browser-firefox-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@browser-firefox-mcpEnumerate forms and inject XSS payloads on http://testphp.vulnweb.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
browser-firefox-mcp
Security-focused Firefox browser MCP server for penetration testing agents. Built on Playwright with a Python-native API designed for vulnerability scanning, session manipulation, network inspection, and reconnaissance.
Features
Firefox-first: Uses Playwright's native Firefox engine for accurate rendering (especially useful for anti-bot detection)
Security tooling: XSS payload injection, form enumeration, DOM analysis, sensitive data leak detection
Session management: Cookie export/inject, token extraction, storage manipulation
Network inspection: Request/response interception and capture via CDP
Reconnaissance: Technology stack fingerprinting, framework detection, metadata extraction
MCP stdio transport: Works with cyberstrikeai, Claude Code, Cursor, and any MCP-compatible client
Related MCP server: mcp-browser-automation
Quick Start (Kali Linux)
git clone https://your-repo/browser-firefox-mcp.git
cd browser-firefox-mcp
uv venv && source .venv/bin/activate
uv pip install -e .
playwright install firefox
python server.py # or: browser-firefox-mcpIntegration with cyberstrikeai
Add to your ~/.config/cyberstrikeai/config.json (or equivalent):
{
"mcp_servers": {
"firefox-browser": {
"command": "python",
"args": ["server.py"],
"cwd": "/path/to/browser-firefox-mcp"
}
}
}The agent will automatically discover tools: navigate, click, fill, screenshot,
inject_payload, scan_forms, capture_network, get_session_info,
recon_technology_stack, etc.
Architecture
┌──────────────────┐ JSON-RPC (stdio) ┌──────────────────┐
│ cyberstrikeai │ ◄──────────────────────► │ server.py │
│ (agent) │ │ (MCP stdio) │
└──────────────────┘ └────────┬─────────┘
│
┌────────────▼─────────┐
│ core/ modules │
│ engine | page │
│ security | session │
│ network | recon │
└────────────┬─────────┘
│
┌───────▼───────┐
│ Firefox (headless) │
└─────────────────┘License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityDmaintenanceA universal browser automation MCP server using Playwright, enabling programmatic control of Chrome with 63 tools for navigation, interaction, media control, and CDP-based diagnostics.63122MIT
- FlicenseBqualityBmaintenanceAn MCP server for generic browser automation using Playwright. Enables MCP clients to navigate pages, inspect elements, execute JavaScript, capture screenshots, and monitor console logs and network traffic via a headless Chromium instance.7
- AlicenseNot gradedqualityCmaintenanceAn MCP server that provides structured control of a Playwright browser for QA, scraping, diagnostics, and reproducible browser workflows.7,623MIT
- FlicenseNot gradedqualityCmaintenanceA policy-aware Meta-MCP server that orchestrates Playwright and Chrome DevTools for secure, high-level browser automation with origin whitelists and credential redaction.
Related MCP Connectors
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Browser MCP for logged-in tasks. Uses your Chrome — credentials stay local. Zero-token replay.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ironessi/browser-firefox-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server