Wraith MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| navigateA | Open a URL and return an indexed snapshot of the page's interactive elements. Automatically attempts WAAP challenges, including HUMAN/PerimeterX Press & Hold,
and dismisses common cookie/consent banners. No separate challenge command is needed.
If verification fails, navigation reports an error; do not assume clearance.
Each line is |
| snapshotA | Re-perceive the current page: a fresh indexed snapshot of its interactive elements (use after the DOM may have changed). |
| clickA | Click the element with the given index (from the latest snapshot). Returns the resulting snapshot (or a compact change summary when
|
| type_textA | Type |
| fill_secretA | Fill a field from an opaque secret capability. The capability names a registered provider and an opaque handle. It also binds the fill to exact origins, one field kind, an expiry, and a use limit. The tool never accepts or returns the secret value. |
| fill_vault_itemC | Fill a visible field from a vault item. The registered provider resolves the item inside Wraith. This tool returns
only |
| scrollA | Scroll the page ( |
| browser_tabsA | Manage tabs. |
| save_stateA | Export the current session (cookies + localStorage) to a Playwright
storageState JSON at |
| readA | Return the current page's readable content as markdown (for extraction / summarisation, as opposed to acting on elements). |
| screenshotA | Capture a screenshot of the current page. Returns an inline PNG image (so a multimodal model can see the page and disambiguate by the same element indices). On an SDK without image content support, falls back to saving a temp PNG and returning its path. Wraith blocks this tool after a secret fill. |
| detect_waapA | Fingerprint a URL's WAAP / anti-bot defenses (Akamai, Cloudflare, Reblaze/Link11, DataDome, Incapsula, SiteMinder, reCAPTCHA, ...). Returns a list of detected vendor names — empty if none. Passive; no browser needed. |
| borrowA | Borrow a warmed, already-authenticated identity for
|
| ensure_high_scoreA | Borrow a logged-in Google identity's reputation and open This is the GENERAL reCAPTCHA-v3 pass: the v3 score is computed inside the google.com reCAPTCHA iframe from the .google.com reputation cookies present in the context, so injecting a warmed Google identity's cookies (delivered 3rd-party with secure+SameSite=None into an un-partitioned context) lifts the score across any sitekey/site. The browser is (re)launched with the un-partition firefox prefs, the reputation cookies are injected, then the URL is navigated (passing any WAAP and dismissing consent first).
WARNING: borrowing your primary Google identity carries anomalous-session / 2FA risk — this is opt-in. After it returns, VERIFY success against the real protected endpoint (accept vs reject); the v3 score is run-variable and there is no trustworthy score readout for a 3rd-party sitekey. Returns the detected reCAPTCHA params and whether the reload request carried the reputation cookies. |
| fetchA | No-browser TLS-impersonation request — the cheap fast path. Replays a captured session against |
| receive_profileA | Pull a synced login from a one-shot pairing A laptop runs |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 16 tools
Tools are mostly distinct, but there is potential confusion within the secret-filling pair (fill_secret vs fill_vault_item) and the identity-injection trio (borrow, ensure_high_score, receive_profile). Descriptions clarify the different sources and mechanisms, so an attentive agent can disambiguate.
Mostly snake_case with verb or verb_noun patterns, e.g., type_text, fill_secret, detect_waap. Deviations like browser_tabs (noun phrase) and single verbs (read, click) are minor and still readable.
16 tools is just above the ideal range but each appears to serve a distinct purpose in this complex browser-automation and anti-bot domain. Not excessive given the specialized capabilities.
The surface covers navigation, interaction, content extraction, session management, secret handling, and advanced identity borrowing. Minor gaps include no explicit back/forward or JS evaluation, but core workflows are well supported.