Skip to main content
Glama
ironessi

browser-firefox-mcp

by ironessi
README.md
# browser-firefox-mcp

Security-focused Firefox browser MCP server for penetration testing agents. Built on Playwright with a Python-native API designed for vulnerability scanning, session manipulation, network inspection, and reconnaissance.

## Features

- **Firefox-first**: Uses Playwright's native Firefox engine for accurate rendering (especially useful for anti-bot detection)
- **Security tooling**: XSS payload injection, form enumeration, DOM analysis, sensitive data leak detection
- **Session management**: Cookie export/inject, token extraction, storage manipulation
- **Network inspection**: Request/response interception and capture via CDP
- **Reconnaissance**: Technology stack fingerprinting, framework detection, metadata extraction
- **MCP stdio transport**: Works with cyberstrikeai, Claude Code, Cursor, and any MCP-compatible client

## Quick Start (Kali Linux)

```bash
git clone https://your-repo/browser-firefox-mcp.git
cd browser-firefox-mcp
uv venv && source .venv/bin/activate
uv pip install -e .
playwright install firefox
python server.py  # or: browser-firefox-mcp
```

## Integration with cyberstrikeai

Add to your `~/.config/cyberstrikeai/config.json` (or equivalent):

```json
{
  "mcp_servers": {
    "firefox-browser": {
      "command": "python",
      "args": ["server.py"],
      "cwd": "/path/to/browser-firefox-mcp"
    }
  }
}
```

The agent will automatically discover tools: `navigate`, `click`, `fill`, `screenshot`,
`inject_payload`, `scan_forms`, `capture_network`, `get_session_info`,
`recon_technology_stack`, etc.

## Architecture

```
┌──────────────────┐     JSON-RPC (stdio)     ┌──────────────────┐
│  cyberstrikeai   │ ◄──────────────────────► │     server.py    │
│   (agent)        │                          │ (MCP stdio)      │
└──────────────────┘                          └────────┬─────────┘
                                                       │
                                          ┌────────────▼─────────┐
                                          │  core/ modules        │
                                          │  engine | page        │
                                          │  security | session   │
                                          │  network | recon      │
                                          └────────────┬─────────┘
                                                       │
                                               ┌───────▼───────┐
                                               │ Firefox (headless) │
                                               └─────────────────┘
```

## License

MIT

TDQS

C2.6/5.0

Scored across 40 tools

Disambiguation3/5

Several tools overlap in purpose, such as inject_xss_payload vs inject_payload and find_reflection vs find_sensitive_data, though descriptions help distinguish them. Most tools are distinct, but the boundaries are not always crystal clear.

Naming Consistency3/5

Naming is mostly verb_noun with underscores, but there are deviations like 'dom_analysis' and 'security_headers_check' that reverse the pattern, and 'new_context' is not a clear verb. Mixed conventions remain readable but lack strict consistency.

Tool Count2/5

With 40 tools, the server exceeds the recommended range for a focused MCP server. Many tools are highly specialized (e.g., network capture, security scanning) and contribute to a heavy surface, making it feel over-scoped.

Completeness4/5

The toolset covers a wide range of browser automation and security testing operations, including navigation, interaction, cookies, storage, network capture, and security checks. Minor gaps like hover/focus or tab management exist, but overall it's comprehensive for its domain.

Maintenance

ActivitySlowing
ResponsivenessNo issues