Pairing controls which browser, not which program
Anything running as your user can read Browsentic Bridge’s lockfile and drive a browser you already paired. Your user account is the trust boundary.
Security
The agent works in your signed-in accounts, so each layer below narrows what it can reach. The two risks no layer removes are at the end.
Connecting
Any web page can open a WebSocket to 127.0.0.1, so Browsentic Bridge checks who is calling before anything else.
Browsers set it and page scripts cannot forge it, so a web page is refused before any credential is read. A Host that is not loopback is refused too, which stops DNS rebinding.
Pairing takes a single-use code that expires in ten minutes. Both sides prove they hold it over fresh nonces, so a program squatting on the port cannot pose as Browsentic Bridge.
Pairing leaves a key bound to that browser. It survives restarts and updates until you run browsentic revoke.
Acting
Reading and clicking need no approval. Anything that commits something or sends data somewhere stops and says what it is about to do.
Deny is final: the agent is told to stop, not to look for another way. A card the agent stops waiting for comes down, so a late yes never runs anything. An MCP client has nobody to ask, so anything that would ask is refused for it by default.
Reading
A hostile page can try to talk the agent into something, so page text is changed before the model reads it, and the run is held to its sites.
Page text arrives inside a marker that is random every time Browsentic Bridge starts, so a page cannot fake the end of it and pass as your instructions.
Passwords, API keys, tokens and card numbers become placeholders. The value stays in your browser and goes back only into a field you approve.
A run stays on the sites it started on or that you named. Going anywhere else asks you, and nothing read from a page can widen the list.
On your computer
The side panel starts a third-party agent CLI as you. Browsentic narrows what that process can touch, as far as each CLI allows.
claude
Claude Code, the strictest
Each CLI offers different levers: Claude Code’s allowlist is the strictest, Codex can still read files through its read-only sandbox, and Antigravity follows your own settings.
Cloud keys, registry tokens and database URLs from your shell are removed before the agent starts. It keeps only what it needs to sign in.
A recording stores which field you filled, not what you typed. Keeping real values is a per-recording choice, off by default.
Keys, logs and config live in ~/.browsentic, readable only by you. Skills, recordings and screenshots live in ~/browsentic.
No speech model is downloaded. In Chrome, audio goes to Google to become text, and Browsentic only receives the text.
Limits
Neither is a bug with a fix on the way. Read both before you rely on Browsentic.
Anything running as your user can read Browsentic Bridge’s lockfile and drive a browser you already paired. Your user account is the trust boundary.
Fencing, scope and approvals make it harder, not impossible. A persuasive page can still mislead the agent, so keep approvals on and be deliberate on sites you do not trust.
Questions
As safe as the limits you keep on it. Browsentic connects to nothing until you pair it, asks before anything that submits, uploads or leaves the site, keeps passwords away from the model and fences page text as data. No layer makes a model immune to a persuasive page, so keep approvals on for anything that matters.
No. Browsentic Bridge refuses any connection whose Origin is a web page, and browsers set that header themselves. An extension still needs a pairing code or session key, and neither ever crosses the wire.
The agent does not. A password, API key, token or card number on a page is replaced by a placeholder before the result leaves the browser, and the value is typed back only into a field you approve. Browsentic Bridge never holds it.
It is started with the browser’s tools and, as far as its CLI allows, without a shell or file access. Claude Code’s allowlist is the strictest; Codex can still read files through its read-only sandbox, and Antigravity follows your own settings.
There is no Browsentic server. The extension talks only to Browsentic Bridge on 127.0.0.1, and the Bridge starts your agent CLI, which talks to its own model provider as it always does. In Chrome, voice input goes to Google to become text.
Open a private GitHub security advisory rather than a public issue, so it is looked at before anything is published.
Free and open source under Apache 2.0, with no API key, subscription or account. One line installs Browsentic Bridge and opens the extension’s store page. Nothing connects until you pair the two.