MCP Security Scan Report: @executeautomation/playwright-mcp-server
Scanned by: AgentScore KYA Scanner (https://agentscores.xyz)
Date: 2026-03-30
Package: @executeautomation/playwright-mcp-server@1.0.12
Repository: git+https://github.com/executeautomation/mcp-playwright.git
Licence: MIT
Runtime dependencies: 10
Risk: LOW (Score: 100/100)
No security issues found. This package passed all checks.
Dependency Chain Scan
Scanned 10 runtime dependencies. 4 flagged, 6 clean.
Flagged Dependencies
@playwright/browser-chromium@1.58.2 (LOW, score 95/100)
- [LOW] 'install' script: node install.js
@playwright/browser-firefox@1.58.2 (LOW, score 95/100)
- [LOW] 'install' script: node install.js
@playwright/browser-webkit@1.58.2 (LOW, score 95/100)
- [LOW] 'install' script: node install.js
express@5.2.1 (LOW, score 90/100)
- [MEDIUM] 28 runtime dependencies (high attack surface)
Clean Dependencies
@modelcontextprotocol/sdk@1.29.0, @playwright/test@1.58.2, cors@2.8.6, mcp-evals@2.0.1, playwright@1.58.2, uuid@13.0.0
What We Check
- Install scripts (postinstall/preinstall hooks with network calls or code execution)
- Prompt injection patterns in metadata (15 patterns targeting AI agent manipulation)
- Suspicious URLs (sketchy TLDs, ngrok, webhook.site, raw public IPs)
- Dependency count (attack surface indicator)
- Metadata completeness (repository, licence, description)
This is a static metadata scan. It does not execute code, analyse runtime behaviour, or claim exploit detection. Full methodology: https://agentscores.xyz/docs
Next Steps
This report is free. If you found it useful, we offer:
- Continuous monitoring: Get alerted when your package or its dependencies change risk level
- Full security review: Deeper analysis of your MCP server implementation, tool definitions, and permission model
- Hardening support: Practical fixes for any issues found
Scan any MCP package yourself: https://agentscores.xyz
Questions or feedback: https://agentscores.xyz/contact
Generated by AgentScore KYA Scanner v1.0 on 2026-03-30. AgentScore is building the MCP security dataset.
MCP Security Scan Report: @executeautomation/playwright-mcp-server
Scanned by: AgentScore KYA Scanner (https://agentscores.xyz)
Date: 2026-03-30
Package: @executeautomation/playwright-mcp-server@1.0.12
Repository: git+https://github.com/executeautomation/mcp-playwright.git
Licence: MIT
Runtime dependencies: 10
Risk: LOW (Score: 100/100)
No security issues found. This package passed all checks.
Dependency Chain Scan
Scanned 10 runtime dependencies. 4 flagged, 6 clean.
Flagged Dependencies
@playwright/browser-chromium@1.58.2 (LOW, score 95/100)
@playwright/browser-firefox@1.58.2 (LOW, score 95/100)
@playwright/browser-webkit@1.58.2 (LOW, score 95/100)
express@5.2.1 (LOW, score 90/100)
Clean Dependencies
@modelcontextprotocol/sdk@1.29.0, @playwright/test@1.58.2, cors@2.8.6, mcp-evals@2.0.1, playwright@1.58.2, uuid@13.0.0
What We Check
This is a static metadata scan. It does not execute code, analyse runtime behaviour, or claim exploit detection. Full methodology: https://agentscores.xyz/docs
Next Steps
This report is free. If you found it useful, we offer:
Scan any MCP package yourself: https://agentscores.xyz
Questions or feedback: https://agentscores.xyz/contact
Generated by AgentScore KYA Scanner v1.0 on 2026-03-30. AgentScore is building the MCP security dataset.