Atlas / MCP servers / mozilla / Firefox DevTools

Firefox DevToolsSAFE

mcp/mozilla/firefox-devtools-1

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
71 40r · 24w · 7d
Transport
stdio
License
NOASSERTION
Stars
456
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@mozilla/firefox-devtools-mcp) [](https://github.com/mozilla/firefox-devtools-mcp/actions/workflows/ci.yml) [](https://codecov.io/gh/mozilla/firefox-devtools-mcp) [](LICENSE-MIT) [](LICENSE-APACHE)

Model Context Protocol server for automating Firefox via WebDriver BiDi (through Selenium WebDriver). Works with Claude Code, Claude Desktop, Cursor, Cline and other MCP clients.

Repository: https://github.com/mozilla/firefox-devtools-mcp

Note: This MCP server requires a local Firefox browser installation and cannot run on cloud hosting services like glama.ai. Use npx @mozilla/firefox-devtools-mcp@latest to run locally, or use Docker with the provided Dockerfile.

Security

Browser MCP servers carry inherent risks. A few key practices:

  • Use a dedicated Firefox profile. Never run the server against your regular profile — the agent has access to whatever the browser can reach, including cookies and saved sessions.
  • Be cautious about which sites you visit. Pages can return content designed to manipulate the agent (prompt injection). Stick to sites you control or trust.
  • Enable only the tool modules you need. The default basic preset already includes evaluate_script; --tool-preset slim drops it. Higher presets such as --tool-preset developer (debugging, network, console, profiler) and --tool-preset mozilla (privileged cont
Read from source at commit 7134318d871dOBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add firefox-devtools-mcp -- npx -y @mozilla/[email protected]
03

Exposed tools (71)

40 read · 24 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
accept_dialogreadAccept browser dialog. Provide promptText for prompts.
clear_console_messagesdestructiveClear collected console messages.
clear_downloadsdestructiveClear the tracked downloads buffer.
clear_snapshotdestructiveClear snapshot UIDs. Usually not needed.
click_by_uidwriteClick element by UID. Set dblClick for double-click.
close_firefox_sessionreadEnds the browser session. If the server connected to your existing Firefox,
close_pagereadClose tab by index.
consoledestructiveRead and clear console messages.
debuggingwriteInspect scripts and set logpoints (Firefox 153+).
dismiss_dialogreadDismiss browser dialog.
downloadsreadMonitor and manage file downloads.
drag_by_uid_to_uidreadDrag element to another (HTML5 drag events).
enable_debuggerwriteEnable the JS debugger for the current page. Required before set_logpoint works. Requires Firefox 153+.
evaluate_privileged_scriptwriteExecute JS function in a privileged (chrome) browsing context. Requires MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 env var. Get context ids from list_privileged_contexts.
evaluate_scriptwriteRun a JS function in the page and return its result. Prefer this for targeted reads (a value, text, computed style, whether an element exists) instead of a full take_snapshot. Use the UID interaction tools for clicking, typing, and filling.
fill_by_uidreadFill text input/textarea by UID.
fill_form_by_uidreadFill multiple form fields at once.
get_firefox_inforeadGet information about the current Firefox instance configuration, including binary path, environment variables, and output file location.
get_firefox_outputreadRetrieve Firefox output (stdout/stderr including MOZ_LOG, warnings, crashes, stack traces). Returns recent output from the capture file. Use filters to focus on specific content.
get_firefox_prefsreadGet Firefox preference values via a privileged API. Requires MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 env var.
get_logpoint_resultswriteGet the results collected by a logpoint since it was set.
get_network_requestreadGet request details by ID, including the response body (and request body when present). Large text bodies are truncated inline; binary bodies are summarized. URL lookup as fallback.
get_page_textreadGet the visible text of the page (document.body.innerText). Caps at maxLength (default 20000 chars); saveTo saves the full text to a file.
get_script_sourcereadGet the source code of a JavaScript file loaded in the page. Requires enable_debugger to have been called.
hover_by_uidreadHover over element by UID.
inputreadInteract with the page via UID-based clicks, typing, key presses, drag, and uploads.
install_extensionwriteInstall a Firefox extension using WebDriver BiDi webExtension.install command. Supports installing from archive (.xpi/.zip), base64-encoded data, or unpacked directory.
launchwriteRestart Firefox under a different launch configuration.
list_console_messagesreadList console messages, filterable by level, time, text, source. Caps at limit (default 50); saveTo saves all matches to a file.
list_downloadsreadList downloads tracked since startup, including status and saved file path.
list_network_requestsreadList network requests, returning IDs for get_network_request. Filter by url/method/status; caps at limit (default 50); saveTo saves all matches to a file.
list_pagesreadList open tabs (index, title, URL). Selected tab is marked.
list_privileged_contextsreadList privileged (privileged) browsing contexts. Requires MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 env var. Use restart_firefox with env parameter to enable.
list_scriptsreadList all JavaScript files currently loaded in the page. Requires enable_debugger to have been called.
managementreadInspect Firefox options and logs, and close the browser.
navigate_historyreadNavigate history back/forward. UIDs become stale.
navigate_pagereadNavigate selected tab to URL.
networkreadList and inspect network requests, and control the HTTP cache.
new_pagereadOpen new tab at URL. Returns tab index.
pagesreadOpen, navigate, select, and close pages.
prefswriteGet and set Firefox preferences.
press_keywritePress a single key, optionally with modifiers, to submit, dismiss, navigate or trigger a shortcut. Not for entering text: use fill_by_uid instead.
privilegedreadAccess privileged (
profilerwriteStart, stop, and query the performance profiler.
profiler_is_activereadCheck whether the Firefox profiler is currently recording.
profiler_startwriteStart the Firefox profiler. Provide either a preset name or explicit recording options (entries, interval, features, threads). Cannot combine both. Valid presets: ${VALID_PRESETS.join(
profiler_stopwriteStop the Firefox profiler and save the recorded profile to a file in the downloads directory. Returns the path to the saved file, or null when nothing was saved.
remove_logpointdestructiveRemove a previously set logpoint.
resolve_uid_to_selectorreadResolve UID to CSS selector. Fails if the element is gone.
restart_firefoxwriteRestart Firefox with different configuration. Allows changing binary path, environment variables, and other options. All current tabs will be closed.
screencastreadRecord screencasts of the page viewport (Firefox 154+).
screencast_startwriteStart recording a screencast (video) of the current page viewport, saving the output to a file in the downloads directory. Returns a screencast id to pass to screencast_stop. Multiple recordings can run at once.
screencast_stopwriteStop an in-progress screencast recording started with screencast_start and finalize the video file. Returns the path to the saved file.
screenshotreadCapture screenshots of the page or specific elements.
screenshot_by_uidreadCapture element screenshot by UID as base64 PNG.
screenshot_pagewriteCapture viewport screenshot as base64 PNG. Set fullPage for the whole scrollable document.
scriptreadEvaluate arbitrary JavaScript in the page context.
select_pagereadSelect active tab by index, URL, or title. Index takes precedence.
select_privileged_contextwriteSelect a privileged browsing context by ID and set WebDriver Classic context to
set_download_behaviorwriteControl how downloads are handled: allow (save to a destination folder), deny (cancel), or reset to default. Avoids the native save-file dialog. Requires a recent Firefox.
set_firefox_prefswriteSet Firefox preferences at runtime a privileged API. Requires MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 env var.
set_logpointwriteSet a logpoint at a specific location. When execution reaches that line, the expression is evaluated and the result is stored without pausing. Use get_logpoint_results to retrieve collected values. Requires enable_debugger to have been called.
set_network_cachewriteControl the HTTP cache. Use behavior=
set_viewport_sizewriteSet viewport dimensions in pixels.
snapshotreadCapture accessibility/DOM snapshots and resolve UIDs.
take_snapshotreadCapture DOM snapshot with stable UIDs. A UID stays valid across snapshots until its element is removed or the page navigates. Output caps at maxLines (default 100); scope with selector or dump the full tree with saveTo.
type_textreadType text key by key into the focused element, optionally followed by a key such as Enter. Use fill_by_uid to set the value of a known input; use this for elements that only react to real typing, such as autocomplete fields and rich text editors.
uninstall_extensiondestructiveUninstall a Firefox extension using WebDriver BiDi webExtension.uninstall command. Requires the extension ID returned by install_extension or obtained from list_extensions.
upload_file_by_uidwriteUpload file to file input by UID.
utilitiesreadHandle dialogs, history navigation, and viewport sizing.
webextensiondestructiveInstall and uninstall web extensions.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (4 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_console_messages, clear_downloads, clear_snapshot, console, remove_logpoint, uninstall_extension, webextension
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.codecov.yml
.codecov.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/utils/paths.ts:42
const hash = createHash('sha1').update(firefoxPath).digest('hex').slice(0, 8);
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/utils/paths.test.ts:48
const hash = createHash('sha1').update(binaryPath).digest('hex').slice(0, 8);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/firefox/events/console.ts:7
import { logDebug } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/firefox/events/debugging.ts:7
import { logDebug } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/firefox/events/downloads.ts:6
import { logDebug } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/firefox/events/network.ts:7
import { logDebug } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/firefox/snapshot/manager.ts:11
import { nativeToLocalValue } from '../../utils/local-value.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
webdriver-bidi-protocol
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SECURITY.md:60
Connects to an already-running Firefox instance instead of launching a fresh one. If that instance is your regular browser profile, the agent has access to your cookies, saved passwords, active sessio
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
SECURITY.md:9
Prompt injection is an attack where malicious content in the environment manipulates an AI agent into taking unintended actions. In browser automation, this means a page's visible text, hidden HTML el
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha 7134318d871dfull audit observations/trust-audit/mcp-server/mozilla__firefox-devtools-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-037134318d871dSAFEB89first audit
06

Questions

What is the Firefox DevTools MCP server?

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

What tools does Firefox DevTools expose?

71 in total: 40 read-only, 24 that write, and 7 that can delete or overwrite (clear_console_messages, clear_downloads, clear_snapshot, console, remove_logpoint). Every one is listed on this page with its risk.

Is Firefox DevTools safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Firefox DevTools need?

It reads FIREFOX_MCP_TEST_NEWKEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Firefox DevTools run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mozilla/firefox-devtools-mcp at 0.10.4.

How current is this page?

The grade is for one exact copy of the source (7134318d871d), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement