# browsentic

A browser extension with an AI side panel that hands your real, logged-in browser to the AI agent you already run. Installs the extension, runs the local daemon, and optionally speaks MCP.

- **Type:** MCP server
- **Trust:** 65/100 (B), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.7.15
- **Author:** io.github.imshaikot
- **License:** MIT
- **npm:** browsentic
- **Source:** https://github.com/imshaikot/browsentic
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

65/100 (B), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: suspicious script found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 4 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-10-02T01:39:37.539Z
- **Version scanned:** 0.7.15
- **CVEs:** none found by OSV at scan time
**Findings**
- injection-shaped content (warning) in the `page.pressKey` tool: Exfiltration-shaped instruction

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `page.applyTheme`
- `page.attachFile` — Attach a file to a file input on the page: either one the user stored in Browsentic (fileId, from page.listFiles) or one you captured off another page (download
- `page.auditContrast` — Score the readability of the page against WCAG contrast rules. Walks the visible text, resolves each run’s foreground against the real background painted behind
- `page.awaitMonitor` — Block until a background monitor completes, then return its final state with the full log. A reply with settled: false means the timeout passed while the watch 
- `page.callSiteTool` — Call one of the tools this site offers through WebMCP (document.modelContext), with arguments matching the schema page.listSiteTools reported. The site’s own co
- `page.captureDownload` — Make the page download a file and keep it. Either click something that produces a download — an “Export CSV” button, a “Download invoice” link — or give a direc
- `page.clickElement` — Click an element like a user would, firing the full pointer and mouse event sequence.
- `page.closeTab` — Close an open tab. With no arguments it closes the tab page actions are currently targeting, and later actions follow the browser to whichever tab it brings to 
- `page.dragElement`
- `page.extractText`
- `page.fillInput` — Fill a text input, textarea, or contenteditable element like a user typing.
- `page.findProgress` — Scan the page for progress signals worth monitoring: progress bars, percent readouts, spinners and busy regions, each with a selector for page.startMonitor. An 
- `page.findSearch`
- `page.focusInput` — Focus an input or editable element and place the caret, or select all its content.
- `page.switchFrame`
- `page.getPageInfo`
- `page.highlightElement` — Visually highlight an element with a temporary outline overlay and optional caption.
- `page.hoverElement` — Hover an element to trigger menus, tooltips, and other hover states.
- `page.listDownloads` — List the files Browsentic has captured with page.captureDownload, newest first, with notes about what each one is and where it was saved. Use a downloadId from 
- `page.listFiles` — List the files the user has stored in Browsentic, with their AI-generated summaries.
- `page.listRecordings` — List the browsing sessions the user recorded in Browsentic, with the goal and step count of each. Use page.readRecording to open one.
- `page.listSiteTools`
- `page.monitorStatus` — Report on background monitors started with page.startMonitor: phase, percent, ETA, how long since anything changed, and the latest log lines.
- `page.navigate` — Navigate the current tab to a URL, or go back, forward, or reload in its history.
- `page.openTab` — Open a URL in a new browser tab. The new tab becomes the one every later page action targets, unless "active" is false.
- `page.pickElement` — Ask the user to point at an element — A-Eye. Their cursor becomes a lens, whatever they hover is outlined, and the element they click comes back with its select
- `page.pressKey` — Send a keyboard key press, with optional modifiers, to an element on the page.
- `page.readRecording` — Read one saved browsing recording in full: its goal, the values it needs supplied, and its ordered steps. The steps are notes about what the user did, not comma
- `page.readTheme`
- `page.screenshot`
- `page.scrollTo` — Scroll the page to an element, an absolute position, or by one viewport in a direction.
- `page.searchSite`
- `page.selectOption` — Choose an option in a <select> dropdown by value, visible label, or position.
- `page.selectText` — Select text on the page, from a target element or by finding an exact phrase.
- `page.startMonitor` — Watch one tab in the background until a progress condition completes — an upload reaching 100%, a build log announcing success, a spinner disappearing. Returns 
- `page.startTimer` — Schedule work for later — “in ten minutes check whether the build finished”, “every two minutes refresh the queue and tell me when something lands”. Returns a t
- `page.stopMonitor` — Stop a background monitor before it completes. The tab is unpinned again if the monitor pinned it. No notification is shown — the stop was asked for.
- `page.stopTimer` — Cancel a scheduled job before it has run out. Nothing further fires and no notification is shown — the stop was asked for.
- `page.submitForm` — Submit a form, firing its submit event and validation as if the user pressed Enter.
- `page.switchTab` — Bring another open tab to the front, making it the tab every later page action targets. Call it with no arguments to list the open tabs and their ids first.

## Install

**Verdict: do-not-install** — Do not install: 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it.
**Blocking**
- 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it. — tool:page.pressKey: Exfiltration-shaped instruction
**Client configuration withheld.** Client configs are withheld because this entry has a blocking finding. Show the warnings below to the person installing it.
If they have seen the findings and still want to proceed, request the plan again with acknowledge_warnings=true.

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 11, ceiling 29 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/browsentic
- Install plan: https://forgeregistry.com/api/v1/packages/browsentic/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/browsentic
- HTML page: https://forgeregistry.com/registry/browsentic
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
