
Security News
US Government Forces Anthropic to Pull Claude Fable Days After Launch
Anthropic says the directive cited national security concerns over a narrow jailbreak, but offered no specific technical details.
@mozilla/firefox-devtools-mcp
Advanced tools
Model Context Protocol (MCP) server for Firefox DevTools automation
Model Context Protocol server for automating Firefox via WebDriver BiDi (through Selenium WebDriver). Works with Claude Code, Claude Desktop, Cursor, Cline and other MCP clients.
Repository: https://github.com/mozilla/firefox-devtools-mcp
Note: This MCP server requires a local Firefox browser installation and cannot run on cloud hosting services like glama.ai. Use
npx firefox-devtools-mcp@latestto run locally, or use Docker with the provided Dockerfile.
Browser MCP servers carry inherent risks. A few key practices:
--enable-script and --enable-privileged-context significantly expand what the agent can do.See SECURITY.md for a full breakdown of risks and how to report vulnerabilities.
--firefox-path)Recommended: use npx so you always run the latest published version from npm.
Option A — Claude Code CLI
claude mcp add firefox-devtools npx firefox-devtools-mcp@latest
Pass options either as args or env vars. Examples:
# Headless + viewport via args
claude mcp add firefox-devtools npx firefox-devtools-mcp@latest -- --headless --viewport 1280x720
# Or via environment variables
claude mcp add firefox-devtools npx firefox-devtools-mcp@latest \
--env START_URL=https://example.com \
--env FIREFOX_HEADLESS=true
Option B — Edit Claude Code settings JSON
Add to your Claude Code config file:
~/Library/Application Support/Claude/Code/mcp_settings.json~/.config/claude/code/mcp_settings.json%APPDATA%\Claude\Code\mcp_settings.json{
"mcpServers": {
"firefox-devtools": {
"command": "npx",
"args": ["-y", "firefox-devtools-mcp@latest", "--headless", "--viewport", "1280x720"],
"env": {
"START_URL": "about:home"
}
}
}
}
Option C — Helper script (local dev build)
npm run setup
# Choose Claude Code; the script saves JSON to the right path
npx @modelcontextprotocol/inspector npx firefox-devtools-mcp@latest --start-url https://example.com --headless
Then call tools like:
list_pages, select_page, navigate_pagetake_snapshot then click_by_uid / fill_by_uidlist_network_requests (always‑on capture), get_network_requestscreenshot_page, list_console_messagesYou can pass flags or environment variables (names on the right):
--firefox-path — absolute path to Firefox binary--headless — run without UI (FIREFOX_HEADLESS=true)--viewport 1280x720 — initial window size--profile-path — use a specific Firefox profile--firefox-arg — extra Firefox arguments (repeatable)--start-url — open this URL on start (START_URL)--accept-insecure-certs — ignore TLS errors (ACCEPT_INSECURE_CERTS=true)--connect-existing — attach to an already-running Firefox instead of launching a new one (CONNECT_EXISTING=true)--marionette-port — Marionette port for connect-existing mode, default 2828 (MARIONETTE_PORT)--pref name=value — set Firefox preference at startup via moz:firefoxOptions (repeatable)--enable-script — enable the evaluate_script tool, which executes arbitrary JavaScript in the page context (ENABLE_SCRIPT=true)--enable-privileged-context — enable privileged context tools: list/select privileged contexts, evaluate privileged scripts, get/set Firefox prefs, and list extensions. Requires MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 (ENABLE_PRIVILEGED_CONTEXT=true)--android-device — enable Firefox for Android mode; value is the ADB device serial (e.g. emulator-5554). Run adb devices to list connected devices. Omit the value or use auto to select the single connected device automatically.--android-package — Android app package name, default org.mozilla.firefox. Other packages: org.mozilla.firefox_beta for Firefox Beta, org.mozilla.fenix for Firefox Nightly, org.mozilla.fenix.debug for Firefox Nightly Debug, org.mozilla.geckoview_example for geckoview (ANDROID_PACKAGE)Note on
--pref: When Firefox runs in automation, it applies RecommendedPreferences that modify browser behavior for testing. The--prefoption allows overriding these defaults when needed.
Use --android-device to automate Firefox running on an Android device. Requires adb on your PATH and geckodriver, which is managed automatically.
# List connected devices
adb devices
# Launch Firefox for Android on the single connected device
npx firefox-devtools-mcp --android-device auto
# Target a specific device
npx firefox-devtools-mcp --android-device <serial>
# Use Firefox Nightly instead
npx firefox-devtools-mcp --android-device <serial> --android-package org.mozilla.fenix
Port forwarding between the host and device is handled automatically by geckodriver.
Use --connect-existing to automate your real browsing session — with cookies, logins, and open tabs intact:
# Start Firefox with Marionette enabled
firefox --marionette
# Run the MCP server
npx firefox-devtools-mcp --connect-existing --marionette-port 2828
Or set marionette.enabled to true in about:config (or user.js) to enable Marionette on every launch.
BiDi-dependent features (console events, network events) are not available in connect-existing mode; all other features work normally.
Warning: Do not leave Marionette enabled during normal browsing. It sets
navigator.webdriver = trueand changes other browser fingerprint signals, which can trigger bot detection on sites protected by Cloudflare, Akamai, etc. Only enable Marionette when you need MCP automation, then restart Firefox normally afterward.
saveTo for CLI environments)MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1)MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1)When using screenshots in Claude Code CLI, the base64 image data can consume significant context.
Use the saveTo parameter to save screenshots to disk instead:
screenshot_page({ saveTo: "/tmp/page.png" })
screenshot_by_uid({ uid: "abc123", saveTo: "/tmp/element.png" })
The file can then be viewed with Claude Code's Read tool without impacting context size.
npm install
npm run build
# Run with Inspector against local build
npx @modelcontextprotocol/inspector node dist/index.js --headless --viewport 1280x720
# Or run in dev with hot reload
npm run inspector:dev
See CONTRIBUTING.md for more details on local development, testing, and CI.
--firefox-path "/Applications/Firefox.app/Contents/MacOS/firefox" (macOS) or the correct path on your OS.take_snapshot) before using UID tools.Solution 1 Wrap with cmd /c (details):
"mcpServers": {
"firefox-devtools": {
"command": "cmd",
"args": ["/c", "npx", "-y", "firefox-devtools-mcp@latest"]
}
}
Solution 2 Use the absolute path to npx (adjust extension — .cmd, .bat, .exe, or .ps1 — to match your setup):
"mcpServers": {
"firefox-devtools": {
"command": "C:\\nvm4w\\nodejs\\npx.ps1",
"args": ["-y", "firefox-devtools-mcp@latest"]
}
}
0.x. Use @latest with npx for the newest release.See CONTRIBUTING.md for how to file issues, run tests, and work on the project locally.
Maintained by Mozilla.
Licensed under either of MIT or Apache 2.0 at your option.
FAQs
Model Context Protocol (MCP) server for Firefox DevTools automation
The npm package @mozilla/firefox-devtools-mcp receives a total of 640 weekly downloads. As such, @mozilla/firefox-devtools-mcp popularity was classified as not popular.
We found that @mozilla/firefox-devtools-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 19 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Anthropic says the directive cited national security concerns over a narrow jailbreak, but offered no specific technical details.

Security News
A network of 152 Chrome live wallpaper extensions hid ad tracking and made extension-driven traffic look like Google search clicks.

Company News
Socket’s first CISO brings deep experience securing high-growth SaaS companies as open source supply chain threats accelerate.