Atlas / MCP servers / jumodada / DrissionPage

DrissionPageCAUTION

mcp/jumodada/drissionpage-4

DrissionPage MCP Server · Browser automation for Claude Code, Codex, and MCP clients

Verdict
CAUTION
Grade
C
Trust score
73 /100
Exposed tools
—
Transport
stdio
License
NOASSERTION
Stars
487
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Professional browser automation for Codex, Claude Code, and MCP clients, powered by DrissionPage. DrissionPage is a Python web automation library built around direct Chromium/CDP control with requests-style HTTP session support. This server exposes its browser-facing capabilities as typed, atomic MCP tools.

[](https://pypi.org/project/drissionpage-mcp/) [](https://pepy.tech/project/drissionpage-mcp) [](https://opensource.org/licenses/Apache-2.0) [](https://www.python.org/downloads/) [](https://github.com/jumodada/Drissionpage-MCP-Server/actions/workflows/ci.yml) [](https://codecov.io/gh/jumodada/Drissionpage-MCP-Server) []()

[](https://drissionpage-mcp.vercel.app)

[Open the interactive Browser Lab](https://drissionpage-mcp.vercel.app) to replay bounded natural pointer motion, drag controls, and verify observable state.

Official Repositories: GitHub | GitCode

English Version | 中文版本

🖱️ Atomic Browser Control with Natural Pointer Motion

DrissionPage MCP 0.8.8 exposes 69 typed browser capabilities. The MCP server provides accurate low-level observation and interaction; the clien

Read from source at commit e31d70a4ab8cOBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add drissionpage-mcp -- None drissionpage-mcp==0.8.8
03

Trust audit

CAUTIONgrade C · trust 73/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (22)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
drissionpage_mcp/doctor.py:38
module = importlib.import_module(module_name)
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
drissionpage_mcp/response_json.py:64
"callback_url",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_browser_owned_capabilities.py:1410
secret = "validation-secret-token"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_server.py:553
secret = "dialog-history-secret"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_server.py:570
secret = "dialog-native-failure-secret"
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
.github/workflows/ci.yml:303
print(f"::add-mask::{token}")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_policy.py:210
@pytest.mark.parametrize("path", ["../escape.png", "nested/../../escape.png"])
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
tests/test_redaction.py:22
callback_url=secret_url,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/ci.yml:212
DP_TEST_SITE_URL: http://127.0.0.1:4321
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/fixtures/http_fixture.py:1015
yield f"http://127.0.0.1:{server.server_port}"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_browser_integration.py:2610
server, "page_navigate", {"url": "http://127.0.0.1/"}
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_browser_integration.py:2668
result = await _execute_tool_text(server, name, {"url": "http://127.0.0.1/"})
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_ci_workflow.py:146
assert "DP_TEST_SITE_URL: http://127.0.0.1:4321" in coverage_job
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
drissionpage_mcp/response_media.py:52
return base64.b64decode(image_data, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_browser_integration.py:311
assert base64.b64decode(images[0].data).startswith(b"\x89PNG")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_response_contract.py:195
"bytes": len(base64.b64decode(ONE_PIXEL_PNG)),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_response_contract.py:1079
raw_png = base64.b64decode(ONE_PIXEL_PNG)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_tool_success_paths.py:32
PNG_1X1 = base64.b64decode(
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
DrissionPage, pydantic, typing-extensions, mcp, pytest, pytest-asyncio, black, isort
Why it matters. 10 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:107
curl -fsSL https://chatgpt.com/codex/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README_CN.md:105
curl -fsSL https://chatgpt.com/codex/install.sh | sh
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha e31d70a4ab8cfull audit observations/trust-audit/mcp-server/jumodada__drissionpage-4.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-01e31d70a4ab8cCAUTIONC73first audit
05

Questions

What is the DrissionPage MCP server?

DrissionPage MCP Server · Browser automation for Claude Code, Codex, and MCP clients

Is DrissionPage safe to connect to an agent?

With care. The audit graded it C (73/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does DrissionPage need?

No credential environment variables were found in its source, so it appears to need none.

How does DrissionPage run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as drissionpage-mcp.

How current is this page?

The grade is for one exact copy of the source (e31d70a4ab8c), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement