The developer community is seeing a new entry in the browser automation space with the release of invisible_playwright_mcp. This tool packages a browser agent as both an MCP server and a local web interface, aiming to integrate directly with AI assistants. The maintainer claims that the underlying Firefox engine remains undetected by anti-bot systems and CAPTCHAs, offering a potential workaround for developers struggling with headless browser detection.
Dual Interfaces for Assistant Integration
The repository supports installation paths for major AI coding assistants, including Claude Code, Codex, and Gemini CLI. When invoked without a subcommand, the package starts the MCP server, while the ui subcommand launches a standalone local interface. This interface presents a chat window alongside a live browser view and requires an OpenRouter key for operation. The project also directs Python developers to invisible_playwright, a related library that mirrors the Playwright API structure.
Configuration and Persistence Options
The agent interacts with pages through simulated pointer movements and key presses. Configuration options include proxy support, seeded browser identities, persistent profile directories, and a headed mode. According to the documentation, a repeated seed produces the same browser identity, while profile directories preserve cookies and login states across restarts. Proxy selection also determines the timezone, locale, and network egress point, allowing for more realistic traffic patterns.
Data Flow and Privacy Considerations
While the agent executes locally with no proprietary server, it does not operate in a vacuum. The local web UI sends conversation history and page content read by the agent to OpenRouter. Similarly, an MCP client sends corresponding data to its respective provider. The engine is downloaded from a GitHub release on first start, and a GeoIP database is fetched when proxies are configured. Each browser launch also triggers a one-line counter file fetch from GitHub, which the maintainer states carries no identifier, though GitHub logs the originating IP address.
Security Warnings and Operational Risks
The README includes critical warnings for users. Changing the interface host from its default loopback address exposes the service without authentication. Additionally, passing an OpenRouter key via the command line risks exposing it in shell history and the Linux process list; using environment variables or a .env file is recommended to mitigate this. The project emphasizes that sessions, profiles, and screenshots are stored locally, but the external data flows to providers remain a key consideration for privacy-conscious teams.
Analysis: The Gap Between Claim and Evidence
The claim of undetectability is currently stronger than the evidence presented in the repository. The README lacks a target-site matrix, testing protocol, success rates, or independent validation to support the anti-bot assertion. This does not prove the claim false, but it leaves developers without a documented basis for estimating reliability against specific site defenses. The tool offers configuration depth, but the core value proposition of stealth remains unverified by public benchmarks.
The Unresolved Control Boundary
Pairing persistent browser state with an agent intended to appear less detectable shifts the central deployment question toward authorization and review. A profile can preserve cookies and logins, page data can leave the machine, and a host change can expose an unauthenticated interface. The unresolved trade-off is whether teams can gain useful browser access without granting overly broad access to stored sessions or sensitive page content. Those risks follow from the project’s documented persistence, data-flow, and host settings. The project also advises users to read site terms of service, respect rate limits, and ensure human review before submitting content.
Key Takeaways
- The tool integrates with Claude Code, Codex, and Gemini CLI via MCP, offering both a server mode and a local web UI.
- Stealth capabilities are claimed by the maintainer but lack independent validation, such as target-site matrices or success rates.
- Significant data leaves the local machine for OpenRouter and provider APIs, requiring careful review of privacy implications.
- Operational security requires attention to host exposure and API key management to prevent unauthorized access or credential leaks.
The Bottom Line
This tool is a promising bridge for MCP-based browser automation, but teams should treat the stealth claims as experimental until independent testing confirms them. The operational security warnings regarding exposed hosts and API keys are essential reading before deployment.