Jet Browser Verifier

io.github.masakaaiv0.8.0更新於 Oct 10, 2026

Verify an isolated WPE WebKit runtime with native-input, DOM, PNG, and cleanup evidence.

已驗證STDIO僅桌面Developer ToolsBrowser Automation

概覽

AI 產生的概覽

讓助理對隔離的 WPE WebKit 執行環境執行一次有界驗證,並回傳原生輸入、DOM、PNG 與清理證據。

功能
此伺服器提供兩個工具。jet_browser_capabilities 會在不啟動 Docker 的情況下回傳固定映像檔、平台、證據契約與明確的非能力範圍(R25)。jet_browser_verify 執行一次有界驗證:啟動不可變的公開 linux/amd64 映像檔、停用瀏覽器網路、開啟映像檔內的本機測試頁、透過原生輸入鍵入內容、檢查 DOM、擷取新的 PNG 並清理(R3、R26)。同一時間只能執行一次驗證,失敗會以 MCP 工具錯誤回傳(R27、R29)。
適用情境
當你需要可重複且隔離地檢查 WPE WebKit 執行環境能否啟動、接受原生輸入、呈現預期的 DOM 並產生有效截圖時使用。它是執行環境驗證器,不是通用瀏覽伺服器,不提供公開網頁導覽、CDP、個人瀏覽器設定檔、憑證、託管服務或遙測(R4、R5)。
執行需求
需要 Node.js 24+ 與 Docker(R7),以及 x86_64 主機或 Docker amd64 模擬(R8)。啟動 MCP 映像檔時需掛載 Docker socket(R14);首次驗證可能從 GHCR 拉取公開映像檔(R9)。未宣告任何驗證、環境變數或標頭。
安裝前請注意
Docker socket 代表主機層級的控制權(R15、R42),請僅為受信任的本機 MCP 用戶端設定此伺服器(R16、R43)。首次執行可能從 GHCR 拉取公開映像檔(R9)。呼叫不接受命令、URL、映像檔、設定檔或路徑參數(R38),驗證器也絕不會附加到正在執行的個人瀏覽器(R41)。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Jet Browser Verifier,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

Jet Browser MCP verifier

This local stdio server gives an MCP client one narrow way to verify Jet Browser. It starts the immutable public linux/amd64 image, disables browser networking, opens the image's local fixture, types through native input, checks the DOM, captures a fresh PNG, and cleans up.

It is a runtime verifier, not a general browsing server. It does not expose public-web navigation, CDP, personal browser profiles, credentials, a hosted service, or telemetry.

Requirements

  • Node.js 24+
  • Docker
  • An x86_64 host, or Docker amd64 emulation

The first verification may pull the public image from GHCR. Browser execution itself uses Docker's --network=none boundary. The image is pinned by digest in server.mjs.

Install from the OCI package

The versioned MCP image starts the stdio server directly. It needs the Docker socket only when jet_browser_verify launches the separately isolated WPE WebKit runtime:

json
{  "mcpServers": {    "jet-browser": {      "command": "docker",      "args": [        "run", "--rm", "-i", "--platform=linux/amd64", "--network=none",        "--mount", "type=bind,src=/var/run/docker.sock,dst=/var/run/docker.sock",        "ghcr.io/masakaai/jet-browser-mcp:0.8.0"      ]    }  }}

Docker socket grants host-level control. Configure this local server only for a trusted MCP client. The outer MCP container has networking disabled, and the browser container it launches independently uses --network=none, resource limits, reduced capabilities, and deterministic cleanup.

The package metadata for the official MCP Registry is server.json. The OCI image carries the matching io.modelcontextprotocol.server.name ownership annotation.

Install from source

bash
git clone https://github.com/masakaai/jet-browser.gitcd jet-browsernpm ci

Add the server to an MCP client with an absolute checkout path:

json
{  "mcpServers": {    "jet-browser": {      "command": "node",      "args": ["/absolute/path/to/jet-browser/integrations/mcp/server.mjs"]    }  }}

The process speaks MCP on stdout and writes operational errors only to stderr. It exits when the client closes stdin.

Tools

ToolBehavior
jet_browser_capabilitiesReturns the pinned image, platform, evidence contract, and explicit non-capabilities without starting Docker.
jet_browser_verifyRuns one bounded verification and returns startup, native-input, DOM, screenshot, network, and image evidence.

Only one verification can run at a time. A client-side cancellation aborts the child process. The server caps child output and total runtime; failures are returned as MCP tool errors rather than protocol failures.

A successful call returns structured content like:

json
{  "status": "passed",  "network": "disabled",  "title": "Jet Browser Ready",  "input": "open-source runtime",  "screenshotBytes": 2048,  "image": "ghcr.io/masakaai/jet-browser@sha256:540a1fec531bf71b62c2c2d030c033249955ffc192ab7e0e7a1ac8d8412a661b"}

The screenshot byte count varies. A pass requires at least 1,000 decoded PNG bytes and exact agreement among the expected page title, native text input, and DOM state.

Verify the integration

The protocol test starts the real stdio server, performs an MCP handshake, lists its tools, and calls the capability tool without requiring Docker:

bash
node --test test/mcp-server.test.mjs

The repository's standalone CI remains the end-to-end runtime proof. To execute that same Docker acceptance locally:

bash
DOCKER_DEFAULT_PLATFORM=linux/amd64 \JET_BROWSER_IMAGE=ghcr.io/masakaai/jet-browser@sha256:540a1fec531bf71b62c2c2d030c033249955ffc192ab7e0e7a1ac8d8412a661b \npm run standalone:smoke

Security boundary

  • The MCP call accepts no command, URL, image, profile, or path argument.
  • The child process receives only the Docker connection variables it needs; application secrets are not forwarded.
  • The container has browser networking disabled, bounded CPU, memory, PIDs, shared memory, and capabilities, and is removed after the check.
  • The verifier never attaches to a running personal browser.
  • Treat Docker access as privileged host access. Only configure this server for trusted local MCP clients.

For a broader embedding boundary, use Jet Browser's versioned tool declarations in sdk/tools.mjs and supervise each isolated container from your own harness.

來源:integrations/mcp/README.md,提交 5114d06

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.8.0最新Oct 10, 2026