Cdpilot MCP server
Zero-dependency browser automation over raw CDP — no Puppeteer, Playwright, or Selenium.
31 stars39 downloads/wk
Reviews
Write oneNobody has reviewed Cdpilot yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Cdpilot tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan3 source files scanned13/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (1)
- highShell command built from a string (injection risk)
exec.shell-concatbin/cdpilot.js: …n bin; } else { try { execSync(`which ${bin} 2>/dev/null`, { stdio: 'pipe' }); …
Install Cdpilot in Claude Code, Cursor or VS Code
Runs npx -y cdpilot on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add cdpilot -- npx -y cdpilot
What the publisher says
From the Cdpilot repository's README, as published. We do not edit it. Read it on GitHub
cdpilot
Zero-dependency browser automation from your terminal. One command, full control.
Quick Start
npx cdpilot launch # Start browser with CDP
npx cdpilot go https://example.com
npx cdpilot shot # Take screenshotNo config files. No boilerplate. Just npx and go.
Why cdpilot?
AI agents and developers need browser control that just works:
- Zero config — npx cdpilot launch starts an isolated browser session
- Zero dependency — No Puppeteer, no Playwright, no Selenium. Pure CDP over HTTP
- 70+ commands — Navigate, click, type, screenshot, network, console, accessibility, video understanding, progressive anti-bot resilience, and more
- AI-agent friendly — Designed for Claude, GPT, Gemini, and any LLM tool-use workflow
- Isolated sessions — Your personal browser stays untouched. cdpilot runs in its own profile
- Visual feedback — Green glow overlay, cursor visualization, click ripples, and keystroke display keep you informed during automation
- Multi-project isolation — Each project gets its own browser instance and port automatically, no conflicts
- AI control warning — Red toast notification appears when you hover during active automation
- Privacy-first — Everything runs locally. No data leaves your machine
Browser Selection (Workload-Aware Auto-Pick)
cdpilot picks the right browser for what you're doing. auto (default) is a two-axis policy — extension workload × platform stability:
Override anytime:
cdpilot browser # show current pick + reason
cdpilot browser vivaldi # pin to Vivaldi
cdpilot browser auto # restore smart defaultWhy the split?
(no error, no warning). Verified — chrome://extensions shows 0 items.
- Chrome 147+ silently drops --load-extension for unpacked extensions
uptime (SIGTRAP in ThreadPoolForegroundWorker). cdpilot detects the OS and demotes Brave automatically until a fixed Brave release ships.
- Vivaldi, Brave, Edge, Chromium honor --load-extension (tested).
- On macOS 26 (Tahoe) Brave 1.89 crashes deterministically at ~7min
Each browser gets its own isolated profile (~/.cdpilot/.../profile-vivaldi etc.) so switching never causes prefs corruption.
Installation
# Use directly (no install needed)
npx cdpilot <command>
# Or install globally
npm i -g cdpilotRequirements: Node.js 18+, Python 3.10+, and one of: Brave Browser, Google Chrome, or Chromium. (The Python websockets module is auto-installed by the pre-flight wizard on first launch.)
First-time setup
npx cdpilot setup # Auto-detect browser, create isolated profile
npx cdpilot launch # Start browser with CDP enabled
npx cdpilot status # Check connectionUpgrading from 0.4.x → 0.5.0 — read this first
One breaking change, the rest is additive.
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Cdpilot: common questions
- Is Cdpilot MCP server safe?
- Mostly: it is graded B (74/100). Read the Cdpilot safety report
- How do I install Cdpilot?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Cdpilot need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Cdpilot maintained?
- The last commit was in the last day (2026-09-27). The latest release is v0.9.2.
- What can I use instead of Cdpilot?
- Servers from other publishers that do the same job: FableCut MCP server, Public Browser MCP server and SeleniumBase MCP server. Compare all Cdpilot alternatives.
Alternatives to Cdpilot
Same job from other publishers: the closest match first, then the best rated.
- FableCutZero-dependency browser video editor AI agents drive via a JSON timeline over MCP; ffmpeg export.not reviewedEstablishedA
Public BrowserChrome over CDP for AI agents. Blind benchmark vs agent-browser: -33% tokens, -33% cost, -32% timenot reviewedGrowingA- SeleniumBase MCPStealthy browser automation, testing, and web-scraping via CDP Mode.not reviewedWidely usedA
- invisible_playwright_mcpAI browser agent: browses, clicks, types, and reads real web pages from plain-English instructions.not reviewedEstablishedA
- SafariNative Safari browser automation for AI agents — 98 tools, zero Chrome overhead.not reviewedEstablishedC