Cloudflare PlaywrightCAUTION
Playwright MCP fork that works with Cloudflare Browser Rendering
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Cloudflare Playwright MCP
[](https://deploy.workers.cloudflare.com/?url=https://github.com/cloudflare/playwright-mcp/tree/main/cloudflare/example)
Overview
This project leverages Playwright for automated browser testing and integrates with Cloudflare Workers, Browser Rendering and `@cloudflare/playwright` for deployment.
Build and Deploy
Follow these steps to set up and deploy the project:
- Install dependencies:
npm ci
- Build:
cd cloudflare npm run build
- Deploy to Cloudflare Workers:
cd cloudflare/example npm ci npx wrangler deploy
Use with Cloudflare AI Playground
Cloudflare playground AI is a great way to test MCP servers using LLM models available in Workers AI.
- Navigate to https://playground.ai.cloudflare.com/
- Ensure model is set to
llama-3.3-70b-instruct-fp8-fast - In MCP Servers, set URL to
https://[my-mcp-url].workers.dev/sse - Click Connect
- Status should update to Connected and it should list 14 available tools
You can now start to interact with the model, and it will run necessary tools to accomplish what was requested.
[!TIP] For best results, give simple instructions consisting of one single action, e. g., "Create a new todo entry", "Go to cloudflare site", "Take a screenshot"
Example of a conversation:
0a22c34195c5OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp -- npx -y @playwright/[email protected]
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@playwright/[email protected]"
]
}
}
}Exposed tools (30)
25 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
browser_click | read | Perform click on a web page |
browser_close | read | Close the page |
browser_console_messages | read | Returns all console messages |
browser_drag | destructive | Perform drag and drop between two elements |
browser_file_upload | write | Upload one or multiple files |
browser_generate_playwright_test | read | Generate a Playwright test for given scenario |
browser_handle_dialog | read | Handle a dialog |
browser_hover | read | Hover over element on page |
browser_install | write | Install the browser specified in the config. Call this if you get an error about the browser not being installed. |
browser_navigate | read | Navigate to a URL |
browser_navigate_back | read | Go back to the previous page |
browser_navigate_forward | read | Go forward to the next page |
browser_network_requests | read | Returns all network requests since loading the page |
browser_pdf_save | write | Save page as PDF |
browser_press_key | read | Press a key on the keyboard |
browser_resize | read | Resize the browser window |
browser_screen_capture | read | Take a screenshot of the current page |
browser_screen_click | read | Click left mouse button |
browser_screen_drag | read | Drag left mouse button |
browser_screen_move_mouse | write | Move mouse to a given position |
browser_screen_type | read | Type text |
browser_select_option | read | Select an option in a dropdown |
browser_snapshot | read | Capture accessibility snapshot of the current page, this is better than screenshot |
browser_tab_close | read | Close a tab |
browser_tab_list | read | List browser tabs |
browser_tab_new | read | Open a new tab |
browser_tab_select | read | Select a tab by index |
browser_take_screenshot | read | Take a screenshot of the current page. You can |
browser_type | read | Type text into editable element |
browser_wait_for | read | Wait for text to appear or disappear or a specified time to pass |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (15)
-----BEGIN PRIVATE KEY-----
browser_drag
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
exec(query: string): Promise<D1ExecResult>;
import { createConnection } from '../../src/index.js';import { ToolCapability } from '../../config.js';import type { ToolCapability } from '../../config.js';path.join(__filename, '../../cli.js'), '--device=Pixel 5', '--cdp-endpoint=http://localhost:1234',
atob(data: string): string;
declare function atob(data: string): string;
const dockerArgs = ['run', '--rm', '-i', '--network=host', '-v', `${test.info().project.outputDir}:/app/test-results`];@cloudflare/playwright-mcp, @types/node, typescript, wrangler
@cloudflare/playwright, @modelcontextprotocol/sdk, agents, yaml, zod-to-json-schema, @cloudflare/workers-types, vite
@modelcontextprotocol/sdk, commander, debug, mime, ws, zod-to-json-schema, @eslint/eslintrc, @eslint/js
docs/imgs/claudemcp.gif
Gates applied: no_behavioural_pass.
0a22c34195c5full audit observations/trust-audit/mcp-server/cloudflare__cloudflare-playwright.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 0a22c34195c5 | CAUTION | B | 86 | first audit |
Questions
What is the Cloudflare Playwright MCP server?
Playwright MCP fork that works with Cloudflare Browser Rendering
What tools does Cloudflare Playwright expose?
30 in total: 25 read-only, 4 that write, and 1 that can delete or overwrite (browser_drag). Every one is listed on this page with its risk.
Is Cloudflare Playwright safe to connect to an agent?
With care. The audit graded it B (86/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Cloudflare Playwright need?
No credential environment variables were found in its source, so it appears to need none.
How does Cloudflare Playwright run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @playwright/mcp at 0.0.30.
How current is this page?
The grade is for one exact copy of the source (0a22c34195c5), read on 2026-10-06. The repository is watched and re-audited when it changes.