Observation-first MCP server for Cockroach Browser, enabling AI agents to snapshot, audit, and propose browser actions through a secure, policy-controlled daemon.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.COCKROACH_BROWSER_PROFILE_PASSPHRASE— Profile import and export require . Passphrases are never accepted as command-line arguments.COCKROACH_BROWSER_TOKEN— "": "<load from your secret store>"COCKROACH_BROWSER_TOKEN_FILE— Daemon clients can use --token, --token-file, COCKROACH_BROWSER_TOKEN, or . They can override the URL with --url or COCKROACH_BROWSER_URL.COCKROACH_BROWSER_URL— "": "http://127.0.0.1:43110",[](https://m8ven.ai/mcp/ajnasnb-cockroach-browser-17ls3n)