An MCP server that automates Playwright-based UI and API testing, supporting test case generation from requirements or API specs, and execution with detailed reports.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE
When Vitest UI server is listening, arbitrary file can be read and executed
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.API_DOC_PATHAPI_KEY— "": "your-api-key"API_URL— "": "http://localhost:3000",BROWSER_HEADLESS— 是否使用无头模式 true UI 测试BROWSER_SLOW_MOBROWSER_TYPE— 浏览器类型 chromium UI 测试BROWSER_VIEWPORT_HEIGHTBROWSER_VIEWPORT_WIDTHCODE_PATH— 注意:Git 相关参数和 参数为二选一关系,要么使用 Git 相关参数从远程仓库克隆代码,要么使用 CODE_PATH 指定本地已有的代码路径。PORTSILENT_TESTSSIMPLE_GIT_BRANCH— "": "main",SIMPLE_GIT_DEPTH— 克隆深度 - 克隆远程仓库SIMPLE_GIT_PASSWORD— "": "password",SIMPLE_GIT_PATH— "": "git",SIMPLE_GIT_USERNAME— "": "username",TEST_BOOL_FALSETEST_BOOL_TRUETEST_INVALID_OBJECTTEST_MODETEST_NUMBERTEST_OBJECTTEST_RETRIESTEST_STORAGE_DIR— 测试结果存储目录 ./test-results 通用TEST_STRINGTEST_TIMEOUT[](https://m8ven.ai/mcp/w1561778301-mcp-playwright-test-1rxrgu)