Sandbox
@EndymionLee/PilotBrowseMCP

MCP server for Chrome browser control

Pilot Browse MCP connects an AI agent to a real Chrome browser through MCP and a Chrome extension. The agent can read pages, click, type, watch network traffic, and save page content or workflows into reusable website manuals. It also includes no-LLM `.pab` automation scripts and examples for Claude Code, Codex, and similar agents.

99 stars3 forksTypeScriptUpdated 1mo ago
Who it's for

Builders who want their agent to explore websites, record browser workflows, and reuse them later.

What it delivers

You can let an agent operate a real browser, learn site-specific steps, and reuse those steps without re-explaining the site each time.

What it does

Real browser control

Exposes Chrome actions like tab management, click, type, scroll, wait, and page inspection through MCP tools.

Website manual learning

Saves explored pages, navigation paths, workflows, and APIs into `website-manuals/` for reuse.

Workflow recording and replay

Lets you mark elements, record actions, generate workflows, and execute saved automation scripts.

Network API toolkit

Monitors, searches, replays, and exports browser requests, and can analyze a site’s API structure from captured traffic.

Token-saving content capture

Writes page content directly to disk with `browser_save_content` and related tools instead of sending everything through the model.

Security and reverse-analysis tools

Includes SQL injection scanning and JavaScript reverse-analysis tools for finding endpoints, functions, and request generators.

README

Pilot Browse MCP

中文

MCP toolset + website capability learner for the browser. Agent autonomously explores websites and builds understanding manuals.


Showcase (Pi Demo)

Capability Learning

Install a skill. As the agent interacts with a website, it automatically discovers APIs and binds them with browser workflows into reusable capabilities.

Agent Explore

Learning output is saved in website-manuals/:

website-manuals/<site>/
  README.md              # Root index
  pages/                 # Page interaction models
  navigation/            # Navigation paths
  workflows/
    README.md            # Workflow index
    flows/               # Workflow JSON files
    scripts/             # PAB automation scripts (.pab files)
  apis/
    README.md            # API index (browse first)
    endpoints/           # API JSON files

Guided Teaching

(Using Bilibili as demo site)

Stuck on complex interactions? Record or mark elements manually to help the agent learn.

Mark Element

Mark Element

Record Workflow

Record Workflow

Manual Reuse

Based on the exploration manual, the agent can quickly understand websites and complete tasks faster.

Two no-LLM modes are also supported:

  • .pab scripts for automation tasks -- capabilities match the agent's MCP tools
  • Python/other scripts for specialized data collection tasks

Demos

Build various workflows, simple demo showcase.

Automation Operations

Agent: Qidian Novel Saver

Search a novel, save the first 5 chapters.


.pab Script: Bilibili Open 3 Trending Videos and Comment
Bilibili open trending videos and comment

Python Script Generation

Generate various scripts based on the exploration manual.

For example, a novel scraper script:

I used Pilot to analyze the novel website structure, chapter API, generated scraping scripts, built Docker images, deployed 9 containers on NAS, and crawled over 4000 novels in 2 days.

PaImage


Install

# Build
cd server && npm install && npm run build
cd extension && npm install && npm run build

# Load extension
# chrome://extensions/ -> Developer mode -> Load unpacked -> extension/dist/

# Start server
cd server && node dist/index.js

MCP Configuration

Example - fill args with the actual path to server/dist/index.js:

{
  "mcpServers": {
    "browser-mcp": {
      "command": "node",
      "args": ["/path/to/server/dist/index.js"]
    }
  }
}

Skills

Check scripts/Skill for available skills.

Quick Start with Examples

Refer to agent-examples/ for ready-to-use agent workspace examples. Run your agent in one of those directories and it will automatically load the MCP config, skills, and project prompts. (Remember to update the MCP path to your actual setup.)


Architecture

AI Agent (Claude Code / Pi / Codex)
    |
    | 1) MCP stdio protocol (JSON-RPC)
    | stdin / stdout
    v
MCP Server (Node.js)          protocol translator
    |
    | 2) WebSocket :9456
    v
Chrome Extension
    |
    | 3) Chrome API
    |
    v
Browser

Features

  • 62 MCP tools -- tab management, content extraction, DOM operations, network interception, file saving, workflow recording, script automation, SQL injection detection, JS reverse
  • PAB scripting -- Python-like DSL for browser automation with if/for/fn support. Run from popup, no LLM needed
  • Element picker -- click any element on the page and tell the agent what it is
  • Workflow recording -- demonstrate operations to the agent, it learns and reuses
  • Network API toolkit -- monitor, search, inspect, replay with overrides, export code, and analyze site API structure
  • Token-efficient saving -- save page content directly to disk, bypassing the LLM
  • Shadow DOM + contenteditable

Tools

CategoryToolWhat it does
Pagebrowser_get_markdownConvert page to clean Markdown via Readability + Turndown
browser_get_textGet plain text of the page (lighter than get_html)
browser_get_htmlGet raw HTML of the page (heavy, last resort)
browser_findFind element by visible text, aria-label, or role
browser_current_pageGet current tab URL and title
browser_inspect_pageSee page structure (headings, sections, buttons)
browser_queryQuery elements by CSS selector (penetrates Shadow DOM)
browser_evaluateExecute JS in page context
browser_extract_articleExtract article metadata (title, author, date, body)
browser_extract_tableExtract HTML table as JSON array
browser_extract_linksExtract all links from the page
browser_extract_imagesExtract image info (src, alt, size)
Actionsbrowser_clickClick an element (composed:true for Shadow DOM)
browser_typeType text into input or contenteditable
browser_scrollScroll the page
browser_waitWait for a given number of milliseconds
browser_wait_for_elementWait for an element to appear
Savingbrowser_save_contentAuto-detect main content and save to file (zero LLM tokens)
browser_save_xpathExtract by XPath and save to file
Networkbrowser_start_network_monitorStart intercepting requests
browser_stop_network_monitorStop monitoring (cache preserved for replay)
browser_network_clear_cacheClear cached requests without stopping monitoring
browser_network_searchSearch cached requests by keyword, method, status
browser_network_detailGet full details of a cached request (headers, body, timing)
browser_network_waitWait for a matching request after an action (replaces fixed delay)
browser_network_replayReplay with overrides (query/headers/body) + extract JSON path
browser_network_exportExport request as curl / fetch / Python / HAR
browser_network_analyzeAnalyze API structure of a site from cached requests
browser_network_overrideSet response override rules (body, status, headers)
Tabsbrowser_list_tabsList all open tabs
browser_open / close / activateTab management
Recordingworkflow_list_recordingsView recordings from popup
workflow_get_recordingGet recording details
workflow_list_elementsView marked elements
workflow_get_elementGet marked element details
workflow_listList processed workflows in website-manuals
workflow_add_elementSave a user-marked element to pages/
workflow_generateSave a processed workflow to website-manuals
workflow_generate_scriptGenerate an MCP automation script
workflow_execute_scriptExecute an MCP automation script
Databrowser_cookiesRead cookies (requires permission)
browser_local_storageRead LocalStorage (requires permission)
browser_screenshotTake screenshot (requires permission)
browser_permissions_list / grant / revokePermission management
Securitysql_injection_list_findingsList security findings (with status)
sql_injection_get_findingGet details of a single finding
sql_injection_scanActively scan for SQL injection (browser-context replay)
sql_injection_stopStop scanning
sql_injection_update_findingAdvance finding status (confirm/fix/false positive)
sql_injection_generate_scriptGenerate a security-check.pab re-check script
sql_injection_requestCustom SQL payload probe + auto verdict/extract
JS Reversejs_extractCollect page JS files
js_analyzeAST analysis: endpoints/functions/crypto/signatures
js_find_functionLocate a function (name/calls/crypto/callers)
js_trace_requestAssociate request params with JS generator functions
js_capability_queryQuery learned capability models
js_reverseFull reverse + save js/ + capabilities/ report

License

MIT

Files in the repo

Repository payload11 top-level entries
  • agent-examples
  • assets
  • extension
  • scripts
  • server
  • .gitignore
  • LICENSE
  • package.json
  • README.md
  • README.zh-CN.md
  • tsconfig.base.json

Discussion (0)

Ask about usage, or say what you built with it

Sign in to join the discussion.

No comments yet. Be the first to say what this is good for.

More connectors

High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.

43k

Universal provider proxy for OpenAI Codex & Claude Code — use any LLM (Claude, Gemini, Grok, DeepSeek, Ollama…) with Codex CLI, App, SDK, and Claude Code

14k
okf-memory/
okf-agent-memory

Git-native persistent memory for AI coding agents. Implements Google OKF v0.2 with sub-300µs in-memory BM25 search, embedded MCP server, and progressive disclosure. Slashes token bloat by 80% with zero external databases or dependencies. Built in pure Go.

547
tirth8205/
code-review-graph

Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.

31k
2akouwu/
reverify

Stop your AI from making things up — it proposes, deterministic tools decide, every claim checked against ground truth with evidence. Grounded facts and context survive resets. Reverse engineering is the proving ground. MCP server + CLI.

1.1k
t8y2/dbxConnectors

20 MB lightweight cross-platform database client for 90+ databases, including MySQL, PostgreSQL, SQLite, Redis, MongoDB, DuckDB, SQL Server, and Dameng. Built-in AI, MCP Server, CLI, desktop and Docker. | 轻量级跨平台数据库管理工具,支持 MySQL、PostgreSQL、SQLite、Redis、MongoDB、达梦等 90+ 数据库,提供桌面端、Docker、CLI、内置 AI 助手和 MCP Server。

19k