CloakBrowser-Agent
Jev-powered stealth browser agent. TypeSafe Jev decides each step in ~0.3 s, CloakBrowser carries it out like a human. MCP server, CLI and Python API.
Install / Use
claude mcp add CloakHQ -- npx -y github:CloakHQ/CloakBrowser-AgentIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
AutomationSupported Platforms
Our assessment of CloakBrowser-Agent
CloakBrowser-Agent scores 75/100 on our quality scale, 2602nd of 2,869 Automation skills we index.
Its MCP Server is 16 KB long, well organised into 24 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 5 days ago, so CloakBrowser-Agent is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
CloakBrowser-Agent compared with similar skills
All 4 of these similar skills score higher than CloakBrowser-Agent; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| CloakBrowser-Agent (this skill)by CloakHQ | 75 | 3 | 5d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 91.8k | 20d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.5k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.9k | 1d ago | MCP Server |
Frequently asked questions
- How do I install CloakBrowser-Agent?
- Run
claude mcp add CloakHQ -- npx -y github:CloakHQ/CloakBrowser-Agent. The install tabs above show the steps for each supported agent. - Which AI agents does CloakBrowser-Agent work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is CloakBrowser-Agent safe to use?
- It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is CloakBrowser-Agent still maintained?
- The repository was last updated 5 days ago, so CloakBrowser-Agent is actively maintained.
Skill content
View source on GitHubCloakBrowser Agent: a Jev-powered stealth browser agent
Give it a goal in plain language. TypeSafe Jev decides every step in ~0.3 s, CloakBrowser carries it out like a human, and you get the result back as markdown.
browse(goal="Find one-way flights from Zurich to London on October 20, 2026, for one adult in economy.
Stop when matching flight options are visible.",
url="https://www.google.com/travel/flights?hl=en")
status: done
tab_id: t1 (still open)
url: https://www.google.com/travel/flights/search?tfs=...
title: Zürich to London | Google Flights
steps: 10 actions, 14 decisions, 22596 ms
actions taken (p = Jev's probability for the chosen target; runner-ups in brackets):
1. click 'Change ticket type. Round trip' p=0.81 ['Open Where from?' p=0.15, 'Flights' p=0.01]
2. click 'One way' p=1.0
3. fill 'Where from?' = 'Zurich' p=0.93 ['Where to? ' p=0.04, 'Departure' p=0.03]
4. click 'Zürich, Switzerland' p=0.77 ['Zurich Airport (ZRH)' p=0.21, 'Open Where from? ' p=0.01]
5. fill 'Where to? ' = 'London' p=0.99 ['Departure' p=0.01]
6. click 'London, United Kingdom' p=0.95 ['Heathrow Airport (LHR)' p=0.02, ...]
7. click 'Open Departure' p=0.97 ['Search' p=0.03]
8. click 'Tuesday, October 20, 2026 , 48 euros, Cheapest price' p=0.98 ['Done. ' p=0.02]
9. click 'Done. Search for one-way flights, departing on October 20, 2' p=0.98 [...]
10. click 'Search' p=0.99 ['Open Where from?' p=0.01]
...
<untrusted_page_content>
# Flight search
...
## Search results
...
from €48
A real run, trimmed.
It works as an MCP server (Claude Code, Cursor, Claude Desktop, any MCP client), a CLI, or a Python library. It runs on CloakBrowser, a stealth Chromium with human-like mouse and keyboard input.
Why Jev
Most browser agents ask a large language model to write the next action, which costs seconds per step. Jev is TypeSafe's first System One model. It doesn't generate text: you give it the current state plus typed questions, and it returns an answer with calibrated probabilities. A browser step is exactly that kind of question: which of these controls, doing what?
- One request per step. Jev answers "which operation" and "which element" together in one request (speculative fan-out: a target question for each possible operation, and only the chosen one is used).
- Fast. In our runs, Jev decisions averaged 0.28–0.43 s each, about 1 s for a whole search task. A text model is called only when a field needs typing.
- Probabilities, not prose. Every decision comes with a distribution and a confidence, so the code can see when the model is unsure.
- Nothing to parse. Answers are typed choices from options we built, so there's no free-form output to go wrong.
- Jev ranks the result too. When the task is done, Jev scores every section of the final page against the goal, and only the relevant sections come back.
How it works
goal ─► OBSERVE read the page → numbered table of the controls a user can actually reach
▲
│ DECIDE one Jev request: which operation (CLICK, TYPE_TEXT, SELECT, SCROLL, WAIT, DONE, BLOCKED)
│ and which element, answered together
│ TYPE_TEXT → a small text model writes only the value for that one field
│
└─ ACT human-like click / typing, after checking the page did not change
DONE → the page is turned into markdown, Jev scores each section against the goal, the best sections are returned
- No site-specific code. The same loop runs on every site and re-plans from the current page after every action. Cookie walls, popups and changed layouts are just more elements to choose from.
- Model output never becomes code. The model picks from indices we built. It never writes selectors, coordinates or scripts.
- Nothing is injected into the page. The page is read without adding anything to it that the site's scripts can see.
- Only reachable controls are offered. Hidden, disabled, and covered elements (for example, behind a modal) aren't in the table.
- A DONE answer isn't taken as proof. Check results that matter.
Requirements
- Python 3.10+
- A TypeSafe API key (Jev)
- A key for any OpenAI-compatible chat model (OpenRouter, OpenAI, DeepSeek, …). It is used only to write field values.
- A CloakBrowser license key for the latest stealth build. A free key takes one GitHub sign-in: run
cloakbrowser loginor go to cloakbrowser.dev/free. A free key allows one browser session at a time, and a paid key raises that limit. Without any key, the older build is used.
The browser binary downloads automatically on first use. Node is not needed.
Install
pip install cloakbrowser-agent
This installs the cloak-agent and cloak-agent-mcp commands, plus cloakbrowser (for cloakbrowser login).
For MCP clients you don't even need to install it: the configs below use uvx, which fetches and runs it on demand.
From source: git clone https://github.com/CloakHQ/CloakBrowser-Agent && cd CloakBrowser-Agent && pip install -e .
Configure
| Variable | Required | Meaning |
|---|---|---|
| TYPESAFE_API_KEY | yes | Jev decisions |
| TYPESAFE_MODEL | no | default jev-latest |
| TEXT_MODEL_BASE_URL | yes | OpenAI-compatible base URL, e.g. https://openrouter.ai/api/v1 |
| TEXT_MODEL_API_KEY | yes | key for that endpoint |
| TEXT_MODEL | yes | model id, e.g. a small fast model |
| TEXT_MODEL_REASONING | no | sent as reasoning_effort (low / medium / high); none omits it |
| TEXT_MODEL_HEADERS | no | JSON object of extra request headers, if your provider needs any |
| CLOAKBROWSER_LICENSE_KEY | recommended | CloakBrowser license key (cb_...). Instead of setting it here, you can run cloakbrowser login once: the saved key is picked up automatically |
| CLOAKBROWSER_RELEASE_CHANNEL | no | preview = launch the Preview build instead of Stable (needs a license key; ignored without one) |
Use as an MCP server
Claude Code
claude mcp add cloak-agent --scope user \
-e TYPESAFE_API_KEY=... \
-e TEXT_MODEL_BASE_URL=https://openrouter.ai/api/v1 -e TEXT_MODEL=... -e TEXT_MODEL_API_KEY=... \
-e CLOAKBROWSER_LICENSE_KEY=cb_... \
-- uvx --from cloakbrowser-agent cloak-agent-mcp
Cursor / Claude Desktop (mcpServers in the client's config)
{
"mcpServers": {
"cloak-agent": {
"command": "uvx",
"args": ["--from", "cloakbrowser-agent", "cloak-agent-mcp"],
"env": {
"TYPESAFE_API_KEY": "...",
"TEXT_MODEL_BASE_URL": "https://openrouter.ai/api/v1",
"TEXT_MODEL": "...",
"TEXT_MODEL_API_KEY": "...",
"CLOAKBROWSER_LICENSE_KEY": "cb_..."
}
}
}
}
Tools
browse(goal, url?, tab_id?) runs one whole task and returns:
status:done,blocked(no control can make progress),needs_input(the goal lacks a value a field needs),budget(step limit reached), orerrortab_id(the tab stays open), the final URL and title, and the number of actions, decisions and milliseconds- every step taken: what was clicked or typed, Jev's probability
pfor it, and the top runner-ups in brackets. A lowp, or a runner-up close behind, shows where the agent was unsure. - stale retries, if any: steps re-decided because the page changed before acting, with what changed
- the relevant page content as markdown, fenced as
<untrusted_page_content>
While a call runs, each step is also sent as a live progress notification (clients that show MCP progress display it).
snapshot(tab_id, screenshot?) shows a tab exactly as the agent sees it: URL, title, scroll position, the operations on offer, the numbered element table ([3] button "Reject all") and the visible text. With screenshot=True it also returns an image of the visible part of the page. Use it to see why a task stopped.
act(tab_id, op?, target?, instruction?, text?, screenshot?) does one step in a tab yourself, for example to get past a page the agent is stuck on. Give either:
op+targetfrom the latest snapshot:CLICK "3",TYPE_TEXT "5"withtext,SELECT "4:2", orSCROLL_DOWN/SCROLL_UP/WAIT. No model is involved:textis typed exactly as given. Password fields are not offered.instruction, one step in plain language ("click Reject all"). Jev picks the element; the reply shows itspand runner-ups.
act returns what it did, whether the page changed, and the new snapshot, so steps can be chained. If the page changed since the snapshot, nothing is done and it answers status: stale. A tab serves one call at a time; a second call on it answers busy. Continue the task with browse(goal, tab_id=...) whenever you like.
close_tab(tab_id) closes a tab.
Working with tabs
| Call | What happens |
|---|---|
| browse(goal, url) | New tab, opens url, runs the goal |
| browse(goal, tab_id="t1") | Continues on the page tab t1 is showing |
| browse(goal, url, tab_id="t1") | Navigates tab t1 to url, then runs the goal |
| browse(goal) | Error: give a url or a tab_id |
A tab_id stays valid until you close_tab it, close it in the browser, or the browser idles out. After that, browse answers status: error (tab 't1' is gone; open tabs: ...).
Multi-call examples
# 1. A task that needs values the goal did not include
browse(goal="Fill in the pizza order form and submit it.", url="https://httpbin.org/forms/post")
→ status: needs_input (No value in the goal for field: Customer name:) tab_id: t1
browse(goal="Fill in the pizza order form with customer name Jane Doe, telephone 555-0100, "
"email jane@example.com, size medium, and submit it.", tab_id="t1")
→ status: done (fills all four fields on the same form, clicks 'Submit order')
# 2. A follow-up step on the page the last task ended on
browse(goal="Search Google for 'CloakBrowser GitHub' and open the CloakHQ/CloakBrowser repository.",
url="https://www.google.com")
→ status: done tab_id: t2
browse(goal="Open the Issues tab of this repository and list the titles of the newest issues.", tab_id="t2")
→ status: done (1 action: click 'Issues')
# 3. Taking over a stuck task: look, do one step by hand, let the agent continue
snapshot(tab_id="t3")
→ [2] searchbox "Search Wikipedia" ops=TYPE_TEXT,CLICK ...
act(tab_id="t3", op="TYPE_TEXT", target="2", text="Kurt Gödel")
→ status: done (new snapshot: [3] option "Kurt Gödel Mathematician and philosopher (1906–1978)" ...)
act(tab_id="t3", op="CLICK", target="3")
→ status: done url: https://en.wikipedia.org/wiki/Kurt_G%C3%B6del
browse(goal="Summarize his incompleteness theorems.", tab_id="t3")
Tips:
- Put every value the task needs into the goal (search terms, form values), because fields are filled from the goal.
- Several
browsecalls can run at once. Each gets its own tab in the same browser.
Browser lifecycle
- The browser starts on the first call, headed by default so you can watch it.
- Tabs stay open after a task so you can see the result.
- After
CLOAK_AGENT_IDLE_MINUTESwithout calls (default 5), the browser closes itself along with its tabs, and it relaunches on the next call. It also closes when the MCP server stops. - An open browser holds one CloakBrowser session. On a free key (one session), close it or let it idle out before running another CloakBrowser script.
| Variable | Default | Meaning |
|---|---|---|
| CLOAK_AGENT_IDLE_MINUTES | 5 | close the browser after this long without calls |
| CLOAK_AGENT_HEADLESS | off |
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
91.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.5kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
85.9k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
