Zamery Browser

io.github.maemreyov0.1.2更新於 Oct 6, 2026

Use your existing Firefox and logged-in tabs, limited to tabs or groups you explicitly share.

概覽

AI 產生的概覽

讓本機代理在你明確共享的分頁與分頁群組上,使用你現有且已登入的 Firefox。

功能
這是一個獨立的 MCP 伺服器,把本機代理連接到你正在使用的 Firefox,範圍僅限你選擇共享的分頁與分頁群組(R2)。工具涵蓋連線與存取狀態(browser_status、browser_request_access)、共享分頁與快照(browser_contexts、browser_snapshot)、點擊/填寫/輸入/按鍵等合成 DOM 操作、交接與占用控制、變更狀態查詢,以及分頁與分頁群組管理(R29-R39)。快照只暴露控制項,不含表單值與隱藏控制項,每次變更都帶穩定的 request_id(R33、R40)。它不暴露原始 JavaScript 或 eval,代理也無法自行授予權限(R4)。
適用情境
當助手需要在你真實且已登入的 Firefox 工作階段中工作,而不是另開無頭瀏覽器時使用,例如讀取或操作你特意共享的特定頁面。適合希望依分頁或分頁群組授權、授權時長可選本次工作階段或 1 至 30 天、並可隨時接管的場景(R20、R23)。它不適合無人看管地自動化整個瀏覽器,因為存取權限始終由你在 Firefox 中授予(R18、R31)。
執行需求
以 npm 套件 @zamery/browser-mcp 透過 stdio 在本機執行,通常用 npx 啟動(R1、R2)。還需要 @zamery/browser-firefox 提供的 Firefox 配套擴充與原生主機(R7),以及桌面版 Firefox 和你要共享的分頁或分頁群組。選用環境變數:ZAMERY_BROWSER_MCP_STATE_DIR、ZAMERY_BROWSER_MCP_CONSUMER_ID、ZAMERY_BROWSER_MCP_BROWSER_INSTANCE_ID、ZAMERY_BROWSER_MCP_PROVIDER(R44-R47)。未宣告任何身分驗證。
安裝前請注意
代理可以對已共享頁面執行點擊、填寫、輸入、按鍵以及分頁與分頁群組變更(R34、R38、R39);每次變更都帶 request_id,結果可能為 outcome_unknown,因此不應換新 id 重試(R40、R41)。登入、一次性驗證碼與付款欄位會被標記為 CREDENTIAL 並拒絕寫入(R27)。consumer id 只是同一作業系統使用者下的路由鍵,並非經過驗證的身分;同一使用者的其他行程也可能與橋接通訊,但仍需自己的授權(R49、R50、R53)。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Zamery Browser,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

@zamery/browser-mcp

A standalone MCP server that lets a local agent (for example Codex) use the Firefox you are already using — with your logins — on only the tabs and tab groups you choose to share.

text
agent host (stdio) → @zamery/browser-mcp → BrowserProvider V2 + optional interfaces  → @zamery/browser-firefox → Native Messaging host → Zamery Browser Companion → your Firefox

It does not depend on Pi or Zamery Workbench. It does not expose raw JavaScript/eval, and the agent cannot grant itself access.

Status: stable 0.1.2, released with Zamery Browser v0.2.3 and Mozilla-signed/public Companion 0.2.5. Clean published-artifact acceptance, signed real-profile acceptance and Official MCP Registry publication all pass.

Install

bash
codex mcp add zamery-firefox -- npx -y @zamery/browser-mcp@latest

You also need the Firefox companion and the native host from @zamery/browser-firefox (see its README).

Official MCP Registry: io.github.maemreyo/zamery-browser.

Codex recipe (needed for screenshots)

In a tested Codex setup the model did not receive inline MCP images, so it guessed what a screenshot showed. browser_screenshot therefore also returns a local image file path, and the model must open it with its image viewer. Add codex/AGENTS.snippet.md to your project's AGENTS.md (or install codex/skill/zamery-browser as a Codex skill). With it, a neutral visual question was answered correctly 3/3 against a real Firefox; without it, 0/2.

How access works

  1. The agent calls browser_status. It always works, even before Firefox is connected or anything is shared, and says what to ask you. If Firefox is connected but nothing is shared, the agent may call browser_request_access once to ask for your attention. The request contains no tab/group/action/duration choices and never grants anything.
  2. Firefox shows a toolbar badge and, if you enabled optional notifications, a generic OS notification. You open the Zamery Browser panel and choose the local agent, the tab(s) or group, what the agent may do, and for how long (this session, or 1–30 days).
  3. The agent calls browser_contexts / browser_snapshot. A snapshot with claim=true (default) takes the write claim; the returned short refs (e1, e2, …) can then be used with browser_click, browser_fill, browser_type, browser_key.
  4. You can take over at any time from the panel. In the default interactive mode, using the claimed page also hands control to you. With explicit Background control, ordinary use of the same shared page only invalidates the agent's old snapshot; it can take a fresh snapshot and continue. While explicit user control is active, the agent cannot act and can only ask you to resume.

Sign-in, one-time-code and payment fields are never filled by the agent: they are flagged CREDENTIAL in snapshots and writes are refused; use browser_handoff (request_user_takeover).

Tools

ToolPurpose
browser_statusConnection, access, expiry, who is in control, and what to do next.
browser_request_accessAsk Firefox to draw the user's attention before a grant exists. It never grants, widens, resumes or confirms access.
browser_contextsTabs shared with the agent.
browser_snapshotControls of a shared tab (no form values, no hidden controls) and, by default, the write claim.
browser_click / browser_fill / browser_type / browser_keySynthetic DOM actions (isTrusted=false). Need the claim and a fresh observation.
browser_handoffrequest_user_takeover, resume (a request only), claim, release.
browser_mutation_statusLook up what happened to an action by its request_id.
browser_tabCreate/navigate/reload/activate/close-own tabs (only what you allowed).
browser_groups, browser_groupRead and change Firefox tab groups you shared.

Every mutation carries a stable request_id. After a timeout or a lost response the outcome may be outcome_unknown: the agent must not retry with a new id; it checks browser_mutation_status and the page.

Configuration (environment)

VariableMeaning
ZAMERY_BROWSER_MCP_STATE_DIRWhere the stable consumer id is stored (default ~/Library/Application Support/Zamery/browser-mcp).
ZAMERY_BROWSER_MCP_CONSUMER_IDOverride the consumer id ([A-Za-z0-9._:-]{8,128}).
ZAMERY_BROWSER_MCP_BROWSER_INSTANCE_IDPin one Firefox profile when several are connected.
ZAMERY_BROWSER_MCP_PROVIDERProvider allowlist selector; only firefox exists. Arbitrary module paths are rejected.

The consumer id binds your grant to this installation, so restarting the MCP process or the agent keeps working under the same approval. It is a same-OS-user routing key, not an authenticated identity.

Trust boundary

The local Firefox bridge trusts the logged-in OS user. Another process of the same user could talk to the bridge, but still needs the grant you created in Firefox for its own consumer id. Page content (titles, URLs, control names) is untrusted data and is labelled as such in tool output.

License

Apache-2.0.

來源:packages/browser-mcp/README.md,提交 7db39b1

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.2最新Oct 6, 2026