SCANNED SEP 20
Stealth Chromium MCP server with hybrid AOM + Set-of-Mark vision and Readability extraction.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security81
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known high-severity CVE affects sharp 0.33.5, a direct dependency. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- 51 of 193 dependencies flagged as unhealthy (1 deprecated). View diagnostics → Partial
Provenance & Transparency48
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (Apache-2.0).Pass
- Actively maintained (last published 158 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability77
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 959 tokens (~73/item across 13 items; 13 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
- Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage86
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 58% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "browser_eval" implies "eval" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Stealth Agent Browser MCP server?
Stealth Agent Browser runs locally as an npm package, launched with npx -y stealth-agent-browser-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · stealth-agent-browser-mcp
claude mcp add ykshah1309-stealth-agent-browser-mcp -- npx -y stealth-agent-browser-mcp
{
"mcpServers": {
"ykshah1309-stealth-agent-browser-mcp": {
"command": "npx",
"args": [
"-y",
"stealth-agent-browser-mcp"
]
}
}
} {
"servers": {
"ykshah1309-stealth-agent-browser-mcp": {
"command": "npx",
"args": [
"-y",
"stealth-agent-browser-mcp"
]
}
}
} codex mcp add ykshah1309-stealth-agent-browser-mcp -- npx -y stealth-agent-browser-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ykshah1309-stealth-agent-browser-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"stealth-agent-browser-mcp"
],
"enabled": true
}
}
} openclaw mcp add ykshah1309-stealth-agent-browser-mcp --command npx --arg -y --arg stealth-agent-browser-mcp
mcp_servers:
ykshah1309-stealth-agent-browser-mcp:
command: "npx"
args: ["-y", "stealth-agent-browser-mcp"] {
"McpServers": {
"ykshah1309-stealth-agent-browser-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"stealth-agent-browser-mcp"
]
}
}
} assistant mcp add ykshah1309-stealth-agent-browser-mcp -t stdio -c npx -a -y stealth-agent-browser-mcp
{
"mcpServers": {
"ykshah1309-stealth-agent-browser-mcp": {
"command": "npx",
"args": [
"-y",
"stealth-agent-browser-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −3
- Stability: pass → 0.80 functional
- 16 Sept 26 0
- Stability: 0.97 → pass security
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 −3
- Stability: pass → 0.80 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/stealth-agent-browser-mcp@0.2.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Vulnerabilities 3 findings
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-3p6v-hrg8-8qj7 | CVE-2025-2792 | low | yes | |
| GHSA-f88m-g3jw-g9cj | high | yes | ||
| GHSA-rgj7-g3m4-5g8c | high | yes |
Background: What a vulnerability scan can and cannot prove →
Dependencies 193 packages
| Packages resolved | 193 |
|---|---|
| Deprecated | 1 |
| Stale | 51 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
browser_click ~92
Click an element addressed by its ref. When SAB_HUMAN_MOUSE=true (default), the cursor travels via a Bezier path with pre-click hesitation — this defeats trajectory analyzers like Datadome that flag teleporting mice.
| Name | Type | Req | Description |
|---|---|---|---|
| button | string | – | – |
| clickCount | integer | – | – |
| ref | string | yes | A [ref=eN] id taken from the last aom/hybrid snapshot. |
No output schema declared.
No examples provided.
browser_eval ~75
Evaluate a JS EXPRESSION in the page's MAIN execution world. Observable by page scripts; use sparingly. Prefer AOM + action tools.
| Name | Type | Req | Description |
|---|---|---|---|
| expression | string | yes | JS expression (not a statement). Executes in the page's MAIN execution world — observable by page scripts. Use sparingly; prefer AOM + actions. |
No output schema declared.
No examples provided.
browser_navigate ~90
Navigate the active session's page to a URL. Returns a snapshot (default: aom-only, cheapest).
| Name | Type | Req | Description |
|---|---|---|---|
| mode | string | – | Snapshot mode to return after navigation. 'aom' is cheapest; 'hybrid' adds a Set-of-Mark annotated screenshot. |
| url | string | yes | Fully-qualified URL to navigate to. |
| waitUntil | string | – | Page lifecycle event to wait for. |
No output schema declared.
No examples provided.
browser_restart ~39
Close the active browser session and start a fresh one with the current config. Required after 'browser_set_proxy' to actually route new requests through the proxy.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
browser_scroll_read ~75
Scroll and return a Readability-extracted Markdown view. With deltaOnly=true, returns '(no change)' if nothing new became visible — keeps context windows lean.
| Name | Type | Req | Description |
|---|---|---|---|
| deltaOnly | boolean | – | Return markdown only if the readable content changed since the last call. |
| direction | string | – | – |
| pixels | integer | – | – |
No output schema declared.
No examples provided.
browser_select ~36
Select one or more options in a <select> addressed by ref.
| Name | Type | Req | Description |
|---|---|---|---|
| ref | string | yes | – |
| values | array | yes | – |
No output schema declared.
No examples provided.
browser_set_proxy ~74
Update the proxy config. Call 'browser_restart' after this for the change to take effect (browser-level constraint — an existing context cannot be re-routed).
| Name | Type | Req | Description |
|---|---|---|---|
| password | string | – | – |
| server | string | – | e.g. http://host:port — omit to clear. |
| username | string | – | – |
No output schema declared.
No examples provided.
browser_set_proxy_pool ~86
Replace the residential proxy pool at runtime. Takes effect on the next 'browser_restart'. Supports sticky sessions via SAB_PROXY_STICKY_TEMPLATE.
| Name | Type | Req | Description |
|---|---|---|---|
| pool | string | – | Residential proxy pool: comma-separated URLs (http://u:p@host:port) or a JSON array. Omit to clear. |
| rotation | string | – | Rotation strategy. Default: per-restart. |
No output schema declared.
No examples provided.
browser_snapshot ~87
Take a snapshot of the current page. 'aom' returns the accessibility YAML (token-lean); 'hybrid' adds a Set-of-Mark screenshot with numeric red boxes matching each ref.
| Name | Type | Req | Description |
|---|---|---|---|
| mode | string | – | 'aom' = accessibility YAML only (cheap). 'vision' = raw screenshot. 'hybrid' = YAML + screenshot with red-boxed refs overlaid. |
No output schema declared.
No examples provided.
browser_solve_captcha ~136
Fallback captcha solver. Detects Turnstile/hCaptcha/reCAPTCHA on the current page (or takes an explicit sitekey), submits to the configured provider (CapSolver or 2Captcha per SAB_CAPTCHA_PROVIDER + SAB_CAPTCHA_API_KEY), polls for a token, and injects it into the widget's response field.
| Name | Type | Req | Description |
|---|---|---|---|
| pageUrl | string | – | Page URL the captcha is bound to. Defaults to the current page. |
| sitekey | string | – | Provide explicitly when auto-detection fails. |
| type | string | – | Override auto-detection. Otherwise the active page is scanned for a known widget. |
No output schema declared.
No examples provided.
browser_tabs ~41
Manage browser tabs: list, new, close, switch.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| index | integer | – | – |
| url | string | – | – |
No output schema declared.
No examples provided.
browser_type ~62
Type into an input or textarea addressed by ref.
| Name | Type | Req | Description |
|---|---|---|---|
| clear | boolean | – | Clear the field before typing. |
| ref | string | yes | Ref of an input/textarea element. |
| submit | boolean | – | Press Enter after typing. |
| text | string | yes | – |
No output schema declared.
No examples provided.
browser_wait_for ~66
Wait until either some text appears on the page or a given ref resolves to a visible element.
| Name | Type | Req | Description |
|---|---|---|---|
| ref | string | – | Ref that must resolve to a visible element. |
| text | string | – | Substring to wait for in page text. |
| timeoutMs | integer | – | – |
No output schema declared.
No examples provided.
What is the Stealth Agent Browser MCP server?
Stealth Agent Browser is an MCP server listed in the public MCP registry as io.github.ykshah1309/stealth-agent-browser-mcp. Stealth Chromium MCP server with hybrid AOM + Set-of-Mark vision and Readability extraction. This page covers its npm package (stealth-agent-browser-mcp).
Is the Stealth Agent Browser MCP server safe to use?
Stealth Agent Browser scores 76 out of 100 on VerifyMCP. We recorded 3 known advisories against it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Stealth Agent Browser MCP server expose?
Stealth Agent Browser exposes 13 tools: browser_navigate, browser_snapshot, browser_click, browser_type, browser_select, and 8 more. Their descriptions and schemas cost roughly 959 tokens of context every time the server is loaded.
Is the Stealth Agent Browser MCP server still maintained?
Stealth Agent Browser is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Stealth Agent Browser MCP server under?
Stealth Agent Browser declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.