Expose browser filesystem through MCP - #144
masnwilliams wants to merge 4 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
…er-files # Conflicts: # README.md
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit d5a2072. Configure here.
Require non-empty session IDs and paths, document which actions use path, inject the Kernel client factory, and test the tool through a real MCP client and server.
dcruzeneil2
left a comment
There was a problem hiding this comment.
LGTM overall — thin, correctly-typed adapter over browsers.fs, consistent with the other manage_* tools, bugbot findings addressed properly, tests exercise the real MCP contract. no new privilege: exec_command --as_root and browser_repl already give full VM filesystem access, this just makes it structured. approving with one should-fix and some nits.
should-fix before merge
- bound
read/download/download_dir_zip.responseBuffer()buffers the whole file, base64s it, and returns it in one JSON-RPC message. nothing upstream caps this either — kernel/kernel'sReadFilebuffers the full body and the in-VM API streams whatever is on disk.download_dir_zipon/home/kernelis a one-liner for a model and will OOM or blow the response limit (the same budgetshell.tscapstimeout_secfor). suggest amax_bytesparam (default ~10–25MB); forread/downloadcallfileInfofirst and refuse over the cap with a hint to narrow vialist/get_info/exec_command; for the zip, stop at the cap and error.
nits
- paths are described as absolute but not enforced. only
upload/upload_zipcheckIsAbson the VM side;read/write/move/delete_*resolve relative paths against the API process cwd.encodedPath()already assumes absolute (prepends/), so a relativereadreturns a resource URI claiming a path that isn't where the file is. a.regex(/^\//)onpath/src_path/dest_pathmakes the schema match its own description. - SDK defaults (60s timeout,
maxRetries: 2) apply to every action. a largewrite/uploadthat times out is re-sent up to three times, and amovethat completed but lost its response gets retried and reports 404.maxRetries: 0for the mutating actions, orlongOperationOptionslikeshell.ts. session_idsays "Browser session ID." — SDK param isidOrName, every other session tool says "ID or name". also addmanage_browser_filesto the two lists of name-accepting tools (README ~L325 andbrowsers.tsnamedescription).readon binary returns mojibake silently; if the decoded text contains U+FFFD, append "appears binary; use download".- the
content-typefallback indownloadis dead — the VM API always returnsapplication/octet-stream— somime_typeis the only way to get a real type; say so in its description. - no tests for
upload_zipor themime_typeoverride.

summary
manage_browser_filesMCP tool backed by the existing browser filesystem SDKtesting
bun test(847 tests passed, after merging main)bunx tsc --noEmitbun run buildcompiled and typechecked successfully, then stopped during page-data collection becauseKERNEL_CLI_PROD_CLIENT_IDis not set in the local environmentNote
Medium Risk
The tool enables destructive VM filesystem changes (delete, move, writes) on live browser sessions; risk is mitigated by existing Kernel API auth but agent misuse could still cause session data loss.
Overview
Adds a new
manage_browser_filesMCP tool that exposes the browser VM filesystem through the existingbrowsers.fsSDK, with project selection aligned to other session-scoped browser tools.The tool is action-driven: list/info/read for inspection; write, upload, and upload_zip with utf8 or base64 payloads (validated before SDK calls); download and download_dir_zip return binary data as embedded MCP resources with
kernel-browser-file://URIs; plus create/move/delete and set_permissions. Text reads return raw content; mutations are marked destructive in tool annotations.Wires the capability into MCP registration under the
browser_filestoolset (aliasesbrowser_fs/manage_browser_files), extends tool-name and project-scoped registration tests, documents it in the README, and adds unit tests covering SDK routing, validation, and resource encoding.Reviewed by Cursor Bugbot for commit 24ae9c8. Bugbot is set up for automated code reviews on this repo. Configure here.