invisible_playwright_mcp
Playwright MCP server undetected by anti-bots and captchas: AI agent browses the web on anti-detect stealth Firefox, Python, undetected browser automation, scraping, computer use.
- 评测生成时间(北京时间)
- 本报告引擎
- v3.16.0
- 当前引擎
- v3.16.0
规则版本一致,但报告只反映生成时的证据,不代表项目代码和安全状态始终不变。
进入后确认来源与额度,提交才会创建任务。
综合采用结论
检测到关键风险,修复前不建议接入
- 基础评测完成+25/25确定性评分与静态安全扫描已完成
- README 有效证据+18/257,052 个去重后的有效字符
- 独立证据来源+16/204 类非重复证据,重复文件不叠加
- 仓库元数据+10/10已取得仓库状态与采用数据
- 活跃记录+5/5已取得最近提交时间
- AI 复核+15/15已完成结构化 AI 证据复核
AIHawk 启动与浏览执行流程
README 与 setup SKILL.md 描述了从安装、引擎下载到代理驱动浏览器的连续步骤,属单一任务顺序处理
左右滑动查看完整图示
- • README「Two ways to use this browser agent」列出插件安装命令
- • skills/setup/SKILL.md:browser_open 在下载中返回进度,完成后才打开浏览器
- • README「What to ask a web browsing agent」描述代理像人一样移动指针、按键操作页面
- 通过: Agent Skills 格式校验 1/1 个通过
- 通过: 1 个有效 Skill 含可核实的指令步骤或示例
- README「Two ways to use this browser agent」给出 claude plugin marketplace add / codex plugin add / gemini extensions install 命令
- README「Options: proxy, profile, seed」列出 --proxy、--seed、--profile-dir、--binary、--host/--port 及优先级 --flag>环境>.env>默认
- README「Privacy Policy」说明引擎与 GeoIP 从 GitHub release 下载、每次启动拉取计数文件
- skills/setup/SKILL.md 说明 browser_open 在引擎下载中返回进度、失败后可 uvx invisible-playwright fetch 重试
- README「Using it responsibly」要求遵守站点条款与速率限制,但未给出具体限速默认值
- 问题与用途描述
- 有效 README
- 安装或接入步骤
- 可执行示例
- 通过: Agent Skills 格式校验 1/1 个通过
- 发现高风险的一键下载执行或安装命令
- 设计分因边界与失败处理证据缺失,由 13 校准为 12
- 缺少限制、权限或边界
- 缺少错误处理或排障
- 未列出 MCP 工具清单与参数,仅指向 wiki 页面
需要让编码代理驱动真实浏览器的用户、需要代理/指纹/持久化 profile 配置的抓取场景、关注数据外发边界的自托管用户
需要离线运行的环境(首次启动需下载引擎与 GeoIP)、要求完整工具 API 文档与错误码说明的集成方
也有自己的公开项目?先看完证据,再用当前规则生成独立报告。
评测我的项目 →unsafe-install-commandREADME.md:37high confidencecurl -LsSf https://astral.sh/uv/install.sh | sh修复:固定版本与校验和,先下载审查再执行,避免管道直接交给 Shell。
unsafe-install-commandREADME.md:79high confidencecurl -LsSf https://astral.sh/uv/install.sh | sh修复:固定版本与校验和,先下载审查再执行,避免管道直接交给 Shell。
unsafe-install-commandskills/setup/SKILL.md:21high confidencecurl -LsSf https://astral.sh/uv/install.sh | sh修复:固定版本与校验和,先下载审查再执行,避免管道直接交给 Shell。
- 01固定版本与校验和,先下载审查再执行,避免管道直接交给 Shell。
- 02补充限制、权限或边界
- 03补充错误处理或排障
方法、证据与局限展开收起
GitHub Repository API
4 个文件 · 18,091 字符
v3.16.0 · AI 复核已启用(deepseek-flash)
- 静态评测不会安装或执行项目代码
- 安全扫描基于高信号文件与已知模式,不能替代人工审计
- 流行度只反映采用程度,不代表安全或工程质量
30 天热度趋势
README
AIHawk is an anti detect browser and web browsing agent, open source, with an MCP server for coding agents: undetected, no captchas, no blocks. Tell it what you want in plain language.
FEATURED IN
Business Insider ·
TechCrunch ·
Semafor ·
Wired ·
The Verge ·
Vanity Fair ·
404 Media
Two ways to use this browser agent
1. From your assistant, over MCP
Windows, in PowerShell:
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
$env:Path = "$env:USERPROFILE\.local\bin;$env:Path"
Linux:
curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env
Then install it in your assistant.
Claude Code:
claude plugin marketplace add feder-cr/aihawk_mcp_server
claude plugin install aihawk@feder-cr
Codex:
codex plugin marketplace add feder-cr/aihawk_mcp_server
codex plugin add aihawk@feder-cr
Gemini CLI:
gemini extensions install https://github.com/feder-cr/aihawk_mcp_server
2. Standalone: the web UI
We bring the interface, you bring an OpenRouter key. Chat on the left, the live browser on the right.
Windows, in PowerShell:
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
$env:Path = "$env:USERPROFILE\.local\bin;$env:Path"
uvx aihawk ui --openrouter-key sk-or-...
Linux:
curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env
uvx aihawk ui --openrouter-key sk-or-...
Then open http://127.0.0.1:8765 and type the same thing.
What to ask a web browsing agent
Anything that needs real web automation: a browser rather than an API, and a person's judgement about what is on the page.
Go to
<paste the URL>. One way, Milan to Lisbon, economy, one checked bag, one adult. Check every date from the 12th to the 16th of next month, one at a time, and read the cheapest fare for each day. The date field is a calendar widget, so click the days rather than typing them. If a date has no availability, say so. Do not guess a number.
It drives the page the way a person would: the pointer moves, keys are pressed.
Options: proxy, profile, seed
--openrouter-keyYour key, or theOPENROUTER_API_KEYvariable.--modelAn OpenRouter model id, orAIHAWK_MODEL. Defaults toz-ai/glm-5.3-flash.--proxyOptional.http://user:pass@proxy.example.com:8080orsocks5://proxy.example.com:1080. Host and port are both required. The timezone, locale and egress follow it.--binaryAn engine binary you already have. It must be the build the seal pins, or startup refuses: this skips the download, not the version check.--seedAn integer. Same seed, same browser identity, every run.--profile-dirA directory to keep the profile in, so logins and cookies survive restarts.--headedShow the browser window. The interface shows you the page anyway.--host,--port127.0.0.1and8765. Changing the host exposes an interface that has no authentication.
A .env beside the command
Rather than retyping the key and the binary path, put them in a .env in the
directory you run from:
OPENROUTER_API_KEY=sk-or-...
STEALTHFOX_BINARY=/path/to/firefox
It is read at startup, and on the way in it never overrides something
already set, so the order is --flag > the environment > .env > the default.
Only the directory you are in is read - there is no search upwards, so running
from a subfolder cannot silently pick up a different key. The startup line names
the variables it applied and never prints their values.
Passing --openrouter-key puts the key in your shell history, and on Linux in
the process list. OPENROUTER_API_KEY in the environment or in a .env avoids
both.
The wiki: AI browser-agent guides
The reading room around the agent lives in the wiki: the AI browser-agent landscape: browser-use, Operator-style and computer-use agents compared, what to check when an agent gets blocked, and what happened to OpenAI Operator, among others. Worked examples, transcripts and their outputs live in articles/.
The rest of the family: engine, core
The MCP server from option 1 ships inside this package: aihawk with no
subcommand is the server, aihawk ui the interface. Its config blocks for
clients that take a file, its settings and its tools are on the wiki page
The MCP server.
- invisible_playwright The engine, as a Python library, for writing code instead of prompts. The API is Playwright's.
- invisible_core Seed to fingerprint to preferences, proxy and geolocation.
Using it responsibly
This automates a browser under your control. Read the terms of the sites you point it at, respect their rate limits, and do not submit anything a human has not read.
Privacy Policy
AIHawk runs on your machine and has no server of its own. What leaves your computer, and to whom:
- The sites you visit see the browser, as they would any Firefox.
- Your model provider. The web UI sends the conversation and what the agent reads on the page to OpenRouter under your key. Over MCP, the client you plugged it into does the same with whichever model it uses.
- GitHub. The engine is downloaded from a GitHub release the first time the server or the interface starts, and a GeoIP database is when a proxy is set. Each browser launch also fetches a one-line counter file from a GitHub release, which is how launches are counted: the request carries no identifier and nothing of yours, and GitHub sees what any HTTPS request shows, your IP address.
Nothing else is collected and nothing is sent to the author. Sessions,
profiles and screenshots are stored locally, under AIHAWK_HOME if set and
otherwise in the application-data directory of your system, and are yours to
delete; nothing is retained anywhere else. Questions go to the
issues.
License
MIT. Everything distributed before 2 September 2026 was released under AGPL-3.0 and stays under it.