AgentVeil
Used as the primary anonymous search backend for the web_search tool, including the DuckDuckGo .onion endpoint when running over Tor, returning titles, links and snippets without accounts or API keys.
Drives a hardened Firefox instance (90+ privacy/security settings, resistFingerprinting, WebRTC disabled, isolated throwaway per-page contexts) for the browser_open, browser_act, browser_read, browser_screenshot and browser_close tools, enabling interactive browsing of pages with all traffic forced through the encrypted tunnel.
Used as an alternative anonymous search backend for the web_search tool when the primary engine is unavailable or returns captchas.
Used as a configurable meta-search backend for the anonymous web_search tool.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@AgentVeilsearch the web anonymously via Tor for latest AI news and summarize it"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
AgentVeil
A privacy-first browser built for AI agents.
AgentVeil gives an AI agent everything it needs to work on the web — search, page fetching, interactive browsing, screenshots, and end-to-end encrypted agent-to-agent messaging — exposed as an MCP server that Claude Code and other MCP clients can use directly. A command-line tool (agentveil) is included as well.
Its core design rule: all traffic leaves through one local proxy tunnel you choose (Tor, or your own SOCKS5 proxy); if the tunnel is unavailable, requests are refused rather than sent directly.
MIT licensed · Windows 10/11 x64 · Python 3.11+
Why a dedicated browser for agents?
Agents browse differently from people: they read untrusted pages at machine speed, follow links they did not choose, and can be manipulated by text hidden in a page. AgentVeil is built around that:
Concern | What AgentVeil does |
Traffic bypassing the configured proxy | The only egress path is the local SOCKS5 tunnel; there is no direct-connection code path. If the tunnel is down, nothing is sent (fail-closed). Tests confirm the browser process opens no non-loopback TCP sockets. |
DNS leaks | Hostnames are handed to the tunnel unresolved (SOCKS5 DOMAIN); DoH, DNS prefetch and speculative connects are disabled. |
WebRTC IP leaks | WebRTC is disabled entirely; the local shim refuses UDP, so no side channel exists. |
Fingerprinting & tracking | Firefox |
Linking unrelated tasks | With Tor, each identity uses random SOCKS credentials → its own circuit and exit IP. |
Interception at the exit | HTTPS-only by default; TLS failures abort. |
Prompt injection | Hidden elements, zero-width and Unicode tag characters are stripped; external content is fenced with unforgeable "untrusted" markers; loopback / LAN / cloud-metadata addresses are unreachable. |
Agent-to-agent communication | Ed25519 signatures + X25519 sealed boxes + length padding; the relay sees only ciphertext and never learns the sender. |
Limits
Privacy from websites and the network is not privacy from your model provider: a cloud LLM sees the agent's prompts and what it reads.
Disable your agent's built-in web tools (they do not go through AgentVeil). For Claude Code:
{ "permissions": { "deny": ["WebFetch", "WebSearch"] } }in.claude/settings.json.Messaging has no forward secrecy; rotate identities for long-lived secrets.
JavaScript widens the attack surface; use
javascript=falsefor untrusted sites and keep Playwright updated.web_fetchhas a Python TLS fingerprint; some sites (e.g. Wikipedia) reject it — usebrowser_openinstead.AgentVeil never solves CAPTCHAs; it switches engines or suggests
new_identity.Only AgentVeil's own traffic is covered, not the rest of the system.
You are responsible for complying with the laws that apply to you.
Related MCP server: Wraith MCP Server
Architecture
Agent (Claude Code / any MCP client)
│ MCP (stdio)
▼
┌──────────────────────────── AgentVeil ────────────────────────────┐
│ web_search / web_fetch ──┐ │
│ browser_* (hardened FF) ─┼─► EgressPolicy │
│ msg_* (E2E messaging) ───┘ · http(s) only, HTTPS enforced │
│ · no loopback / LAN / metadata │
│ · tunnel down → refuse (fail-closed) │
│ Firefox ─► isolation shim (local SOCKS: TCP CONNECT only, │
│ per-connection policy check, per-identity credentials) │
└───────────────────────────────┬───────────────────────────────────┘
│ SOCKS5 (hostnames resolved remotely)
▼
Local tunnel: Tor / sing-box / Xray / both chainedFile | Role |
Egress policy, tunnel health check, the only HTTP client factory | |
Isolation shim between Firefox and the tunnel | |
Hardened Firefox (90+ privacy/security prefs) and page interaction | |
JS-free fetching, per-hop redirect checks, text extraction & sanitizing | |
DuckDuckGo (onion service under Tor) / DDG Lite / Mojeek / SearXNG | |
E2E messaging: crypto, blind relay, client | |
MCP server (14 tools) | |
Generates a torrc from the Tor Expert Bundle |
Quick start (Windows)
See INSTALL.md for the full guide, including the offline installer.
powershell -ExecutionPolicy Bypass -File scripts\install.ps1Start a tunnel — either:
Tor (no server needed):
.venv\Scripts\agentveil.exe tor-config --bundle C:\tor --bridges none C:\tor\tor\tor.exe -f $HOME\.agentveil\torrcYour own SOCKS5 proxy (sing-box, Xray, …): set
kind = "socks",port = <port>,control_port = 0inagentveil.toml. Templates: tunnels/.
Self-test:
.venv\Scripts\agentveil.exe status --deepConnect your agent: the installer writes .mcp.json in the project folder (Claude Code picks it up), or:
claude mcp add agentveil -- "C:\AgentVeil\.venv\Scripts\python.exe" -m agentveil -c "C:\AgentVeil\agentveil.toml" mcpTools
Tool | Purpose |
| Search with no account or API key |
| Fetch a page as clean text + links, paged via |
| Open a page in hardened Firefox → |
| click / type / press / select / check / hover / scroll / back / forward / reload / goto / wait |
| Re-read a page (paged) |
| Screenshot |
| Close a page and destroy its storage |
| New circuit / exit IP; discard all pages and cookies |
| Tunnel, exit IP and policy check; |
| This agent's messaging identity, fingerprint and contact card |
| Add a peer's contact card (verify the fingerprint out of band) |
| List contacts |
| Send / receive end-to-end encrypted messages |
CLI equivalents: agentveil search …, agentveil fetch URL, agentveil open URL --screenshot a.png, agentveil new-identity, agentveil msg ….
Agent-to-agent messaging
Run a relay:
agentveil relay --port 8787(in-memory, no logs, sender-blind).Optionally publish it as a Tor onion service (
HiddenServiceDir/HiddenServicePort 80 127.0.0.1:8787in torrc).Set
relay_urlinagentveil.tomlon both sides.Exchange contact cards from
msg_whoami(avc1.…), add them withmsg_add_contact, and compare fingerprints over another channel.msg_send/msg_receive. Incoming messages are labelled verified/unknown and always presented as untrusted data.
Set AGENTVEIL_PASSPHRASE before first use to store the identity key encrypted (Argon2id + XSalsa20-Poly1305).
Optional OS-level kill switch
scripts/firewall-killswitch.ps1 adds Windows Firewall rules that block AgentVeil's Python interpreter, Playwright's Firefox and its driver from reaching any non-loopback address — only the tunnel client (a separate program) can go online. Run from an elevated PowerShell; -Remove undoes it. The rule applies to the base Python interpreter used by the venv, so other programs on that interpreter (including pip) are affected too.
Tests
.venv\Scripts\python.exe -m pytest -qThe suite uses a recording SOCKS5 proxy and hostnames that exist only in that proxy (site.test) to prove that:
hostnames always reach the tunnel unresolved (the local resolver cannot resolve
site.test);with the tunnel down, zero requests reach the target and Firefox is never started;
Firefox contacts nothing but the requested site — no telemetry, update or safe-browsing traffic;
Firefox and its driver hold no non-loopback TCP sockets at the OS level;
WebRTC is absent, WebGL is off, timezone is UTC+0, language en-US;
tracking pixels to 127.0.0.1, redirects into private networks and environment proxy variables are all blocked/ignored;
messages resist tampering, forgery, re-forwarding and replay; nobody else can read or drain a mailbox;
the MCP server works end-to-end over stdio and reports clear
FAIL-CLOSED/BLOCKEDerrors.
This server cannot be deployed
Maintenance
Related MCP Connectors
Stealth web browser for agents: search, fetch, click, download and type in persistent MCP sessions.
Scrape, crawl and search the web for AI agents via MCP.
A paid remote MCP for AI agent browser MCP session, built to return verdicts, receipts, usage logs,
Hyperbrowser MCP — wraps the Hyperbrowser AI-agent browsing API
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to control Tor Browser with full anonymity preservation, including navigation, Tor circuit management, and traffic interception.MIT
- AlicenseAqualityBmaintenanceProvides an MCP-native agent browser that enables autonomous agents to perceive and interact with web pages through stealth browsing, identity borrowing, and WAAP detection.162MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to perform local-first web search, fetch, crawl, extract, cache, research, and autonomous information gathering through MCP, with no API keys or cloud dependencies.805 npmAGPL 3.0
- AlicenseNot gradedqualityBmaintenanceEnables agents to browse the web anonymously over Tor, host hidden onion services, communicate through encrypted groups, and discover peers without exposing their identity or infrastructure.2MIT