Skip to main content
Glama
87,318 servers. Updated
20 Best Browser Automation MCP Servers: compared and ranked, September 2026Ranked from 2,971 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"browser use" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    C
    quality
    B
    maintenance
    Security-focused Firefox browser MCP server for penetration testing, built on Playwright, enabling vulnerability scanning, session manipulation, network inspection, and reconnaissance.
    40
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to control a local Chromium browser via CDP for page snapshots, screenshots, human-like interactions, autonomous crawling, API/GraphQL reconnaissance, authenticated differential testing, and Burp-like intercept, repeater, and intruder workflows with scope enforcement and audit logging.
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables interactive Ghidra reverse-engineering inside an AI client by rendering live decompiler, function browser, and call graph views. Users can click symbols to rename them and follow calls to navigate, all without leaving the conversation.
    10
    71 npm
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Connects AI assistants to AttackForge's Self-Service API with full endpoint coverage, response size optimization, and local caching for efficient use in long conversations.
    11
    -
  • F
    license
    A
    quality
    D
    maintenance
    Enables LLM-powered browser automation and security testing with features like browser management, network monitoring, DOM manipulation, and captcha handling.
    52
    1
    -
  • A
    license
    B
    quality
    F
    maintenance
    A security testing tool that enables automated vulnerability detection including XSS and SQL injection, along with comprehensive browser interaction capabilities for web application penetration testing.
    3
    12
    246 npm
    22
    MIT
  • A
    license
    B
    quality
    C
    maintenance
    Enables deterministic security testing of AI agents that use tools by serving synthetic MCP environments with poisoned data, fake secrets, and privileged actions. Records agent tool calls and evaluates security invariants (e.g., canary leaks, forbidden access, approval binding) without an LLM judge or real systems.
    8
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Read-only observation of a single live URL: parses static HTML to report security posture, forms, links, accessibility signals, and leaks, with described fixes. SSRF-gated and safe, never executes JavaScript.
    93 npm
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to perform security testing on web applications by controlling a Firefox browser with 39 security tools, including injection testing and access control analysis.
    22
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables interacting with HackerOne through the official REST API for managing reports, earnings, and programs, plus browser automation to read disclosed reports, search hacktivity writeups, and view program policies even behind Cloudflare.
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Wraps common web penetration testing tools in a Docker container and exposes them as Claude tools for educational use in controlled lab environments.
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    A Kali Linux MCP server that integrates network security and penetration testing tools like Nmap, Whois, Dig, Ping, Nikto, Hydra, and SQLMap into a Dockerized environment for use with LLMs.
    5 npm
    3
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables secure execution of penetration testing commands on Kali Linux through Server-Sent Events with intelligent command validation, real-time monitoring, and comprehensive audit logging. Designed for authorized security research and penetration testing workflows.
    1
    -