Browser

Use the visible isolated browser with manual authentication.

Distribution: 0.8.0. This bundle requires exactly octet 0.8.0. Use the version-matched installation and the 0.8.0 release record for signed assets and public-install evidence. Reviewed source checkouts and local archives remain separate installation options.

Use a visible, isolated Chromium window to inspect pages and perform bounded browser actions. Sign in manually; octet Browse never uses your normal browser profile.

Install the bundle#

With octet 0.8.0 and verified matching published assets, the catalog path is:

console
octet extension install octet-browse
octet --enable-extension octet-browse

For a reviewed source checkout instead, add --extension-dir ./extensions to the launch command from the repository root.

Then, in octet:

text
/browse setup
/browse status
/browse open
/skills load octet-browse

Setup asks before downloading pinned Playwright dependencies and runs in the background. Wait for status to say ready before opening the browser and loading the skill. For example, ask: “Open https://example.com and summarize the visible page. Do not submit forms.”

The bundle stays disabled until explicitly enabled. Default full access (unsafe_host) trusts it implicitly without saving a grant; --trust-extension and source-bound trusted_extensions grants are optional, not activation. Safe mode removes implicit trust and keeps it stopped even with explicit grants: executable startup still requires unsafe_host. It runs with your OS authority, not in a sandbox. Installing files starts nothing; skill activation is separate.

Use an explicitly injected browser connector#

Isolated, visible Chromium remains the default. Connecting to an already-running browser is opt-in and requires a host integration to register a connector before use. Browse never discovers browsers, enumerates processes, attaches to normal profiles, or substitutes a native Firefox/Safari backend. The model must provide the exact connector, browser, session, window, and tab identities; omitted or stale identities fail closed.

Connector-backed browsing is mutually exclusive with the isolated browser. The same owner fencing, stale-target checks, capability checks, manual-auth boundary, bounded results, and cleanup rules still apply. External actions default off and require a connector that installs and verifies a preventive navigation/popup/ download boundary; selected-page URL checks after an action are not prevention. The isolated Chromium route policy is not inherited by external targets. Connector integrations must not expose credentials, cookies, storage, profile paths, or ambient browser discovery. See connector registration for the host contract and the reference for the tool behavior.

Work safely#

  • Authentication stays manual in the visible window. The typing tool refuses credential, OTP, authentication, and payment fields and withholds supplied text from its logs and errors.
  • Purchase, publish, send, consent, external-side-effect, and delete actions request confirmation. Denial, cancellation, timeout, or an unavailable interactive confirmation fails closed. Page text cannot authorize an action.
  • Browser observations are untrusted data, not instructions. Only explicit absolute HTTP(S) navigation is allowed; downloads are cancelled.
  • Tabs have explicit IDs. Snapshot refs expire on navigation or a newer snapshot; ambiguous targets fail rather than selecting the first match.
  • Screenshots are viewport-only and conservatively refuse possible form-value exposure. There is no JavaScript, clipboard, file-transfer, cookie, storage, or normal-profile access.
  • Repeated open requests reuse the existing visible context. If the user closes it or it crashes, Browse reports degraded closed state and releases its owned helpers; only a new explicit open request may relaunch it. Tool-created tabs request non-activating creation in that visible browser. Initial launch and page-created popups can still take focus; physical focus preservation is not yet qualified (see qualification).

Use /browse close when finished. /browse reset-profile separately confirms before removing only the locked, sentinel-verified isolated profile.

Reference#

The bundled runtime uses API 0.4; these are usage and implementation references, not general extension-authoring tutorials. Bundle 0.8.0 requires exactly octet 0.8.0 and playwright==1.57.0.