Fixes https://github.com/microsoft/playwright-mcp/issues/376
Useful to limit the agent when using the playwright-mcp server with an agent in auto-invocation mode. Not intended to be a security feature.