Skip to content

feat(mcp): add --allowed-tools and --blocked-tools options - #42931

Open
Yury Semikhatsky (yury-s) wants to merge 4 commits into
microsoft:mainfrom
yury-s:fix-mcp-1770
Open

Yury Semikhatsky (yury-s) wants to merge 4 commits into
microsoft:mainfrom
yury-s:fix-mcp-1770

Conversation

@yury-s

@yury-s Yury Semikhatsky (yury-s) commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Add --allowed-tools / --blocked-tools (PLAYWRIGHT_MCP_ALLOWED_TOOLS / PLAYWRIGHT_MCP_BLOCKED_TOOLS, allowedTools / blockedTools in config) to adjust the MCP tool set by exact name.
  • --allowed-tools enables tools on top of the enabled capabilities (e.g. browser_pdf_save without --caps=pdf); --blocked-tools removes tools (e.g. browser_run_code_unsafe) and takes precedence.
  • Blocked tools are hidden from tools/list and rejected on tools/call; unknown tool names fail at startup.

Fixes microsoft/playwright-mcp#1770

Move browser_run_code_unsafe and WebMCP tools into core-run-code and
core-webmcp capabilities that stay enabled by default but can be turned
off via --disable-caps, PLAYWRIGHT_MCP_DISABLE_CAPS or the
disabledCapabilities config field.

Fixes: microsoft/playwright-mcp#1770
@github-actions

This comment has been minimized.

Revert the core capability split and instead filter tools by exact name.
Both lists also apply to the tools registered by the page through WebMCP.
@yury-s Yury Semikhatsky (yury-s) changed the title feat(mcp): allow disabling core capabilities with --disable-caps feat(mcp): add --allowed-tools and --blocked-tools options Sep 25, 2026
@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

Comment thread packages/playwright-core/src/tools/backend/context.ts Outdated
Comment thread packages/playwright-core/src/tools/backend/tools.ts Outdated
--allowed-tools now enables tools on top of the enabled capabilities.
WebMCP tools are controlled by the webmcp option only.
@github-actions

This comment has been minimized.

@github-actions

Copy link
Copy Markdown
Contributor

Hi, I'm the Playwright bot and I took a first look at the CI failures.

🟢 The failures look like pre-existing flakes, not caused by this PR

All three failing tests have also failed on other PRs recently, and none of them use the new --allowed-tools / --blocked-tools filtering. Note that the MCP run was cancelled, so the report may be incomplete.

Details

This PR adds tool allow/block lists in filteredTools() and new config/CLI/env plumbing. With neither option set, the filter behaves the same as before: only core and capability-enabled tools, with skill-only tools excluded. None of the failing tests pass these options.

Pre-existing flake / infra

Triaged by the Playwright bot - agent run

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

8809 passed, 1500 skipped


Merge workflow run.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Upstream issue draft — microsoft/playwright-mcp

2 participants