browser-control-mcp: safe hh.ru applications
browser-control-mcp
A local MCP server that controls an open Chrome session via CDP, helps apply on hh.ru, blocks payments and confirms before sending
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Can submit a real application and cover letter after confirmation
- Controls the user's already-open Chrome session through the powerful CDP protocol
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/browser-control-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Run in a terminal
claude mcp add --transport stdio --env 'CDP_URL=<CDP_URL value>' browser-control-mcp -- nodeOr add to the file .mcp.json, in the project
{
"mcpServers": {
"browser-control-mcp": {
"command": "node",
"args": [],
"env": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"browser-control-mcp": {
"command": "node",
"args": [],
"env": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Run in a terminal
code --add-mcp '{"name":"browser-control-mcp","type":"stdio","command":"node","args":[],"env":{"CDP_URL":"<CDP_URL value>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"browser-control-mcp": {
"type": "stdio",
"command": "node",
"args": [],
"env": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add browser-control-mcp --env 'CDP_URL=<CDP_URL value>' -- nodeOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.browser-control-mcp]
command = "node"
args = []
env = { CDP_URL = "<CDP_URL value>" }If the file already exists, append the block to the end.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
gemini mcp add -s user -e 'CDP_URL=<CDP_URL value>' browser-control-mcp nodeOr add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"browser-control-mcp": {
"command": "node",
"args": [],
"env": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"browser-control-mcp": {
"command": "node",
"args": [],
"env": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"browser-control-mcp": {
"command": "node",
"args": [],
"env": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"browser-control-mcp": {
"command": "node",
"args": [],
"env": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"browser-control-mcp": {
"type": "local",
"command": [
"node"
],
"environment": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"browser-control-mcp": {
"command": "node",
"args": [],
"env": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"browser-control-mcp": {
"command": "node",
"args": [],
"env": {
"CDP_URL": "<CDP_URL value>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
NODE_ENVoptional- Node environment
LOG_LEVELoptional- Logging level
CDP_URLrequired- URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional- Comma-separated list of allowed domains
DRY_RUNoptional- Enable dry run mode
REQUIRE_CONFIRMATIONoptional- Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional- Allowed browser domains
BROWSER_DENIED_DOMAINSoptional- Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional- Allow private network access
APPLICATION_STORE_PATHoptional- Path to application storage file
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Clone the repository, run npm install and cp .env.example .env, launch Chrome with --remote-debugging-port=9222 --user-data-dir pointing at your profile, then run npm run dev, connect the server to Codex via MCP, and keep DRY_RUN=true until you're ready to confirm each application by hand.
Other ways from the author
npm install && cp .env.example .envInstalling dependencies and a base config, after cloning the repository.
This is third-party code. Review the repository files before installing.
What it does
The server attaches to an already-running Chrome instance through the Chrome DevTools Protocol on a local port, rather than opening its own browser, and stores no logins, passwords or cookies. A dedicated hh.ru module opens a vacancy page in the current user session, checks that the user is logged in, parses the vacancy, finds employer questions and drafts a cover letter, but only fills in answers and the letter after confirmation and never submits an application without explicit permission. Every action is classified by risk: read and low run immediately, sensitive and irreversible need a one-time token with a limited lifetime, and critical actions (payments, purchases, money transfers) are blocked outright with no way to confirm them. Dry-run is on by default: even a confirmed flow won't press the final apply button until it's explicitly turned off. A separate generic browser-control module gives basic tab-opening, clicking and field-filling tools under the same risk model, not tied to hh.ru.
Who it is for. For job seekers who want to automate filling in an hh.ru application but insist on manual confirmation before it's actually sent.
Good fit when
- You need help drafting a cover letter and answers to employer questions in a real hh.ru tab
- It matters that an application never goes out without explicit confirmation, and that payment actions are blocked outright
- You need general risk-aware browser control, not just the hh.ru flow
Not a fit when
- You need fully autonomous bulk application submission with no confirmation: the MVP deliberately doesn't do that
- You don't want to open Chrome with a debug port: the author describes CDP access as very powerful and says it should only listen on 127.0.0.1
- You need ready-made candidate-answer tools (parse_resume_context, fill_question_answers): those are listed as planned, not implemented
Example request
Open this hh.ru vacancy, check if the employer has a required question, and draft a cover letter, but don't submit without meLimitations
The project calls itself an MVP and a TypeScript learning exercise. It requires running Chrome with an open local debug port, and the author explicitly warns against exposing it externally. Several tools (resume context parsing, filling candidate answers, a full submit_response) are listed in the README as planned, not implemented. There's no automatic tab recovery by URL or title after a tab closes or Chrome restarts if several similar tabs exist.
How to disable. Stop the MCP process and close the debug-port Chrome instance, then remove the server from your client configuration.
MCP
- Transport
- stdio
- Authentication
- not required
| Environment variables | |
|---|---|
| CDP_URL required | The local Chrome DevTools Protocol address, defaults to http://127.0.0.1:9222. |
| DRY_RUN | On by default (true): the final apply button is never pressed even with confirmation. |
| ALLOWED_DOMAINS | The list of domains where hh.ru automation is allowed, e.g. hh.ru,ramenskoe.hh.ru. |
Security check
- Can submit a real application and cover letter after confirmation
- Controls the user's already-open Chrome session through the powerful CDP protocol
README in short
The README describes the safety model in detail: no credential storage, dry-run by default, one-time confirmation tokens with a TTL, a full block on payment actions, and separate prepare/submit tool pairs for different hh.ru application flows. It includes an architecture diagram, a table of implemented and planned MCP tools, Chrome debug-port launch instructions for macOS, Linux and Windows, and a list of environment variables. It separately notes the project is not an official Google, Chromium or hh.ru product.
FAQ
Can the server submit an application without my knowledge?
No, by design an application is never sent without explicit confirmation, and with DRY_RUN=true the final button isn't pressed at all.
Can the server make a payment or purchase?
No, such actions are classified as critical and are blocked outright with no way to confirm them.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI