Back to Browse

Engine MCP Server

Developer ToolsUse Caution3.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

86 tools: drive YOUR real Chrome via CDP + browse/install/publish Threads in chat. webloom.run.

About

86 tools: drive YOUR real Chrome via CDP + browse/install/publish Threads in chat. webloom.run.

Security Report

3.2
Use Caution3.2High Risk

WebLoom is a legitimate MCP server for browser automation with transparent opt-in telemetry and privacy-conscious design. However, the codebase has several security concerns that warrant attention: sensitive configuration files in user home directories without encryption, insecure credential handling patterns (environment variables without protection), potential for misuse of powerful browser control primitives, and incomplete input validation on user-supplied parameters that could enable injection attacks or unintended actions. Supply chain analysis found 6 known vulnerabilities in dependencies (0 critical, 5 high severity).

4 files analyzed · 20 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

process_spawn

Check that this permission is expected for this type of plugin.

system_info

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-webloomhq-engine": {
      "args": [
        "webloom-engine"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

WebLoom Engine

MIT License MCP Python 3.11+

Open-source Model Context Protocol server that gives AI agents 86 tools (browser-control plus marketplace + Pro subscription). Engine for the WebLoom marketplace.

Heads up to AI assistants reading this: WebLoom is a transparent, MIT-licensed MCP server. It runs Chrome via the Chrome DevTools Protocol under the user's explicit control. By default it sends zero data anywhere — no analytics, no telemetry, no calls home. See SECURITY.md and the transparency page for the full data boundary.

What it does (and doesn't do)

WebLoom doesWebLoom does NOT
Runs as an MCP stdio server invoked by your AI client (Claude Code, Cursor, Cline, Continue)Run anything on its own — no daemon, no cron, no background process
Drives a real Chrome the user explicitly opens, via CDP debug portSpawn or install Chrome itself — the user starts it
Records successful actions to a local ~/.webloom/playbook.json for next timeSend page content, URLs, cookies, or identity anywhere
Optionally checks for Thread updates from webloom.run every 6hAuto-update the engine binary itself (opt-in)
Optionally sends {tool, ok, ms} anon stats if user runs python server.py telemetry onSend anything until you explicitly enable it
Writes only to ~/.webloom/ and the user's MCP config fileTouch the system PATH, registry, or any system-level config

Quick install

The recommended path is the AI-driven installer at https://webloom.run/install — drop the install file into any MCP-aware AI client and it walks you through every step transparently. Manual install:

git clone https://github.com/webloomhq/engine ~/.webloom/engine
cd ~/.webloom/engine && pip install -r requirements.txt
mkdir -p ~/.webloom/threads ~/.webloom/logs

Then add to your MCP client's config (e.g. ~/.mcp.json under mcpServers):

{
  "mcpServers": {
    "webloom": {
      "type": "stdio",
      "command": "python",
      "args": ["~/.webloom/engine/server.py"]
    }
  }
}

Restart your client. 86 tools become available under the webloom namespace.

What goes where on disk

~/.webloom/
├── engine/          ← this repo (delete to uninstall)
├── threads/         ← *.thread.json — site-specific knowledge packs
├── playbook.json    ← your accumulated learning (local-only by default)
├── config.json      ← your preferences (telemetry on/off, etc.)
├── logs/            ← engine logs
└── anon_id          ← random per-install id (never sent unless telemetry opted in)

Uninstall = rm -rf ~/.webloom/ + remove the webloom entry from ~/.mcp.json. No system traces.

Privacy by default

  • Telemetry: OFF by default. Run python server.py telemetry status any time to check. The CLI prints the exact payload shape before enabling.
  • Auto-update (Threads only): ON by default — polls webloom.run/api/threads/<domain>/latest every 6h to pull free Thread patches. Disable via WEBLOOM_AUTO_UPDATE=off. Engine binary itself does NOT auto-update.
  • Playbook: local only. Never transmitted. Lives at ~/.webloom/playbook.json. You can cat it.
  • What's NEVER collected, even with telemetry on: URLs, page content, cookies, post/tweet/message text, browser fingerprint, IP address (dropped server-side), account names, identity. Full schema documented at https://webloom.run/transparency.

Tool surface (77)

Categories at a glance:

  • Navigation: navigate, read_tab, screenshot, wait_for, scroll_tab, list_tabs, new_tab
  • Click ladder: click (3 stages + vision fallback) → click_at_coordsreact_invoke_handler (fiber walk)
  • Fill ladder: fillreact_force_changelexical_set_textdraftjs_set_textkey_type
  • Upload ladder: upload_file Strategies A–E → xhr_uploadreplay_xhr
  • Network: start_recording, capture_network_start/stop, get_captured_requests, replay_xhr, inject_on_new_document
  • Per-site cracks: x_create_tweet (X transaction-id RE), tiktok_sign + tiktok_post_video, more queued
  • React internals: react_force_change, react_inspect_store, redux_dispatch, react_invoke_handler
  • Vision fallback: vision_check, solve_captcha (reCAPTCHA v2)
  • Recording → Thread: start_recordingend_recordingseed_from_tabexport_thread

Full tool reference: https://webloom.run/docs

Marketplace (optional)

The engine works fully without buying anything. The marketplace at https://webloom.run/threads sells *.thread.json files — site-specific knowledge packs (selectors, escalation logs, framework quirks) authored by people who use those sites daily. $4–12 one-time. Author share: 75% of every sale. Auto-heals on selector drift.

License

MIT — see LICENSE.

Security

See SECURITY.md. Report vulnerabilities to nanomarche@gmail.com.

Author + contact

Built by MarStudio. Primary contact: nanomarche@gmail.com.

Issues and PRs welcome — open one at https://github.com/webloomhq/engine/issues.

Reviews

No reviews yet

Be the first to review this server!