Atlas / MCP servers / cloudflare / Cloudflare Playwright

Cloudflare PlaywrightCAUTION

mcp/cloudflare/cloudflare-playwright

Playwright MCP fork that works with Cloudflare Browser Rendering

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
30 25r · 4w · 1d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
258
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Cloudflare Playwright MCP

[](https://deploy.workers.cloudflare.com/?url=https://github.com/cloudflare/playwright-mcp/tree/main/cloudflare/example)

Overview

This project leverages Playwright for automated browser testing and integrates with Cloudflare Workers, Browser Rendering and `@cloudflare/playwright` for deployment.

Build and Deploy

Follow these steps to set up and deploy the project:

  1. Install dependencies:
npm ci
  1. Build:
cd cloudflare
npm run build
  1. Deploy to Cloudflare Workers:
cd cloudflare/example
npm ci
npx wrangler deploy

Use with Cloudflare AI Playground

Cloudflare playground AI is a great way to test MCP servers using LLM models available in Workers AI.

  • Navigate to https://playground.ai.cloudflare.com/
  • Ensure model is set to llama-3.3-70b-instruct-fp8-fast
  • In MCP Servers, set URL to https://[my-mcp-url].workers.dev/sse
  • Click Connect
  • Status should update to Connected and it should list 14 available tools

You can now start to interact with the model, and it will run necessary tools to accomplish what was requested.

[!TIP] For best results, give simple instructions consisting of one single action, e. g., "Create a new todo entry", "Go to cloudflare site", "Take a screenshot"

Example of a conversation:

Read from source at commit 0a22c34195c5OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp -- npx -y @playwright/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@playwright/[email protected]"
      ]
    }
  }
}
03

Exposed tools (30)

25 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
browser_clickreadPerform click on a web page
browser_closereadClose the page
browser_console_messagesreadReturns all console messages
browser_dragdestructivePerform drag and drop between two elements
browser_file_uploadwriteUpload one or multiple files
browser_generate_playwright_testreadGenerate a Playwright test for given scenario
browser_handle_dialogreadHandle a dialog
browser_hoverreadHover over element on page
browser_installwriteInstall the browser specified in the config. Call this if you get an error about the browser not being installed.
browser_navigatereadNavigate to a URL
browser_navigate_backreadGo back to the previous page
browser_navigate_forwardreadGo forward to the next page
browser_network_requestsreadReturns all network requests since loading the page
browser_pdf_savewriteSave page as PDF
browser_press_keyreadPress a key on the keyboard
browser_resizereadResize the browser window
browser_screen_capturereadTake a screenshot of the current page
browser_screen_clickreadClick left mouse button
browser_screen_dragreadDrag left mouse button
browser_screen_move_mousewriteMove mouse to a given position
browser_screen_typereadType text
browser_select_optionreadSelect an option in a dropdown
browser_snapshotreadCapture accessibility snapshot of the current page, this is better than screenshot
browser_tab_closereadClose a tab
browser_tab_listreadList browser tabs
browser_tab_newreadOpen a new tab
browser_tab_selectreadSelect a tab by index
browser_take_screenshotreadTake a screenshot of the current page. You can
browser_typereadType text into editable element
browser_wait_forreadWait for text to appear or disappear or a specified time to pass
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (15)

MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/testserver/key.pem:1
-----BEGIN PRIVATE KEY-----
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
browser_drag
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cloudflare/example/worker-configuration.d.ts:2210
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cloudflare/example/worker-configuration.d.ts:4635
exec(query: string): Promise<D1ExecResult>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cloudflare/src/index.ts:7
import { createConnection } from '../../src/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cloudflare/src/index.ts:8
import { ToolCapability } from '../../config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/tool.ts:21
import type { ToolCapability } from '../../config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cdp.spec.ts:87
path.join(__filename, '../../cli.js'), '--device=Pixel 5', '--cdp-endpoint=http://localhost:1234',
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
cloudflare/example/worker-configuration.d.ts:206
atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
cloudflare/example/worker-configuration.d.ts:292
declare function atob(data: string): string;
LOWContainer / deploy · priv.container · CWE-250, CWE-16
tests/fixtures.ts:176
const dockerArgs = ['run', '--rm', '-i', '--network=host', '-v', `${test.info().project.outputDir}:/app/test-results`];
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
cloudflare/example/package.json
@cloudflare/playwright-mcp, @types/node, typescript, wrangler
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
cloudflare/package.json
@cloudflare/playwright, @modelcontextprotocol/sdk, agents, yaml, zod-to-json-schema, @cloudflare/workers-types, vite
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, commander, debug, mime, ws, zod-to-json-schema, @eslint/eslintrc, @eslint/js
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
docs/imgs/claudemcp.gif
docs/imgs/claudemcp.gif
Why it matters. 7201224 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 0a22c34195c5full audit observations/trust-audit/mcp-server/cloudflare__cloudflare-playwright.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-060a22c34195c5CAUTIONB86first audit
06

Questions

What is the Cloudflare Playwright MCP server?

Playwright MCP fork that works with Cloudflare Browser Rendering

What tools does Cloudflare Playwright expose?

30 in total: 25 read-only, 4 that write, and 1 that can delete or overwrite (browser_drag). Every one is listed on this page with its risk.

Is Cloudflare Playwright safe to connect to an agent?

With care. The audit graded it B (86/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Cloudflare Playwright need?

No credential environment variables were found in its source, so it appears to need none.

How does Cloudflare Playwright run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @playwright/mcp at 0.0.30.

How current is this page?

The grade is for one exact copy of the source (0a22c34195c5), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement