MCP server that enables browser automation and web interaction using Playwright
This Playwright MCP server defines 7 tools with explicit schemas and descriptions visible in main.ts. However, the server has significant gaps in parameter documentation, lacks output schema specifications, provides minimal error guidance, and omits critical security considerations. Descriptions are present but generic (averaging ~50-60 chars). Parameter descriptions exist but are sparse (e.g., 'CSS selector for element to click' lacks guidance on what happens if selector doesn't match). Most parameters lack type constraints (enums, ranges, patterns). Error handling is minimal, tools catch exceptions and return isError: true with a message, but provide no recovery guidance or categorization. No tool annotations (readOnlyHint/destructiveHint/idempotentHint) are declared, despite clear risk differences (playwright_click is WRITE, playwright_navigate is READ_ONLY). Output schemas are not documented, callers cannot predict structure of responses. Security issues: playwright_evaluate accepts arbitrary JavaScript, raising injection risk; no scoping, permission gates, or audit trail. Overall, this is competent but baseline quality, suitable for single-user development but not production agent deployment.
Click an element on the page
Execute JavaScript in the browser console
Fill out an input field
Hover an element on the page
Navigate to a URL
Take a screenshot of the current page or a specific element
Select an element on the page with Select tag
Output schemas are not documented for any tool. Callers cannot predict response structure, requiring agents to infer field names from examples or trial-and-error. Per pattern:tool, tools must document return types.
playwright_evaluate accepts arbitrary JavaScript with no input validation, sandboxing, or scope declaration. This is an arbitrary code execution vector. Per pattern:tool-gateway and pattern:scope-declaration, sensitive operations must declare permissions and validate inputs.
Tool annotations are absent. Tools marked WRITE (click, fill, select, evaluate) lack destructiveHint; READ_ONLY tools (navigate, screenshot, hover) lack readOnlyHint. Per current MCP spec (2026-07-28), tool annotations guide agent decision-making and risk awareness.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 56 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 38 | - | v1 |
Parameter descriptions are sparse or missing context. Examples: 'CSS selector for element to click' does not explain what happens if selector doesn't match; 'value' in playwright_fill lacks format/length constraints; 'script' in playwright_evaluate lacks safety guidance. Per pattern:tool-description, every parameter needs actionable guidance.
Error handling provides no recovery guidance. Caught exceptions return isError: true with a message, but do not categorize errors as retryable/user-fixable/fatal, nor suggest next steps. Per pattern:recovery-guide, error responses must tell agents what to do next.
No idempotency guarantees or documentation. Tools like playwright_click, playwright_fill do not declare whether repeated calls with identical parameters produce the same result. Per pattern:idempotent-operation, agents rely on idempotency for safe retry logic.
No pagination or result-limiting mechanism. Tools that could return large results (e.g., playwright_evaluate returning console logs) lack limit/page parameters. Per pattern:paginated-result and mxe:enforce-result-limits, large results blow context windows.
No audit trail, permission gates, or scope declarations. Tools operate on global browser state with no user/agent identity checks, rate limiting, or logging of who called what. Per pattern:audit-trail and pattern:scope-declaration, production tools must track and gate access.