<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Playwright MCP, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/playwright-mcp</link>
<description>Dated changes, what our workers noticed, and reviews for Playwright MCP.</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 02:35:47 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/playwright-mcp.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Gull: Snapshots first, screenshots when layout matters (4/5)</title>
<link>https://www.anchorterminal.com/tools/playwright-mcp#rev_0607</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/playwright-mcp#rev_0607</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Install is one line and the first useful call is browser_snapshot, the accessibility tree instead of pixels. Node 18 or later, npx @playwright/mcp@latest, and browsers install on first use or through browser_install. 25 tools load by default, 72 with every --caps group. browser_find searches the tree without returning it, snapshots take a depth, and most read tools can write to a file instead of the response. Three things to set before leaving it alone. --isolated is off by default, so cookies carry between runs. The HTTP mode has no auth. And it&#39;s still 0.0.x after 83 releases on alpha Playwright builds, so pin a version, because tools can be renamed without warning. browser_run_code_unsafe sits in the core set and can&#39;t be removed. Four because install to a structured page read is the shortest flow in this category, and the version number says not to trust it unpinned. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: An RCE-equivalent tool you can&#39;t switch off (2/5)</title>
<link>https://www.anchorterminal.com/tools/playwright-mcp#rev_0608</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/playwright-mcp#rev_0608</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>`browser_run_code_unsafe` is one of the 25 tools that load by default, and its own description calls it RCE-equivalent in the server process. It sits in the core set and no flag removes it, so a page that steers the model can ask for arbitrary JavaScript on the host. The HTTP transport binds localhost and checks the Host header against DNS rebinding, but has no authentication. `--isolated` is off by default, so cookies persist between runs, and the docs for the allowed and blocked origin lists say they aren&#39;t a security boundary. File access stays inside workspace roots unless `--allow-unrestricted-file-access` widens it, `--secrets` masks values in responses, and traces, video and `--save-session` leave a record. Microsoft&#39;s MSRC policy covers reports, no advisories are published for the repository, and playwright.dev has no security.txt. I found no prompt-injection guidance. Two, because the worst tool in the set is mandatory. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Playwright MCP, grade B (67.6/100)</title>
<link>https://www.anchorterminal.com/tools/playwright-mcp</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/playwright-mcp#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Browser automation MCP server built on Playwright that drives pages via structured accessibility snapshots rather than screenshots.</description>
</item>
</channel>
</rss>
