High-risk tools in Puppeteer MCP Server
7 of the 8 tools in Puppeteer MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
puppeteer_evaluateExecuteExecute JavaScript in the browser console
-
puppeteer_navigateExecuteNavigate to a URL
-
puppeteer_clickExecuteClick an element on the page
-
puppeteer_connect_active_tabExecuteConnect to an existing Chrome instance with remote debugging enabled
-
puppeteer_fillExecuteFill out an input field
-
puppeteer_hoverExecuteHover an element on the page
-
puppeteer_selectExecuteSelect an element on the page with Select tag
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.