microsoft/playwright-mcp
Playwright MCP server
Top heuristic: Write actions detected without obvious tool safety annotations.
Public MCP scan radar
A no-execution snapshot of popular public MCP repos across browser automation, DevTools, GitHub, database, cloud, Notion, Atlassian, and browser-control surfaces. Scores are heuristic triage signals, not confirmed vulnerabilities or certifications.
How to read this
The scanner fetched public GitHub metadata plus a limited set of raw text files from each repo on June 20, 2026 Asia/Shanghai time. It looked for MCP surfaces, remote transports, write actions, credentials, auth gates, redaction, tests, and CI.
A low score means the selected files produced more review signals. It may also miss tests or controls that live outside the fetched slice, so paid work still starts with scope confirmation and fresh validation.
Radar snapshot
Playwright MCP server
Top heuristic: Write actions detected without obvious tool safety annotations.
Chrome DevTools for coding agents
Top heuristic: Remote listener needs an explicit exposure policy.
GitHub's official MCP Server
Top heuristic: Remote listener needs an explicit exposure policy.
MCP Toolbox for Databases
Top heuristic: No obvious tests found in the fetched slice.
Open source MCP Servers for AWS
Top heuristic: Credential signals detected without redaction signals in the fetched slice.
Official Notion MCP Server
Top heuristic: Remote listener needs an explicit exposure policy.
MCP server for Atlassian tools
Top heuristic: No obvious tests found in the fetched slice.
Browser-control MCP server
Top heuristic: Remote listener detected without nearby auth or permission signals.
Convert a signal