Enables local browser automation using Stagehand without cloud services. Supports navigation, data extraction, and autonomous agent tasks through natural language.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.ANTHROPIC_API_KEY— Anthropic API key - for StagehandBROWSERBASE_API_KEY— Required credentials + PROJECT_ID Only LLM API keyBROWSERBASE_PROJECT_ID— "": "your_project_id",EVAL_PASS_THRESHOLDGEMINI_API_KEY— Google Gemini API key - is requiredGOOGLE_API_KEYGOOGLE_GENERATIVE_AI_API_KEYHEADLESS— Run browser headless true NoMODEL_API_KEYOPENAI_API_KEY— e =your_key \OPENAI_BASE_URLPASS_THRESHOLDSCREENSHOT_DIR— Screenshot save directory /tmp/stagehand-screenshots NoSCREENSHOT_ENABLED— Enable auto screenshots true NoSTAGEHAND_ENV— e =LOCAL \STAGEHAND_SESSION_ID[](https://m8ven.ai/mcp/1000ml-io-stagehand-mcp-local-1ra2gp)