Browser automation and safety

Letting it act in your browser, and the per-site allow, ask and block controls that bound it.

The companion can act in your browser: read a page, click, type, navigate. Because that is a real capability, the permission model is strict.

What it can do

Input is delivered as genuine browser input rather than synthetic events, so pages behave exactly as they would with you at the keyboard.

The permission model

Permission is per origin, with three states:

Three rules make this hold:

  1. Interact requires an explicit allow. Reading may proceed under ask; acting on a page never happens without you having allowed that origin.
  2. There is no global override. You cannot allow everything at once. Every origin is decided on its own.
  3. The blocklist beats an allow. Banking, payments, webmail, health sites and government domains are refused even if you allowed them. An over-broad permission cannot expose those.

Revoking

Change an origin back to ask or block at any time. Decisions persist until you change them.

Why it is built this way

An agent with your browser has your identity everywhere you are signed in. The design assumes a mistake will happen and bounds the damage: default to asking, require deliberate consent to act, and put certain categories out of reach entirely.

Next