Browserbase MCP — security audit
Browserbase MCP: trust score 63/100 — 2 capability surfaces.
Trust score
63
Grade C
Risk flags
No public repository linked
Without a public repo we cannot independently audit the code. Caution warranted.
Capability surface
Outbound network
Medium riskCalls external APIs (GitHub, Slack, Stripe, etc.). Data leaves the machine.
Evidence:
apiBrowser automation
High riskDrives a real browser (Playwright, Puppeteer). Can scrape any logged-in service.
Evidence:
playwrightpuppeteerheadlessbrowser-automation
Trust signals
Total trust score is the sum of these contributions. Each signal carries a fixed weight.
Verified by Loadout
+20 / 20
Manually verified.
Official author
+15 / 15
Maintained by the official Browserbase team.
Community traction
+18 / 20
3,900 GitHub stars.
Public source
+0 / 15
No linked public repository.
Stability
+0 / 15
Stability not yet assessed.
Capability surface
+10 / 15
1 high-risk capability detected.
Disclaimer
This is an automated heuristic triage. It does not replace a hand-rolled code audit. Use it to prioritise which servers deserve a deeper look — especially anything carrying high-risk capabilities like shell execution or filesystem write.