
Jet Browser Verifier
io.github.masakaaiv0.8.0更新于 Oct 10, 2026
Verify an isolated WPE WebKit runtime with native-input, DOM, PNG, and cleanup evidence.
概览
让助手对隔离的 WPE WebKit 运行时执行一次有界验证,并返回原生输入、DOM、PNG 与清理证据。
- 功能
- 该服务器提供两个工具。jet_browser_capabilities 在不启动 Docker 的情况下返回固定镜像、平台、证据约定和明确的非能力范围(R25)。jet_browser_verify 执行一次有界验证:启动不可变的公共 linux/amd64 镜像,禁用浏览器网络,打开镜像内的本地夹具,通过原生输入键入内容,检查 DOM,截取新的 PNG 并清理(R3、R26)。同一时间只能运行一次验证,失败会以 MCP 工具错误返回(R27、R29)。
- 适用场景
- 当你需要可重复、隔离地检查 WPE WebKit 运行时能否启动、接受原生输入、渲染出预期 DOM 并生成有效截图时使用。它是运行时验证器,不是通用浏览服务器,不提供公共网页导航、CDP、个人浏览器配置文件、凭据、托管服务或遥测(R4、R5)。
- 运行要求
- 需要 Node.js 24+ 和 Docker(R7),以及 x86_64 主机或 Docker amd64 模拟(R8)。启动 MCP 镜像时需挂载 Docker socket(R14);首次验证可能从 GHCR 拉取公共镜像(R9)。未声明任何认证、环境变量或请求头。
安装
在 SourceWeft 中
- 打开 控制台中的 Jet Browser Verifier,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
Jet Browser MCP verifier
This local stdio server gives an MCP client one narrow way to verify Jet Browser. It starts the immutable public linux/amd64 image, disables browser networking, opens the image's local fixture, types through native input, checks the DOM, captures a fresh PNG, and cleans up.
It is a runtime verifier, not a general browsing server. It does not expose public-web navigation, CDP, personal browser profiles, credentials, a hosted service, or telemetry.
Requirements
- Node.js 24+
- Docker
- An x86_64 host, or Docker amd64 emulation
The first verification may pull the public image from GHCR. Browser execution itself uses Docker's --network=none boundary. The image is pinned by digest in server.mjs.
Install from the OCI package
The versioned MCP image starts the stdio server directly. It needs the Docker socket only when jet_browser_verify launches the separately isolated WPE WebKit runtime:
Docker socket grants host-level control. Configure this local server only for a trusted MCP client. The outer MCP container has networking disabled, and the browser container it launches independently uses --network=none, resource limits, reduced capabilities, and deterministic cleanup.
The package metadata for the official MCP Registry is server.json. The OCI image carries the matching io.modelcontextprotocol.server.name ownership annotation.
Install from source
Add the server to an MCP client with an absolute checkout path:
The process speaks MCP on stdout and writes operational errors only to stderr. It exits when the client closes stdin.
Tools
Only one verification can run at a time. A client-side cancellation aborts the child process. The server caps child output and total runtime; failures are returned as MCP tool errors rather than protocol failures.
A successful call returns structured content like:
The screenshot byte count varies. A pass requires at least 1,000 decoded PNG bytes and exact agreement among the expected page title, native text input, and DOM state.
Verify the integration
The protocol test starts the real stdio server, performs an MCP handshake, lists its tools, and calls the capability tool without requiring Docker:
The repository's standalone CI remains the end-to-end runtime proof. To execute that same Docker acceptance locally:
Security boundary
- The MCP call accepts no command, URL, image, profile, or path argument.
- The child process receives only the Docker connection variables it needs; application secrets are not forwarded.
- The container has browser networking disabled, bounded CPU, memory, PIDs, shared memory, and capabilities, and is removed after the check.
- The verifier never attaches to a running personal browser.
- Treat Docker access as privileged host access. Only configure this server for trusted local MCP clients.
For a broader embedding boundary, use Jet Browser's versioned tool declarations in sdk/tools.mjs and supervise each isolated container from your own harness.
来源:integrations/mcp/README.md,提交 5114d06
工具
0版本历史
1- v0.8.0最新Oct 10, 2026


