DrissionPageCAUTION
DrissionPage MCP Server · Browser automation for Claude Code, Codex, and MCP clients
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Professional browser automation for Codex, Claude Code, and MCP clients, powered by DrissionPage. DrissionPage is a Python web automation library built around direct Chromium/CDP control with requests-style HTTP session support. This server exposes its browser-facing capabilities as typed, atomic MCP tools.
[](https://pypi.org/project/drissionpage-mcp/) [](https://pepy.tech/project/drissionpage-mcp) [](https://opensource.org/licenses/Apache-2.0) [](https://www.python.org/downloads/) [](https://github.com/jumodada/Drissionpage-MCP-Server/actions/workflows/ci.yml) [](https://codecov.io/gh/jumodada/Drissionpage-MCP-Server) []()
[](https://drissionpage-mcp.vercel.app)
[Open the interactive Browser Lab](https://drissionpage-mcp.vercel.app) to replay bounded natural pointer motion, drag controls, and verify observable state.
Official Repositories: GitHub | GitCode
English Version | 中文版本
🖱️ Atomic Browser Control with Natural Pointer Motion
DrissionPage MCP 0.8.8 exposes 69 typed browser capabilities. The MCP server provides accurate low-level observation and interaction; the clien
e31d70a4ab8cOBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add drissionpage-mcp -- None drissionpage-mcp==0.8.8
Trust audit
CAUTIONgrade C · trust 73/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (22)
module = importlib.import_module(module_name)
"callback_url",
secret = "validation-secret-token"
secret = "dialog-history-secret"
secret = "dialog-native-failure-secret"
print(f"::add-mask::{token}")@pytest.mark.parametrize("path", ["../escape.png", "nested/../../escape.png"])callback_url=secret_url,
DP_TEST_SITE_URL: http://127.0.0.1:4321
yield f"http://127.0.0.1:{server.server_port}"server, "page_navigate", {"url": "http://127.0.0.1/"}result = await _execute_tool_text(server, name, {"url": "http://127.0.0.1/"})assert "DP_TEST_SITE_URL: http://127.0.0.1:4321" in coverage_job
return base64.b64decode(image_data, validate=True)
assert base64.b64decode(images[0].data).startswith(b"\x89PNG")
"bytes": len(base64.b64decode(ONE_PIXEL_PNG)),
raw_png = base64.b64decode(ONE_PIXEL_PNG)
PNG_1X1 = base64.b64decode(
DrissionPage, pydantic, typing-extensions, mcp, pytest, pytest-asyncio, black, isort
curl -fsSL https://chatgpt.com/codex/install.sh | sh
curl -fsSL https://chatgpt.com/codex/install.sh | sh
Gates applied: no_behavioural_pass.
e31d70a4ab8cfull audit observations/trust-audit/mcp-server/jumodada__drissionpage-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | e31d70a4ab8c | CAUTION | C | 73 | first audit |
Questions
What is the DrissionPage MCP server?
DrissionPage MCP Server · Browser automation for Claude Code, Codex, and MCP clients
Is DrissionPage safe to connect to an agent?
With care. The audit graded it C (73/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does DrissionPage need?
No credential environment variables were found in its source, so it appears to need none.
How does DrissionPage run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as drissionpage-mcp.
How current is this page?
The grade is for one exact copy of the source (e31d70a4ab8c), read on 2026-10-01. The repository is watched and re-audited when it changes.