mcp-playwright (executeautomation/mcp-playwright) is an MCP server listed on the M8ven Trust Index. It scores 72 out of 100, grade C. It declares 33 tools. No publisher has claimed this listing.
A Model Context Protocol server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages, take screenshots, and execute JavaScript in a real browser environment.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
executeautomation
Source: ModelScope
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
start_codegen_sessionStart a new code generation session to record Playwright actions
end_codegen_sessionEnd a code generation session and generate the test file
get_codegen_sessionGet information about a code generation session
clear_codegen_sessionClear a code generation session without generating a test
playwright_navigateNavigate to a URL
playwright_screenshotTake a screenshot of the current page or a specific element
playwright_clickClick an element on the page
playwright_iframe_clickClick an element in an iframe on the page
playwright_iframe_fillFill an element in an iframe on the page
playwright_fillfill out an input field
playwright_selectSelect an element on the page with Select tag
playwright_hoverHover an element on the page
playwright_upload_fileUpload a file to an input[type='file'] element on the page
playwright_evaluateExecute JavaScript in the browser console
playwright_console_logsRetrieve console logs from the browser with filtering options
playwright_resizeResize the browser viewport using manual dimensions or device presets. Supports 143+ device presets including iPhone, iPad, Android devices, and desktop browsers with proper user-agent and touch emulation.
playwright_closeClose the browser and release all resources
playwright_getPerform an HTTP GET request
playwright_postPerform an HTTP POST request
playwright_putPerform an HTTP PUT request
playwright_patchPerform an HTTP PATCH request
playwright_deletePerform an HTTP DELETE request
playwright_expect_responseAsk Playwright to start waiting for a HTTP response. This tool initiates the wait operation but does not wait for its completion.
playwright_assert_responseWait for and validate a previously initiated HTTP response wait operation.
playwright_custom_user_agentSet a custom User Agent for the browser
playwright_get_visible_textGet the visible text content of the current page
playwright_get_visible_htmlGet the HTML content of the current page. By default, all <script> tags are removed from the output unless removeScripts is explicitly set to false.
playwright_go_backNavigate back in browser history
playwright_go_forwardNavigate forward in browser history
playwright_dragDrag an element to a target location
playwright_press_keyPress a keyboard key
playwright_save_as_pdfSave the current page as a PDF file
playwright_click_and_switch_tabClick a link and switch to the newly opened tab
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CHROME_EXECUTABLE_PATHLOG_FILE_PATHLOG_FORMATLOG_LEVELLOG_MAX_FILESLOG_MAX_FILE_SIZELOG_OUTPUTSTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
33/33 tools missing one or more hints — start_codegen_session (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); end_codegen_session (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_codegen_session (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +30 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
16/33 tools referenced in tests (48%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
3 child_process/subprocess calls in production code — runs shell commands (src/toolHandler.ts:168, run-tests.cjs:5, run-tests.js:5)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 2 high severity in production deps — @modelcontextprotocol/sdk@1.24.3 (high), @modelcontextprotocol/sdk@1.24.3 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/executeautomation/mcp-playwright)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check