SOTA stealth browser automation with Camoufox + MCP integration
17 tools with consistent verb_noun naming (browser_*). All have descriptions (avg 120 chars, within baseline 34-392). Input schemas present with type definitions for all params. However, output schemas are undocumented, responses are inferred from code (e.g., snapshot returns dict with refs, title, url, markdown). No enum constraints on direction param (browser_scroll accepts 'up'/'down' as free strings). Error handling returns generic {"error": str(e)} without recovery guidance or categorization. No tool annotations (readOnlyHint/destructiveHint). Descriptions lack dependency hints and prerequisites. Parameter descriptions are minimal (e.g., 'The ref index' without explaining what happens if ref is stale). Missing output schema documentation is a critical gap per pattern:tool.
Click an interactive element identified by its ref index from the last snapshot. Returns an updated snapshot.
Close the browser and reset internal state. Use before reinitializing with different settings.
Execute arbitrary JavaScript in the page context and return the result.
Return all cookies for the current page context as a list of cookie objects.
Extract the visible text content of the current page as markdown.
Hover over an element identified by its ref index. Useful for triggering tooltips or dropdown menus. Returns an updated snapshot.
Output schemas undocumented. Code shows snapshots return {refs, title, url, markdown, screenshot?}, but no formal schema in tool definitions. LLMs cannot plan downstream calls without knowing response structure.
browser_scroll direction param accepts free-form string ('up'/'down') without enum constraint. LLMs may pass invalid values like 'left', 'right', 'forward'. Should declare enum: ['up', 'down'].
Error handling returns generic {"error": str(e)} without recovery guidance. RefStale exception and other errors do not tell LLM what to do next (retry? call different tool? ask user?). Per pattern:recovery-guide, errors must guide next steps.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | <=2025-11-25 | v2 |
Load cookies from a previously saved named session into the current browser context.
Navigate back in the browser history and return a snapshot of the resulting page.
Navigate to a URL and return a snapshot of the page with all interactive elements.
Press a keyboard key (e.g. 'Enter', 'Tab', 'Escape', 'ArrowDown'). Returns an updated snapshot.
Reload the current page and return a fresh snapshot.
Save current browser cookies to a named session file for later restoration.
Capture a full-page screenshot as a base64-encoded PNG string.
Scroll the page up or down by the given number of pixels. direction must be 'up' or 'down'. Returns an updated snapshot.
Select an option by value in a <select> element identified by its ref index. Returns an updated snapshot.
Take a snapshot of the current page. Returns all interactive elements with ref indices, page title, URL, and markdown content. Set include_screenshot=True to also get a base64 PNG.
Type text into an input element identified by its ref index. Clicks the element first, optionally clears existing content, then types with human-like timing. Returns an updated snapshot.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Current MCP spec (2026-07-28) supports tool annotations to help LLMs reason about side effects. browser_click, browser_type, browser_press_key are destructive; browser_open, browser_screenshot are read-only.
Parameter descriptions lack context. 'The ref index of the element to click' does not explain what happens if ref is out of range, or that refs are only valid until next snapshot. Should include dependency hints per pattern:tool-description.