BrowserPilot: MIT-licensed local MCP browser control with per-action approvals
ZenovaStore · reddit · 2026-10-04
The maintainer released BrowserPilot, an MIT-licensed local MCP browser-control layer connecting an agent to an existing Chromium profile via an unpacked extension or an isolated Playwright profile, exposing a 50-tool registry over stdio: semantic targeting, tab management, screenshots, PDF, video frames, extraction, staged uploads/downloads, human handoff.
Security design:
- All sites start unapproved; clicks, typing, uploads and download triggers require one-use local approvals bound to the exact request;
- No arbitrary JS, shell, cookie or browser-storage tools; actions don't steal focus.
Caveats stated by the author: a tab group isn't a session sandbox (shared profile accounts), read access can expose personal info to your agent, and the project has had no independent security audit. Requires Node 22+, no hosted service; agent costs separate. Ships with 27 automated tests and a validation doc.
More from coding & agent
- Sriram Krishnan: Agents need fundamentally better security primitives, and we're in an awkward intermediate era — latticecut · 2026-10-04
- How do juniors become seniors when AI does junior work? — Paimaamu · 2026-10-04
- Engineering's goal isn't code—it's engineers who understand systems — Paimaamu · 2026-10-04
- Open-source MCP server gives AI assistants live HTTP/HTTPS capture, replay and mocking on Windows — Remote-Lecture8035 · 2026-10-04
- eptwts: AI wrappers shouldn't compete on price but on harness quality — eptwts · 2026-10-04
- xAI Launches Grok Bot: AI Teammates That Log Into Your Tools and Finish Work Autonomously — elonmusk · 2026-10-04