# Chrome Mcp Stealth

> MCP server for stealth browser automation via Chrome DevTools Protocol. Bezier mouse curves, Gaussian typing delays, anti-detection patches. Built for Claude Code.

- **Type:** MCP server
- **Install:** `agentstack add mcp-riaan-fourie-chrome-mcp-stealth`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Riaan-Fourie](https://agentstack.voostack.com/s/riaan-fourie)
- **Installs:** 0
- **Category:** [Web & Browser](https://agentstack.voostack.com/c/web-and-browser)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Riaan-Fourie](https://github.com/Riaan-Fourie)
- **Source:** https://github.com/Riaan-Fourie/chrome-mcp-stealth

## Install

```sh
agentstack add mcp-riaan-fourie-chrome-mcp-stealth
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Chrome MCP Stealth

MCP server for stealth browser automation via Chrome DevTools Protocol. Connects to a real Chrome instance with human-like interaction patterns (Bezier mouse curves, Gaussian typing delays, scroll jitter) to avoid bot detection.

## Why

Standard browser automation tools (Playwright, Puppeteer, Selenium) are trivially detected by modern anti-bot systems. Sites fingerprint mouse movements (straight lines, instant teleportation), typing patterns (uniform delays), and JavaScript properties (`navigator.webdriver`, missing plugins) to block automated access.

Chrome MCP Stealth solves this by layering human-like behavior on top of Playwright's CDP connection to a real Chrome instance — not a headless browser, not a fresh profile, but your actual browser with cookies, extensions, and history intact.

## Features

- **Stealth mode**: Bezier mouse movement, Gaussian keystroke delays, scroll jitter, anti-detection JS patches
- **Fast mode**: Instant actions with no delays — available on non-protected domains
- **Security**: 4-layer defense against prompt injection, data exfiltration, and credential leaks
- **Single file**: Entire server is one `index.js` file (~630 lines)

## How Stealth Works

**Mouse movement** follows cubic Bezier curves with randomized control points, producing natural arcs instead of straight lines. Each move uses 12–50 interpolation steps with ease-in-out timing and occasional overshoot corrections.

**Typing** uses Gaussian-distributed inter-key delays (~75ms mean), with extra pauses after punctuation and periodic "thinking pauses" every ~10 characters — mimicking human typing rhythm.

**Scrolling** is broken into jittered multi-step increments with settling delays, avoiding the instant jumps that flag automation.

**Anti-detection patches** remove `navigator.webdriver`, clean Playwright/Selenium artifacts from `window`, inject realistic `chrome.runtime` and plugin stubs.

See [ARCHITECTURE.md](ARCHITECTURE.md) for full implementation details.

## Security Model

1. **Prompt injection scanner** — 20+ regex patterns detect instruction override attempts, social engineering, and data exfiltration commands in page content
2. **Content sanitization** — Hidden/invisible elements are stripped before returning page text, preventing injection via zero-size or off-screen elements
3. **Content spotlighting** — All page content is wrapped in `` tags with security footers
4. **Domain controls** — Cloud metadata endpoints are blocked entirely; banking/email domains trigger warnings; stealth-only domains enforce stealth mode

Additionally, all output is scanned for credential patterns (API keys, tokens, JWTs) and redacted before being returned.

## Tools (11)

| Tool | Purpose |
|------|---------|
| `chrome_set_mode` | Switch between stealth/fast mode |
| `chrome_navigate` | Navigate to URL |
| `chrome_snapshot` | Get sanitized accessibility tree |
| `chrome_screenshot` | Take PNG screenshot |
| `chrome_click` | Click element (Bezier mouse in stealth) |
| `chrome_type` | Type text (Gaussian delays in stealth) |
| `chrome_tabs` | List/switch/create/close tabs |
| `chrome_evaluate` | Run JS in page context (output redacted) |
| `chrome_wait` | Wait for selector or timeout |
| `chrome_scroll` | Scroll up/down (jittered in stealth) |
| `chrome_page_info` | Get current URL, title, domain risk |

## Setup

1. Launch Chrome with CDP:
   ```bash
   /Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome \
     --remote-debugging-port=9222 \
     --user-data-dir=~/.chrome-debug-profile
   ```

2. Install and run:
   ```bash
   npm install
   npm start
   ```

3. Register in your MCP config:
   ```json
   {
     "chrome-stealth": {
       "command": "node",
       "args": ["path/to/chrome-mcp/index.js"],
       "env": { "CDP_ENDPOINT": "http://127.0.0.1:9222" }
     }
   }
   ```

## Stealth-Only Domains

LinkedIn (`linkedin.com`, `www.linkedin.com`) enforces stealth mode — fast mode is blocked. This is enforced at 5 layers: navigation, mode switch, every interaction, post-redirect, and tab switch.

## Dependencies

- `@modelcontextprotocol/sdk` — MCP protocol implementation
- `playwright-core` — Chrome DevTools Protocol connection

## License

MIT

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Riaan-Fourie](https://github.com/Riaan-Fourie)
- **Source:** [Riaan-Fourie/chrome-mcp-stealth](https://github.com/Riaan-Fourie/chrome-mcp-stealth)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-riaan-fourie-chrome-mcp-stealth
- Seller: https://agentstack.voostack.com/s/riaan-fourie
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
