This MCP Server Pentest provides automated web vulnerability testing and browser interaction capabilities:
- Test for security vulnerabilities (XSS, SQL injection)
- Capture screenshots (full-page or specific elements)
- Simulate browser interactions (navigation, clicks, form filling, hovering)
- Select options in dropdown menus using selectors or text content
- Execute and monitor custom JavaScript in the browser context
- Test web applications for security and compatibility
Provides automated browser testing capabilities including XSS and SQL injection vulnerability detection, navigation, screenshot capture, and interaction with web elements through Playwright's Firefox integration.
Enables execution of JavaScript code in the browser context to interact with web pages, monitor console logs, and perform dynamic testing operations.
Utilizes npm packages for installation and execution of browser testing components through the npx command.
Supports dependency management and package installation for the server components using Yarn package manager.
Features
- Full browser xss, sql vulnerability automatic detection
- Screenshots of the entire page or specific elements
- Comprehensive network interaction (navigation, clicks, form filling)
- Console log monitoring
- JavaScript execution in the browser context
Installation
Installing
Configuration
The installation process will automatically add the following configuration to your Claude config file:
Components
Tools
broser_url_reflected_xss
Test whether the URL has an XSS vulnerability
browser_url_sql_injection
Test whether the URL has SQL injection vulnerabilities
browser_navigate
Navigate to any URL in the browser
browser_screenshot
Capture screenshots of the entire page or specific elements
browser_click
Click elements on the page using CSS selector
browser_click_text
Click elements on the page by their text content
browser_hover
Hover over elements on the page using CSS selector
browser_hover_text
Hover over elements on the page by their text content
browser_fill
Fill out input fields
browser_select
Select an option in a SELECT element using CSS selector
browser_select_text
Select an option in a SELECT element by its text content
browser_evaluate
Execute JavaScript in the browser console
local-only server
The server can only run on the client's local machine because it depends on local resources.
Tools
A security testing tool that enables automated vulnerability detection including XSS and SQL injection, along with comprehensive browser interaction capabilities for web application penetration testing.
Related Resources
Related MCP Servers
- AsecurityAlicenseAqualityA browser monitoring and interaction tool that enables AI applications to capture and analyze browser data through a Chrome extension, supporting functions like console monitoring, screenshots, DOM analysis, and website auditing.Last updated -14931JavaScriptMIT License
- AsecurityAlicenseAqualityProvides tools for frontend testing including code analysis, test generation, test execution, and React component testing for Jest and Cypress frameworks.Last updated -417TypeScriptMIT License
- AsecurityFlicenseAqualityA tool that allows penetration testing through Kali Linux commands executed via a Multi-Conversation Protocol server, supporting security testing operations like SQL injection and command execution.Last updated -539TypeScript
- -securityAlicense-qualityA comprehensive system that helps organizations track, manage, and respond to security vulnerabilities effectively through features like vulnerability tracking, user management, support tickets, API key management, and SSL certificate management.Last updated -PythonMIT License