{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/chrome-devtools-mcp.json",
        "name": "Chrome DevTools MCP",
        "score": 77,
        "shared": [
          "browser.control",
          "browser.debug"
        ],
        "slug": "chrome-devtools-mcp"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/browserless.json",
        "name": "Browserless",
        "score": 70.4,
        "shared": [
          "browser.control",
          "browser.debug"
        ],
        "slug": "browserless"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/steel.json",
        "name": "Steel",
        "score": 70.4,
        "shared": [
          "browser.control",
          "browser.debug"
        ],
        "slug": "steel"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/anchor-browser.json",
        "name": "Anchor Browser",
        "score": 67.3,
        "shared": [
          "browser.control",
          "browser.debug"
        ],
        "slug": "anchor-browser"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/skyvern.json",
        "name": "Skyvern",
        "score": 63.1,
        "shared": [
          "browser.control",
          "browser.debug"
        ],
        "slug": "skyvern"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/airtop.json",
        "name": "Airtop",
        "score": 55.3,
        "shared": [
          "browser.control",
          "browser.debug"
        ],
        "slug": "airtop"
      }
    ],
    "tool": {
      "slug": "agent-browser",
      "name": "agent-browser",
      "vendor": "Vercel Labs",
      "vendorUrl": "https://agent-browser.dev",
      "kind": "mcp",
      "category": "browser",
      "summary": "agent-browser is an open-source command-line tool from Vercel Labs that lets AI agents drive Chrome through accessibility-tree snapshots and element refs. It runs locally as a Rust binary and includes a stdio MCP server.",
      "url": "https://www.anchorterminal.com/tools/agent-browser",
      "markdownUrl": "https://www.anchorterminal.com/tools/agent-browser.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agent-browser.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agent-browser.json",
      "repo": "https://github.com/vercel-labs/agent-browser",
      "license": "Apache-2.0",
      "transports": [
        "stdio"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "agent-browser"
        }
      ],
      "auth": "none",
      "authNotes": "No account or key. The CLI and its daemon run on the owner's machine. Site logins are held in a local auth vault encrypted with AES-256-GCM, in saved state files (plaintext unless `AGENT_BROWSER_ENCRYPTION_KEY` is set) or in a reused Chrome profile. Cloud browser providers and the optional `chat` command need their own keys in environment variables.",
      "pricing": "free",
      "pricingNotes": "Free and open source under Apache-2.0, with nothing to buy and no hosted service. The optional `chat` command and dashboard chat bill the user's own Vercel AI Gateway key, and cloud browser providers bill separately (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 158,
      "popularity": {
        "githubStars": 43679,
        "npmWeekly": 2069828,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://agent-browser.dev",
      "llmsTxt": "https://agent-browser.dev/llms.txt",
      "capabilities": [
        "browser.control",
        "browser.debug"
      ],
      "tags": [
        "official",
        "local",
        "open-source",
        "browser",
        "cli",
        "mcp",
        "rust",
        "no-auth",
        "llms-txt"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 66.6,
        "grade": "B",
        "agentReady": false,
        "rank": 263,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 70,
          "payments": 60,
          "reliability": 48,
          "schema": 84,
          "security": 67,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 48,
            "points": 9.6,
            "reason": "Scored as local software. Official npm and Homebrew packages at 0.38.2 with native binaries for five platforms, but crates.io holds 0.19.0 from 14 March 2026 while the README lists `cargo install` (18 of 20). Public CI runs Rust tests on Linux, macOS and Windows plus native end-to-end tests, and the ten most recent runs on main, 1 to 8 October 2026, concluded in failure. In the newest, Windows Rust tests and the end-to-end job failed and the other jobs passed (10 of 25). 840 open issues and pull requests. Open issues from the last week include `click` reporting success on hidden elements (#2056), the CLI re-sending a command the daemon already ran (#2032) and `--allowed-domains` failing on fresh launches (#2031), most without a reply (10 of 25). Every release has a changelog entry and breaking changes get their own heading, on a 0.x line (10 of 15). 0.38.2 with a Labs badge and no stable declaration (0)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 84,
            "points": 13.65,
            "reason": "Graded on the CLI and its MCP server. Every MCP tool has a JSON Schema input with `additionalProperties` false, and `agent-browser.schema.json` covers the config file (25). llms.txt and a Markdown copy of each docs page at agent-browser.dev (10). Tool descriptions are one line, such as `Scroll the page or an element`, with parameter descriptions that say when to omit a field. Few say when not to use a tool (12). Enums, minimums, defaults and required lists, with a free-form `extraArgs` string array on every tool (12). Many CLI examples and a `--json` result shape, with error codes such as `tab_gone` named in passing and no error catalogue found (10). Versioned releases and CHANGELOG.md for each (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 78,
            "points": 12.68,
            "reason": "The CLI adds no tool definitions to context, and the MCP server defaults to 29 `core` tools with seven further profiles and paged tools/list up to 158 (22 of 25). `snapshot -i`, `-c`, `-d`, `-s` and `--delta`, `--max-output`, and network request filters by type, method and status (20). Clicks fail early and name the covering element, and JSON errors carry codes such as `tab_gone` with recovery data, with no documented list of codes (14). `readOnlyHint` and `openWorldHint` on every tool, no `destructiveHint`, and open issue #2032 reports the CLI re-sending a command after it reached the daemon (12). Refs and defaults keep commands short. One CLI, no SDK in a second language (10)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 67,
            "points": 11.73,
            "reason": "The tool needs no credential. Site passwords sit in a local vault encrypted with AES-256-GCM and are filled without reaching the model, while saved state files are plaintext unless a key is set (22 of 30). Domain allowlist, action policy file and confirmation for chosen action categories, all opt-in, with no restriction by default (16 of 20). Content boundary markers with a per-process nonce, output caps and a written threat model with ten known limitations, also opt-in (12 of 15). A local dashboard shows a command and result feed, with no persistent audit log found (7 of 15). No SECURITY.md in the repository and no published advisories. vercel.com's security.txt names HackerOne, and the changelog records hardening of the dashboard (0.35.2) and allowlist (0.32.0) (10 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 60,
            "points": 7.5,
            "reason": "Free, self-hosted, nothing to buy, so 20 + 20 + 20 under the self-hosted rule. No payment protocol (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 70,
            "points": 6.13,
            "reason": "0.38.2 on 1 October 2026 (30). 19 tagged releases since 13 July 2026 (20). 34 commits to main since 8 September, but of the 19 newest open issues 12 had no comment and none had a label, including two off-topic ones left open (10 of 25). Not in the official MCP registry, where a search for agent-browser returned only other publishers. npm and Homebrew are current and crates.io is 19 minor versions behind (5 of 15). No runtime npm dependencies and a lockfile, with CI failing on main (5 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 61,
            "points": 5.34,
            "note": "editorial 68, provenance 53",
            "reason": "Apache-2.0, copyright Vercel Inc. (30). No privacy statement for the software. The docs say where credentials, keys and state are stored, that saved state expires after 30 days by default, and that `chat` goes to the Vercel AI Gateway (18 of 30). No deprecation policy. The changelog flagged the `-C` snapshot flag as deprecated under a Breaking Changes heading (6 of 20). No telemetry code found in the source, and the README and docs do not state this either way (14 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The CLI adds no tool definitions to context, and the MCP server defaults to 29 `core` tools with seven further profiles and paged tools/list up to 158 (22 of 25). `snapshot -i`, `-c`, `-d`, `-s` and `--delta`, `--max-output`, and network request filters by type, method and status (20). Clicks fail early and name the covering element, and JSON errors carry codes such as `tab_gone` with recovery data, with no documented list of codes (14). `readOnlyHint` and `openWorldHint` on every tool, no `destructiveHint`, and open issue #2032 reports the CLI re-sending a command after it reached the daemon (12). Refs and defaults keep commands short. One CLI, no SDK in a second language (10).",
            "maintenance": "0.38.2 on 1 October 2026 (30). 19 tagged releases since 13 July 2026 (20). 34 commits to main since 8 September, but of the 19 newest open issues 12 had no comment and none had a label, including two off-topic ones left open (10 of 25). Not in the official MCP registry, where a search for agent-browser returned only other publishers. npm and Homebrew are current and crates.io is 19 minor versions behind (5 of 15). No runtime npm dependencies and a lockfile, with CI failing on main (5 of 10).",
            "payments": "Free, self-hosted, nothing to buy, so 20 + 20 + 20 under the self-hosted rule. No payment protocol (0).",
            "reliability": "Scored as local software. Official npm and Homebrew packages at 0.38.2 with native binaries for five platforms, but crates.io holds 0.19.0 from 14 March 2026 while the README lists `cargo install` (18 of 20). Public CI runs Rust tests on Linux, macOS and Windows plus native end-to-end tests, and the ten most recent runs on main, 1 to 8 October 2026, concluded in failure. In the newest, Windows Rust tests and the end-to-end job failed and the other jobs passed (10 of 25). 840 open issues and pull requests. Open issues from the last week include `click` reporting success on hidden elements (#2056), the CLI re-sending a command the daemon already ran (#2032) and `--allowed-domains` failing on fresh launches (#2031), most without a reply (10 of 25). Every release has a changelog entry and breaking changes get their own heading, on a 0.x line (10 of 15). 0.38.2 with a Labs badge and no stable declaration (0).",
            "schema": "Graded on the CLI and its MCP server. Every MCP tool has a JSON Schema input with `additionalProperties` false, and `agent-browser.schema.json` covers the config file (25). llms.txt and a Markdown copy of each docs page at agent-browser.dev (10). Tool descriptions are one line, such as `Scroll the page or an element`, with parameter descriptions that say when to omit a field. Few say when not to use a tool (12). Enums, minimums, defaults and required lists, with a free-form `extraArgs` string array on every tool (12). Many CLI examples and a `--json` result shape, with error codes such as `tab_gone` named in passing and no error catalogue found (10). Versioned releases and CHANGELOG.md for each (15).",
            "security": "The tool needs no credential. Site passwords sit in a local vault encrypted with AES-256-GCM and are filled without reaching the model, while saved state files are plaintext unless a key is set (22 of 30). Domain allowlist, action policy file and confirmation for chosen action categories, all opt-in, with no restriction by default (16 of 20). Content boundary markers with a per-process nonce, output caps and a written threat model with ten known limitations, also opt-in (12 of 15). A local dashboard shows a command and result feed, with no persistent audit log found (7 of 15). No SECURITY.md in the repository and no published advisories. vercel.com's security.txt names HackerOne, and the changelog records hardening of the dashboard (0.35.2) and allowlist (0.32.0) (10 of 20).",
            "transparency": "Apache-2.0, copyright Vercel Inc. (30). No privacy statement for the software. The docs say where credentials, keys and state are stored, that saved state expires after 30 days by default, and that `chat` goes to the Vercel AI Gateway (18 of 30). No deprecation policy. The changelog flagged the `-C` snapshot flag as deprecated under a Breaking Changes heading (6 of 20). No telemetry code found in the source, and the README and docs do not state this either way (14 of 20)."
          },
          "sources": [
            {
              "what": "repository, README and source at commit 0207911 (7 October 2026)",
              "url": "https://github.com/vercel-labs/agent-browser",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog",
              "url": "https://github.com/vercel-labs/agent-browser/blob/main/CHANGELOG.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP tool definitions, profiles and annotations",
              "url": "https://github.com/vercel-labs/agent-browser/blob/main/cli/src/mcp.rs",
              "seen": "2026-10-08"
            },
            {
              "what": "CI workflow",
              "url": "https://github.com/vercel-labs/agent-browser/blob/main/.github/workflows/ci.yml",
              "seen": "2026-10-08"
            },
            {
              "what": "CI runs on main and the jobs of the newest run",
              "url": "https://api.github.com/repos/vercel-labs/agent-browser/actions/workflows/ci.yml/runs?branch=main\u0026per_page=10",
              "seen": "2026-10-08"
            },
            {
              "what": "stars, open issue count and creation date",
              "url": "https://api.github.com/repos/vercel-labs/agent-browser",
              "seen": "2026-10-08"
            },
            {
              "what": "newest 40 open issues and pull requests",
              "url": "https://api.github.com/repos/vercel-labs/agent-browser/issues?state=open\u0026per_page=40\u0026sort=created\u0026direction=desc",
              "seen": "2026-10-08"
            },
            {
              "what": "repository security advisories (none)",
              "url": "https://api.github.com/repos/vercel-labs/agent-browser/security-advisories",
              "seen": "2026-10-08"
            },
            {
              "what": "community profile (no security policy or contributing file)",
              "url": "https://api.github.com/repos/vercel-labs/agent-browser/community/profile",
              "seen": "2026-10-08"
            },
            {
              "what": "security documentation",
              "url": "https://agent-browser.dev/security.md",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt",
              "url": "https://agent-browser.dev/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "npm latest",
              "url": "https://registry.npmjs.org/agent-browser/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/agent-browser",
              "seen": "2026-10-08"
            },
            {
              "what": "crates.io",
              "url": "https://crates.io/api/v1/crates/agent-browser",
              "seen": "2026-10-08"
            },
            {
              "what": "Homebrew formula",
              "url": "https://formulae.brew.sh/api/formula/agent-browser.json",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=agent-browser",
              "seen": "2026-10-08"
            },
            {
              "what": "OSV advisories for the npm package (none)",
              "url": "https://api.osv.dev/v1/query",
              "seen": "2026-10-08"
            },
            {
              "what": "Vercel security.txt",
              "url": "https://vercel.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://pubapi.registry.google/rdap/domain/agent-browser.dev",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: why CI fails on main. We read the job list of one run (8 October), not the logs",
            "unchecked: the split of the 840 open items between issues and pull requests, and maintainer replies beyond the newest 40",
            "unchecked: whether the vercel-labs organisation has a default security policy outside this repository. The community profile lists none",
            "No terms of service or privacy policy governs the software, so `provenance.terms` and `provenance.privacy` are left out",
            "The crates.io package is at 0.19.0 and we did not confirm who publishes it",
            "`kind` is `mcp` because the listing shape has no value for a CLI. The CLI is the main surface and the MCP server mirrors it"
          ]
        },
        "negative": 0,
        "verdict": "Snapshots with element refs, a 29-tool default MCP profile and opt-in domain allowlists, action policies and content boundary markers suit agent use. The project is at 0.38.2 with no stable release, the ten most recent CI runs on main failed between 1 and 8 October 2026, and every security control is off by default.",
        "bestFor": "Coding agents with a shell that want short commands and compact snapshots.",
        "strengths": [
          "Accessibility-tree snapshots give each element a ref such as `@e2`, with `-i`, `-c`, `-d` and `--delta` to cut the output",
          "The stdio MCP server loads 29 tools by default and 158 with `--tools all`, each with a typed schema and `readOnlyHint`",
          "Domain allowlist, action policy, action confirmation and content boundary markers are documented with a threat model and known limitations",
          "19 tagged releases between 13 July and 1 October 2026, each with a changelog entry",
          "llms.txt and a Markdown copy of every docs page at agent-browser.dev, plus bundled skills served by `agent-browser skills get`"
        ],
        "weaknesses": [
          "The ten most recent CI runs on main, 1 to 8 October 2026, all concluded in failure. In the newest, Windows Rust tests and native end-to-end tests failed",
          "Version 0.38.2 with a Vercel Labs badge and no stable release or deprecation policy",
          "All security controls are opt-in. By default there is no limit on navigation, actions or output",
          "crates.io holds 0.19.0 from 14 March 2026, although the README lists `cargo install agent-browser` as an install route",
          "No SECURITY.md in the repository, and 840 open issues and pull requests, with most of the newest issues unlabelled and unanswered"
        ],
        "agentNotes": [
          "Run `agent-browser install` once after `npm install -g agent-browser`. It downloads Chrome for Testing",
          "Take a fresh `snapshot -i` after any navigation. Refs survive same-document changes only",
          "Pass `--json` for machine-readable results and `--max-output` to cap page text",
          "Set `--allowed-domains`, `--action-policy` and `--content-boundaries` for untrusted sites. None is on by default, and the allowlist rejects `--profile`, `--cdp` and `--restore`",
          "Start MCP with `agent-browser mcp`, and add profiles such as `--tools core,network` only when needed"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 66.6
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 70,
          "payments": 60,
          "reliability": 48,
          "schema": 84,
          "security": 67,
          "transparency": 68
        },
        "provenanceScore": 53
      },
      "connect": {
        "install": "npm install -g agent-browser \u0026\u0026 agent-browser install",
        "config": {
          "mcpServers": {
            "agent-browser": {
              "args": [
                "mcp"
              ],
              "command": "agent-browser"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/browser.control",
        "tool": "https://letme.dev/agent-browser"
      },
      "notable": [
        "Client and daemon are both Rust and speak CDP directly, with no Node.js or Playwright at run time. The daemon exits after one hour idle (https://github.com/vercel-labs/agent-browser#architecture)",
        "The MCP server has eight tool profiles. `core` is the default with 29 tools, `all` has 158, and tools/list is paged 64 at a time (https://github.com/vercel-labs/agent-browser/blob/main/cli/src/mcp.rs)",
        "Latest release 0.38.2 on 1 October 2026, on npm and Homebrew. crates.io holds 0.19.0 from 14 March 2026 (https://registry.npmjs.org/agent-browser/latest, https://formulae.brew.sh/api/formula/agent-browser.json, https://crates.io/api/v1/crates/agent-browser)",
        "The security page says every security control is opt-in and lists ten known limitations, including best-effort WebSocket blocking (https://agent-browser.dev/security.md)",
        "The ten most recent CI runs for pushes to main, 1 to 8 October 2026, concluded in failure (https://api.github.com/repos/vercel-labs/agent-browser/actions/workflows/ci.yml/runs?branch=main)",
        "No telemetry or analytics code found in a search of the source on 8 October 2026. The optional `chat` command sends prompts to the Vercel AI Gateway with the user's own key (https://github.com/vercel-labs/agent-browser#ai-chat)",
        "Cloud browsers from Browserless, Browserbase, Browser Use, Kernel and AgentCore attach through `--provider`, each with that provider's own key (https://github.com/vercel-labs/agent-browser#integrations)"
      ],
      "area": "developer",
      "details": [
        {
          "label": "Interfaces",
          "value": "CLI (`agent-browser \u003ccommand\u003e`, `--json` output, `batch` for several commands) and a stdio MCP server (`agent-browser mcp`, protocol 2025-11-25)"
        },
        {
          "label": "MCP tool profiles",
          "value": "`core` (default, 29 tools), `network`, `state`, `debug`, `tabs`, `react`, `mobile`, `all` (158 tools). Combine with commas, for example `--tools core,network`"
        },
        {
          "label": "Install routes",
          "value": "npm 0.38.2, Homebrew 0.38.2, crates.io 0.19.0 (stale). Native binaries for macOS ARM64 and x64, Linux ARM64 and x64, Windows x64"
        },
        {
          "label": "Browsers",
          "value": "Chrome for Testing by default, with existing Chrome, Brave, Playwright and Puppeteer installs detected. `--engine` also takes `lightpanda` and `obscura` (experimental). Safari on iOS through Appium"
        },
        {
          "label": "Security controls",
          "value": "All opt-in. `--allowed-domains`, `--action-policy`, `--confirm-actions`, `--content-boundaries`, `--max-output`, an auth vault encrypted with AES-256-GCM, and `AGENT_BROWSER_ENCRYPTION_KEY` for saved state"
        },
        {
          "label": "Telemetry",
          "value": "None found in the source. Not stated either way in the README or docs"
        }
      ],
      "provenance": {
        "legalEntity": "Vercel Inc.",
        "domain": "agent-browser.dev",
        "domainRegistered": "2026-01-13",
        "domainNote": "The LICENSE file reads Copyright 2025 Vercel Inc., and the repository sits in the vercel-labs organisation on GitHub. agent-browser.dev has no security.txt (HTTP 404). vercel.com's is valid until 28 September 2027 and names HackerOne.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/vercel-labs/agent-browser/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No terms or privacy document governs this software beyond the Apache-2.0 licence, so `terms` and `privacy` are left out."
        ],
        "score": 53,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Vercel Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "agent-browser.dev, registered 2026-01-13 (under a year)",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "nothing hosted, so the Apache-2.0 licence stands in",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "nothing hosted, not scored",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/agent-browser.json"
    },
    "verify": {
      "accepts": "a page on agent-browser.dev or one of its subdomains, or the README of github.com/vercel-labs/agent-browser",
      "badgeUrl": "https://www.anchorterminal.com/badges/agent-browser.svg",
      "body": {
        "slug": "agent-browser",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/agent-browser",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/agent-browser\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/agent-browser.svg\" alt=\"agent-browser on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![agent-browser on Anchor Terminal](https://www.anchorterminal.com/badges/agent-browser.svg)](https://www.anchorterminal.com/tools/agent-browser)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/agent-browser\"\u003eagent-browser on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/agent-browser",
    "json": "https://www.anchorterminal.com/tools/agent-browser.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/agent-browser.md",
    "slim": "https://www.anchorterminal.com/tools/agent-browser.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 66.6/100 · rank #263 of 842 · #10 in Browser automation · not agent-ready · confidence medium**\n\n\n## Assessment\n\nSnapshots with element refs, a 29-tool default MCP profile and opt-in domain allowlists, action policies and content boundary markers suit agent use. The project is at 0.38.2 with no stable release, the ten most recent CI runs on main failed between 1 and 8 October 2026, and every security control is off by default.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Vercel Labs (https://agent-browser.dev) |\n| Kind | MCP server |\n| Category | Browser automation (https://www.anchorterminal.com/categories/browser) |\n| Transport | stdio |\n| Auth | None · No account or key. The CLI and its daemon run on the owner's machine. Site logins are held in a local auth vault encrypted with AES-256-GCM, in saved state files (plaintext unless `AGENT_BROWSER_ENCRYPTION_KEY` is set) or in a reused Chrome profile. Cloud browser providers and the optional `chat` command need their own keys in environment variables. |\n| Pricing | Free (Free · OSS) · Free and open source under Apache-2.0, with nothing to buy and no hosted service. The optional `chat` command and dashboard chat bill the user's own Vercel AI Gateway key, and cloud browser providers bill separately (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the README, the docs or the source (checked 2026-10-08). |\n| Licence | Apache-2.0 |\n| Tools exposed | 158 |\n| Packages | npm: `agent-browser` |\n| Source | https://github.com/vercel-labs/agent-browser |\n| Docs | https://agent-browser.dev |\n| llms.txt | https://agent-browser.dev/llms.txt |\n| Last release | 2026-10-01 |\n| GitHub stars | 43,679 (as of 2026-10-08) |\n| npm downloads / week | 2,069,828 |\n| Interfaces | CLI (`agent-browser \u003ccommand\u003e`, `--json` output, `batch` for several commands) and a stdio MCP server (`agent-browser mcp`, protocol 2025-11-25) |\n| MCP tool profiles | `core` (default, 29 tools), `network`, `state`, `debug`, `tabs`, `react`, `mobile`, `all` (158 tools). Combine with commas, for example `--tools core,network` |\n| Install routes | npm 0.38.2, Homebrew 0.38.2, crates.io 0.19.0 (stale). Native binaries for macOS ARM64 and x64, Linux ARM64 and x64, Windows x64 |\n| Browsers | Chrome for Testing by default, with existing Chrome, Brave, Playwright and Puppeteer installs detected. `--engine` also takes `lightpanda` and `obscura` (experimental). Safari on iOS through Appium |\n| Security controls | All opt-in. `--allowed-domains`, `--action-policy`, `--confirm-actions`, `--content-boundaries`, `--max-output`, an auth vault encrypted with AES-256-GCM, and `AGENT_BROWSER_ENCRYPTION_KEY` for saved state |\n| Telemetry | None found in the source. Not stated either way in the README or docs |\n| Capabilities | browser.control, browser.debug |\n| Tags | official, local, open-source, browser, cli, mcp, rust, no-auth, llms-txt |\n| JSON | https://www.anchorterminal.com/api/v1/tools/agent-browser.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 48 | 9.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 84 | 13.7 |\n| Agent ergonomics | 13% | 16.2 | 78 | 12.7 |\n| Security \u0026 auth | 14% | 17.5 | 67 | 11.7 |\n| Payments \u0026 pricing | 10% | 12.5 | 60 | 7.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 70 | 6.1 |\n| Transparency \u0026 trust (editorial 68, provenance 53) | 7% | 8.8 | 61 | 5.3 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **66.6 → B** |\n\n### Why each score\n\n- Reliability 48: Scored as local software. Official npm and Homebrew packages at 0.38.2 with native binaries for five platforms, but crates.io holds 0.19.0 from 14 March 2026 while the README lists `cargo install` (18 of 20). Public CI runs Rust tests on Linux, macOS and Windows plus native end-to-end tests, and the ten most recent runs on main, 1 to 8 October 2026, concluded in failure. In the newest, Windows Rust tests and the end-to-end job failed and the other jobs passed (10 of 25). 840 open issues and pull requests. Open issues from the last week include `click` reporting success on hidden elements (#2056), the CLI re-sending a command the daemon already ran (#2032) and `--allowed-domains` failing on fresh launches (#2031), most without a reply (10 of 25). Every release has a changelog entry and breaking changes get their own heading, on a 0.x line (10 of 15). 0.38.2 with a Labs badge and no stable declaration (0).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 84: Graded on the CLI and its MCP server. Every MCP tool has a JSON Schema input with `additionalProperties` false, and `agent-browser.schema.json` covers the config file (25). llms.txt and a Markdown copy of each docs page at agent-browser.dev (10). Tool descriptions are one line, such as `Scroll the page or an element`, with parameter descriptions that say when to omit a field. Few say when not to use a tool (12). Enums, minimums, defaults and required lists, with a free-form `extraArgs` string array on every tool (12). Many CLI examples and a `--json` result shape, with error codes such as `tab_gone` named in passing and no error catalogue found (10). Versioned releases and CHANGELOG.md for each (15).\n- Agent ergonomics 78: The CLI adds no tool definitions to context, and the MCP server defaults to 29 `core` tools with seven further profiles and paged tools/list up to 158 (22 of 25). `snapshot -i`, `-c`, `-d`, `-s` and `--delta`, `--max-output`, and network request filters by type, method and status (20). Clicks fail early and name the covering element, and JSON errors carry codes such as `tab_gone` with recovery data, with no documented list of codes (14). `readOnlyHint` and `openWorldHint` on every tool, no `destructiveHint`, and open issue #2032 reports the CLI re-sending a command after it reached the daemon (12). Refs and defaults keep commands short. One CLI, no SDK in a second language (10).\n- Security \u0026 auth 67: The tool needs no credential. Site passwords sit in a local vault encrypted with AES-256-GCM and are filled without reaching the model, while saved state files are plaintext unless a key is set (22 of 30). Domain allowlist, action policy file and confirmation for chosen action categories, all opt-in, with no restriction by default (16 of 20). Content boundary markers with a per-process nonce, output caps and a written threat model with ten known limitations, also opt-in (12 of 15). A local dashboard shows a command and result feed, with no persistent audit log found (7 of 15). No SECURITY.md in the repository and no published advisories. vercel.com's security.txt names HackerOne, and the changelog records hardening of the dashboard (0.35.2) and allowlist (0.32.0) (10 of 20).\n- Payments \u0026 pricing 60: Free, self-hosted, nothing to buy, so 20 + 20 + 20 under the self-hosted rule. No payment protocol (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 70: 0.38.2 on 1 October 2026 (30). 19 tagged releases since 13 July 2026 (20). 34 commits to main since 8 September, but of the 19 newest open issues 12 had no comment and none had a label, including two off-topic ones left open (10 of 25). Not in the official MCP registry, where a search for agent-browser returned only other publishers. npm and Homebrew are current and crates.io is 19 minor versions behind (5 of 15). No runtime npm dependencies and a lockfile, with CI failing on main (5 of 10).\n- Transparency \u0026 trust 61: Apache-2.0, copyright Vercel Inc. (30). No privacy statement for the software. The docs say where credentials, keys and state are stored, that saved state expires after 30 days by default, and that `chat` goes to the Vercel AI Gateway (18 of 30). No deprecation policy. The changelog flagged the `-C` snapshot flag as deprecated under a Breaking Changes heading (6 of 20). No telemetry code found in the source, and the README and docs do not state this either way (14 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/agent-browser.md (JSON https://www.anchorterminal.com/fixes/agent-browser.json)\n\n### What we couldn't check\n\n- unchecked: why CI fails on main. We read the job list of one run (8 October), not the logs\n- unchecked: the split of the 840 open items between issues and pull requests, and maintainer replies beyond the newest 40\n- unchecked: whether the vercel-labs organisation has a default security policy outside this repository. The community profile lists none\n- No terms of service or privacy policy governs the software, so `provenance.terms` and `provenance.privacy` are left out\n- The crates.io package is at 0.19.0 and we did not confirm who publishes it\n- `kind` is `mcp` because the listing shape has no value for a CLI. The CLI is the main surface and the MCP server mirrors it\n\n### Sources\n\n- repository, README and source at commit 0207911 (7 October 2026): \u003chttps://github.com/vercel-labs/agent-browser\u003e (seen 2026-10-08)\n- changelog: \u003chttps://github.com/vercel-labs/agent-browser/blob/main/CHANGELOG.md\u003e (seen 2026-10-08)\n- MCP tool definitions, profiles and annotations: \u003chttps://github.com/vercel-labs/agent-browser/blob/main/cli/src/mcp.rs\u003e (seen 2026-10-08)\n- CI workflow: \u003chttps://github.com/vercel-labs/agent-browser/blob/main/.github/workflows/ci.yml\u003e (seen 2026-10-08)\n- CI runs on main and the jobs of the newest run: \u003chttps://api.github.com/repos/vercel-labs/agent-browser/actions/workflows/ci.yml/runs?branch=main\u0026per_page=10\u003e (seen 2026-10-08)\n- stars, open issue count and creation date: \u003chttps://api.github.com/repos/vercel-labs/agent-browser\u003e (seen 2026-10-08)\n- newest 40 open issues and pull requests: \u003chttps://api.github.com/repos/vercel-labs/agent-browser/issues?state=open\u0026per_page=40\u0026sort=created\u0026direction=desc\u003e (seen 2026-10-08)\n- repository security advisories (none): \u003chttps://api.github.com/repos/vercel-labs/agent-browser/security-advisories\u003e (seen 2026-10-08)\n- community profile (no security policy or contributing file): \u003chttps://api.github.com/repos/vercel-labs/agent-browser/community/profile\u003e (seen 2026-10-08)\n- security documentation: \u003chttps://agent-browser.dev/security.md\u003e (seen 2026-10-08)\n- llms.txt: \u003chttps://agent-browser.dev/llms.txt\u003e (seen 2026-10-08)\n- npm latest: \u003chttps://registry.npmjs.org/agent-browser/latest\u003e (seen 2026-10-08)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/agent-browser\u003e (seen 2026-10-08)\n- crates.io: \u003chttps://crates.io/api/v1/crates/agent-browser\u003e (seen 2026-10-08)\n- Homebrew formula: \u003chttps://formulae.brew.sh/api/formula/agent-browser.json\u003e (seen 2026-10-08)\n- MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=agent-browser\u003e (seen 2026-10-08)\n- OSV advisories for the npm package (none): \u003chttps://api.osv.dev/v1/query\u003e (seen 2026-10-08)\n- Vercel security.txt: \u003chttps://vercel.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://pubapi.registry.google/rdap/domain/agent-browser.dev\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 53/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Vercel Inc. | 20/20 |\n| Domain age | agent-browser.dev, registered 2026-01-13 (under a year) | 0/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | nothing hosted, so the Apache-2.0 licence stands in | 10/10 |\n| Privacy policy | nothing hosted, not scored | n/a |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe LICENSE file reads Copyright 2025 Vercel Inc., and the repository sits in the vercel-labs organisation on GitHub. agent-browser.dev has no security.txt (HTTP 404). vercel.com's is valid until 28 September 2027 and names HackerOne.\n\nNo terms or privacy document governs this software beyond the Apache-2.0 licence, so `terms` and `privacy` are left out.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The Apache-2.0 licence stands in and the check scores in full.\n\n\n**Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored.\n\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Accessibility-tree snapshots give each element a ref such as `@e2`, with `-i`, `-c`, `-d` and `--delta` to cut the output\n- The stdio MCP server loads 29 tools by default and 158 with `--tools all`, each with a typed schema and `readOnlyHint`\n- Domain allowlist, action policy, action confirmation and content boundary markers are documented with a threat model and known limitations\n- 19 tagged releases between 13 July and 1 October 2026, each with a changelog entry\n- llms.txt and a Markdown copy of every docs page at agent-browser.dev, plus bundled skills served by `agent-browser skills get`\n\n## Weaknesses\n\n- The ten most recent CI runs on main, 1 to 8 October 2026, all concluded in failure. In the newest, Windows Rust tests and native end-to-end tests failed\n- Version 0.38.2 with a Vercel Labs badge and no stable release or deprecation policy\n- All security controls are opt-in. By default there is no limit on navigation, actions or output\n- crates.io holds 0.19.0 from 14 March 2026, although the README lists `cargo install agent-browser` as an install route\n- No SECURITY.md in the repository, and 840 open issues and pull requests, with most of the newest issues unlabelled and unanswered\n\n## Before you call it (notes for agents)\n\n1. Run `agent-browser install` once after `npm install -g agent-browser`. It downloads Chrome for Testing\n2. Take a fresh `snapshot -i` after any navigation. Refs survive same-document changes only\n3. Pass `--json` for machine-readable results and `--max-output` to cap page text\n4. Set `--allowed-domains`, `--action-policy` and `--content-boundaries` for untrusted sites. None is on by default, and the allowlist rejects `--profile`, `--cdp` and `--restore`\n5. Start MCP with `agent-browser mcp`, and add profiles such as `--tools core,network` only when needed\n\n## Connect\n\nInstall:\n\n```bash\nnpm install -g agent-browser \u0026\u0026 agent-browser install\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"agent-browser\": {\n      \"args\": [\n        \"mcp\"\n      ],\n      \"command\": \"agent-browser\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/agent-browser. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Chrome DevTools MCP | BB | 77 | 23 | browser.control, browser.debug | no | https://www.anchorterminal.com/tools/chrome-devtools-mcp.md |\n| Browserless | BB | 70.4 | 148 | browser.control, browser.debug | no | https://www.anchorterminal.com/tools/browserless.md |\n| Steel | BB | 70.4 | 149 | browser.control, browser.debug | yes | https://www.anchorterminal.com/tools/steel.md |\n| Anchor Browser | B | 67.3 | 237 | browser.control, browser.debug | no | https://www.anchorterminal.com/tools/anchor-browser.md |\n| Skyvern | B | 63.1 | 369 | browser.control, browser.debug | no | https://www.anchorterminal.com/tools/skyvern.md |\n| Airtop | C | 55.3 | 592 | browser.control, browser.debug | no | https://www.anchorterminal.com/tools/airtop.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Client and daemon are both Rust and speak CDP directly, with no Node.js or Playwright at run time. The daemon exits after one hour idle (source: \u003chttps://github.com/vercel-labs/agent-browser#architecture\u003e)\n- The MCP server has eight tool profiles. `core` is the default with 29 tools, `all` has 158, and tools/list is paged 64 at a time (source: \u003chttps://github.com/vercel-labs/agent-browser/blob/main/cli/src/mcp.rs\u003e)\n- Latest release 0.38.2 on 1 October 2026, on npm and Homebrew. crates.io holds 0.19.0 from 14 March 2026 (source: \u003chttps://registry.npmjs.org/agent-browser/latest, https://formulae.brew.sh/api/formula/agent-browser.json, https://crates.io/api/v1/crates/agent-browser\u003e)\n- The security page says every security control is opt-in and lists ten known limitations, including best-effort WebSocket blocking (source: \u003chttps://agent-browser.dev/security.md\u003e)\n- The ten most recent CI runs for pushes to main, 1 to 8 October 2026, concluded in failure (source: \u003chttps://api.github.com/repos/vercel-labs/agent-browser/actions/workflows/ci.yml/runs?branch=main\u003e)\n- No telemetry or analytics code found in a search of the source on 8 October 2026. The optional `chat` command sends prompts to the Vercel AI Gateway with the user's own key (source: \u003chttps://github.com/vercel-labs/agent-browser#ai-chat\u003e)\n- Cloud browsers from Browserless, Browserbase, Browser Use, Kernel and AgentCore attach through `--provider`, each with that provider's own key (source: \u003chttps://github.com/vercel-labs/agent-browser#integrations\u003e)\n\n## Compare\n\n- [agent-browser vs Airtop](https://www.anchorterminal.com/compare/agent-browser-vs-airtop.md): B 66.6 vs C 55.3\n- [agent-browser vs Anchor Browser](https://www.anchorterminal.com/compare/agent-browser-vs-anchor-browser.md): B 66.6 vs B 67.3\n- [agent-browser vs Browser Use](https://www.anchorterminal.com/compare/agent-browser-vs-browser-use.md): B 66.6 vs BB 77.9\n- [agent-browser vs Browserbase](https://www.anchorterminal.com/compare/agent-browser-vs-browserbase.md): B 66.6 vs BB 76.2\n- [agent-browser vs Browserless](https://www.anchorterminal.com/compare/agent-browser-vs-browserless.md): B 66.6 vs BB 70.4\n- [agent-browser vs Chrome DevTools MCP](https://www.anchorterminal.com/compare/agent-browser-vs-chrome-devtools-mcp.md): B 66.6 vs BB 77\n- [agent-browser vs Hyperbrowser](https://www.anchorterminal.com/compare/agent-browser-vs-hyperbrowser.md): B 66.6 vs B 66.9\n- [agent-browser vs Notte](https://www.anchorterminal.com/compare/agent-browser-vs-notte.md): B 66.6 vs B 63.2\n- [agent-browser vs Playwright MCP](https://www.anchorterminal.com/compare/agent-browser-vs-playwright-mcp.md): B 66.6 vs B 67.6\n- [agent-browser vs Puppeteer (archived MCP reference server)](https://www.anchorterminal.com/compare/agent-browser-vs-puppeteer-reference-server-archived.md): B 66.6 vs F 30.6\n- [agent-browser vs Skyvern](https://www.anchorterminal.com/compare/agent-browser-vs-skyvern.md): B 66.6 vs B 63.1\n- [agent-browser vs Steel](https://www.anchorterminal.com/compare/agent-browser-vs-steel.md): B 66.6 vs BB 70.4\n- [agent-browser vs TinyFish](https://www.anchorterminal.com/compare/agent-browser-vs-tinyfish.md): B 66.6 vs B 67.7\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on agent-browser.dev or one of its subdomains, or the README of github.com/vercel-labs/agent-browser. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"agent-browser\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/agent-browser\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/agent-browser.svg\" alt=\"agent-browser on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![agent-browser on Anchor Terminal](https://www.anchorterminal.com/badges/agent-browser.svg)](https://www.anchorterminal.com/tools/agent-browser)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/agent-browser\"\u003eagent-browser on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say agent-browser is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/agent-browser-dark.png\n- Light: https://www.anchorterminal.com/assets/share/agent-browser-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Browser automation",
        "url": "https://www.anchorterminal.com/categories/browser"
      },
      {
        "name": "agent-browser",
        "url": ""
      }
    ],
    "description": "agent-browser is an open-source command-line tool from Vercel Labs that lets AI agents drive Chrome through accessibility-tree snapshots and element refs. It runs locally as a Rust binary and includes a stdio MCP server.",
    "facts": [
      "rank #263 of 842",
      "None auth",
      "0 desk reviews"
    ],
    "h1": "agent-browser",
    "image": "https://www.anchorterminal.com/assets/og/tools-agent-browser.png",
    "path": "/tools/agent-browser",
    "published": "2026-10-01",
    "section": "tools",
    "title": "agent-browser review for AI agents, grade B (66.6/100)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/agent-browser"
  },
  "tokens": {
    "markdown": 5750,
    "slim": 1280
  },
  "version": 1
}
