by mozilla
Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging Protocol
# Add to your Claude Code skills
git clone https://github.com/mozilla/firefox-devtools-mcpGuides for using ai agents skills like firefox-devtools-mcp.
Last scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server: Middleware bypass via repeated slashes in serveStatic",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Large numeric range defeats documented `max` DoS protection",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "express-rate-limit: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to path traversal via percent-encoded dot segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono missing validation of cookie name on write path in setCookie()",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "qs: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tmp: tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-05-30T15:45:15.186Z",
"npmAuditRan": true,
"pipAuditRan": true
}firefox-devtools-mcp is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by mozilla. Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging Protocol. It has 371 GitHub stars.
firefox-devtools-mcp returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/mozilla/firefox-devtools-mcp" and add it to your Claude Code skills directory (see the Installation section above).
firefox-devtools-mcp is primarily written in TypeScript. It is open-source under mozilla on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh firefox-devtools-mcp against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Model Context Protocol server for automating Firefox via WebDriver BiDi (through Selenium WebDriver). Works with Claude Code, Claude Desktop, Cursor, Cline and other MCP clients.
Repository: https://github.com/mozilla/firefox-devtools-mcp
Note: This MCP server requires a local Firefox browser installation and cannot run on cloud hosting services like glama.ai. Use
npx @mozilla/firefox-devtools-mcp@latestto run locally, or use Docker with the provided Dockerfile.
Browser MCP servers carry inherent risks. A few key practices:
basic preset already includes evaluate_script; --tool-preset slim drops it. Higher presets such as --tool-preset developer (debugging, network, console, profiler) and --tool-preset mozilla (privileged context) expand what the agent can do further.See SECURITY.md for a full breakdown of risks and how to report vulnerabilities.
--firefox-path)Recommended: use npx so you run the latest published version from npm.
claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest
# Headless + viewport via args
claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest -- --headless --viewport 1280x720
# Or via environment variables
claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest \
--env START_URL=https://example.com \
--env FIREFOX_HEADLESS=true
codex mcp add firefox-devtools -- npx @mozilla/firefox-devtools-mcp@latest
# Headless + viewport via args
codex mcp add firefox-devtools -- \
npx @mozilla/firefox-devtools-mcp@latest -- --headless --viewport 1280x720
# Or via environment variables
codex mcp add firefox-devtools \
--env START_URL=https://example.com \
--env FIREFOX_HEADLESS=true \
-- npx @mozilla/firefox-devtools-mcp@latest
Add to Claude Code’s mcp_settings.json:
{
"mcpServers": {
"firefox-devtools": {
"command": "npx",
"args": ["-y", "@mozilla/firefox-devtools-mcp@latest", "--headless", "--viewport", "1280x720"],
"env": {
"START_URL": "about:blank"
}
}
}
}
Add to ~/.codex/config.toml:
[mcp_servers.firefox-devtools]
command = "npx"
args = ["-y", "@mozilla/firefox-devtools-mcp@latest", "--headless", "--viewport", "1280x720"]
[mcp_servers.firefox-devtools.env]
START_URL = "about:blank"
npm run setup
# Choose Claude Code; the script saves JSON to the right path
npx @modelcontextprotocol/inspector npx @mozilla/firefox-devtools-mcp@latest --start-url https://example.com --headless
Then call tools like:
list_pages, select_page, navigate_pagetake_snapshot then click_by_uid / fill_by_uidlist_network_requests (always‑on capture), get_network_requestlist_downloads (always‑on capture), set_download_behaviorscreenshot_page, list_console_messagesYou can pass flags or environment variables (names on the right):
--firefox-path — absolute path to Firefox binary--headless — run without UI (FIREFOX_HEADLESS=true)--viewport 1280x720 — initial window size--profile-path — use a specific Firefox profile--firefox-arg — extra Firefox arguments (repeatable)--start-url — open this URL on start (START_URL)--accept-insecure-certs — ignore TLS errors (ACCEPT_INSECURE_CERTS=true)--connect-existing — attach to an already-running Firefox instead of launching a new one (CONNECT_EXISTING=true)--marionette-port — Marionette port for connect-existing mode, default 2828 (MARIONETTE_PORT)--pref name=value — set Firefox preference at startup via moz:firefoxOptions (repeatable)--tool-preset — select which tool modules to enable: slim, basic (default), developer, mozilla, or all. See Tool modules and presets. (TOOL_PRESET)--tools — explicit list of tool modules to enable, overriding --tool-preset entirely (e.g. --tools pages network script). See Tool modules and presets.--enable-script — deprecated, use --tool-preset developer or --tools ... script debugging. Selects the developer tool preset. (ENABLE_SCRIPT=true)--enable-privileged-context — deprecated, use --tool-preset mozilla or --tools ... privileged prefs. Selects the mozilla tool preset. Requires MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 (ENABLE_PRIVILEGED_CONTEXT=true)--android-device — enable Firefox for Android mode; value is the ADB device serial (e.g. emulator-5554). Run adb devices to list connected devices. Omit the value or use auto to select the single connected device automatically.--android-wipe-app-data — confirm that Android mode wipes all data of the target app. Required together with --android-device. (ANDROID_WIPE_APP_DATA=true)--android-package — Android app package name, default org.mozilla.firefox. Other packages: org.mozilla.firefox_beta for Firefox Beta, org.mozilla.fenix for Firefox Nightly, org.mozilla.fenix.debug for Firefox Nightly Debug, org.mozilla.geckoview_example for geckoview (ANDROID_PACKAGE)--unrestricted-save-paths — let the saveTo parameter write anywhere on disk instead of the default roots. See Saving bulky output to disk and the security note in SECURITY.md. (UNRESTRICTED_SAVE_PATHS=true)--log-file — write MCP server logs to a file instead of stderr. Useful for debugging sessions with MCP clients that hide server output. Set DEBUG=* to also include verbose debug logs. Example: --log-file /tmp/firefox-mcp.logTools are grouped into modules. You choose which modules to expose either with a named preset
(--tool-preset) or with an explicit list (--tools). When both are given, --tools wins and
the preset is ignored.
Modules: pages, snapshot, input, network, console, screenshot, downloads,
utilities, management, webextension, profiler, screencast, script, debugging,
prefs, privileged.
Presets (each is a superset of the previous):
slim — pages, snapshot, input, screenshotbasic (default) — slim plus downloads, script, utilities, management, webextension, screencastdeveloper — basic plus debugging, network, console, profilermozilla — developer plus prefs, privilegedall — every moduleNote that basic, the default, includes script and therefore the evaluate_script tool.
See SECURITY.md for what that means for the attack
surface, and use --tool-preset slim or an explicit --tools list to drop it.
# Use the developer preset (adds network, console, debugging and profiler tools)
npx @mozilla/firefox-devtools-mcp --tool-preset developer
# Enable only the modules you need
npx @mozilla/firefox-devtools-mcp --tools pages network console
The prefs and privileged modules require MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 and are only
available in the Mozilla-internal build. The public package skips them even if requested and
logs a warning naming the modules it dropped.
--pref)Use --android-device to automate Firefox running on an Android device. Requires adb on your PATH and geckodriver, which is managed automatically.
Warning: Android mode wipes all data of the target app before every session. Tabs, history, bookmarks, passwords, cookies and settings are all lost. geckodriver runs
adb shell pm clear <package>when creating the session and offers no way to skip