跳到主要内容
Supermarket
返回能力市场
MCP Server
productivity
MIT

AIHawk

Anti detect browser and web browsing agent: an open-source MCP server for undetected browsing, AI web scraping and computer use agents. No captchas.

feder-crfeder-cr
39/ 100

公开评测 · 综合采用结论

检测到关键风险,修复前不建议接入

查看评测依据 评测我的项目基于公开项目证据,非安全认证或安装推荐
31.6kstars
4.7kforks
最近更新 9天前
评测生成时间(北京时间)
本报告引擎
v3.14.0
当前引擎
v3.16.0

本报告与当前引擎使用不同规则;原分数不会自动更新,不同版本的分数不宜直接对比。

重新评测此项目

进入后确认来源与额度,提交才会创建任务。

Evaluation report

综合采用结论

39
F
满分 100
暂不建议使用关键风险
决策摘要

检测到关键风险,修复前不建议接入

88%
高置信度
80
文档
34
安全
82
质量
100
活跃
65
采用
  • 基础评测完成+25/25确定性评分与静态安全扫描已完成
  • README 有效证据+17/256,860 个去重后的有效字符
  • 独立证据来源+16/204 类非重复证据,重复文件不叠加
  • 仓库元数据+10/10已取得仓库状态与采用数据
  • 活跃记录+5/5已取得最近提交时间
  • AI 复核+15/15已完成结构化 AI 证据复核
How it works · 架构图

AIHawk 组件与数据流向

README 描述 MCP 客户端、aihawk 服务、引擎与外部服务之间的依赖与数据外发关系,无明确时序,适合架构图

AI 提取 · 证据约束

左右滑动查看完整图示

AIHawk 组件与数据流向README 描述 MCP 客户端、aihawk 服务、引擎与外部服务之间的依赖与数据外发关系,无明确时序,适合架构图MCP 调用驱动浏览器访问页面发送对话与页面内容编码代理客户端MCP 客户端aihawk MCP 服务本地服务invisible_playwright浏览器引擎目标网站被访问方模型提供方OpenRouter
图示依据
  • • claude mcp add --scope user stealth -- uvx aihawk
  • • invisible_playwright 为引擎,API 为 Playwright 的
  • • 隐私政策:web UI 将对话与页面内容发送至 OpenRouter
五维表现
面向需要真实浏览器自动化的编码代理,MCP 接入与独立 UI 两条路径清晰、示例具体;但工具清单、权限边界与错误排障缺失,安全默认值仅部分说明。
质量证据
  • 安装命令:uvx invisible-playwright fetch 与 claude mcp add --scope user stealth -- uvx aihawk
  • 参数章节 Options: proxy, profile, seed 列出 --proxy、--seed、--profile-dir、--binary、--headed、--host/--port
  • 配置优先级声明:--flag > 环境变量 > .env > 默认,且 .env 只读当前目录、不向上搜索
  • 隐私政策列出外发对象:访问站点、模型提供方(OpenRouter)、GitHub 下载引擎与 GeoIP 数据库
  • License 章节:MIT,2026 年 9 月 2 日前发布内容仍为 AGPL-3.0
采用建议
优势
  • 问题与用途描述
  • 有效 README
  • 安装或接入步骤
  • 可执行示例
  • 提供 MCP 与独立 Web UI 两种使用路径,覆盖 Claude Code、Codex、Gemini CLI 接入命令
关注点
  • 发现高风险的一键下载执行或安装命令
  • 缺少限制、权限或边界
  • 缺少错误处理或排障
  • MCP 工具清单与参数未在 README 展示,仅指向 wiki 页面
  • 缺少错误处理与排障说明,如启动失败、被拦截、代理不可用时的表现
适合

需要让编码代理驱动真实浏览器完成多步网页操作的开发者、希望本地运行、自带 OpenRouter key 的网页自动化场景、需要代理、固定指纹或持久登录态(--profile-dir)的抓取任务

不建议直接用于

需要明确权限沙箱与细粒度访问控制的合规环境、要求完整错误码与排障手册的生产运维场景、仅需调用网页 API、无需浏览器渲染的任务

也有自己的公开项目?先看完证据,再用当前规则生成独立报告。

评测我的项目 →
文档证据
80/100
问题与用途描述10 分
有效 README12 分
安装或接入步骤14 分
可执行示例16 分
输入、参数或工具说明11 分
输出或结果说明9 分
限制、权限或边界12 分
错误处理或排障8 分
许可证信息5 分
结构化章节3 分
安全证据
关键风险
发现高风险的一键下载执行或安装命令
unsafe-install-commandREADME.md:38high confidence
curl -LsSf https://astral.sh/uv/install.sh | sh

修复:固定版本与校验和,先下载审查再执行,避免管道直接交给 Shell。

发现高风险的一键下载执行或安装命令
unsafe-install-commandREADME.md:80high confidence
curl -LsSf https://astral.sh/uv/install.sh | sh

修复:固定版本与校验和,先下载审查再执行,避免管道直接交给 Shell。

发现高风险的一键下载执行或安装命令
unsafe-install-commandskills/setup/SKILL.md:19high confidence
curl -LsSf https://astral.sh/uv/install.sh | sh

修复:固定版本与校验和,先下载审查再执行,避免管道直接交给 Shell。

优先改进清单
  1. 01固定版本与校验和,先下载审查再执行,避免管道直接交给 Shell。
  2. 02补充限制、权限或边界
  3. 03补充错误处理或排障
方法、证据与局限展开
数据来源

GitHub Repository API

扫描范围

4 个文件 · 14,792 字符

评测引擎

v3.14.0 · AI 复核已启用(deepseek-flash)

局限
  • 静态评测不会安装或执行项目代码
  • 安全扫描基于高信号文件与已知模式,不能替代人工审计
  • 流行度只反映采用程度,不代表安全或工程质量

30 天热度趋势

README

AIHawk

AIHawk is an anti detect browser and web browsing agent, open source, with an MCP server for coding agents: undetected, no captchas, no blocks. Tell it what you want in plain language.

FEATURED IN
Business Insider · TechCrunch · Semafor · Wired · The Verge · Vanity Fair · 404 Media


Two ways to use this browser agent

1. From your assistant, over MCP

Windows, in PowerShell:

powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
$env:Path = "$env:USERPROFILE\.local\bin;$env:Path"
uvx invisible-playwright fetch

Linux:

curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env
uvx invisible-playwright fetch

Then tell your assistant it exists.

Claude Code:

claude mcp add --scope user stealth -- uvx aihawk

Codex:

codex mcp add stealth -- uvx aihawk

Gemini CLI:

gemini mcp add --scope user stealth uvx aihawk

2. Standalone: the web UI

We bring the interface, you bring an OpenRouter key. Chat on the left, the live browser on the right.

Windows, in PowerShell:

powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
$env:Path = "$env:USERPROFILE\.local\bin;$env:Path"
uvx invisible-playwright fetch
uvx aihawk ui --openrouter-key sk-or-...

Linux:

curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env
uvx invisible-playwright fetch
uvx aihawk ui --openrouter-key sk-or-...

Then open http://127.0.0.1:8765 and type the same thing.


What to ask a web browsing agent

Anything that needs real web automation: a browser rather than an API, and a person's judgement about what is on the page.

Go to <paste the URL>. One way, Milan to Lisbon, economy, one checked bag, one adult. Check every date from the 12th to the 16th of next month, one at a time, and read the cheapest fare for each day. The date field is a calendar widget, so click the days rather than typing them. If a date has no availability, say so. Do not guess a number.

It drives the page the way a person would: the pointer moves, keys are pressed.

Options: proxy, profile, seed

  • --openrouter-key Your key, or the OPENROUTER_API_KEY variable.
  • --model An OpenRouter model id, or AIHAWK_MODEL. Defaults to z-ai/glm-5.3-flash.
  • --proxy Optional. http://user:pass@proxy.example.com:8080 or socks5://proxy.example.com:1080. Host and port are both required. The timezone, locale and egress follow it.
  • --binary An engine binary you already have. It must be the build the seal pins, or startup refuses: this skips the download, not the version check.
  • --seed An integer. Same seed, same browser identity, every run.
  • --profile-dir A directory to keep the profile in, so logins and cookies survive restarts.
  • --headed Show the browser window. The interface shows you the page anyway.
  • --host, --port 127.0.0.1 and 8765. Changing the host exposes an interface that has no authentication.

A .env beside the command

Rather than retyping the key and the binary path, put them in a .env in the directory you run from:

OPENROUTER_API_KEY=sk-or-...
STEALTHFOX_BINARY=/path/to/firefox

It is read at startup, and on the way in it never overrides something already set, so the order is --flag > the environment > .env > the default. Only the directory you are in is read - there is no search upwards, so running from a subfolder cannot silently pick up a different key. The startup line names the variables it applied and never prints their values.

Passing --openrouter-key puts the key in your shell history, and on Linux in the process list. OPENROUTER_API_KEY in the environment or in a .env avoids both.

The wiki: AI browser-agent guides

The reading room around the agent lives in the wiki: the AI browser-agent landscape: browser-use, Operator-style and computer-use agents compared, what to check when an agent gets blocked, and what happened to OpenAI Operator, among others. Worked examples, transcripts and their outputs live in articles/.

The rest of the family: engine, core

The MCP server from option 1 ships inside this package: aihawk with no subcommand is the server, aihawk ui the interface. Its config blocks for clients that take a file, its settings and its tools are on the wiki page The MCP server.

  • invisible_playwright The engine, as a Python library, for writing code instead of prompts. The API is Playwright's.
  • invisible_core Seed to fingerprint to preferences, proxy and geolocation.

Using it responsibly

This automates a browser under your control. Read the terms of the sites you point it at, respect their rate limits, and do not submit anything a human has not read.

Privacy Policy

AIHawk runs on your machine and has no server of its own. What leaves your computer, and to whom:

  • The sites you visit see the browser, as they would any Firefox.
  • Your model provider. The web UI sends the conversation and what the agent reads on the page to OpenRouter under your key. Over MCP, the client you plugged it into does the same with whichever model it uses.
  • GitHub. The engine is downloaded from a GitHub release by uvx invisible-playwright fetch, and a GeoIP database is when a proxy is set. Each browser launch also fetches a one-line counter file from a GitHub release, which is how launches are counted: the request carries no identifier and nothing of yours, and GitHub sees what any HTTPS request shows, your IP address.

Nothing else is collected and nothing is sent to the author. Sessions, profiles and screenshots are stored locally, under AIHAWK_HOME if set and otherwise in the application-data directory of your system, and are yours to delete; nothing is retained anywhere else. Questions go to the issues.

License

MIT. Everything distributed before 2 September 2026 was released under AGPL-3.0 and stays under it.