Docs: tool descriptions for browser-embedding servers do not mention the browser's own background traffic
Maintainers usually reply within 1 day
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 68/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Active
- Domain
- documentation, web-dev
Research direction
Start by checking the README and tool descriptions for the archived src/puppeteer server, then look for documentation covering future servers that embed browser engines. Add a concise note that the embedded browser may make background requests beyond the requested navigation, and confirm the wording fits the chosen documentation home.
Written by the indexing model from the issue text.
Description
Hello, and thanks for the reference servers: having a set of them with real schemas is what made
the measurement below possible at all.
While measuring where MCP tool calls cause outbound traffic to go, I ran
@modelcontextprotocol/[email protected] in a container behind a terminating proxy and
drove a single puppeteer_navigate call at one URL. Besides the requested navigation, the run
recorded connections to two destinations that the tool's description does not mention:
clients2.google.com and accounts.google.com.
These are the embedded Chromium's own background requests, not something the server asks for. I
checked rather than assumed: launching the same browser binary with the same flags through the
same proxy, with no MCP server in the process tree and the same navigation, reproduces both
destinations. Neither request carried any of the call's arguments.
So this is not a report about the server doing something unexpected with a user's data. It is a
documentation gap, and I think it is worth a line because of where these servers get deployed:
puppeteer_navigateis documented as navigating to a URL. A reader reasonably concludes that
the destinations a call produces are the URL they passed.- Anyone deploying an MCP server in an environment where egress is reviewed (a regulated network,
an allowlisted proxy, an air-gapped-ish build system) will size their allowlist from that
reading, and the first background request will fail or will show up in an audit as unexplained. - The property belongs to the class, not to this package: any MCP server that embeds a browser
engine will carry the same background traffic, whoever writes it.
A sentence in the README or in the tool description, along the lines of "this server runs a full
browser; the browser makes its own background requests (update and connectivity checks) in
addition to the navigation you request", would close the gap.
I realise src/puppeteer has moved to the archived set, so this may be better framed as a
convention for any future server that embeds a browser engine rather than as a fix to that
package. Happy to send a PR against whichever document you think is the right home for it, or to
drop it if you would rather not document archived servers.
Measurement details, if useful: container-only, no real credentials, a single navigation to an
RFC 2606 reserved domain, three repetitions of the control. I am not publishing anything that
identifies a deployment, and I am happy to share the method.
Thanks again.
- Dominant language
- TypeScript
- Stars
- 90.6k
- Forks
- 11.7k
- Avg merge
- 8h 36m
- Merged PRs (30d)
- 23
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from modelcontextprotocol/servers
-
AGENTS.md: the dependency lockstep bullet and the npm test annotation are stalePossibly taken A pull request linked to this issue is open or already merged. Openagent guidance documentation v2
Difficulty 1/5 1-3 hours Newbie friendliness 92/100
modelcontextprotocol/servers#4924 · 1 comment ·
Maintainers usually reply within 1 day
-
mcp-server-fetch: `fetch` prompt returns JSON-RPC error code 0 with the raw exception text for an invalid URLPossibly taken @DawnofGenX claimed this 4 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
modelcontextprotocol/servers#4914 ·
Maintainers usually reply within 1 day
-
CLAUDE.md: tool-naming rule (kebab-case) disagrees with filesystem and memory serversPossibly taken @liang0417 claimed this 5 days ago. Open
Difficulty 1/5 Under an hour Newbie friendliness 92/100
modelcontextprotocol/servers#4892 · 1 comment ·
Maintainers usually reply within 1 day
-
Filesystem README recommends deprecated MCP Roots protocol for restricting directory accessPossibly taken @its-amann claimed this 10 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
modelcontextprotocol/servers#4844 ·
Maintainers usually reply within 1 day
-
Docs: `fetch` installs npm packages during a tool call, which is worth stating for deploymentsPossibly taken @teddiesloco claimed this 14 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
modelcontextprotocol/servers#4830 · 1 comment ·
Maintainers usually reply within 1 day
All issues in modelcontextprotocol/servers
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
prime-radiant-inc/evener#3726 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
FuRongJun-1999/dsh-memory#56 ·
Maintainers usually reply within 1 day
-
bug via-triage
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
pingdotgg/t3code#15682 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
openwatersio/slackwater.xyz#152 ·
Maintainers usually reply within 1 day
-
[BUG] 请修改标题为您遇到的问题Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
OpenListTeam/OpenList-Worker#103 ·
Maintainers usually reply within 1 day