REPOSITORY EVIDENCE / INDEXABLE REPORT

microsoft/playwright-mcp — MCP & Agent Security Evidence Report

MCP client configuration, build-time command execution, CI/CD and dependency evidence were observed in this selected bounded review. Evidence observations are review signals, not a safe/unsafe verdict.

Is microsoft/playwright-mcp safe to run?

ShadowMCP does not issue a safe/unsafe verdict. This report records bounded evidence tied to a specific commit so reviewers can identify what deserves inspection before use.

Scan identity

Report schemashadowmcp.repo-evidence.v9
Scannershadowmcp.web-repo-scan.v22 semantics
Scan completed2026-09-24T08:16:00.000Z
Repository branchmain
Scanned commitf1257a5a67aff872f947fae274759f7d54853862
Indexation gateIndexable quality gate passed.

Evidence summary

Review priority
Priority review

This is a triage priority, not a repository risk rating.

The repository is Microsoft's Playwright MCP server and has substantial developer adoption. The bounded review observed MCP client configuration examples, child-process execution in repository tooling, GitHub automation and explicit Playwright/MCP SDK dependency declarations.

Evidence categories

MCP configuration

Found

Selected configuration evidence was observed. This does not establish how any user's client is configured.

  • README.mdmcpServers configuration examples for Playwright

Shell / command execution

Found

Selected repository-tooling execution evidence was observed. This does not prove a vulnerability or unsafe operation.

  • roll.jsexecSync imported from child_process for repository roll tooling

CI/CD automation

Found

Repository-level GitHub workflow automation is present in the selected scope.

  • .github/workflows/GitHub Actions workflow directory observed
  • .github/dependabot.ymldependency update automation configuration

Supply-chain / dependencies

Found

Selected package dependency declarations were observed; this is not a complete dependency audit.

  • package.jsonPlaywright runtime packages and @modelcontextprotocol/sdk dev dependency declared

Scope and limitations

Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.

  • Public, selected and bounded repository evidence only.
  • FOUND means evidence observed, not risk or malicious behavior proven.
  • Search matches were reviewed against immutable commit f1257a5a67aff872f947fae274759f7d54853862.
  • No repository clone or target-code execution.
  • No secret/token values are included.
  • No CVE or package-reputation lookup.
  • No numeric security score and no safe/unsafe verdict.

Repository context

Trust/community metadata is descriptive context only; it is not a security guarantee.

Repository age / activitycreated 2025-03-21 · active through September 2026
Community signalsstars 37,529 · forks 3,192 · open issues 6
OwnershipOrganization · microsoft
LicenseApache-2.0
Repository statearchived NO · fork NO · default branch main

Continue the review