| FMRS | 59 / 100 · C | 78 / 100 · B | 76 / 100 · B |
| Reliability | 10 / 20 | 13 / 20 | 13 / 20 |
|---|
| Security and permissions | 9 / 20 | 12 / 20 | 12 / 20 |
|---|
| Maintenance | 11 / 20 | 18 / 20 | 17 / 20 |
|---|
| Documentation | 15 / 20 | 18 / 20 | 17 / 20 |
|---|
| Setup experience | 14 / 20 | 17 / 20 | 17 / 20 |
| Best for | - Developers who need an AI agent to carry out a continuous JavaScript reverse-engineering workflow.
- Analysis tasks requiring a headed browser, persistent login state, and replayable local artifacts.
- Research involving relationships among scripts, breakpoints, network traffic, and WebSockets.
| - Scenarios where an AI assistant needs to actually drive a browser to complete a task
- Web automation testing and end-to-end verification
| - Frontend developers who want AI-assisted web debugging and performance analysis
- Scenarios that need browser automation and performance diagnostics in the same tool
|
| Not for | - Generic browsing or simple automation that does not require reverse-engineering capabilities.
- Users seeking a general-purpose scraping framework or a guarantee of bypassing every site defense.
- Sensitive environments where the MCP client must not access browser content or host files.
| - Simple static-text scraping (a lightweight scraper is a better fit)
- Environments sensitive to browser resource usage that can't run a full browser engine
| - Cases that only need to scrape page text without performance analysis or complex interaction (a lighter scraping tool is a better fit)
|
| Required permissions | - It can inspect, debug, and modify data in the browser.
- evaluate_script.localFilePath and outputFile/filePath parameters can make the MCP process read or write host files.
- Without --allowedRoots, local-file access is unrestricted; the option can constrain permitted directories.
- The default profile persists cookies and localStorage; --isolated uses a temporary profile.
| - Requires installing and running a browser engine (Chromium/Firefox/WebKit) locally or on a server
- browser_navigate can visit any URL; browser_evaluate can run arbitrary JavaScript in the page context
| - Requires a local Chrome browser instance to run
- navigate_page can visit any URL; type_text/fill_form and similar tools can enter arbitrary content into the page
|
| Risks and side effects | - Browser contents are exposed to the MCP client; do not use it on pages containing sensitive information.
- Unrestricted local-file access may expose or modify host files.
- Verbose debugging logs may reveal pages, cookies, scripts, or credentials; the README advises against DEBUG=* .
- With --cloak, first launch may silently download about 200 MB, and its profile is physically separate from the default profile.
| - browser_evaluate executing arbitrary scripts carries risk if a malicious page is visited — restrict to trusted sites or an isolated environment
- Long-running browser instances consume significant memory and CPU
| - Browser automation tools can access and manipulate the content of open pages — use only in a trusted development/test environment
- performance_start_trace and similar tracing tools continuously record browser activity — avoid leaving them running on pages containing sensitive information
|
| Supported clients | Claude Code, Cursor, VS Code Copilot, Codex | Claude Desktop, Claude Code, VS Code, Cursor, Windsurf, JetBrains, Zed, Cline, Amp, Kiro, LM Studio, Antigravity, Goose | Claude Code, VS Code, Cursor, Windsurf, JetBrains, Cline, Amp, Kiro, Antigravity |
| Tools | 24 | 10 | 22 |