4 min read

Playwright MCP: Let an AI Agent Drive a Real Browser (GitHub, Scanned)

Microsoft's MCP server that lets AI agents browse, click and test real web pages through Playwright.

Playwright MCP logo
✅
Scan: safe. Nothing to warn about. This repository is a thin wrapper of 39 files; the server's code ships inside Microsoft's playwright-core package, and the advisories are in test-only dependencies. Scanned Sep 28, 2026; the full report is below.

Playwright MCP gives an AI agent a browser. Added to an MCP client such as Claude Code, Claude Desktop, VS Code, Cursor, Codex or goose, it exposes tools to open pages, click, type, fill forms, take screenshots and read what is on the page, all driven by Playwright. Instead of working from screenshots, the model reads the page's accessibility tree, a structured list of elements with their roles and labels, so it works with ordinary text models and acts on elements by reference rather than by pixel position.

That makes it useful well beyond testing: agents use it to check their own front-end changes, reproduce a bug, fill in a tedious web form or read a site that has no API. By default it opens a visible browser with a persistent profile for each workspace, so logins survive between sessions; --isolated keeps the profile in memory, --headless hides the window, and a browser extension lets it attach to your existing Chrome or Edge.

It is built by Microsoft's Playwright team, Apache-2.0 licensed, and has about 37,800 stars. The team now also offers Playwright CLI with skills, which it suggests for coding agents because it uses fewer tokens; the MCP server remains the better fit for long, exploratory browser sessions.

Who it is for

Developers using AI coding agents who want them to see and test what they build, people automating repetitive web tasks through an assistant, and QA engineers trying out agent-driven testing.

Getting started

1. Add it to Claude Code

claude mcp add playwright npx @playwright/mcp@latest

2. Or to Codex

codex mcp add playwright npx "@playwright/mcp@latest"

3. For other MCP clients, add this to the client's server config

{"mcpServers":{"playwright":{"command":"npx","args":["@playwright/mcp@latest"]}}}

Needs Node.js 18 or newer. The default profile keeps cookies and logins between sessions, so anything you sign into there is available to the agent next time; add --isolated for throwaway sessions. The README notes that --allowed-origins and --blocked-origins are not a security boundary.

Safety scan

We cloned microsoft/playwright-mcp at commit f183dad on Sep 28, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious patterns, no bare-IP URLs, no install hooks and no committed binaries across 39 files and about 4,100 lines, half of them the README.
  • The npm package's only runtime dependencies are playwright and playwright-core, pinned to a specific Microsoft build. The MCP server's actual code lives in the main microsoft/playwright repository, which this scan did not cover; what you run is Microsoft's published package, not code from this repository.
  • package-lock.json pins 96 packages with 12 advisories (10 moderate, 2 low), all in Hono, qs and body-parser. They arrive with @modelcontextprotocol/sdk, a dev dependency used by the tests, and are not installed for users.
  • Behaviour worth knowing: the default persistent profile stores cookies and logins under ms-playwright in your user cache, the --extension mode can drive your real Chrome or Edge sessions, and the README says --allowed-origins is not a security boundary.
  • Two workflows, no pull_request_target, with both third-party actions pinned to commits. Security policy, Dependabot, licence and contributing guide present; no CodeQL.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflows2 workflows. None use pull_request_target. 0 of 2 third-party actions pinned to a tag rather than a commit.
Network hosts4 distinct hosts referenced from source; most often www.apache.org, playwright.dev, github.com, portal.microsofticm.com. No URLs to bare IP addresses.
Known vulnerabilities12 advisories across 96 pinned packages: 0 critical, 0 high, 10 moderate, 2 low. package-lock.json: 96 packages, 12 advisories.
Project hygieneHas security policy, automated dependency updates, licence file, contributing guide. Missing CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Worst known vulnerabilities (12 of 12)
AdvisorySeverityPackageSummary
GHSA-frvp-7c67-39w9moderate@hono/node-server@1.19.14Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
GHSA-54fx-42gc-7vw4moderatehono@4.12.31Hono: Algorithmic Complexity DoS in Language Middleware
GHSA-8j4g-w8fx-2239moderatehono@4.12.31Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
GHSA-crvj-82cr-hjcxmoderatehono@4.12.31Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
GHSA-f23p-vx2j-j53rmoderatehono@4.12.31Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
GHSA-g6gw-c38x-mqfcmoderatehono@4.12.31Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
GHSA-gqvv-2mrq-wpjvmoderatehono@4.12.31Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
GHSA-hxh3-vqpv-xpqvmoderatehono@4.12.31hono/jsx renders plain strings unescaped in boundary components, leading to XSS
GHSA-4mjr-xmp4-gh2gmoderateqs@6.15.2qs: Denial of Service via Attacker Controlled isBuffer
GHSA-x5fp-wj9c-mxmxmoderateqs@6.15.2qs array-limit bypass via bracket-key comma parsing
GHSA-v422-hmwv-36x6lowbody-parser@2.2.2body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
GHSA-79qm-7rj5-m7r9lowhono@4.12.31Hono: Proxy Helper does not remove response headers listed in the `Connection` header

By the numbers

Stars37.8K
Forks3,212
Contributors71
Commits595
Open issues0
Open pull requests0
Releases73
Latest releasev0.0.83
LicenceApache-2.0
Main languageTypeScript
Project age1 year
Last pushSep 28, 2026
Tracked files39
Lines of code4,134
Checkout size220 KB

Lines by language: Markdown 2,009, TypeScript 1,027, YAML 467, JavaScript 357, Shell 180, JSON 94.

Questions

Is Playwright MCP free?

Yes. It is Apache-2.0 licensed and free, published by Microsoft on npm as @playwright/mcp. It makes no model calls itself; the cost is the tokens your AI client uses, and page snapshots on busy sites can be large.

Does Playwright MCP need a vision model?

No. It works from the accessibility tree, so any text model that supports tool calls can use it. Screenshots are available as a tool for the times a visual check is needed.

Can the agent use my logged-in accounts?

Only if you set it up that way. By default it uses its own browser profile, separate from your everyday browser, and keeps whatever you sign into there. Reaching your real Chrome or Edge sessions requires installing the Playwright extension and starting the server with --extension.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.