Skip to content

Free MCP security scan report for @executeautomation/playwright-mcp-server #211

Description

@Thezenmonster

MCP Security Scan Report: @executeautomation/playwright-mcp-server

Scanned by: AgentScore KYA Scanner (https://agentscores.xyz)
Date: 2026-03-30
Package: @executeautomation/playwright-mcp-server@1.0.12
Repository: git+https://github.com/executeautomation/mcp-playwright.git
Licence: MIT
Runtime dependencies: 10


Risk: LOW (Score: 100/100)

No security issues found. This package passed all checks.


Dependency Chain Scan

Scanned 10 runtime dependencies. 4 flagged, 6 clean.

Flagged Dependencies

@playwright/browser-chromium@1.58.2 (LOW, score 95/100)

  • [LOW] 'install' script: node install.js

@playwright/browser-firefox@1.58.2 (LOW, score 95/100)

  • [LOW] 'install' script: node install.js

@playwright/browser-webkit@1.58.2 (LOW, score 95/100)

  • [LOW] 'install' script: node install.js

express@5.2.1 (LOW, score 90/100)

  • [MEDIUM] 28 runtime dependencies (high attack surface)

Clean Dependencies

@modelcontextprotocol/sdk@1.29.0, @playwright/test@1.58.2, cors@2.8.6, mcp-evals@2.0.1, playwright@1.58.2, uuid@13.0.0


What We Check

  • Install scripts (postinstall/preinstall hooks with network calls or code execution)
  • Prompt injection patterns in metadata (15 patterns targeting AI agent manipulation)
  • Suspicious URLs (sketchy TLDs, ngrok, webhook.site, raw public IPs)
  • Dependency count (attack surface indicator)
  • Metadata completeness (repository, licence, description)

This is a static metadata scan. It does not execute code, analyse runtime behaviour, or claim exploit detection. Full methodology: https://agentscores.xyz/docs


Next Steps

This report is free. If you found it useful, we offer:

  • Continuous monitoring: Get alerted when your package or its dependencies change risk level
  • Full security review: Deeper analysis of your MCP server implementation, tool definitions, and permission model
  • Hardening support: Practical fixes for any issues found

Scan any MCP package yourself: https://agentscores.xyz
Questions or feedback: https://agentscores.xyz/contact


Generated by AgentScore KYA Scanner v1.0 on 2026-03-30. AgentScore is building the MCP security dataset.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions