GitHub - autokeren/ghostfox: The agent-native stealth browser you can own —…
The agent-native stealth browser you can own. Self-hosted · Open source · MCP-first · Engine-level anti-detect
Spots The agent-native stealth browser you can own. Self-hosted · Open source · MCP-first · Engine-level anti-detect

AI agents get blocked. Headless Chrome triggers Cloudflare 403s on ~20% of the web, and hosted "stealth browsers" route your agent's cookies, identities and sessions through someone else's cloud.
Ghostfox is the alternative: a complete browser stack you run yourself — a fingerprint-coherent stealth engine plus a Rust MCP runtime, in one repo. The moat — why this isn't just another wrapper.
We own the engine. The anti-detect lives in C++ patches inside our own Firefox fork — not in injected JS that detectors can read. Upstream Camoufox has signaled partially-closed patches ahead; wrappers inherit that risk, a fork that owns its engine doesn't.
A living proof corpus. Every claim here has a receipt: bilibili icon-click ×6, hCaptcha on production signups, TikTok OAuth+OTP live, 500/500 identity audits, Docker E2E. Features get copied in a week — verified history can't be.
Agent-native ergonomics. 43 coherent MCP tools, fire-then-verify receipts, evidence recording, and a playbook (AGENTS.md) distilled from real runs. Agents (and their prompts) build habits on this surface — switching costs are real.
Canonical distribution. PyPI, npm, GHCR and the official MCP Registry under one name, with the docs, benchmarks and changelogs to back it. Forks will exist; the verified trunk is here.
Captcha suite — 8 families, solved on-device (v0.6.7+). The runtime ships native MCP solvers with local models — no paid captcha farms, no cloud, no browser rent:
E2E-verified against production sites (not vendor demos): bilibili icon-click ×6 "Verification Succeeded", hCaptcha on real signups (dashboard.hcaptcha.com, dosya.co), TikTok OAuth+OTP live session. Debug cortex — page tools that tell you WHY (v0.7). Agents stop guessing when a page misbehaves: page_console — every console.log/warn/error since load page_errors — uncaught JS exceptions with stack traces page_network_start/read/body — request/response capture with body fetch That's the DevTools trio, exposed over MCP.
Multi-model vision (optional). page_vision + page_ocr + page_match_image + page_pixels + page_contrast — wire any vision-capable model (Cloudflare Workers AI, GLM, Qwen, ...) as cross-checks for grid puzzles and layout questions. Keys are optional; the native solvers above run fully local.
The agent-native stealth browser you can own.
