
Zamery Browser
io.github.maemreyov0.1.2更新于 Oct 6, 2026
Use your existing Firefox and logged-in tabs, limited to tabs or groups you explicitly share.
概览
让本地代理在你明确共享的标签页和标签组上使用你现有的、已登录的 Firefox。
- 功能
- 这是一个独立的 MCP 服务器,把本地代理连接到你在用的 Firefox,范围仅限你选择共享的标签页和标签组(R2)。工具涵盖连接与访问状态(browser_status、browser_request_access)、共享标签页与快照(browser_contexts、browser_snapshot)、点击/填写/输入/按键等合成 DOM 操作、交接与占用控制、变更状态查询,以及标签页和标签组管理(R29-R39)。快照只暴露控件,不含表单值和隐藏控件,每次变更都带稳定的 request_id(R33、R40)。它不暴露原始 JavaScript 或 eval,代理也无法自行授予权限(R4)。
- 适用场景
- 当助手需要在你真实且已登录的 Firefox 会话中工作,而不是另开无头浏览器时使用,例如读取或操作你特意共享的特定页面。适合希望按标签页或标签组授权、授权时长可选本次会话或 1 至 30 天、并可随时接管的场景(R20、R23)。它不适合无人值守地自动化整个浏览器,因为访问权限始终由你在 Firefox 中授予(R18、R31)。
- 运行要求
- 以 npm 包 @zamery/browser-mcp 通过 stdio 在本地运行,通常用 npx 启动(R1、R2)。还需要 @zamery/browser-firefox 提供的 Firefox 配套扩展与原生主机(R7),以及桌面版 Firefox 和你要共享的标签页或标签组。可选环境变量:ZAMERY_BROWSER_MCP_STATE_DIR、ZAMERY_BROWSER_MCP_CONSUMER_ID、ZAMERY_BROWSER_MCP_BROWSER_INSTANCE_ID、ZAMERY_BROWSER_MCP_PROVIDER(R44-R47)。未声明任何身份验证。
安装
在 SourceWeft 中
- 打开 控制台中的 Zamery Browser,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
@zamery/browser-mcp
A standalone MCP server that lets a local agent (for example Codex) use the Firefox you are already using — with your logins — on only the tabs and tab groups you choose to share.
It does not depend on Pi or Zamery Workbench. It does not expose raw JavaScript/eval, and the agent cannot grant itself access.
Status: stable
0.1.2, released with Zamery Browserv0.2.3and Mozilla-signed/public Companion0.2.5. Clean published-artifact acceptance, signed real-profile acceptance and Official MCP Registry publication all pass.
Install
You also need the Firefox companion and the native host from @zamery/browser-firefox (see its README).
Official MCP Registry: io.github.maemreyo/zamery-browser.
Codex recipe (needed for screenshots)
In a tested Codex setup the model did not receive inline MCP images, so it guessed what a screenshot showed. browser_screenshot therefore also returns a local image file path, and the model must open it with its image viewer. Add codex/AGENTS.snippet.md to your project's AGENTS.md (or install codex/skill/zamery-browser as a Codex skill). With it, a neutral visual question was answered correctly 3/3 against a real Firefox; without it, 0/2.
How access works
- The agent calls
browser_status. It always works, even before Firefox is connected or anything is shared, and says what to ask you. If Firefox is connected but nothing is shared, the agent may callbrowser_request_accessonce to ask for your attention. The request contains no tab/group/action/duration choices and never grants anything. - Firefox shows a toolbar badge and, if you enabled optional notifications, a generic OS notification. You open the Zamery Browser panel and choose the local agent, the tab(s) or group, what the agent may do, and for how long (this session, or 1–30 days).
- The agent calls
browser_contexts/browser_snapshot. A snapshot withclaim=true(default) takes the write claim; the returned short refs (e1,e2, …) can then be used withbrowser_click,browser_fill,browser_type,browser_key. - You can take over at any time from the panel. In the default
interactivemode, using the claimed page also hands control to you. With explicit Background control, ordinary use of the same shared page only invalidates the agent's old snapshot; it can take a fresh snapshot and continue. While explicit user control is active, the agent cannot act and can only ask you to resume.
Sign-in, one-time-code and payment fields are never filled by the agent: they are flagged CREDENTIAL in snapshots and writes are refused; use browser_handoff (request_user_takeover).
Tools
Every mutation carries a stable request_id. After a timeout or a lost response the outcome may be outcome_unknown: the agent must not retry with a new id; it checks browser_mutation_status and the page.
Configuration (environment)
The consumer id binds your grant to this installation, so restarting the MCP process or the agent keeps working under the same approval. It is a same-OS-user routing key, not an authenticated identity.
Trust boundary
The local Firefox bridge trusts the logged-in OS user. Another process of the same user could talk to the bridge, but still needs the grant you created in Firefox for its own consumer id. Page content (titles, URLs, control names) is untrusted data and is labelled as such in tool output.
License
Apache-2.0.
来源:packages/browser-mcp/README.md,提交 7db39b1
工具
0版本历史
1- v0.1.2最新Oct 6, 2026


