general MCP Server
Secure ChromeMCP Server - Query and Debugging sites using Google Chrome with additional security hardening layers
Discovered via unknown and last synced 3mo ago.
1. Install the package
npx @pansec/chrome-mcp-secure
2. Add to claude_desktop_config.json
{
"mcpServers": {
"pansec-chrome-mcp-secure": {
"command": "npx",
"args": [
"@pansec/chrome-mcp-secure"
]
}
}
}Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)
Security engineers and DevOps professionals who need to automate browser-based testing and site inspection with enhanced security controls. QA teams and penetration testers benefit from querying web applications through Claude while maintaining strict security boundaries and audit trails.
Use Claude to intelligently navigate and test web applications through Chrome while maintaining security hardening. Perfect for identifying vulnerabilities, testing authentication flows, and validating security headers across different environments.
Query live websites through Claude's natural language interface to troubleshoot issues, inspect DOM elements, and test functionality without direct SSH access. Useful for remote debugging while maintaining audit logs of all interactions.
Automate compliance checks and security audits by having Claude interact with web interfaces while applying additional hardening layers. Generate detailed reports of findings with full session traceability for regulatory requirements.
Leverage GCP integration to test internal applications and cloud-hosted sites with Claude, combining browser automation with cloud security policies. Ideal for teams already using Google Cloud infrastructure.
The server implements additional security layers beyond standard Chrome automation to protect sensitive data and prevent unauthorized access. Specific hardening details depend on your deployment configuration, but typically include request validation, execution sandboxing, and audit logging.
Yes, the MCP can handle authenticated sessions and credential-based access. However, credentials should be managed through secure environment variables or credential management systems rather than hardcoded in prompts.
The GCP tag indicates this server is designed to integrate with Google Cloud environments, supporting testing of GCP-hosted applications and leveraging GCP security services. It's particularly useful for teams whose infrastructure lives in Google Cloud.
Session interactions are logged for security and compliance purposes, allowing teams to audit all browser actions performed through Claude. Log retention and access controls depend on your deployment configuration and security policies.
Use Case
`.\setup.ps1`
Get URL, title, interactive elements
Store encrypted login credentials
Simple
Description
List all Chrome tabs
Wait for element to appear
Update an existing credential
Chrome-MCP-Secure
Description
Get scroll position, viewport size
List stored credentials (no passwords shown)
Google, Cloudflare TLS
Solution
`./setup.sh`
Type text at cursor
Navigate with HTTPS cert bypass
Protection
Threat
Setup Script
Check Chrome connection and version
Click element by CSS selector
Click at coordinates
Scroll to coordinates
Execute JavaScript
Fill form field
Get credential metadata
Auto-fill login forms using stored credentials
Check vault encryption status
Coverage
`./setup.sh`
Extract text from element
ChaCha20-Poly1305
[lxe/chrome-mcp](https://github.com/lxe/chrome-mcp)
Navigate to URL
Capture page screenshot
Remove a stored credential
✅
rt=1702732800000 outcome=success msg=Tool navigate executed: success request=https://internal.company.com cn1=1702732800-abc123 cn1Label=correlationId ``` --- > **Security-hardened fork** of [lxe/chrome-mcp](https://github.com/lxe/chrome-mcp) > Maintained by [Pantheon Security](https://github.com/Pantheon-Security) --- ## Real-World Results > **"We used this MCP for hours building out our security dashboard - the reliability was incredible. The amount of work we produced was huge compared to manual browser interaction."** > — Pantheon Security team ### Production Tested
Implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress traffic, apply hierarchical firewall policies across the organization, and monitor firewall rule effectiveness using VPC Flow Logs.
Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.
Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.
Implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.
Sample code and notebooks for Generative AI on Google Cloud, with Gemini Enterprise Agent Platform
The secure gateway connecting AI agents to enterprise systems.
DecisionBox connects to your data warehouse, runs autonomous AI agents that write and execute SQL, and surfaces validated insights and actionable recommendations — without you asking a single question.
Learn how to use the cloud-gcp Claude skill. Complete guide with installation instructions and examples.
Learn how to use the implementing-gcp-vpc-firewall-rules Claude skill. Complete guide with installation instructions and examples.
Learn how to use the auditing-gcp-iam-permissions Claude skill. Complete guide with installation instructions and examples.