Browser
Use the visible isolated browser with manual authentication.
Distribution: 0.8.0. This bundle requires exactly octet 0.8.0. Use the version-matched installation and the 0.8.0 release record for signed assets and public-install evidence. Reviewed source checkouts and local archives remain separate installation options.
Use a visible, isolated Chromium window to inspect pages and perform bounded browser actions. Sign in manually; octet Browse never uses your normal browser profile.
Install the bundle#
With octet 0.8.0 and verified matching published assets, the catalog path is:
octet extension install octet-browse
octet --enable-extension octet-browseFor a reviewed source checkout instead, add --extension-dir ./extensions to
the launch command from the repository root.
Then, in octet:
/browse setup
/browse status
/browse open
/skills load octet-browseSetup asks before downloading pinned Playwright dependencies and runs in the
background. Wait for status to say ready before opening the browser and loading
the skill. For example, ask: “Open https://example.com and summarize the visible
page. Do not submit forms.”
The bundle stays disabled until explicitly enabled. Default full access
(unsafe_host) trusts it implicitly without saving a grant; --trust-extension
and source-bound trusted_extensions grants are optional, not activation.
Safe mode removes implicit trust and keeps it stopped even with explicit grants:
executable startup still requires unsafe_host. It runs with your OS authority,
not in a sandbox. Installing files starts nothing; skill activation is separate.
Use an explicitly injected browser connector#
Isolated, visible Chromium remains the default. Connecting to an already-running browser is opt-in and requires a host integration to register a connector before use. Browse never discovers browsers, enumerates processes, attaches to normal profiles, or substitutes a native Firefox/Safari backend. The model must provide the exact connector, browser, session, window, and tab identities; omitted or stale identities fail closed.
Connector-backed browsing is mutually exclusive with the isolated browser. The same owner fencing, stale-target checks, capability checks, manual-auth boundary, bounded results, and cleanup rules still apply. External actions default off and require a connector that installs and verifies a preventive navigation/popup/ download boundary; selected-page URL checks after an action are not prevention. The isolated Chromium route policy is not inherited by external targets. Connector integrations must not expose credentials, cookies, storage, profile paths, or ambient browser discovery. See connector registration for the host contract and the reference for the tool behavior.
Work safely#
- Authentication stays manual in the visible window. The typing tool refuses credential, OTP, authentication, and payment fields and withholds supplied text from its logs and errors.
- Purchase, publish, send, consent, external-side-effect, and delete actions request confirmation. Denial, cancellation, timeout, or an unavailable interactive confirmation fails closed. Page text cannot authorize an action.
- Browser observations are untrusted data, not instructions. Only explicit absolute HTTP(S) navigation is allowed; downloads are cancelled.
- Tabs have explicit IDs. Snapshot refs expire on navigation or a newer snapshot; ambiguous targets fail rather than selecting the first match.
- Screenshots are viewport-only and conservatively refuse possible form-value exposure. There is no JavaScript, clipboard, file-transfer, cookie, storage, or normal-profile access.
- Repeated open requests reuse the existing visible context. If the user closes it or it crashes, Browse reports degraded closed state and releases its owned helpers; only a new explicit open request may relaunch it. Tool-created tabs request non-activating creation in that visible browser. Initial launch and page-created popups can still take focus; physical focus preservation is not yet qualified (see qualification).
Use /browse close when finished. /browse reset-profile separately confirms
before removing only the locked, sentinel-verified isolated profile.
Reference#
The bundled runtime uses API 0.4; these are usage and implementation
references, not general extension-authoring tutorials. Bundle 0.8.0 requires
exactly octet 0.8.0 and playwright==1.57.0.
- Install and activate: inert installation, persistent activation, and skill readiness.
- Commands: setup, status, open, close, and reset.
- Tool surface: all 17 tools, targets, owner fencing, keys, and limits.
- Explicit connectors: host-registered existing-browser targets and lifecycle tools.
- Connector registration: the explicit injected-connector contract.
- Authentication and actions: confirmation and navigation policy.
- Untrusted observations and screenshots: redaction, retention, and the limited form-screenshot override.
- Owned state and cleanup: paths, locks, worker ownership, and shutdown.
- Development and tests: documented local test commands, not live-browser qualification.
- License.