browser-testbench (llakie/browser-testbench) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 26 tools. No publisher has claimed this listing.

C
Caution
74/100

browser-testbench

Cross-platform browser testbench for remotely controlling, debugging, and automating real browsers, iOS simulators, and Android emulators.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

llakie

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Tool annotations don’t match behaviour
1 read-only tool performs write/delete/exec — take_screenshot (line 153: mkdir(dirname(screenshotPath), { recursive: true }))
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: BROWSER_TESTBENCH_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes26 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

list_targets

List concrete browser and simulator target IDs and their current readiness.

doctor

Inspect prerequisites without triggering macOS permission dialogs.

verify_target

Run the built-in remote-control smoke test against one concrete ready target and close it afterward.

start_session

Start one interactive browser or simulator session using a concrete ID returned by list_targets.

navigate

Navigate the active session to a URL and return a compact page inspection.

inspect_page

Return the URL, title, and compact list of interactive/semantic elements in the active web page.

click

Click an element in the active session using a CSS selector.

type

Type text into an element in the active session.

element_action

Perform a form or element action: inspect state/count, fill, append text, clear, check, uncheck, select, upload, focus, blur, submit, press keys, hover, double/right click, drag, scroll into view, or capture an element screenshot. All selectors are standard CSS selectors.

browser_action

Control browser navigation, scrolling, tabs/windows, frames, JavaScript dialogs, cookies, web storage, or viewport size.

take_screenshot

Capture the active browser or device screen and return both the path and image.

tap

Tap absolute screen coordinates in the active iOS or Android simulator session.

swipe

Swipe the active mobile screen. Area and speed apply to Android; velocity applies to iOS. Android defaults to the current window area.

pinch

Pinch in or out on the active mobile screen. Area and speed apply to Android; velocity applies to iOS.

get_page_source

Return page source from the active session, capped to a requested size.

wait_for_element

Wait until an element is present and visible in the active session.

wait_condition

Wait for an element, text, URL, element state, value, count, attribute, or text inside a specific element.

wait_for_text

Wait until text appears in the active page.

wait_for_url

Wait until the active URL contains a value.

wait_for_state

Wait for an element to become visible, hidden, present, absent, enabled, disabled, checked, or unchecked.

wait_for_value

Wait until a form control has an exact value.

wait_for_count

Wait until a selector matches an exact number of elements.

get_diagnostics

Return captured console output and HTTP request/response diagnostics for the active session.

clear_diagnostics

Clear collected console and HTTP diagnostics for the active session.

get_devtools_instructions

Explain how to open the native developer tools for the active browser or simulator.

close_session

Close the active interactive browser/device session and its Appium process.

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configANDROID_AVD_HOME
🔐 secretBROWSER_TESTBENCH_TOKEN
configBROWSER_TESTBENCH_URLRemoteTestbench connects to http://127.0.0.1:55808 by default. Set a different address through or the constructor. The client provides:
configPROGRAMFILES
configPROGRAMFILES(X86)
// quality suggestions

Dependencies

9 runtime dependencies (10 dev), 1 flagged: selenium-webdriver

Tool annotations

14/26 tools have annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

26/26 tools missing one or more hints — list_targets (missing: destructiveHint, idempotentHint, openWorldHint); doctor (missing: destructiveHint, idempotentHint, openWorldHint); verify_target (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +23 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool annotations match behaviour

1 read-only tool performs write/delete/exec — take_screenshot (line 153: mkdir(dirname(screenshotPath), { recursive: true }))

Either remove the readOnlyHint:true annotation, or remove the write/delete call from the tool handler.

Tool inputs are validated

21/26 tool handlers declare input schemas (81%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Shell command execution

1 call in production code run through a shell (src/infrastructure/command-runner.ts:41)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/llakie/browser-testbench?variant=verified)](https://m8ven.ai/mcp/llakie/browser-testbench)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: a033a76ce4b7caed31072c0bbc9dc18d74a93006
code hash: ab163eaa8989d69b8c03f5b1c50738efec05864163956646b192027170f01f08
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client