browser-control-mcp: safe hh.ru applications

browser-control-mcp

A local MCP server that controls an open Chrome session via CDP, helps apply on hh.ru, blocks payments and confirms before sending

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Can submit a real application and cover letter after confirmation
  • Controls the user's already-open Chrome session through the powerful CDP protocol
All reasons and checks
Russian stack

eno004731-cpu/browser-control-mcp

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add mcp/browser-control-mcp

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Assembled automatically, review before installing.

Run in a terminal

claude mcp add --transport stdio --env 'CDP_URL=<CDP_URL value>' browser-control-mcp -- node

Or add to the file .mcp.json, in the project

{
  "mcpServers": {
    "browser-control-mcp": {
      "command": "node",
      "args": [],
      "env": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Install in Cursor

The button opens the agent and offers to add the server. If nothing happens, copy the config below.

Add to the file ~/.cursor/mcp.json, for all projects

{
  "mcpServers": {
    "browser-control-mcp": {
      "command": "node",
      "args": [],
      "env": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Install in VS Code

The button opens the agent and offers to add the server. If nothing happens, copy the config below.

Run in a terminal

code --add-mcp '{"name":"browser-control-mcp","type":"stdio","command":"node","args":[],"env":{"CDP_URL":"<CDP_URL value>"}}'

Or add to the file .vscode/mcp.json, in the project

{
  "servers": {
    "browser-control-mcp": {
      "type": "stdio",
      "command": "node",
      "args": [],
      "env": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the servers key.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

codex mcp add browser-control-mcp --env 'CDP_URL=<CDP_URL value>' -- node

Or add to the file ~/.codex/config.toml, for all projects

[mcp_servers.browser-control-mcp]
command = "node"
args = []
env = { CDP_URL = "<CDP_URL value>" }

If the file already exists, append the block to the end.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

gemini mcp add -s user -e 'CDP_URL=<CDP_URL value>' browser-control-mcp node

Or add to the file ~/.gemini/settings.json, for all projects

{
  "mcpServers": {
    "browser-control-mcp": {
      "command": "node",
      "args": [],
      "env": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/devin/mcp_config.json, for all projects

{
  "mcpServers": {
    "browser-control-mcp": {
      "command": "node",
      "args": [],
      "env": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Formerly Windsurf.

Add to the file cline_mcp_settings.json, for all projects

{
  "mcpServers": {
    "browser-control-mcp": {
      "command": "node",
      "args": [],
      "env": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .roo/mcp.json, in the project

{
  "mcpServers": {
    "browser-control-mcp": {
      "command": "node",
      "args": [],
      "env": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

A fork of Roo Code, same .roo folders.

Add to the file opencode.json, in the project

{
  "mcp": {
    "browser-control-mcp": {
      "type": "local",
      "command": [
        "node"
      ],
      "environment": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcp key.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/zed/settings.json, for all projects

{
  "context_servers": {
    "browser-control-mcp": {
      "command": "node",
      "args": [],
      "env": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the context_servers key.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .codeassistant/mcp.json, in the project

{
  "mcpServers": {
    "browser-control-mcp": {
      "command": "node",
      "args": [],
      "env": {
        "CDP_URL": "<CDP_URL value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

NODE_ENVoptional
Node environment
LOG_LEVELoptional
Logging level
CDP_URLrequired
URL for Chrome DevTools Protocol
ALLOWED_DOMAINSoptional
Comma-separated list of allowed domains
DRY_RUNoptional
Enable dry run mode
REQUIRE_CONFIRMATIONoptional
Require confirmation for sensitive actions
BROWSER_ALLOWED_DOMAINSoptional
Allowed browser domains
BROWSER_DENIED_DOMAINSoptional
Denied browser domains
BROWSER_ALLOW_PRIVATE_NETWORKoptional
Allow private network access
APPLICATION_STORE_PATHoptional
Path to application storage file

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

You will need: Node.js

Checked against the repository on Sep 26, 2026, commit 3c44313.

Text for your agent

Clone the repository, run npm install and cp .env.example .env, launch Chrome with --remote-debugging-port=9222 --user-data-dir pointing at your profile, then run npm run dev, connect the server to Codex via MCP, and keep DRY_RUN=true until you're ready to confirm each application by hand.

Other ways from the author
npm install && cp .env.example .env

Installing dependencies and a base config, after cloning the repository.

This is third-party code. Review the repository files before installing.

What it does

The server attaches to an already-running Chrome instance through the Chrome DevTools Protocol on a local port, rather than opening its own browser, and stores no logins, passwords or cookies. A dedicated hh.ru module opens a vacancy page in the current user session, checks that the user is logged in, parses the vacancy, finds employer questions and drafts a cover letter, but only fills in answers and the letter after confirmation and never submits an application without explicit permission. Every action is classified by risk: read and low run immediately, sensitive and irreversible need a one-time token with a limited lifetime, and critical actions (payments, purchases, money transfers) are blocked outright with no way to confirm them. Dry-run is on by default: even a confirmed flow won't press the final apply button until it's explicitly turned off. A separate generic browser-control module gives basic tab-opening, clicking and field-filling tools under the same risk model, not tied to hh.ru.

Who it is for. For job seekers who want to automate filling in an hh.ru application but insist on manual confirmation before it's actually sent.

Good fit when

  • You need help drafting a cover letter and answers to employer questions in a real hh.ru tab
  • It matters that an application never goes out without explicit confirmation, and that payment actions are blocked outright
  • You need general risk-aware browser control, not just the hh.ru flow

Not a fit when

  • You need fully autonomous bulk application submission with no confirmation: the MVP deliberately doesn't do that
  • You don't want to open Chrome with a debug port: the author describes CDP access as very powerful and says it should only listen on 127.0.0.1
  • You need ready-made candidate-answer tools (parse_resume_context, fill_question_answers): those are listed as planned, not implemented

Example request

Open this hh.ru vacancy, check if the employer has a required question, and draft a cover letter, but don't submit without me

Limitations

The project calls itself an MVP and a TypeScript learning exercise. It requires running Chrome with an open local debug port, and the author explicitly warns against exposing it externally. Several tools (resume context parsing, filling candidate answers, a full submit_response) are listed in the README as planned, not implemented. There's no automatic tab recovery by URL or title after a tab closes or Chrome restarts if several similar tabs exist.

How to disable. Stop the MCP process and close the debug-port Chrome instance, then remove the server from your client configuration.

MCP

Transport
stdio
Authentication
not required
Environment variables
Environment variables
CDP_URL
required
The local Chrome DevTools Protocol address, defaults to http://127.0.0.1:9222.
DRY_RUN
On by default (true): the final apply button is never pressed even with confirmation.
ALLOWED_DOMAINS
The list of domains where hh.ru automation is allowed, e.g. hh.ru,ramenskoe.hh.ru.

Security check

  • Can submit a real application and cover letter after confirmation
  • Controls the user's already-open Chrome session through the powerful CDP protocol

README in short

The README describes the safety model in detail: no credential storage, dry-run by default, one-time confirmation tokens with a TTL, a full block on payment actions, and separate prepare/submit tool pairs for different hh.ru application flows. It includes an architecture diagram, a table of implemented and planned MCP tools, Chrome debug-port launch instructions for macOS, Linux and Windows, and a list of environment variables. It separately notes the project is not an official Google, Chromium or hh.ru product.

FAQ

Can the server submit an application without my knowledge?

No, by design an application is never sent without explicit confirmation, and with DRY_RUN=true the final button isn't pressed at all.

Can the server make a payment or purchase?

No, such actions are classified as critical and are blocked outright with no way to confirm them.

Official

A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes

MCP serverMedium risk46.5KRepository stars
Editors’ pick

A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more

CLIHigh risk31.2KRepository stars
Editors’ pick

Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server

CLIMedium riskNo VPN needed30.1KRepository stars
Editors’ pick

A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI

MCP serverMedium risk28.1KRepository stars
Foxx AIbrowser-control-mcp: safe hh.ru applications

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.