by AgentDeskAI
Monitor browser logs directly from Cursor and other MCP compatible IDEs.
# Add to your Claude Code skills
git clone https://github.com/AgentDeskAI/browser-tools-mcpGuides for using mcp servers skills like browser-tools-mcp.
Last scanned: 4/18/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-04-18T05:43:36.172Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}browser-tools-mcp is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by AgentDeskAI. Monitor browser logs directly from Cursor and other MCP compatible IDEs. It has 7,298 GitHub stars.
Yes. browser-tools-mcp passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/AgentDeskAI/browser-tools-mcp" and add it to your Claude Code skills directory (see the Installation section above).
browser-tools-mcp is primarily written in TypeScript. It is open-source under AgentDeskAI on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh browser-tools-mcp against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Give your AI coding agent eyes on the browser. BrowserTools MCP streams console output, network activity, screenshots and Lighthouse audits from your real Chrome session — the one already logged into your app — to any MCP-compatible client: Cursor, Claude Code, Windsurf, Cline, Zed, Gemini CLI, and others.
Version 2.0 is a rewrite. One process instead of three, no unauthenticated local server, credentials scrubbed before they leave the browser, and a real test suite. If you are coming from 1.x, read MIGRATION.md — and upgrade, because 1.2.x has a critical vulnerability. See SECURITY.md.
Tools like Chrome DevTools MCP and Playwright MCP drive a fresh, automated browser. That is the right choice for writing tests. It is the wrong choice for debugging the app you are actually looking at, because since Chrome 136 the browser refuses remote debugging on your default profile — the one holding your logins. So you end up recreating your auth state in a throwaway profile before you can debug anything.
BrowserTools attaches to the session you are already in, through a DevTools extension. You stay logged in, on the page you were already on, and your agent reads what you see. It also reports Lighthouse-grade performance, accessibility and SEO data, which the automation-first servers do not.
Two pieces: an MCP server (one command) and a Chrome extension.
{
"mcpServers": {
"browser-tools": {
"command": "npx",
"args": ["-y", "@agentdeskai/browser-tools-mcp@latest"]
}
}
}
On Windows, if your client cannot find npx, use "command": "cmd" with
"args": ["/c", "npx", "-y", "@agentdeskai/browser-tools-mcp@latest"].
Requires Node 22.19 or newer. Check with node --version; if you use nvm or
asdf, make sure your editor inherits the same version.
chrome://extensions and turn on Developer mode.chrome-extension directory.That is the whole setup. There is no second server to start — the MCP server runs the connector itself.
Open Chrome DevTools (F12) on the page you want to inspect. Capture begins as soon as DevTools is open; the BrowserTools panel is only for settings and status. Then ask your agent something like "check the console for errors" or "run an accessibility audit on this page".
Not working? Run npx @agentdeskai/browser-tools-mcp --doctor, which reports
exactly which piece is missing.
To watch capture happen live — useful when checking a fresh install — start the
connector with --verbose:
npx @agentdeskai/browser-tools-server --verbose
· console error tab 42 Uncaught TypeError: total is not a function
· network 500 POST tab 42 https://myapp.local/api/pay (1310ms)
Without it the connector only reports connect and disconnect, so a working setup and a silent one look the same.
| Tool | What it does |
|---|---|
getConsoleLogs |
Console output, filterable by keyword with paging |
getConsoleErrors |
Error-level output and uncaught exceptions |
getNetworkLogs |
XHR/fetch requests with status, timing and bodies |
getNetworkErrors |
Only failed and 4xx/5xx requests |
getSelectedElement |
The element selected in the Elements panel |
getPageInfo |
Which page the browser is currently on |
getConnectionStatus |
Whether the extension is connected, and capture counts |
listBrowserTabs |
Every tab with DevTools open, and the id to address it by |
takeScreenshot |
Screenshot returned as an image, plus its file path |
refreshBrowser |
Reloads the inspected tab |
getBrowserStorage |
localStorage, sessionStorage and cookies (values gated) |
wipeLogs |
Clears captured telemetry before a clean reproduction |
runAccessibilityAudit |
Lighthouse accessibility audit |
runPerformanceAudit |
Lighthouse performance audit with Core Web Vitals |
runSEOAudit |
Lighthouse SEO audit |
runBestPracticesAudit |
Lighthouse best-practices audit |
Three prompts ship alongside them — debuggerMode, auditMode and
nextjsSeoAudit — giving your agent a systematic workflow instead of a wall of
static text in every tool listing.
All tools declare MCP output schemas, so clients receive structured data rather than prose they have to parse, and read-only tools are annotated as such so clients can auto-approve them safely.
Every tab with DevTools open is tracked separately. Telemetry is attributed to the tab that produced it, and retention is per tab, so a chatty page cannot push out the history of the one you care about.
Tools act on the current tab — the one you most recently opened DevTools on.
A tab whose connection drops and comes back does not steal that position, which
is what used to make screenshots capture the wrong page. Every result reports
the tabId and url it came from, plus otherTabs, so a wrong-tab answer is
visible rather than silent. To target a specific tab, call listBrowserTabs and
pass its tabId to any tool; pass allTabs: true to read across every tab.
Whole-history payloads are exposed as MCP resources rather than inlined, and
tools link to them with resource_link so your agent fetches them only when it
decides to:
| Resource | What it is |
|---|---|
browser-tools://console/{tabId|all} |
Every console entry, with no per-call budget |
browser-tools://network/{tabId|all} |
Every captured request, including bodies |
browser-tools://har/{tabId|all} |
The same traffic as a HAR 1.2 file |
browser-tools://screenshot/{name} |
A screenshot you captured earlier |
browser-tools://audit/{reportId} |
The unabridged Lighthouse result behind a summary |
Log tools attach a link when a read had to be cut short; network reads always
offer the HAR; screenshots always link to the stored image, which is the only
way to see one too large to inline. The last 20 full Lighthouse reports are kept
under audits/ in the screenshot directory.
Log payloads are the usual cause of a blown context window. Every read tool
takes limit and offset, and the log tools take keyword filters:
getConsoleErrors({ keywords: ["hydration"], limit: 20 })
getNetworkLogs({ urlKeywords: ["/api/"], bodyKeywords: ["quota"], limit: 10 })
Results are returned newest-first and always report total alongside
returned, so an agent knows when it is only seeing part of the picture.
This tool captures whatever your browser sees, so it treats that data carefully:
127.0.0.1 and refuses non-loopback
addresses. In 1.x it bound 0.0.0.0, reachable by anyone on your network.Authorization, Cookie and
similar headers, plus JWTs, cloud keys and vendor tokens found anywhere in
captured strings, become [REDACTED].Report vulnerabilities per SECURITY.md.
Flags, or the matching BROWSER_TOOLS_* environment variables:
| Flag | Purpose |
|---|---|
--port <n> |
Connector port (default 3025) |
--screenshot-dir <path> |
Where screenshots are written |
--only <a,b> |
Expose only these tools |
--exclude <a,b> |
Hide these tools |
--doctor |
Check the setup and exit |
--verbose |
Print each captured entry as it arrives |
--host <addr> |
Loopback address to bind (default 127.0.0.1) |
--connect <url> |
Attach to a connector already running elsewhere |
--token <t> |
Auth token to use with --connect |
--no-redact |
Disable credential scrubbing (not recommended) |
To share one browser session between several MCP clients, start the connector
once with npx @agentdeskai/browser-tools-server and every client will attach to
it automatically.
screenshotMaxBytes, 3 MB by default).
A capture that would exceed it is re-encoded as JPEG and, if still too large,
downscaled. A viewport capture of dense content on a high-DPI display can
otherwise run past 13 MB, which is more than a model's context can take and
past the read buffer newer MCP stdio transports enforce. If an image still
cannot fit, it is written to disk and the tool returns the path instead of
inlining it.browser/chrome shim, browser_specific_settings, and a capture mode that
does not need chrome.debugger — but it has never been loaded in Firefox, and
nothing in the test suite covers it. Screenshots in particular go through the
DevTools protocol and will not work there. Treat Fi