Atlas / MCP servers / mcpware / Pagecast

PagecastBLOCK

mcp/mcpware/pagecast

Record any browser page as GIF or video via MCP — powered by Playwright + ffmpeg

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
9 6r · 3w · 0d
Transport
stdio
License
MIT
Stars
48
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@mcpware/pagecast) [](https://www.npmjs.com/package/@mcpware/pagecast) [](LICENSE) [](https://github.com/mcpware/pagecast) [](https://github.com/mcpware/pagecast/fork)

English | 廣東話

Turn AI browser interactions into polished product demos.

Tell your AI to demo your app. Pagecast records the browser, tracks every click and keystroke, and exports a shipping-ready GIF or MP4 — with tooltip zoom overlays and cinematic pan effects. No screen recorder. No video editor. No post-production. Make a demo gif automatically after every PR if you want.

Without Pagecast — plain screen recording, you do the demonstration yourself and record yourself and you need to repead every time you changed the UI. You can see the cursor moving, but the actual interactions are too small to follow:

With Pagecast (tooltip mode) — a magnified close-up appears on every interaction so viewers can actually see what's happening, and it design what to demo and make a new demo gif automatically:

With Pagecast (cinematic mode) — the camera crops and pans to follow each action, and it design what to demo and make a new demo gif automatically:

Two ways to use Pagecast

1. Product demo tool (the main use case)

You built a web app. You need a demo GIF for the README. Normally you'd:

  1. Open a screen recorder, manually click through the demo
  2. Open a video editor, zoom into the important parts
  3. Export, figure out ffmpeg, o
Read from source at commit 69b9ec1f0f48OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add pagecast -- npx -y @mcpware/[email protected]
03

Exposed tools (9)

6 read · 3 write · 0 destructive.

ToolRiskDescription
cinematic_exportreadConvert a recorded .webm to GIF or MP4 with cinematic crop-pan effects. Crops the entire frame to focus on the interaction area, then pans smoothly between targets. Think of it as a virtual cameraman that follows the action. Two rendering modes: -
convert_to_gifreadConvert a .webm video to an optimized GIF using ffmpeg two-pass palette method.
convert_to_mp4readConvert a .webm video to MP4 (H.264). Widely compatible for social media, sharing, and embedding.
interact_pagereadPerform actions on a recording page (scroll, click, hover, type, press, select, wait, navigate). Actions are performed sequentially and recorded in the video.
list_recordingsreadList all .webm and .gif recordings in the output directory.
record_and_exportwriteAll-in-one: open URL, wait for specified duration, stop recording, auto-export to the right format. Use the
record_pagewriteOpen a URL in a browser and start recording video. Returns a session ID. Call stop_recording when done. Instead of specifying width/height, you can use the
smart_exportread
stop_recordingwriteStop a recording session and save the video as .webm file.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
src/converter.js:21
throw new Error('ffmpeg not found. Install it: sudo apt install ffmpeg (Linux) / brew install ffmpeg (macOS)');
Why it matters. asks for elevated privileges
MEDIUMInventory / provenance · inv.binary · CWE-1104
test-recordings/recording-0dc6354d.webm
recording-0dc6354d.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/7e387b17f6865c58e6de2022141a45d3.webm
7e387b17f6865c58e6de2022141a45d3.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/recording-4f9aea3c.webm
recording-4f9aea3c.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/recording-5c454afb.webm
recording-5c454afb.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, playwright, zod, remotion, @remotion/cli, @remotion/media-utils, react, react-dom
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
docs/demo-cinematic.gif
docs/demo-cinematic.gif
Why it matters. 2274334 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/demo-original.webm
docs/demo-original.webm
Why it matters. 1879356 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/demo-tooltip.gif
docs/demo-tooltip.gif
Why it matters. 2599543 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/demo.gif
docs/demo.gif
Why it matters. 1513515 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/moltbook-demo.gif
docs/moltbook-demo.gif
Why it matters. 2112996 bytes not read
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 69b9ec1f0f48full audit observations/trust-audit/mcp-server/mcpware__pagecast.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0869b9ec1f0f48BLOCKD69first audit
06

Questions

What is the Pagecast MCP server?

Record any browser page as GIF or video via MCP — powered by Playwright + ffmpeg

What tools does Pagecast expose?

9 in total: 6 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Pagecast safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Pagecast need?

No credential environment variables were found in its source, so it appears to need none.

How does Pagecast run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mcpware/pagecast at 0.3.0.

How current is this page?

The grade is for one exact copy of the source (69b9ec1f0f48), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement