CloakBrowser MCP
Frameworks & Eval · tested 2026-08-14 · by the Hlido desk, not the vendor
In short: A Playwright-MCP-compatible browser server that publishes a version compatibility matrix and says parity with upstream is verified in CI — the honest answer to 'will this break when Playwright MCP updates?'
Quick answer
CloakBrowser MCP scores 77/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-14). STEADY because the surface is unusually complete and honest for a wrapper project: current version, a full compatibility matrix with CI-verified parity, three packaging routes, comparison and recipe sections, and a clear Pricing: Paid.
CloakBrowser MCP is positioned precisely: a drop-in Playwright-MCP-compatible server that runs upstream @playwright/mcp as the canonical tool surface, with CloakBrowser Chromium and deployment features layered around it. Because the tools are unchanged upstream tools, the compatibility question becomes the whole risk, and the docs answer it directly with a matrix mapping every cloakbrowser-mcp release to its @playwright/mcp version, Playwright MCP Docker base image, CloakBrowser version and transports — with a Parity column reading 'Compared in CI'. Publishing a compatibility matrix at all is uncommon; testing that parity in CI and saying so is genuinely good engineering practice made legible to a buyer. The added value is stated as deployment-oriented rather than functional: persistent profiles, extension loading, context validation, GeoIP-aware proxy matching for regional QA, and humanized input behaviour for interaction-sensitive flows. Version is current and visible (v1.11.0), packaging covers npm, Docker and Streamable HTTP, and the documentation is translated into ten languages, which signals a maintainer investing well beyond a weekend project. The thing to be clear-eyed about is what 'CloakBrowser' and 'humanized input behavior' mean: these are anti-detection features. There is a legitimate use — regional QA and testing interaction-sensitive flows are real jobs — but the same capabilities evade bot detection, and the documentation does not address the acceptable-use question that raises. Buyers in regulated contexts should resolve that before adopting.
Why STEADY
STEADY because the surface is unusually complete and honest for a wrapper project: current version, a full compatibility matrix with CI-verified parity, three packaging routes, comparison and recipe sections, and a clear statement of what it adds versus what it inherits. Held out of the top band because the anti-detection capabilities at the centre of the value proposition are presented without any acceptable-use discussion, and because a wrapper inherits upstream's release cadence as a standing dependency risk.
What we saw
4 screenshots captured by the Hlido engine during the reviewed run (run-47b7472de3d037be-swimmwatch-github-io). Our own captures — not vendor marketing material.
What it does well
- Publishes a full version compatibility matrix across cloakbrowser-mcp, @playwright/mcp, Docker base and CloakBrowser
- States that upstream parity is compared in CI, rather than merely asserting compatibility
- Honest about what it inherits versus what it adds — upstream tools unchanged, deployment features layered on
- Current version visible (v1.11.0) with prior releases and their pinnings retained
- Three packaging routes: npm, Docker and Streamable HTTP
- Documentation translated into ten languages, plus comparison and recipe sections
What it fails at
- Anti-detection features (CloakBrowser, humanized input) are central to the value proposition and carry no acceptable-use discussion
- As a wrapper, it inherits upstream's release cadence — a standing dependency risk the matrix documents but cannot remove
- The tool surface is deliberately upstream's, so it is documented there rather than here
- No statement on how persistent profiles store cookies or credentials
- GeoIP-aware proxy matching implies proxy infrastructure that is not described or sourced
Red flags
- 'CloakBrowser' and 'humanized input behavior' are anti-detection capabilities. The stated uses — regional QA, interaction-sensitive testing — are legitimate, but the same features defeat bot detection and the docs raise no acceptable-use question at all.
- Persistent profiles and extension loading imply stored browser state, potentially including credentials and cookies, with no documented handling or isolation model.
Best for
- Teams already on Playwright MCP who need persistent profiles, extension loading or regional QA
- QA engineers testing geo-specific behaviour where proxy matching is the requirement
- Deployments needing Docker or Streamable HTTP packaging that upstream does not provide as directly
Not recommended for
- Organisations whose policies prohibit anti-bot-detection tooling — resolve this before adopting
- Users who need only standard browser automation; upstream Playwright MCP is the simpler dependency
- Teams unwilling to carry a wrapper's upstream-tracking risk, however well documented
Pricing & access
- ModelPaid
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-14.
Compared to
-
Microsoft Playwright MCP
upstream-simplicity-vs-deployment-features
This wraps that. Take upstream unless you specifically need persistent profiles, extension loading, GeoIP proxy matching or the Docker/HTTP packaging — every wrapper adds a tracking dependency, and this one documents that cost more honestly than most.
-
WaveXisMCP
reimplementation-vs-wrapping
WaveXisMCP reimplements browser control in Python with its own 220-tool surface; CloakBrowser deliberately keeps upstream's tools and changes only execution. Opposite strategies — reimplementation versus compatible wrapping.
Agent relevance
MCP Behavioral-testable
Agentic-Commerce Readiness 46/100 · SURFACE-ONLY
Independent readiness for agent delegation & transaction. How it’s scored · check live
Drop-in Playwright MCP compatible over stdio and Streamable HTTP, so any agent already configured for upstream works unchanged — the compatibility matrix makes the version contract explicit, which is exactly what an agent operator needs to pin against.
Agent-friendly score: 8/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Homepage publicly accessible and value proposition clearly stated — source (2026-08-14) verified
- Pricing page discoverable in 2 clicks from homepage — source (2026-08-14)
- Documentation or live demo accessible without login — source (2026-08-14) verified
- Integration list or supported frameworks documented — source (2026-08-14) verified
- Authentication / data handling claims publicly stated — source (2026-08-14)



