Skip to content

Browser Automation

The browser tool wraps a Playwright MCP server. Multi-layered security — SSRF guard, DNS-rebinding backstop, input sanitization, JS execution restrictions, audit logging.

Terminal window
npx playwright install chromium
ActionArgsPurpose
navigateurlOpen a URL
clickrefClick an element by accessibility reference
typeref, textType text into an input
select_optionref, valueSelect from a dropdown
hoverrefHover an element
press_keykeyPress a keyboard key
screenshot—Capture the current page as an image
snapshot—Accessibility tree (structured page content)
evaluateexpressionExecute JS in the page context
waittimeWait for a duration
tabNewurl?Open a new tab
tabClose—Close the current tab
tabSwitch—Switch between open tabs
tabList—List open tabs
goBack / goForward—Navigation history

NavigationGuard before every navigate:

  • Address blocklist: RFC 1918 (10.x, 172.16-31.x, 192.168.x), loopback (127.x, ::1), link-local (169.254.x), IPv6 unique-local (fc00::/7).
  • Encoding-obfuscation resistant — catches octal, decimal, hex IP encodings.
  • Post-navigation DNS backstop — verifies resolved IP didn’t switch to a private range after page load.
  • Protocol allowlist — http: / https: only.
  • Length caps on hostname, path, and total URL.

InputGuard before every browser call:

  • Element refs — length-capped, shell metacharacters blocked.
  • Key names — restricted to a safe character set.
  • No raw user input reaches evaluate() without sanitization.

The evaluate action screens for dangerous access patterns — network calls, dynamic code execution, and storage/cookie access — before running. Prefer snapshot / screenshot for read-only inspection when you don’t need to run JS.

Open localhost:3000, take a screenshot of the login page, and check if the form is accessible
Navigate to our staging site, fill in the registration form with test data, and verify the success page
Open the dashboard, click the "Export" button, and verify the CSV download contains the expected columns

Agent-driven browsing runs through the Playwright MCP server and needs no dedicated CodeBuddy settings — configure the server under codebuddy.mcp.servers like any other MCP integration.

The one related setting controls how CodeBuddy opens plain external URLs (news links, reader):

{ "codebuddy.browserType": "system" }
ValueBehavior
systemOpen in the OS default browser (default)
simpleOpen in a lightweight built-in webview
readerOpen in the Smart Reader panel
  • Security — SSRF and DNS-rebinding guards
  • Tools — the browser tool in the broader tool list