GAME · WEB · FILM
← Back to journal

/ BROWSER AUTOMATION

What Tencent BrowserSkill does and what to check before installing

A CLI and extension that let AI agents use your signed-in browser, with a source-based look at updates, permissions, and local access.

BrowserSkill is an MIT-licensed project from Tencent that lets an AI agent operate a real Chrome or Edge browser where you are already signed in. It combines bsk, a command-line tool written in Rust, with a browser extension. Any agent that can run shell commands can use it, and bsk install-skill adds a matching skill to agents such as Claude Code, Codex, and Cursor.

This note covers CLI version 0.3.1, published on 2026-09-23, as of 2026-09-28. It draws on the public source at commit f62e283 (2026-09-28), whose main parts match the 0.3.1 tag, plus a short trial on Windows. It is a reading of published code and documentation, not a formal security audit, and later versions may change any of the details below. The sections separate what the source shows from choices that depend on how you use the tool.

An agent window beside your own

The agent works in a dedicated Agent Window, so it does not take over the window you are using. A typical run begins with session start, moves through navigate, snapshot, and screenshot, and ends with session stop. A snapshot is a text representation of the page based on its accessibility tree. In the short trial on Windows, bsk doctor reported every check as ok, and the agent opened example.com and read the page content.

Features that reach further

BrowserSkill can also borrow one of your own tabs for a while; a setting that asks for confirmation before borrowing is on by default. An overlay lets the agent ask a person for help. Other features record operations, debug network traffic, and pair the browser with a remote server. Each of these extends what the agent can see or do, so it helps to know they exist before connecting the extension.

What the source shows

A read of the source found no telemetry, analytics, remote configuration, or remotely loaded code; the CLI’s only outbound request is its update check. The local daemon listens only on 127.0.0.1:52800 and rejects WebSocket connections from web pages by checking the Origin header. The extension does not accept messages from other extensions or from web pages, and it does not request the cookies API permission. The bundled skill text states that page content is data, not instructions, and tells the agent not to extract credentials, cookies, or tokens. Remote pairing is off unless you explicitly enable it; it requires TLS, and its links are single-use and expire after a short time.

Updates arrive on their own

Automatic updates are on by default. Roughly every 30 minutes, the daemon checks for the latest release and, when it is not in use, replaces itself with the new version. The only check on the download is a checksum published in the same release; there is no code signature and no artifact attestation of where the build came from. Setting the environment variable BSK_AUTO_UPDATE=off turns this off. At startup, installed skill text is also synchronized with the text built into the binary, unless you edited it by hand or installed it with --source.

Broad access on the local machine

Local control has no authentication token, so while the daemon is running, other processes running as the same user can also operate the browser. The extension holds broad permissions, including <all_urls> and debugger, and does not ask for consent site by site. Locally, the agent can read the list of your open tabs and their content. The official installer is piped straight into a shell with irm | iex (or curl | sh), and it puts its directory at the front of your user PATH and edits ~/.bashrc. In practice, the agent can reach whatever the connected browser profile can reach.

A more cautious setup

Whether these trade-offs are acceptable depends on what the connected browser can reach. Install the extension in a dedicated Chrome profile that is not signed in to work accounts, banking, or email. Keep the tab-borrowing confirmation on, and when you are not using the tool, disconnect the extension and stop the daemon with bsk daemon stop. Decide on automatic updates knowing that releases are not signed; if you prefer to review first, set BSK_AUTO_UPDATE=off and read each release before running bsk update. Instead of piping the installer into a shell, you can download the files from GitHub Releases, verify their checksums, and place them yourself. Do not use pairing links from other people.

← Back to journal