Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
SAFARI_MCP_GUARDNoEnable or disable the safety guard (Layer 2). Overrides `guard_enabled` in the config file.true
SAFARI_MCP_DENY_EXTRANoComma-separated additional deny-list patterns to merge with the default deny list.
SAFARI_MCP_GUARD_MODELNoThe Ollama model used by the guard. Any Ollama model can be specified.qwen3.5:4b
SAFARI_MCP_OLLAMA_HOSTNoThe base URL of the Ollama server.http://127.0.0.1:11434
SAFARI_MCP_LOAD_TIMEOUTNoTimeout in seconds when waiting for a page to load.20.0
SAFARI_MCP_GUARD_TIMEOUTNoTimeout in seconds for guard model calls.20.0

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
list_tabsA

List every open Safari tab, with the handle you use to address it.

Call this first. Every other tool takes a tab argument, and this shows you what is addressable: a 1-based index within window 1, or any distinctive substring of a tab's URL or title.

Returns one line per tab as [w<window>:t<index>] <title> — <url>.

read_pageA

Read the visible text of a tab, or of one element inside it.

This is the workhorse — prefer it over screenshots. It returns rendered text (innerText), so it reflects what a person would actually see rather than raw markup.

Args: tab: Tab index within window 1, or a substring of its URL or title. selector: Optional CSS selector. Omit it to read the whole page. max_chars: Truncate beyond this many characters. Default 8000.

find_elementsA

Inspect the elements a CSS selector matches, before acting on them.

Use this to check that a selector hits what you think it does, and to read the index you will pass to click or fill. Returns JSON with each match's tag, id, class, visible text, href, name, type and current value.

Args: tab: Tab index within window 1, or a substring of its URL or title. selector: The CSS selector to inspect. limit: Most elements to describe. Default 20.

open_tabA

Open a URL in a new Safari tab and wait for it to finish loading.

Prefer this over navigate when starting a task: it leaves whatever the person was already reading untouched. Returns the new tab's handle and its final URL, which may differ from the one you asked for if the site redirected.

Args: url: The URL to open. Parentheses and spaces are encoded for you.

navigateA

Point an existing tab at a URL and wait for the load to complete.

Returns the URL actually landed on, so you can see redirects. Parentheses, spaces and other characters Safari's URL setter silently refuses are percent-encoded for you.

Args: tab: Tab index within window 1, or a substring of its URL or title. url: Where to send it.

clickA

Click an element. Check it with find_elements first.

Passes through the denylist and then the local safety gate, either of which may refuse — the refusal explains itself and is worth relaying verbatim rather than retrying.

Args: tab: Tab index within window 1, or a substring of its URL or title. selector: CSS selector for the element. index: Which match to click when the selector hits several. Default 0.

fillA

Type a value into an input, textarea, or contenteditable element.

Sets the value through the element's native setter and then dispatches input and change with bubbles: true. That matters: Google Forms, React and other frameworks listen for those events and ignore a bare assignment to .value, so a naive fill looks correct on screen and submits empty.

Args: tab: Tab index within window 1, or a substring of its URL or title. selector: CSS selector for the field. value: The text to enter. index: Which match to fill when the selector hits several. Default 0.

run_jsA

Run arbitrary JavaScript in a tab. The escape hatch; prefer the others.

Your code runs as a function body, so return the value you want back. The result is JSON-encoded, so return plain data rather than DOM nodes.

Args: tab: Tab index within window 1, or a substring of its URL or title. code: JavaScript to execute. Use return to produce a result.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.4/5.0

Scored across 8 tools

Disambiguation5/5

Each tool targets a distinct action: listing tabs, reading content, inspecting elements, opening/navigating tabs, clicking, filling, and executing JS. Even overlapping actions like open_tab vs. navigate are clearly separated by whether they open a new tab or reuse an existing one. There is no ambiguity in selecting the right tool for a task.

Naming Consistency4/5

Most names follow a verb_noun pattern (list_tabs, read_page, find_elements, open_tab, run_js), but navigate, click, and fill are bare verbs without an object. The names are still predictable and all lowercase snake_case, but the pattern is not perfectly uniform.

Tool Count5/5

Eight tools is a well-scoped set for browser automation. Each tool has a clear purpose and no redundant utilities; the count feels appropriate for the domain without being sparse or bloated.

Completeness4/5

The surface covers the core browser automation lifecycle: inspect (list_tabs, read_page, find_elements), act (click, fill), navigate (open_tab, navigate), and an escape hatch (run_js). Missing operations like back/forward, close tab, or direct URL getter are minor and can be worked around with run_js or navigate.

Maintenance

ActivityMaintained
ResponsivenessResponsive