ie-mode-mcp
ie-mode-mcp
MCP-Server zur Steuerung von Legacy-Webanwendungen, die im IE-Modus von Microsoft Edge laufen, über MCP (Model Context Protocol) durch KI-Agenten.
AI Agent ──(MCP / stdio)──> ie-mode-mcp ──> BrowserManager ──> selenium-webdriver
│
IEDriverServer.exe
│
Microsoft Edge (IE Mode)
│
Legacy Web ApplicationBesteht nur aus Node.js 22 / TypeScript / selenium-webdriver (kein HTTP-Server, keine DB, kein DI, kein Logging-Framework)
MCP-Transport ist nur stdio
Es gibt nur eine Browsersitzung, WebDriver-Operationen erfolgen vollständig sequenziell
Der vollständige HTML-Code wird nicht zurückgegeben;
inspect_pagegibt eine für LLMs zusammengefasste Bildschirminformation zurückKein Genehmigungsablauf. Die Operation wird ausgeführt, sobald das Tool aufgerufen wird
Inhaltsverzeichnis
Related MCP server: ie-mcp
1. Schnellstart
Führen Sie Folgendes unter Windows aus.
git clone https://github.com/sumikof/iedriver-mcp.git
cd iedriver-mcp
npm install
npm run build
# IEDriverServer.exe のパスと、遷移を許可する Origin を指定して起動
$env:IE_MCP_DRIVER_PATH = "C:\tools\IEDriverServer.exe"
$env:IE_MCP_ALLOWED_ORIGINS = "http://legacy01.local"
node dist/index.jsWenn {"level":"info","event":"started","transport":"stdio"} auf stderr ausgegeben wird, war der Start erfolgreich.
Normalerweise wird der Server nicht manuell gestartet, sondern automatisch über die MCP-Konfiguration des KI-Agenten gestartet.
2. Voraussetzungen
Element | Inhalt |
OS | Windows 11 / Windows 10 (Angemeldete interaktive Sitzung) |
Node.js | 22 oder höher |
Browser | Microsoft Edge (IE-Modus muss verfügbar sein) |
Treiber | IEDriverServer.exe (Selenium 4.x. 32-Bit-Version empfohlen) |
IEDriverServer.exe wird von der Selenium-Downloadseite heruntergeladen und in einem beliebigen Ordner (z. B.
C:\tools\) abgelegt. Da die 64-Bit-Version bekannte Einschränkungen hat, empfiehlt Selenium offiziell die Verwendung der 32-Bit-Version.Da IEDriver von der GUI, dem Fensterfokus und nativen Ereignissen beeinflusst wird, wird die Verwendung einer dedizierten Windows-VM oder einer dedizierten Windows-Sitzung empfohlen.
Ein Betrieb des Browsers in einem Windows-Dienst (Session 0) wird nicht unterstützt.
Der MCP-Server, IEDriver und Edge laufen in derselben Windows-Umgebung.
3. Windows-Vorkonfiguration
IEDriver wird stark von den Umgebungseinstellungen beeinflusst. Konfigurieren Sie diese zuerst manuell, bevor Sie den MCP-Server starten.
3.1 IE-Modus von Edge verfügbar machen
Überprüfen Sie zuerst durch manuelle Bedienung von Edge, ob die Zielseite im IE-Modus geöffnet werden kann. Der IE-Modus wird über eine der
folgenden Richtlinien aktiviert (unter Software\Policies\Microsoft\Edge).
Richtlinie (Anzeigename) | Registrierungswertname |
Configure Internet Explorer integration |
|
Configure the Enterprise Mode Site List |
|
Send all intranet sites to Internet Explorer | (Wird über Gruppenrichtlinien ab Edge 77 konfiguriert) |
Die genaue Konfiguration hängt von den Richtlinien Ihrer Organisation ab. Für Details konsultieren Sie bitte die Dokumentation von Microsoft zum IE-Modus und Ihren Administrator. Stellen Sie sicher, dass Windows / Edge auf dem neuesten Stand sind.
3.2 Von IEDriver geforderte Einstellungen
Element | Erforderlicher Zustand | Behandlung in diesem Server |
Browser-Zoom | 100% | Nicht zwingend erforderlich, da |
Geschützter Modus (Protected Mode) | Gleiche Einstellung für alle Zonen | Wenn nicht einheitlich, wird beim Start eine Ausnahme ausgelöst. Vereinheitlichen Sie die Einstellungen unter Internetoptionen → Sicherheit. |
Bitanzahl von IEDriverServer | 32-Bit empfohlen | — |
Wenn die Einstellungen für den geschützten Modus nicht einheitlich sind, schlägt browser_start fehl. Die Einstellung
introduceFlakinessByIgnoringProtectedModeSettings von IEDriver wird nicht verwendet, da sie zu instabilem Verhalten führt.
4. Installation und Build
npm install # 依存パッケージの取得
npm run build # TypeScript を dist/ へビルドDas Artefakt ist dist/index.js. Nach dem Build kann es auch mit npm start (= node dist/index.js) gestartet werden.
5. Umgebungsvariablen
Es werden keine Konfigurationsdateien (YAML / JSON) verwendet, sondern nur Umgebungsvariablen.
Umgebungsvariable | Beschreibung | Standardwert |
| Pfad zu msedge.exe | Nicht angegeben (wird von IEDriver automatisch erkannt) |
| Pfad zu IEDriverServer.exe | Nicht angegeben (wird in |
| Kommagetrennte Liste der Origins, für die |
|
| Standard-Timeout für Elementsuche und Wartezeiten (ms) |
|
IE_MCP_EDGE_PATH=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
IE_MCP_DRIVER_PATH=C:\tools\IEDriverServer.exe
IE_MCP_ALLOWED_ORIGINS=http://legacy01.local,http://legacy02.local
IE_MCP_TIMEOUT_MS=10000Da IE Driver 4.5.0 und höher Edge in Umgebungen ohne IE (Standard in Windows 11) automatisch erkennt, ist
IE_MCP_EDGE_PATHnormalerweise nicht erforderlich. Nur angeben, wenn die automatische Erkennung fehlschlägt.Für reproduzierbare Abläufe wird empfohlen,
IE_MCP_DRIVER_PATHexplizit anzugeben.IE_MCP_ALLOWED_ORIGINSist eine einfache Einschränkung zur Vermeidung von Fehlbedienungen und prüft auf exakte Übereinstimmung des Origin (Schema + Host + Port). Es erfolgt keine Einschränkung auf Pfadebene.
6. Startmethoden
Manueller Start (für Funktionstests)
PowerShell:
$env:IE_MCP_DRIVER_PATH = "C:\tools\IEDriverServer.exe"
$env:IE_MCP_ALLOWED_ORIGINS = "http://legacy01.local"
node dist/index.jsEingabeaufforderung:
set IE_MCP_DRIVER_PATH=C:\tools\IEDriverServer.exe
set IE_MCP_ALLOWED_ORIGINS=http://legacy01.local
node dist\index.jsWartet über stdio auf Verbindungen vom Client. Da die Standardein-/ausgabe für das MCP-Protokoll verwendet wird,
erfolgt keine Reaktion auf Tastatureingaben in diesem Zustand (normal). Alle Logs werden auf stderr ausgegeben.
Zum Beenden Strg+C drücken (der Browser wird ebenfalls automatisch geschlossen).
Hinweis: Der Browser wird nicht gestartet, nur weil der MCP-Server gestartet wird. Der Browser wird gestartet, wenn der Agent
browser_startaufruft.
Normaler Betrieb
Der KI-Agent (MCP-Client) startet diesen Server als untergeordneten Prozess. Manuelles Starten ist nicht erforderlich. Nehmen Sie die Konfiguration im nächsten Kapitel vor.
7. Registrierung beim KI-Agenten
Fügen Sie Folgendes zur Konfigurationsdatei des MCP-Clients hinzu.
{
"mcpServers": {
"ie-mode": {
"command": "node",
"args": ["C:\\ie-mode-mcp\\dist\\index.js"],
"env": {
"IE_MCP_DRIVER_PATH": "C:\\tools\\IEDriverServer.exe",
"IE_MCP_EDGE_PATH": "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
"IE_MCP_ALLOWED_ORIGINS": "http://legacy01.local,http://legacy02.local",
"IE_MCP_TIMEOUT_MS": "10000"
}
}
}
}Escape-Tasten im Pfad innerhalb des JSON (z. B.
C:\\...).Geben Sie in
argsden absoluten Pfad zum gebautendist/index.jsan.Bei Claude Code kann es auch mit
claude mcp addregistriert werden.
claude mcp add ie-mode --env IE_MCP_DRIVER_PATH=C:\tools\IEDriverServer.exe --env IE_MCP_ALLOWED_ORIGINS=http://legacy01.local -- node C:\ie-mode-mcp\dist\index.jsNach der Registrierung ist die Verbindung erfolgreich, wenn auf Client-Seite 10 Tools einschließlich browser_start sichtbar sind.
8. Tool-Referenz
Es werden 10 Tools bereitgestellt. Die Low-Level-API von WebDriver (findElement / executeScript usw.) wird nicht bereitgestellt.
Tool | Eingabe | Übersicht |
| Keine | Startet Edge IE Mode. Wenn bereits gestartet, wird die vorhandene Sitzung wiederverwendet |
| Keine | Beendet den Browser. Kann beliebig oft aufgerufen werden, ohne einen Fehler zu verursachen |
|
| Navigiert nach Überprüfung der URL-Whitelist |
|
| Gibt URL / Titel / Bildschirmtext / bedienbare Elemente zurück |
|
| Wartet auf Sichtbarkeit und Aktivierung, dann klicken |
|
| Eingabe in input / textarea |
|
| Wählt eine Option in |
|
| Wartet, bis eine Bedingung erfüllt ist |
|
| Wechselt zu einem Popup oder einem anderen Fenster |
| Keine | Gibt den aktuellen Bildschirm als PNG (MCP image content) zurück |
Gemeinsam: Selector
{ "by": "id | name | css | xpath | linkText", "value": "searchButton" }Da in Legacy-Webanwendungen name und xpath häufig verwendet werden, werden diese unterstützt.
Gemeinsam: frame (iframe ist 1 Ebene)
Alle Element-Operationstools akzeptieren ein optionales frame. Wenn angegeben, wird zuerst zu defaultContent zurückgekehrt,
dann in den Frame gewechselt und darin nach dem Element gesucht.
{
"frame": { "by": "name", "value": "mainFrame" },
"selector": { "by": "id", "value": "searchButton" }
}browser_start
{}{ "status": "ready", "reused": false }reused: true zeigt an, dass die vorhandene Sitzung unverändert verwendet wurde. Wenn die vorhandene Sitzung abgestorben ist,
wird sie automatisch neu gestartet.
navigate
{ "url": "http://legacy01.local/customer" }{ "url": "http://legacy01.local/customer", "title": "顧客検索" }inspect_page
Das wichtigste Tool für den Agenten, um den Bildschirm zu verstehen. Es wird nicht der vollständige HTML-Code zurückgegeben,
sondern nur URL / Titel / angezeigter Text / bedienbare Elemente (a button input textarea select iframe).
Nicht sichtbare Elemente und Inputs mit type="hidden" werden ausgeschlossen.
{ "frame": { "by": "name", "value": "mainFrame" } }{
"url": "http://legacy01.local/customer",
"title": "顧客検索",
"text": "顧客検索 顧客名 支店 検索",
"elements": [
{ "tag": "input", "id": "customerName", "name": "customerName", "type": "text" },
{ "tag": "select", "id": "branch", "name": "branch", "text": "東京支店", "optionCount": 12 },
{ "tag": "button", "id": "searchButton", "text": "検索" },
{ "tag": "iframe", "name": "mainFrame" }
],
"truncated": false
}truncated: truezeigt an, dass die Elementliste bei der Obergrenze (300 Elemente) abgeschnitten wurde.Wenn die Elementliste ein
iframeenthält, rufen Sie es erneut mit Angabe vonframeauf, um dessen Inhalt zu sehen.
click
{ "selector": { "by": "id", "value": "searchButton" } }{ "url": "http://legacy01.local/customer", "title": "顧客検索" }Wartet auf Sichtbarkeit und Aktivierung, dann klicken. click wiederholt sich nicht automatisch (um doppelte Verarbeitung bei bereits erfolgreicher Registrierung, Aktualisierung oder Sendung durch erneutes Klicken zu vermeiden).
type
{
"selector": { "by": "id", "value": "customerName" },
"text": "山田太郎",
"clear": true
}Wenn clear (Standard true) true ist, wird nach clear() eingegeben, bei false wird angehängt.
select
{
"selector": { "by": "id", "value": "branch" },
"by": "text",
"value": "東京支店"
}{ "text": "東京支店", "value": "13", "index": 2 }by ist text / value / index (index beginnt bei 0).
wait_for
Verwendet kein festes Sleep, sondern wartet explizit.
{
"type": "visible",
"selector": { "by": "id", "value": "resultTable" },
"timeoutMs": 10000
}
| Erforderliche Eingabe | Bedingung |
|
| Element ist im DOM vorhanden |
|
| Element wird angezeigt |
|
| Element wird angezeigt und ist bedienbar |
|
| Der Text des Elements enthält |
|
| Die aktuelle URL enthält |
|
| Der Titel enthält |
Wenn timeoutMs weggelassen wird, wird IE_MCP_TIMEOUT_MS verwendet.
switch_window
{ "target": "newest" }{ "index": 1 }{ "url": "http://legacy01.local/detail", "title": "顧客詳細", "index": 1, "windowCount": 2 }newest pollt kurzzeitig, bis ein neuer Window-Handle erscheint. Wenn keiner erkannt wird,
wird zum letzten vorhandenen Fenster gewechselt.
screenshot
{}Gibt ein PNG-Bild (MCP image content) zurück. Nützlich zur Überprüfung von Layouts oder Fehlerbildschirmen, die allein anhand des DOM nicht beurteilt werden können.
9. Anwendungsbeispiele
Grundlegende Schleife
browser_start → navigate → inspect_page → click / type / select → wait_for → inspect_pageWiederholen: Bildschirm mit inspect_page erfassen → Bedienen → mit wait_for auf Ergebnis warten → erneut inspect_page.
Beispiel: Kunden „Yamada Taro“ suchen und Detailseite öffnen
# | Tool | Argumente |
1 |
|
|
2 |
|
|
3 |
|
|
4 |
|
|
5 |
|
|
6 |
|
|
7 |
|
|
8 |
|
|
9 |
|
|
10 |
|
|
11 |
|
|
Beispiel: Bedienung innerhalb eines iframes
{"tool": "inspect_page", "args": {}}
{"tool": "inspect_page", "args": { "frame": { "by": "name", "value": "mainFrame" } }}
{"tool": "click", "args": {
"frame": { "by": "name", "value": "mainFrame" },
"selector": { "by": "id", "value": "searchButton" }
}}Die Frame-Angabe muss bei jeder Operation erneut übergeben werden (da intern jedes Mal zu defaultContent
zurückgekehrt und dann in den Frame gewechselt wird, bleibt der Zustand nicht erhalten).
Beispiel: Popup bedienen und zum ursprünglichen Fenster zurückkehren
{"tool": "click", "args": { "selector": { "by": "id", "value": "openPopup" } }}
{"tool": "switch_window", "args": { "target": "newest" }}
{"tool": "inspect_page", "args": {}}
{"tool": "switch_window", "args": { "index": 0 }}10. Fehler und Behebung
Fehler werden nicht als Selenium-Stack-Trace, sondern mit folgendem Code zurückgegeben (isError: true).
{
"error": "ELEMENT_NOT_FOUND",
"message": "Element was not found: id=searchButton",
"selector": { "by": "id", "value": "searchButton" }
}Fehlercode | Bedeutung | Behebung |
| Browser nicht gestartet |
|
| Element / Frame nicht gefunden | Tatsächliche Elemente mit |
| Bedingung von | Bedingung / |
| Angegebenes Fenster existiert nicht |
|
| Navigation fehlgeschlagen | URL / Netzwerk / Authentifizierung überprüfen |
| IEDriver / Edge unerwartet beendet | Mit |
| Origin nicht in der Whitelist |
|
| Ungültige Argumente | Eingabespezifikation des Tools überprüfen |
| Sonstiges (einschließlich Startfehler) |
|
Wiederherstellung nach DRIVER_LOST
Wenn der Browser oder Treiber abstürzt, wird der interne WebDriver verworfen, und nachfolgende Operationen führen
zu BROWSER_NOT_STARTED. Es erfolgt keine automatische Wiederherstellung oder automatische Wiederholung der letzten Operation (um
Nebenwirkungen wie doppelte Registrierungen zu vermeiden). Der Agent muss browser_start erneut aufrufen, den Bildschirmzustand
mit inspect_page überprüfen und dann die Bedienung fortsetzen. Da die vorherige Operation möglicherweise bereits erfolgreich war,
dürfen Registrierungs- und Aktualisierungsoperationen nicht unverändert wiederholt werden.
11. Logging
Da stdout vom MCP-Protokoll verwendet wird, werden alle Logs auf stderr als einzelne JSON-Zeile ausgegeben.
{"level":"info","event":"started","transport":"stdio"}
{"level":"info","tool":"navigate","url":"http://legacy01.local/customer","durationMs":842}
{"level":"info","tool":"type","selector":{"by":"id","value":"password"},"textLength":16,"durationMs":128}
{"level":"error","tool":"click","selector":{"by":"id","value":"x"},"error":"ELEMENT_NOT_FOUND","message":"Element was not found: id=x","durationMs":5012}Der eingegebene String selbst, Cookies, Authentifizierungsinformationen und der vollständige HTML-Code werden nicht aufgezeichnet (bei type nur die Zeichenanzahl).
Zum Speichern in einer Datei stderr umleiten.
node dist/index.js 2>> C:\logs\ie-mode-mcp.log12. Fehlerbehebung
Symptom | Zu prüfen |
| Ist |
Ausnahmen im Zusammenhang mit dem geschützten Modus | Internetoptionen → Sicherheit: Schutzeinstellungen für alle Zonen vereinheitlichen |
Ausnahmen im Zusammenhang mit Zoom | Zoom von Edge / IE auf 100 % zurücksetzen |
Edge startet, wechselt aber nicht in den IE-Modus | IE-Modus-Richtlinie (Site-Liste usw.) prüfen. Vorher manuell prüfen, ob IE-Modus angezeigt werden kann |
Vorgänge bleiben hängen / Elemente können nicht angeklickt werden | Ist das Fenster minimiert oder inaktiv? Wird instabil, wenn die Remotedesktopverbindung getrennt ist |
Elemente von | Handelt es sich um einen Bildschirm innerhalb eines Frames? (Mit |
Tool wird auf Agent-Seite nicht angezeigt | Wird |
Keine Ausgabe auf der Standardausgabe | Normal. Die Ausgabe erfolgt auf stderr |
screenshot ist hilfreich für die Ursachenforschung. Damit können Zustände (Modale, Authentifizierungsdialoge,
Rendering-Fehler) überprüft werden, die allein anhand der DOM-Informationen nicht beurteilt werden können.
13. Entwicklung
src/
├─ index.ts MCP Server のエントリーポイント(stdio)
├─ config.ts 環境変数と stderr ログ
├─ tools.ts MCP Tool の Schema と Handler
├─ browser.ts BrowserManager(Selenium / IEDriver 操作の集約)
├─ selectors.ts Selector → Selenium の By 変換
└─ errors.ts Selenium Error → MCP Error Code 変換npm run build # tsc でビルド
npm start # node dist/index.jsMCP-Tools greifen nicht direkt auf Selenium zu, sondern immer über
BrowserManager.Alle WebDriver-Operationen werden über eine Promise Chain sequenziert, sodass selbst bei parallelem Aufruf von Tools nur jeweils ein Befehl an IEDriver gesendet wird.
Nur Operationen ohne Nebenwirkungen (Elementsuche, Window-Handle-Erkennung) werden wiederholt.
clickund Senden werden nicht wiederholt.
14. Einschränkungen
Die erste Implementierung unterstützt Folgendes nicht:
Mehrere Browsersitzungen / Mehrere Benutzer / HTTP-Transport / REST-API / DB / Sitzungspersistenz /
Automatische Browserwiederherstellung / Komplexe Wiederholungsrichtlinie / WebDriver Grid / Allgemeine Selenium-API /
executeScript-Tool / Mehrstufige iframes (nur eine Ebene) / Element-Cache / Metriken / Genehmigungsablauf / Authentifizierung und Autorisierung
Available Tools
10 toolsbrowser_closeClose browserB
Close the browser session. Safe to call repeatedly.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are available so the description carries the full burden. It only says 'close the browser session' and 'safe to call repeatedly', but does not disclose whether this terminates all browser state or if there are side effects on open windows, tabs, or downloads. The behavioral context is thin.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences that are front-loaded and to the point. Every sentence adds value: the first states the action, the second clarifies safety/repeatability. No wasted words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given zero parameters and no output schema, the description covers the basic purpose and safety. However, it lacks details on what happens after closing (e.g., can browser_start reopen cleanly) or any cleanup behavior, which might be useful context for an agent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters and schema coverage is 100%. The description adds value by stating it is safe to call repeatedly, which implies no parameters are needed and calls are idempotent. With no parameters to explain, this is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool closes the browser session with a specific verb and resource. It distinguishes enough from siblings like 'navigate' which moves within a session.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description notes it is safe to call repeatedly, which implies idempotency, but does not explicitly tell when to call it (e.g., end of a browsing task) or when not to (e.g., still need to interact). No sibling differentiation is provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
browser_startStart Edge IE ModeA
Start Microsoft Edge in IE Mode through IEDriverServer. Only one browser session exists; calling this while a session is running returns the existing one. Also use this to recover after a DRIVER_LOST error.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description must carry the full burden of behavioral disclosure. It transparently reveals that only one browser session exists, that calling the tool again returns the existing session, and that it can be used for recovery. This is strong for a start tool, but it could additionally mention potential side effects like timeouts or prerequisites for the IEDriverServer.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences long, front-loading the primary purpose in the first sentence and adding behavioral nuance in the second. Every sentence provides essential information without redundancy or fluff, achieving maximum conciseness.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (no parameters, no output schema, straightforward start action), the description is complete. It covers the core function, the singleton behavior, error recovery, and is sufficient for an AI agent to understand when and how to invoke the tool alongside its sibling tools.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters and 100% schema coverage, so the baseline is 4. The description adds no parameter information, which is appropriate since there are none to document. No additional semantic value is needed.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool starts Microsoft Edge in IE Mode via IEDriverServer, using the specific verb 'Start' and the resource 'Microsoft Edge in IE Mode'. It also distinguishes itself from sibling tools by noting that only one browser session exists and that calling it again returns the existing session, which is unique among the provided sibling tools.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context for when to use the tool: normally to start the browser, and also to recover after a DRIVER_LOST error. It implicitly advises against calling it multiple times for new sessions by stating that subsequent calls return the existing session. However, it does not explicitly list alternatives or state when not to use it, though no alternative starting tool exists among the siblings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
clickClick elementA
Click an element after waiting for it to be visible and enabled. This operation is never retried automatically, because a repeated click may submit or register data twice.
| Name | Required | Description | Default |
|---|---|---|---|
| frame | No | Optional iframe/frame to switch into first. One level of nesting is supported. | |
| selector | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It discloses two key behaviors: waiting for the element to be visible and enabled, and the lack of automatic retry with a rationale. However, it does not mention timeout behavior, scroll-into-view, or what happens if the element is not found.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, front-loaded with the core purpose, and every sentence adds value. No fluff or repetition.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's potential side effects (e.g., triggering navigation or form submission), the description is minimal. It does not mention return values, scroll behavior, or failure modes. It is adequate for a simple click but lacks completeness for an AI agent to fully anticipate outcomes.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 50%, and the description adds no information about the parameters. It does not explain the 'frame' or 'selector' parameters beyond what is already in the schema. The description should compensate for the missing schema descriptions but fails to do so.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states 'Click an element after waiting for it to be visible and enabled,' using a specific verb and resource. It distinguishes the tool from siblings like 'type' and 'select' by specifying the action and the precondition (visibility and enabled state).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly warns that the operation is never retried automatically because a repeated click may submit or register data twice. This gives a clear usage caution about retries, though it does not explicitly compare to alternative tools or state when not to use click.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
inspect_pageInspect pageA
Return the current URL, title, visible page text and the operable elements (a, button, input, textarea, select, iframe). The full HTML is never returned. Pass frame to inspect the contents of an iframe listed by a previous inspect_page call.
| Name | Required | Description | Default |
|---|---|---|---|
| frame | No | Optional iframe/frame to switch into first. One level of nesting is supported. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden of disclosing behavior. It explicitly states 'The full HTML is never returned' and that frame must reference an iframe from a previous call. The read-only nature is implied by 'Return' but not stated outright, though this is likely sufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two succinct sentences that front-load the main purpose and then add the iframe caveat. Every sentence earns its place with no redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool has one well-described parameter, no output schema, and no annotations. The description covers the output, a key constraint (no full HTML), and iframe usage, making it reasonably complete for an inspection tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3. The description adds meaning beyond the schema by clarifying that the frame must come from a previous inspect_page call, which is not stated in the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb ('Return') and enumerates exactly what is returned (URL, title, visible text, operable elements). This clearly distinguishes it from sibling tools like 'click' or 'navigate'.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies when to use the tool (to inspect page state) and gives specific guidance for iframe usage ('Pass frame to inspect the contents of an iframe listed by a previous inspect_page call'). It doesn't explicitly exclude alternatives, but the context is clear given the sibling list.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
screenshotScreenshotB
Capture the current browser window as a PNG image.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description bears the full burden. It states the action (capture) and format (PNG) but omits crucial details: whether it modifies state, if a browser window must be open, what exactly 'current browser window' captures (viewport vs full page), and if there are side effects.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single 9-word sentence, efficient and front-loaded. However, it could include additional essential context (e.g., 'captures the visible viewport area') without losing conciseness, making it slightly under-specified.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given zero parameters and no output schema, the description should clarify what the tool returns (e.g., base64 PNG data). It only says 'as a PNG image' but doesn't confirm the output type. The scope of 'current browser window' is ambiguous, and prerequisites are missing, leaving the agent uncertain.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There are zero parameters, and the schema coverage is 100% (trivially). The description adds minimal meaning by specifying 'current browser window' as the implicit input. A baseline of 4 is appropriate given no parameters to document.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb ('capture') and resource ('current browser window') with a clear output format ('PNG image'). It is distinct from sibling tools like 'navigate' or 'inspect_page' which serve different purposes.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use screenshot versus alternatives. Despite having sibling tools (e.g., inspect_page, wait_for), no exclusions or context is given. An agent must infer use case from tool purpose alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
selectSelect optionB
Choose an option of an HTML element by visible text, value or index.
| Name | Required | Description | Default |
|---|---|---|---|
| by | Yes | How to identify the option. | |
| frame | No | Optional iframe/frame to switch into first. One level of nesting is supported. | |
| value | Yes | Option text, value, or zero-based index. | |
| selector | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden. It discloses that selection is based on visible text, value or index, which is helpful. However, it doesn't mention side effects (e.g., whether the change triggers JavaScript events), error handling (e.g., what if option not found), or scope (e.g., operates within current page context).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that efficiently communicates the core action and identification methods. It is front-loaded with the key verb and resource. No waste, though it could optionally add a brief usage hint without breaching conciseness.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has 4 parameters with nested objects and no output schema, the description is somewhat complete but lacks coverage of return behavior (e.g., what happens on success/failure), frame handling nuances, and edge cases. For a selection action in a browser automation context, more behavioral detail would be helpful.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 75%, meaning most parameters are documented in the schema. The description adds that selection can be by 'visible text, value or index', which maps to the 'by' enum, and that the 'value' parameter can be text or zero-based index. This provides modest added meaning beyond the schema, but the 'frame' and 'selector' objects remain documented primarily in schema, not description.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'choose' and resource 'HTML <select> element', specifying three identification methods (visible text, value, index). This distinguishes it from sibling tools like click or type, though it doesn't explicitly contrast with them.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies when to use by saying 'choose an option of an HTML <select> element', which suggests this is for dropdown selections. However, it does not provide explicit when-not-to-use guidance, mention prerequisites (e.g., element must exist), or compare with alternatives like click on an option directly.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
switch_windowSwitch windowA
Switch to another browser window or popup. Use target:"newest" after an action that opens a window, or index to select a window by its zero-based position.
| Name | Required | Description | Default |
|---|---|---|---|
| index | No | Zero-based window index. | |
| target | No | Switch to the newest window. | |
| timeoutMs | No | How long to poll for a new window. Defaults to IE_MCP_TIMEOUT_MS. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden. It mentions polling behavior via timeoutMs parameter but does not state if switching is destructive, if it requires a window to exist, what happens if the window is closed, or any state changes. The description does not disclose potential side effects or preconditions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is short and front-loaded with the core purpose in the first sentence. The second sentence adds specific usage hints. It could potentially omit 'or popup' as redundant with 'window', but overall concise.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given 3 unrequired parameters, no output schema, no annotations, the description covers the basic purpose and usage hints. However, it lacks details on return values, error scenarios (e.g., window not found), or behavior when switching to a window that fails to load.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so baseline is 3. The description adds context for the 'target' parameter (use after action that opens window) and 'index' (zero-based position), but the timeoutMs parameter meaning is already clear from schema. No additional semantic value beyond schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool switches to another browser window or popup, specifying the verb 'switch' and the resource 'browser window or popup'. It distinguishes itself from sibling tools like browser_start, browser_close, and navigate by focusing on window selection rather than creation, closure, or navigation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit guidance on when to use this tool: after an action that opens a window, use target 'newest', or use index to select by position. It implicitly distinguishes from sibling tools by indicating this is for window focus rather than content navigation or page interaction.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
typeType textA
Type text into an input or textarea. Set clear to false to append instead of replacing.
| Name | Required | Description | Default |
|---|---|---|---|
| text | Yes | Text to send to the element. | |
| clear | No | Clear the field first. Default true. | |
| frame | No | Optional iframe/frame to switch into first. One level of nesting is supported. | |
| selector | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It reveals that the tool can clear or append text via the 'clear' parameter, which is good. However, it does not mention potential side effects (e.g., triggering change events), error conditions (element not found), or behavior when the element is not a text input. This is adequate but not comprehensive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise at one sentence plus one usage tip. Every word earns its place, clearly stating the action and a key parameter behavior. No filler or redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description should ideally mention return values (e.g., success indicator, element state). It doesn't, leaving that unclear. With nested objects (selector, frame) and no explanation of selector strategies beyond the schema enums, it completes the basic usage but misses context on what happens after typing (e.g., waits for stability, triggers events).
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is high at 75%, so the schema documents most parameters well. The description adds value by explaining the 'clear' boolean behavior (append vs replace) beyond the schema's default value note. It doesn't add to 'selector' or 'frame' parameters, which are already well-described in the schema, so this is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool types text into an input or textarea, using a specific verb and resource. It distinguishes from siblings like 'click' or 'select' by targeting text entry specifically, but doesn't differentiate from a potential 'send_keys' equivalent if one existed among siblings, so a slight deduction.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides a key usage guideline: set clear to false to append instead of replacing text. This gives basic advice on when to use a parameter. However, it lacks guidance on when to use this tool versus alternatives like clicking an element first or waiting, and doesn't mention prerequisites (e.g., element must be visible/interactable).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
wait_forWait for conditionA
Wait until a condition holds. present/visible/enabled/text require a selector; text/url/title require text, which is matched as a substring. Use this instead of sleeping after an action.
| Name | Required | Description | Default |
|---|---|---|---|
| text | No | Expected substring for text/url/title conditions. | |
| type | Yes | Condition to wait for. | |
| frame | No | Optional iframe/frame to switch into first. One level of nesting is supported. | |
| selector | No | ||
| timeoutMs | No | Timeout in milliseconds. Defaults to IE_MCP_TIMEOUT_MS. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description explains key behavioral traits: that present/visible/enabled/text require a selector, text/url/title require text matched as substring, and that it waits for the condition. With no annotations provided, the description carries the full burden of transparency. It lacks details on timeout behavior or error handling, but covers core usage.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise with two sentences, front-loading the key purpose and condition types. Every sentence adds value, avoiding any redundancy. The structure is efficient for an AI agent.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity (5 parameters, nested objects, no output schema), the description is adequate. It explains the core waiting concept and parameter dependencies. However, it lacks details on return values or what happens on timeout/failure, which the schema alone doesn't cover. The sibling 'inspect_page' might share similar conditions, but no differentiation is made.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 80%, so the schema already documents most parameters well. The description adds value by clarifying the relationship between condition types and required parameters (e.g., 'present/visible/enabled/text require a selector; text/url/title require text'). This bridges gaps between parameters, though it does not detail the 'frame' parameter beyond what the schema provides.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool waits until a condition holds, with specific verb+resource ('Wait for condition'). It lists the condition types and distinguishes itself from sleeping after an action, which differentiates it from sibling tools like 'click' or 'navigate'.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states when to use this tool ('Use this instead of sleeping after an action'), providing clear guidance on avoiding poor alternatives. However, it does not specify when not to use it or which sibling would be more appropriate for different scenarios, such as synchronous checks.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
10 tool updates
v0.1.0- First observed
browser_close - First observed
browser_start - First observed
click - First observed
inspect_page - First observed
navigate - First observed
screenshot - First observed
select - First observed
switch_window - First observed
type - First observed
wait_for
TDQS
Scored across 10 tools
Each tool has a clearly distinct purpose: session management (start/close), navigation, inspection, interaction (click, type, select), window switching, waiting, and screenshot. No two tools overlap in functionality.
The naming pattern is inconsistent: some tools use a 'browser_' prefix (browser_start, browser_close), while others are bare verbs (navigate, click, type) or compound snake_case (inspect_page, switch_window, wait_for). This mix of styles could cause confusion.
With 10 tools, the set is well-scoped for browser automation. It covers session lifetime, navigation, element interaction, inspection, window handling, and waiting without being bloated or too thin.
The tools cover fundamental browser actions but miss common features like back/forward navigation, JavaScript execution, alert handling, or cookie management. The set is functional for basic scenarios but has notable gaps for comprehensive automation.
Maintenance
Related MCP Connectors
Let AI agents query data and act across all your business apps via MCP.
Governed app access for AI agents: 1,000+ apps & 12,000+ tools via Code Mode MCP.
Stealth web browser for agents: search, fetch, click, download and type in persistent MCP sessions.
Live browser debugging for AI assistants — DOM, console, network via MCP.
Related MCP Servers
- AlicenseAqualityCmaintenanceExposes Selenium WebDriver as an MCP server, enabling AI agents and LLMs to control real browsers for automation tasks like navigation, element interaction, and screenshot capture.2221 PyPI3MIT
- AlicenseAqualityCmaintenanceEnables LLMs to drive Edge in IE mode for automating legacy IE-only web applications, supporting tasks like clicking, filling forms, and data extraction via Selenium.28MIT
- AlicenseAqualityCmaintenanceMCP server providing browser automation for AI agents, enabling actions like clicking and typing, structured data extraction, content validation, multi-step task execution, and memory enrichment from web pages.8344 npmMIT
- AlicenseAqualityCmaintenanceEnables AI agents and MCP clients to automate web browsers via Selenium WebDriver, supporting Chrome, Firefox, and Edge in headless or visible mode with tools for navigation, interaction, content extraction, screenshots, and scripting.2131 npmMIT