Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"puppeteer-core": {
"args": [
"-y",
"puppeteer-core"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Puppeteer is a JavaScript library which provides a high-level API to control > DevTools Protocol or WebDriver BiDi. > Puppeteer runs in the headless (no visible UI) by default
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y 'puppeteer-core' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
Malicious code in puppeteer-core (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: ghsa-malware (280757b24c4ec5428a205e302200508a0438aa8f51e0a6ad95dbd3728f6a4db1) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in browser
🔥 Official Firecrawl MCP Server - Adds powerful web scraping and search to Cursor, Claude and any other LLM clients.
MCP server for Firecrawl — search, scrape, and interact with the web. Supports both cloud and self-hosted instances. Features include web search, scraping, page interaction, batch processing, and LLM-powered content analysis.
The Apify MCP server enables your AI agents to extract data from social media, search engines, maps, e-commerce sites, or any other website using thousands of ready-made scrapers, crawlers, and automation tools available on the Apify Store.
Multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval — skill-guided workflows, no API keys.
MCP Security Weekly
Get CVE alerts and security updates for Puppeteer Core and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.