Open-source browser AI agent extension. ReAct loop, your own key, runs locally in any Chromium browser.
TypeScript
7
576 commits
updated Oct 1, 2026
Browser-resident AI agent. Lives in your Chromium side panel, uses your real session — not a headless cloud VM.
You type something into the side panel — "apply to the first AI Engineer job on hh.ru with my resume", "open the page for the Shutterstock image of the dog", "check the LM Arena leaderboard for the top open-source model right now" — and a LangGraph.js Plan-and-Execute agent runs the task inside one of your own browser tabs, using whatever sessions you're already logged into. No headless replay, no cloud VM, no copy-paste of credentials.
Forked from Nanobrowser (Apache-2.0) and reshaped into a LangGraph.js Plan-and-Execute runtime:
agentMode='unified')taskParameters (URLs / queries / names), each subgoal runs a focused ReAct step, replanner decides continue-or-finish[Browd]-prefixed tab; user tabs visible as metadata only; cross-over only via the explicit take_over_user_tab actionhitl_click_at escape hatch for isTrusted=false antibot wallsLegacy Planner+Navigator pipeline is still selectable via Options → Agent Mode for fallback.
chrome://extensions in Chrome/Edge/Brave).git clone https://github.com/wyddy7/browd
cd browd
pnpm install
pnpm build
Then load the dist/ directory as an unpacked extension (steps 3–7 above). pnpm dev runs a watch build; background and content-script changes still need an extension-card reload after each rebuild.
These are the constraints currently shipping. They are documented up front rather than buried, because the fixes are larger than the value:
visionMode='always' — each turn re-attaches a fresh screenshot at ~10–14k tokens, so usage compounds with turn count. The exact cost depends on your provider and model; Browd shows a live token ring so you can watch it as the task runs.isTrusted=false antibot walls. Any CDP / extension-driven click generates isTrusted=false MouseEvents. Hard-gated sites (LinkedIn /jobs filters, some Cloudflare gates, Google Images result tiles) silently no-op those clicks. Browd detects the loop within three attempts and offers hitl_click_at — the agent pauses and asks you to click the blocked element yourself, then continues.Local setup, repo layout, testing commands, and pull-request expectations live in CONTRIBUTING.md. The AI-agent contract for working in chrome-extension/src/background/agent/ is in CLAUDE.md.
Browd is derived from Nanobrowser, released under Apache-2.0. The Plan-and-Execute agent topology, LangGraph.js integration, and Chrome Web Store packaging path here diverge from upstream, but the inherited foundation — side-panel architecture, Planner+Navigator pipeline, untrusted-content wrap, and i18n scaffolding — is theirs.
The unified agent runtime uses LangGraph.js's createReactAgent and StateGraph. URL → markdown extraction goes through Jina Reader by default with a linkedom fallback.
Apache-2.0 — see LICENSE. Upstream copyright and license notices are preserved in this repository.
* The demo GIF at the top is sped up — the actual run took roughly three minutes. Agentic browser tasks are not instant; see Known limits for the honest performance picture.
TypeScript
89.1%
JavaScript
7.8%
CSS
1.8%
Open-source browser AI agent extension. ReAct loop, your own key, runs locally in any Chromium browser.
TypeScript
7
576 commits
updated Oct 1, 2026
Browser-resident AI agent. Lives in your Chromium side panel, uses your real session — not a headless cloud VM.
You type something into the side panel — "apply to the first AI Engineer job on hh.ru with my resume", "open the page for the Shutterstock image of the dog", "check the LM Arena leaderboard for the top open-source model right now" — and a LangGraph.js Plan-and-Execute agent runs the task inside one of your own browser tabs, using whatever sessions you're already logged into. No headless replay, no cloud VM, no copy-paste of credentials.
Forked from Nanobrowser (Apache-2.0) and reshaped into a LangGraph.js Plan-and-Execute runtime:
agentMode='unified')taskParameters (URLs / queries / names), each subgoal runs a focused ReAct step, replanner decides continue-or-finish[Browd]-prefixed tab; user tabs visible as metadata only; cross-over only via the explicit take_over_user_tab actionhitl_click_at escape hatch for isTrusted=false antibot wallsLegacy Planner+Navigator pipeline is still selectable via Options → Agent Mode for fallback.
chrome://extensions in Chrome/Edge/Brave).git clone https://github.com/wyddy7/browd
cd browd
pnpm install
pnpm build
Then load the dist/ directory as an unpacked extension (steps 3–7 above). pnpm dev runs a watch build; background and content-script changes still need an extension-card reload after each rebuild.
These are the constraints currently shipping. They are documented up front rather than buried, because the fixes are larger than the value:
visionMode='always' — each turn re-attaches a fresh screenshot at ~10–14k tokens, so usage compounds with turn count. The exact cost depends on your provider and model; Browd shows a live token ring so you can watch it as the task runs.isTrusted=false antibot walls. Any CDP / extension-driven click generates isTrusted=false MouseEvents. Hard-gated sites (LinkedIn /jobs filters, some Cloudflare gates, Google Images result tiles) silently no-op those clicks. Browd detects the loop within three attempts and offers hitl_click_at — the agent pauses and asks you to click the blocked element yourself, then continues.Local setup, repo layout, testing commands, and pull-request expectations live in CONTRIBUTING.md. The AI-agent contract for working in chrome-extension/src/background/agent/ is in CLAUDE.md.
Browd is derived from Nanobrowser, released under Apache-2.0. The Plan-and-Execute agent topology, LangGraph.js integration, and Chrome Web Store packaging path here diverge from upstream, but the inherited foundation — side-panel architecture, Planner+Navigator pipeline, untrusted-content wrap, and i18n scaffolding — is theirs.
The unified agent runtime uses LangGraph.js's createReactAgent and StateGraph. URL → markdown extraction goes through Jina Reader by default with a linkedom fallback.
Apache-2.0 — see LICENSE. Upstream copyright and license notices are preserved in this repository.
* The demo GIF at the top is sped up — the actual run took roughly three minutes. Agentic browser tasks are not instant; see Known limits for the honest performance picture.
TypeScript
89.1%
JavaScript
7.8%
CSS
1.8%