Browser Automation
The browser tool wraps a Playwright MCP server. Multi-layered security — SSRF guard, DNS-rebinding backstop, input sanitization, JS execution restrictions, audit logging.
npx playwright install chromiumActions
Section titled “Actions”| Action | Args | Purpose |
|---|---|---|
navigate | url | Open a URL |
click | ref | Click an element by accessibility reference |
type | ref, text | Type text into an input |
select_option | ref, value | Select from a dropdown |
hover | ref | Hover an element |
press_key | key | Press a keyboard key |
screenshot | — | Capture the current page as an image |
snapshot | — | Accessibility tree (structured page content) |
evaluate | expression | Execute JS in the page context |
wait | time | Wait for a duration |
tabNew | url? | Open a new tab |
tabClose | — | Close the current tab |
tabSwitch | — | Switch between open tabs |
tabList | — | List open tabs |
goBack / goForward | — | Navigation history |
Security layers
Section titled “Security layers”SSRF + DNS-rebinding
Section titled “SSRF + DNS-rebinding”NavigationGuard before every navigate:
- Address blocklist: RFC 1918 (
10.x,172.16-31.x,192.168.x), loopback (127.x,::1), link-local (169.254.x), IPv6 unique-local (fc00::/7). - Encoding-obfuscation resistant — catches octal, decimal, hex IP encodings.
- Post-navigation DNS backstop — verifies resolved IP didn’t switch to a private range after page load.
- Protocol allowlist —
http:/https:only. - Length caps on hostname, path, and total URL.
Input sanitization
Section titled “Input sanitization”InputGuard before every browser call:
- Element refs — length-capped, shell metacharacters blocked.
- Key names — restricted to a safe character set.
- No raw user input reaches
evaluate()without sanitization.
JS execution restrictions
Section titled “JS execution restrictions”The evaluate action screens for dangerous access patterns — network calls, dynamic code execution, and storage/cookie access — before running. Prefer snapshot / screenshot for read-only inspection when you don’t need to run JS.
Example prompts
Section titled “Example prompts”Open localhost:3000, take a screenshot of the login page, and check if the form is accessibleNavigate to our staging site, fill in the registration form with test data, and verify the success pageOpen the dashboard, click the "Export" button, and verify the CSV download contains the expected columnsSettings
Section titled “Settings”Agent-driven browsing runs through the Playwright MCP server and needs no dedicated CodeBuddy settings — configure the server under codebuddy.mcp.servers like any other MCP integration.
The one related setting controls how CodeBuddy opens plain external URLs (news links, reader):
{ "codebuddy.browserType": "system" }| Value | Behavior |
|---|---|
system | Open in the OS default browser (default) |
simple | Open in a lightweight built-in webview |
reader | Open in the Smart Reader panel |