@pansec/chrome-mcp-secure

general MCP Server

Secure ChromeMCP Server - Query and Debugging sites using Google Chrome with additional security hardening layers

Install Ready
generalgeneralgcp
5 views5 stars2 forksv2.3.1MIT

Why This Matters

Discovered via unknown and last synced 3mo ago.

Install Ready
Source
unknown
Stars
5
Last synced
3mo ago
Install
Instructions detected

Install

1. Install the package

npx @pansec/chrome-mcp-secure

2. Add to claude_desktop_config.json

{
  "mcpServers": {
    "pansec-chrome-mcp-secure": {
      "command": "npx",
      "args": [
        "@pansec/chrome-mcp-secure"
      ]
    }
  }
}

Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)

40
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Who Is This For?

Security engineers and DevOps professionals who need to automate browser-based testing and site inspection with enhanced security controls. QA teams and penetration testers benefit from querying web applications through Claude while maintaining strict security boundaries and audit trails.

Use Cases

Automated security testing of web applications

Use Claude to intelligently navigate and test web applications through Chrome while maintaining security hardening. Perfect for identifying vulnerabilities, testing authentication flows, and validating security headers across different environments.

Debugging production sites via Claude conversations

Query live websites through Claude's natural language interface to troubleshoot issues, inspect DOM elements, and test functionality without direct SSH access. Useful for remote debugging while maintaining audit logs of all interactions.

Secure browser automation for compliance audits

Automate compliance checks and security audits by having Claude interact with web interfaces while applying additional hardening layers. Generate detailed reports of findings with full session traceability for regulatory requirements.

GCP-integrated web application reconnaissance

Leverage GCP integration to test internal applications and cloud-hosted sites with Claude, combining browser automation with cloud security policies. Ideal for teams already using Google Cloud infrastructure.

Frequently Asked Questions

What security hardening is applied compared to standard Chrome automation?

The server implements additional security layers beyond standard Chrome automation to protect sensitive data and prevent unauthorized access. Specific hardening details depend on your deployment configuration, but typically include request validation, execution sandboxing, and audit logging.

Can this work with authenticated applications and credentials?

Yes, the MCP can handle authenticated sessions and credential-based access. However, credentials should be managed through secure environment variables or credential management systems rather than hardcoded in prompts.

What's the relationship between this MCP and Google Cloud Platform?

The GCP tag indicates this server is designed to integrate with Google Cloud environments, supporting testing of GCP-hosted applications and leveraging GCP security services. It's particularly useful for teams whose infrastructure lives in Google Cloud.

How are session logs and audit trails handled?

Session interactions are logged for security and compliance purposes, allowing teams to audit all browser actions performed through Claude. Log retention and access controls depend on your deployment configuration and security policies.

Available Tools (40)

Format

Use Case

Windows

`.\setup.ps1`

get_page_info

Get URL, title, interactive elements

store_credential

Store encrypted login credentials

Complexity

Simple

Module

Description

get_tabs

List all Chrome tabs

wait_for_element

Wait for element to appear

update_credential

Update an existing credential

Pantheon-Security

Chrome-MCP-Secure

Tool

Description

get_page_state

Get scroll position, viewport size

list_credentials

List stored credentials (no passwords shown)

Adoption

Google, Cloudflare TLS

Requirement

Solution

Linux

`./setup.sh`

type

Type text at cursor

bypass_cert_and_navigate

Navigate with HTTPS cert bypass

Data

Protection

Timeline

Threat

Platform

Setup Script

health

Check Chrome connection and version

click_element

Click element by CSS selector

click

Click at coordinates

scroll

Scroll to coordinates

evaluate

Execute JavaScript

fill

Fill form field

get_credential

Get credential metadata

secure_login

Auto-fill login forms using stored credentials

get_vault_status

Check vault encryption status

Standard

Coverage

macOS

`./setup.sh`

get_text

Extract text from element

Property

ChaCha20-Poly1305

Feature

[lxe/chrome-mcp](https://github.com/lxe/chrome-mcp)

navigate

Navigate to URL

screenshot

Capture page screenshot

delete_credential

Remove a stored credential

Cross-platform

✅

3

rt=1702732800000 outcome=success msg=Tool navigate executed: success request=https://internal.company.com cn1=1702732800-abc123 cn1Label=correlationId ``` --- > **Security-hardened fork** of [lxe/chrome-mcp](https://github.com/lxe/chrome-mcp) > Maintained by [Pantheon Security](https://github.com/Pantheon-Security) --- ## Real-World Results > **"We used this MCP for hours building out our security dashboard - the reliability was incredible. The amount of work we produced was huge compared to manual browser interaction."** > — Pantheon Security team ### Production Tested