Automation#Browser automation

browser-control: run Playwright inside your own browser

A local driver from anomaly: agents send Playwright snippets that run in your everyday Chromium via a relay and extension, with secret redaction.

Project facts

GitHub Ecosystem
Repositorygithub.com/anomalyco/browser-control
License
MIT
Language
TypeScript
Stars
439
Data checked
2026-10-10

Snapshot figures reflect the check date and may change over time.

Playwright scripts are easy to write, but by default they drive a clean automation browser: no login state, no extensions, and any authenticated API call first requires smuggling cookies in. browser-control, open-sourced by anomaly in July 2026 under MIT (about 440 stars as of October 10, 2026), flips that around and makes your everyday Chromium the execution environment: the agent sends a Playwright snippet, a local relay forwards it to a browser extension, the code runs inside your real profile, and the agent gets back the result, logs, and a summary of what changed on the page. The chain is agent/CLI → local relay (127.0.0.1:19989) → extension → your browser; the driver contains no model and makes no planning decisions — it executes exactly the code the agent writes.

Core features

  • Code-first execution: execute takes a Playwright snippet (with browser, context, and page objects plus helper functions) and returns results and logs. Sessions carry persistent state and an append-only journal, so work resumes where it stopped.
  • Inspect before acting: snapshot() returns a compact page snapshot with refs like [ref=e12]; the next snippet clicks by ref, and structural drift fails loudly instead of hitting the wrong target. Deltas, semantic search, labeled screenshots, and pixel diffs are built in.
  • Adopt an existing tab: attach any open tab to a session from the extension toolbar; the session owns it exclusively and releases it without closing.
  • Human handoff: handoff() parks CAPTCHAs, 2FA, and payment confirmations behind an in-page completion control the script waits on. demonstrate() goes the other way, recording a workflow you perform once into editable Playwright code, with passwords replaced by secret references.
  • Read-only sessions and secret redaction: --read-only sessions reject mouse and keyboard CDP commands; HAR exports swap cookies, tokens, and API keys for ${BC_SECRET_N} references, with plaintext kept in a 0600 profile and child-process output redacted through secrets run.
  • MCP and an OpenCode plugin: MCP clients connect to the browser-control-mcp entrypoint; OpenCode installs the whole thing as a managed plugin with one command, and shell agents learn the workflow from the official skill (npx skills add anomalyco/browser-control --skill browser-control).
  • A same-origin request client: the npm package also exports an Effect-style TypeScript client, so applications can send same-origin requests through a session without generated code — cookies stay in the browser, responses validate against a schema, and sensitive requests return redacted values until explicitly revealed.

Typical use cases

  • Have a coding agent reproduce a bug or call an authenticated API using your signed-in GitHub or admin account.
  • Demonstrate a manual workflow once and turn the generated Playwright code into a reusable script.
  • Keep evidence for flaky failures: WebM recordings, a rolling flight-recorder buffer, and before/after screenshot diffs.

Quick start

npm install --global @opencode-ai/browser-control
browser-control execute 'await page.goto("https://example.com"); return { title: await page.title() }'

One manual step remains: print the extension directory the README documents and load it unpacked from chrome://extensions with developer mode on. The first command starts the relay, opens a tab, and returns the page title plus the --session command to continue; browser-control doctor checks the setup anytime. Node 22.19 or newer is required, and Chrome, Brave, Edge, and Arc all work.

Summary

browser-control suits developers who want agents on real login state but would rather orchestrate with Playwright than with prose. Next to BrowserSkill and its separate Agent Window, it has no agent-owned window — sessions and tab adoption draw the boundary — and no authenticated remote mode, so it stays on one machine. The similarly named Browser Control MCP by eyalzh is a different project that manages Firefox tabs; do not mix them up. Two limits to accept: the extension is unpacked-only for now (no Chrome Web Store listing yet), and read-only mode is not a security sandbox — trusted code can still mutate pages through page.evaluate. The driver explicitly trusts local agent code, and the extension asks for broad permissions (debugger, tabCapture), so decide who gets to run it.