High-risk tools in Playwright
17 of the 25 tools in Playwright are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
browser_clickExecuteClick an element on a web page
-
browser_closeExecuteClose the browser instance
-
browser_dragExecuteDrag an element to another location
-
browser_file_uploadExecuteUpload a local file to a web page
-
browser_handle_dialogExecuteHandle a browser dialog
-
browser_hoverExecuteHover over an element on the page
-
browser_installExecuteInstall the browser binary
-
browser_navigateExecuteNavigate to a URL in the browser
-
browser_navigate_backExecuteNavigate back in browser history
-
browser_navigate_forwardExecuteNavigate forward in browser history
-
browser_press_keyExecutePress a keyboard key or combination
-
browser_resizeExecuteResize the browser window
-
browser_select_optionExecuteSelect an option from a dropdown
-
browser_tab_closeExecuteClose a specific browser tab
-
browser_tab_newExecuteOpen a new browser tab
-
browser_tab_selectExecuteSwitch to a specific browser tab
-
browser_typeExecuteType text into an input field
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.