Hronaut combines durable browser workspaces with semantic interaction, browser diagnostics, QA evidence, network inspection, and mediated local wallets. This is the complete advertised tool surface—not a sample list.
Verified against the public Hronaut source on September 2, 2026.
What this proves
The MCP surface covers more than clicks and screenshots.
An agent can keep task-owned browser state, address pages through semantic refs, collect bounded debugging evidence, reproduce defects, and hand control back to a person. The catalog describes capability, not blanket permission: workspace ownership, input validation, authentication, interaction locks, and explicit confirmations still apply.
Complete catalog
Find the tool group your workflow needs.
Names below are the exact MCP names advertised by Hronaut. Compatible clients also receive human-readable titles and explicit read-only, destructive, idempotent, and open-world hints.
18 tools
Workspaces, tabs, and browser state
Create or resume isolated workspaces, select visible tabs, inspect origin storage, and manage browser-owned records.
Tool hints help clients. Hronaut still enforces the boundary.
Safety annotations are advisory metadata for compatible clients and approval interfaces. Hronaut only marks a tool read-only when every supported mode is observational; combined list/edit/clear tools remain non-read-only. Browser-facing reads stay open-world because sanitized page and network evidence still originates outside Hronaut.
Those hints do not replace owner-token authentication, task-owned workspace authorization, tab validation, input bounds, human interaction locks, wallet policy checks, or side-effect confirmations. Review the security and release trust page before granting an agent access to valuable signed-in sessions.