Large Language ModelsGenerate 3D modelsGenerate images
Is Claude MCP Safe? Playwright, Browser and Blender MCP Risks
Claude MCP is only as safe as the servers you connect and the permissions you grant. This article shows what Playwright MCP, browser MCP servers and Blender MCP can reach, the attacks that already happened, and the exact settings that limit the damage.
Claude MCP is as safe as the servers you connect and the permissions you hand out. The Model Context Protocol itself is only a messaging format. The danger sits in what a server can reach on your machine, which untrusted text the model reads along the way, and how often you click "Always allow" without looking. Three popular servers show the whole range of that problem: Playwright, browser MCP servers and Blender MCP. One drives a browser, one borrows your logged-in sessions, and one runs arbitrary Python inside a 3D app. Below you will find what each of them can do, what has already gone wrong in the real world, and the exact settings that keep the damage small.
The Short Answer
Anthropic introduced MCP in November 2024 as a standard way for Claude to call outside tools: read files, query databases, click through web pages, drive creative software. Thousands of community servers now exist, and most were written by people you will never meet.
So is it safe? Here is the honest scorecard:
Safe enough: read-only servers on data you could already share, with a narrow scope and manual approval on every call.
Risky: servers that act for you inside a browser or app where you are already signed in.
Dangerous by design: any tool that executes code, such as execute_blender_code.
💡 Developer Simon Willison calls the worst combination the lethal trifecta: access to private data, exposure to untrusted content, and a way to send data out. Give one agent all three and a single hostile web page can steer it. A browser server already supplies two of the three before you add anything else.
The rest of this article is about least privilege: give each server the smallest reach that still gets the job done, and put a sandbox around anything that can run code.
How MCP Servers Get Their Power
They Run as You
Local MCP servers are ordinary programs that your client launches on your computer, usually through npx, uvx or Docker. They inherit your account's permissions: your files, your environment variables, your network. The protocol ships no sandbox. Claude Code's own documentation says it plainly: verify you trust each server before connecting it, because servers that fetch external content can expose you to prompt injection.
The track record shows why that advice matters:
June 2025: Anthropic's own MCP Inspector, a debugging tool, shipped with a remote code execution flaw that has since been patched.
July 2025: the popular mcp-remote package had a command injection bug (CVE-2025-6514).
Early 2026: one industry tally counted more than 30 CVEs filed against MCP implementations in roughly two months.
Launching a server with npx -y some-package downloads and runs the newest code every single time. Pin a version you have reviewed instead.
The Model Reads Every Description
Each tool arrives with a text description that the model reads and you usually never see. In April 2025, Invariant Labs named the resulting attack tool poisoning: "malicious instructions are embedded within MCP tool descriptions that are invisible to users but visible to AI models." A related trick, the rug pull, changes a description after you approved the server.
Content can poison the model too. In May 2025, researchers at Invariant Labs showed that hostile text planted in public GitHub issues could push an agent connected to the GitHub MCP server into leaking private repository code into a public pull request. The server did nothing wrong. The agent simply obeyed text it should have treated as data.
Playwright MCP Risks
Microsoft's Playwright MCP hands Claude a real browser. The model reads each page through structured snapshots and then clicks, types and moves between pages. That is exactly why it is so useful for testing and research, and exactly why it deserves the most careful setup of the three.
A Browser That Acts for You
A browser is a bundle of sessions. By default, Playwright MCP keeps a persistent profile on disk (on Windows, under %USERPROFILE%\AppData\Local\ms-playwright\), so anything you sign into during one run is still signed in during the next. The browser opens in headed mode by default, and every page it loads feeds text straight into the model's context.
Put those facts together and the risk is clear. A page you visit for research can contain instructions, and the model has click and type tools available to follow them.
Why Origin Filters Fall Short
The README is blunt: "Playwright MCP is not a security boundary." The --allowed-origins flag defaults to allowing everything, and the documentation states that it does not serve as a security boundary and does not affect redirects. The --blocked-origins flag is evaluated before the allowlist, but the same limits apply. Treat both as a speed bump that catches honest mistakes, not as a wall.
File access is stricter by default. The server restricts the file system to the workspace roots and blocks file:// URLs. The --allow-unrestricted-file-access flag lifts both limits, so never use it in a session that visits the open web.
Settings That Shrink the Damage
--isolated keeps the profile in memory and discards it when the browser closes.
--headless suits unattended runs, though you lose the chance to watch what happens.
--allowed-origins with a short list of your own staging sites reduces accidental wandering.
Leave --allow-unrestricted-file-access off.
Avoid --extension on your daily browser: it connects Claude to a running Edge or Chrome instance, with every session inside it.
Replace PINNED_VERSION with a release you have actually checked.
Browser MCP and Logged-In Sessions
"Browser MCP" is really a family of servers: Google's Chrome DevTools MCP, extension bridges that drive your everyday Chrome, and Anthropic's own Chrome extension. They share one trait. They can see and change what is inside a browser you actually use.
The Chrome DevTools MCP README says it directly: the server "exposes content of the browser instance to the MCP clients allowing them to inspect, debug, and modify any data in the browser or DevTools." It also notes that Google collects usage statistics by default, such as tool success rates, latency and environment details. You can turn that off with --no-usage-statistics or the CHROME_DEVTOOLS_MCP_NO_USAGE_STATISTICS environment variable.
Real Profile Versus Throwaway Profile
Browser setup
What Claude can reach
Verdict
Your daily Chrome profile
Email, banking, work apps, saved sessions
Avoid
Dedicated profile with test accounts
Only what you sign into there
Acceptable
In-memory isolated profile
Nothing that persists
Good
Headless browser in a container
Nothing outside the container
Best for unattended runs
The rule is simple: Claude should only ever see accounts you could afford to lose.
Prompt Injection From Web Pages
Hidden text is the standard attack. A page can include white-on-white paragraphs, a form field you cannot see, or instructions tucked into a tab title or URL. The model reads all of it like any other content.
Picture the chain. You ask Claude to compare two laptop reviews. One page carries invisible text telling the assistant to open your webmail tab and forward the latest message. If the browser holds a live email session and the server lets it open any site, the only barrier left is the model's judgment.
Anthropic measured this during the August 2025 research preview of its Chrome extension. Across 123 test cases spanning 29 attack scenarios, deliberately targeted attacks succeeded 23.6% of the time without safety mitigations and 11.2% with them. That is still roughly one attack in nine. A third-party browser server has none of those classifiers, so assume the model will sometimes follow what a page tells it.
Blender MCP Risks
Blender MCP (the ahujasid/blender-mcp project) pairs an add-on running inside Blender with a server that Claude talks to. Claude can then build scenes, set materials and import assets from a plain sentence. The risk differs from a browser, because here the tool is a Python interpreter.
Code Execution Is the Feature
The execute_blender_code tool runs whatever Python Claude sends, inside Blender. Blender's Python can import os and subprocess, read and write files, and open network connections. The README warning is short: the tool "allows running arbitrary Python code in Blender, which can be powerful but potentially dangerous," and you should always save your work before using it.
A CVE entry, CVE-2026-10688, was listed in SentinelOne's vulnerability database on June 4, 2026 against exactly this tool: no sanitizing, no sandboxing, and no official patch at the time of the entry. Read that as a description of the design, not a surprise. The tool does what it says, so the protection has to come from you.
A Socket With No Login
The add-on talks to the server over a TCP socket, port 9876 by default. The README notes that this socket has no authentication or encryption and should stay on localhost, with an SSH tunnel for remote use. Localhost-only still means every other process running under your account can connect and send commands.
Third-Party Asset Services
The add-on reaches out to Poly Haven, Sketchfab, Poly Pizza and AI 3D generators such as Hunyuan3D, Tripo and Hyper3D Rodin. Each one needs its own credentials or receives your prompts. By default the project collects minimal anonymous usage data: install ID, session ID, tool names, success and timing, versions and operating system. Prompts, generated code and screenshots are sent only if you opt in. Setting DISABLE_TELEMETRY=true turns it all off.
Downloaded .blend files can also carry scripts. Blender's Auto Run Python Scripts preference ships disabled, so keep it that way.
Risk Ranking at a Glance
Server
Biggest exposure
How it is abused
Best containment
Playwright MCP
Persistent logged-in profile, open web
Hostile page text steers clicks and typing
--isolated, Docker, short origin list
Browser MCP on your real Chrome
Every session in the browser
Prompt injection, poisoned tool descriptions
Dedicated profile with test accounts
Blender MCP
Arbitrary Python, unauthenticated socket
Injected text reaches the code tool
Virtual machine, low-privilege account, tool denied by default
Any server run with npx -y
Unreviewed code at each launch
Supply chain attacks and rug pulls
Pinned versions, reviewed releases
In plain words: Blender MCP has the highest ceiling, because code runs with your privileges. Browser MCP on a real profile is the most likely to hurt, because the sessions it exposes are valuable and the web is full of hostile text. Playwright with --isolated is the easiest of the three to make boring.
A Safer Setup, Step by Step
Permissions in Claude Code
Claude Code asks for approval before it uses project servers from a .mcp.json file in interactive sessions, which protects you when you clone an unfamiliar repository. In non-interactive runs (claude -p or the Agent SDK) those servers load without a prompt. Block that with disabledMcpjsonServers, exclude project settings with --setting-sources, or start with --strict-mcp-config so only servers you pass explicitly are used.
Individual tools are controlled with rules shaped like mcp__<server>__<tool>:
The names after mcp__ are whatever you called the servers in your own config. Denying execute_blender_code removes much of what Blender MCP does, so allow it only on a disposable machine with your work saved.
Containers and Throwaway Profiles
Containment beats vigilance. Run Playwright in Docker. Run Blender in a virtual machine, or under a separate low-privilege user that cannot read your home folder. Give every server its own scoped, short-lived tokens, and never place a long-lived admin credential in the environment of a server you did not write. Pin versions, then re-read the tool list after each update to catch rug pulls.
Review Before You Approve
Claude Desktop and Claude Code both let you approve a tool once or always. Build better habits around that choice:
Read the call, not just the tool name. A request to open an unfamiliar domain deserves a pause.
Treat "Always allow" as a permanent grant. Revisit your grants every month.
Split sessions. Do not run a browsing server in the same session as one that reads secrets or sends email.
Watch for surprises. An agent that suddenly wants a file outside the project is worth stopping.
Use Claude Sonnet 5 on PicassoIA
You can audit your own setup with Claude Sonnet 5 on PicassoIA. It reasons through multi-step tasks and reads images, so it handles a config file or a screenshot of a permission dialog equally well.
Strip secrets first. Replace every token in your MCP config with REDACTED.
Open the model and paste the config into Prompt with a direct question, for example: "List every way each server here could read files, send data out or run code. Rank them by damage."
Set effort to high. The default low disables thinking, which is fast but shallow. high or max suits a review with several dependent steps.
Add a System Prompt such as "You are a cautious security reviewer. Flag anything that grants broad permissions."
Keep Max Tokens at 8192, the default, so long findings are not cut off.
Attach a screenshot of an approval dialog in the Image field if you want a second opinion on whether its wording hides what the call does.
Compare the answer with the checklist above, then ask follow-up questions about any server it flagged.
💡 The model sees only what you paste. It cannot inspect your machine, so it will miss anything outside the config. Use it as a second reader, not as a sign-off.
If you run a pipeline that moderates text, Llama Guard 4 12B screens content against unsafe categories. It is a moderation model, not a sandbox, so it should never be your only defence.
Build Your Own Images on Picasso IA
The images in this article came from text prompts alone, with no 3D app and no MCP server in the loop. If you work in Blender, generating reference images first is a safe way to plan a scene before any agent touches a live project file.
Try Seedream 5 Pro or GPT Image 2 for photorealistic scenes, then compare the results side by side. Write a prompt with a clear subject, a lighting direction and a lens, run it a few times, and see which model fits your style. You can browse every available model at picassoia.com/en/all-models. Pick one and start experimenting with your own images on Picasso IA today.