# browser_set_storage_state

A write tool on the Playwright MCP server.

Agent View of the PolicyLayer registry record for `browser_set_storage_state`. HTML page: https://policylayer.com/tools/hanato238-playwright-mcp/browser-set-storage-state

## Facts

- Tool: `browser_set_storage_state`
- Server: Playwright (`hanato238/playwright-mcp`) — https://policylayer.com/tools/hanato238-playwright-mcp.md
- Homepage: https://github.com/Hanato238/playwright-mcp
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "browser_set_storage_state",
    "arguments": {}
  }
}
```

## Why browser_set_storage_state is rated Medium

Setting storage state modifies browser data that persists and affects subsequent page behavior. While reversible (storage can be cleared/overwritten), this is a write operation that could be misused to inject malicious data, forge authentication tokens, or manipulate session state. Not destructive (data is not irreversibly deleted), not financial, and not execute (though effects depend on what data is stored).

From the tool's own definition: "Tool name 'browser_set_storage_state' indicates modification of browser storage state (localStorage, sessionStorage, etc.). Empty description limits evidence, but naming pattern aligns with sibling cookie/storage management tools like browser_cookie_set."

## Use case

AI agents use browser_set_storage_state to create or update resources in Playwright, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Playwright environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Playwright:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "browser_set_storage_state": {
      "limits": [
        {
          "counter": "browser_set_storage_state_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Playwright (65)

- `browser_cookie_clear` — Destructive — https://policylayer.com/tools/hanato238-playwright-mcp/browser-cookie-clear.md
- `browser_cookie_delete` — Destructive — https://policylayer.com/tools/hanato238-playwright-mcp/browser-cookie-delete.md
- `browser_localstorage_clear` — Destructive — https://policylayer.com/tools/hanato238-playwright-mcp/browser-localstorage-clear.md
- `browser_localstorage_delete` — Destructive — https://policylayer.com/tools/hanato238-playwright-mcp/browser-localstorage-delete.md
- `browser_sessionstorage_clear` — Destructive — https://policylayer.com/tools/hanato238-playwright-mcp/browser-sessionstorage-clear.md
- `browser_sessionstorage_delete` — Destructive — https://policylayer.com/tools/hanato238-playwright-mcp/browser-sessionstorage-delete.md
- `browser_click` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-click.md
- `browser_close` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-close.md
- `browser_drag` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-drag.md
- `browser_drop` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-drop.md
- `browser_evaluate` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-evaluate.md
- `browser_handle_dialog` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-handle-dialog.md
- `browser_hide_highlight` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-hide-highlight.md
- `browser_hover` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-hover.md
- `browser_mouse_click_xy` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-mouse-click-xy.md
- `browser_mouse_down` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-mouse-down.md
- `browser_mouse_drag_xy` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-mouse-drag-xy.md
- `browser_mouse_move_xy` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-mouse-move-xy.md
- `browser_mouse_up` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-mouse-up.md
- `browser_mouse_wheel` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-mouse-wheel.md
- `browser_navigate` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-navigate.md
- `browser_navigate_back` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-navigate-back.md
- `browser_network_request` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-network-request.md
- `browser_network_state_set` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-network-state-set.md
- `browser_pdf_save` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-pdf-save.md
- `browser_press_key` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-press-key.md
- `browser_resize` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-resize.md
- `browser_resume` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-resume.md
- `browser_route` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-route.md
- `browser_run_code_unsafe` — Execute — https://policylayer.com/tools/hanato238-playwright-mcp/browser-run-code-unsafe.md
- …and 35 more: https://policylayer.com/tools/hanato238-playwright-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=hanato238-playwright-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/hanato238-playwright-mcp
