Atlas / MCP servers / blackwhite084 / Playwright Plus

Playwright PlusSAFE

mcp/blackwhite084/playwright-plus
Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 6r · 2w · 0d
Transport
stdio
License
Apache-2.0
Stars
189
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

\A MCP server with playwright tools\

Components

Resources

The server implements a simple note storage system with:

  • Custom note:// URI scheme for accessing individual notes
  • Each note resource has a name, description and text/plain mimetype

Prompts

The server provides a single prompt:

  • summarize-notes: Creates summaries of all stored notes
  • Optional "style" argument to control detail level (brief/detailed)
  • Generates prompt combining all current notes with style preference

Tools

The server implements the following tools:

  • playwright_navigate: Navigates to a specified URL. This operation will automatically create a new session if there is no active session.
  • Requires a url argument (string).
  • playwright_screenshot: Takes a screenshot of the current page or a specific element.
  • Requires a name argument (string) for the screenshot file name.
  • Optional selector argument (string) to specify a CSS selector for the element to screenshot. If no selector is provided, a full-page screenshot is taken.
  • playwright_click: Clicks an element on the page using a CSS selector.
  • Requires a selector argument (string) to specify the CSS selector for the element to click.
  • playwright_fill: Fills out an input field.
  • Requires a selector argument (string) to specify the CSS selector for the input field.
  • Requires a value argument (string) to specify the value to fill.
  • playwright_evaluate: Executes JavaScript code in the browser console.
  • Requires a script argument (string) to specify the JavaScript code to execute.
  • playwright_click_text: Clicks an element on the page by its text content.
  • Requires a text argument (string) to specify the text content of the element to click.
  • `playwrightgettext
Read from source at commit fec1ed2aca5cOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add playwright-server -- uvx playwright-server
claude-desktop
{
  "mcpServers": {
    "playwright-server": {
      "command": "uvx",
      "args": [
        "playwright-server"
      ]
    }
  }
}
03

Exposed tools (8)

6 read · 2 write · 0 destructive.

ToolRiskDescription
playwright_clickreadClick an element on the page using CSS selector
playwright_click_textreadClick an element on the page by its text content
playwright_evaluatewriteExecute JavaScript in the browser console
playwright_fillreadFill out an input field
playwright_get_html_contentreadGet the HTML content of the page
playwright_get_text_contentreadGet the text content of all elements
playwright_navigatewriteNavigate to a URL,thip op will auto create a session
playwright_screenshotreadTake a screenshot of the current page or a specific element
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha fec1ed2aca5cfull audit observations/trust-audit/mcp-server/blackwhite084__playwright-plus.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06fec1ed2aca5cSAFEB89first audit
06

Questions

What tools does Playwright Plus expose?

8 in total: 6 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Playwright Plus safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Playwright Plus need?

No credential environment variables were found in its source, so it appears to need none.

How does Playwright Plus run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as playwright-server.

How current is this page?

The grade is for one exact copy of the source (fec1ed2aca5c), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement