visual-ui-debug-agent-mcp (samihalawa/visual-ui-debug-agent-mcp) is an MCP server listed on the M8ven Trust Index. It scores 50 out of 100, grade D. It declares 30 tools. No publisher has claimed this listing.
An MCP server that enables AI agents to autonomously test, debug, and analyze web interfaces visually using Playwright, with 30 tools for screenshots, workflows, performance, and visual comparison.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
samihalawa
Source: Glama · also listed on github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
enhanced_page_analyzerAnalyze a page with screenshots, console logs, interactive element mapping, and performance metrics
api_endpoint_testerTest multiple API endpoints and verify responses
navigation_flow_validatorTest a sequence of user actions across multiple pages
screenshot_urlTake a screenshot of a URL
dom_inspectorInspect DOM elements and their properties
batch_screenshot_urlsCapture screenshots of multiple URLs in a grid layout for easy comparison
console_monitorMonitor console logs on a page
performance_analysisAnalyze page performance metrics
visual_comparisonCompare two URLs visually and highlight differences
screenshot_local_filesTake screenshots of local HTML files in a directory
playwright_navigateNavigate to a URL
playwright_clickClick an element on the page
playwright_iframe_clickClick an element in an iframe on the page
playwright_fillFill out an input field
playwright_selectSelect an option in a dropdown
playwright_hoverHover over an element on the page
playwright_evaluateExecute JavaScript in the browser console context
playwright_console_logsRetrieve console logs captured so far
playwright_get_visible_textGet the visible text content of the current page
playwright_get_visible_htmlGet the HTML content of the current page
playwright_go_backNavigate back in browser history
playwright_go_forwardNavigate forward in browser history
playwright_press_keyPress a keyboard key (optionally focusing an element first)
playwright_dragDrag an element to a target location
playwright_screenshotTake a screenshot of the current page or a specific element
ui_workflow_validatorExecute and validate a sequence of UI interactions simulating a user workflow.
tunnel_helperGuide user to expose local ports via Cloudflare tunnel or manage tunnel URLs
debug_memorySave and retrieve debugging context including .env variables, selectors, and issues
sitemap_crawlerCrawl a website recursively to generate a comprehensive sitemap with all endpoints, links, and visible text content. Perfect for detecting inconsistent content, broken links, and navigation issues.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
MCP_SERVER_URLTEST_URLVUDA_ACTION_WAIT_BEFOREVUDA_DEFAULT_TIMEOUTVUDA_FLOW_STEP_DELAYVUDA_INTERACTION_DELAYVUDA_NAVIGATION_TIMEOUTVUDA_PERFORMANCE_THRESHOLDVUDA_SELECTOR_TIMEOUTVUDA_STABILITY_WAITVUDA_UI_UPDATE_WAITDependencies
11 dependencies, 1 flagged: playwright
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
30/30 tools missing one or more hints — enhanced_page_analyzer (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); api_endpoint_tester (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); navigation_flow_validator (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +27 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
No eval / new Function
1 eval() or new Function() call — dynamic code execution
Replace eval / Function with explicit parsing or safer alternatives.
Production dependencies are patched
0 critical, 14 high severity in production deps — @modelcontextprotocol/sdk@1.24.0 (high), @modelcontextprotocol/sdk@1.24.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
1/6 production deps stale: node-fetch@2023-11-30 (2.5y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/samihalawa/visual-ui-debug-agent-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check