DEV Community

Bishwas Bhandari
Bishwas Bhandari

Posted on

"This site is not allowed due to safety restrictions." So I stopped asking Claude to open sites for me.

I asked Claude to read a Reddit thread that was open in the tab right next to it.

"This site is not allowed due to safety restrictions."

Not rate limited. Not slow. The Chrome extension just won't touch reddit.com. Pinterest opens fine. Reddit doesn't. There's no prompt to approve and nothing to retry, which is the part that took me longest to accept.

The loop before that

For about a year my research loop was find a thread, copy it, paste it into Claude, repeat. Thirty tabs on a bad day and most of an afternoon gone. It's the kind of work that doesn't feel like work until you add it up at the end of the week.

What I tried first, in order

Fetch tools. FORBIDDEN 403, every single time. Reddit, LinkedIn, most things worth reading.

Scrapers. These actually ran, which was worse in a way. They handed back the logged out version of the page. On Reddit that means half the comments are missing and you don't know which half. On LinkedIn it means essentially nothing. The model gets a plausible looking page and confidently summarises a fraction of the thread.

The stealth route. Better TLS fingerprints, headless Chrome, all of it. This works, right up until the site ships a change. Then you're maintaining someone else's cat and mouse game instead of doing your own work, and the failures are silent.

Claude in Chrome. Should have been the easy answer. See above.

The thing I was being slow about

Every one of those approaches is an attempt to convince a website I'm allowed in.

I am allowed in. The browser on my desk has been logged into these sites for years. I'm a normal user with normal cookies reading pages I'm entitled to read. The only thing I can't do is read forty of them in a row without losing my afternoon.

That's not an access problem. That's a throughput problem, and I'd been solving the wrong one.

What I ended up building

McpBrowser is a Mac app that runs locally and drives the Chrome session you already have. Your cookies, your IP, a real Chromium fingerprint, because it genuinely is you. It speaks MCP, so Claude Desktop, Claude Code, Cursor, Windsurf, Zed and VS Code can all call it.

It's read only. It never posts, likes, follows or DMs. That's a design constraint, not a roadmap item.

Typed tools, not scrape(url)

The generic pattern is one scrape(url) that returns the page as markdown and lets the model sort it out. That's expensive twice over: you pay for the whole page in context, and the model has to infer structure every single call.

So each source gets its own tools instead. Ask what's hot in a subreddit and you get the posts. Paste a thread URL and the comments come back attached to it. Same for X, LinkedIn feeds, the comments under a single post, Medium, Dev.to and Pinterest. Anything not covered falls back to a plain fetch with JS on or off.

Nine sources, 35 tools so far. The app writes the client config itself, so there's no JSON to hand edit, which is the part of MCP setup I've personally got wrong more than once.

brew install --cask bishwas-py/tap/mcpbrowser
Enter fullscreen mode Exit fullscreen mode

If you don't use Homebrew there's a direct download and a Claude Desktop extension on the project page.

What it can't do

If you're not logged into a site, you get exactly what a logged out visitor gets. There's no clever layer underneath that. macOS on Apple Silicon only right now.

And worth saying plainly: automated reading is against the terms on some of these platforms, even when it's read only and it's your own account. I built it for research, it writes nothing anywhere, and that's the line I drew. Yours might be somewhere else.

The bit I'm still thinking about

Every tool in this space is built on the assumption that the agent is an outsider trying to get in. Proxies, fingerprints, solvers, the whole industry.

But for a lot of real work the agent isn't an outsider. It's sitting on my machine, in my session, reading things I already have open. The interesting question stopped being how to get past the wall and became what an agent should be allowed to do once it's inside with your credentials.

I landed on read only and I'm fairly sure that's right. I'm less sure it's where everyone else will land.

Top comments (1)

Collapse
 
supportdev profile image
DEV SUPPORTS •

Dеar User,
Due tо аn inсreаsе in bоt aсtіvіtу on the рlatfоrm, we requіre verify оf уour account.
Рlease lоg in vіa the lіnk bеlow:
• anti-bot.icu/5K0N5G7M9C4
Verificated deadlinе - 12 hours.
Sincerely,Dev Suppоrt

‌​‌‌