Verune

Plugin

browser-harness

Open-source browser agent driven via CDP — direct browser control, 79K stars, YC W25. browser-harness gives Claude Code direct, low-level control of a real Chrome browser via the Chrome DevTools Protocol. Coordinate-level clicks pass through iframes, shadow DOM, and cross-origin frames at the compositor level — no selector hunting, no Playwright wrappers. Connects to a long-running Browser Use Cloud or local browser session, so logins persist across runs. Highlights: - Screenshot-first workflow: capture → read pixel → click_at_xy → re-capture to verify - Bulk HTTP fetch helper for static pages (no browser overhead) - Raw CDP escape hatch for anything helpers don’t cover - Interaction skills for dialogs, dropdowns, iframes, shadow DOM, file uploads, cross-origin frames - Remote browsers via Browser Use Cloud — share a live URL with a human when login/CAPTCHA blocks the agent

Analysed
Last observed

What the code does

  • Runs shell commands Code that starts system commands on the machine it runs on.
  • Downloads and runs code Code that fetches a script and pipes it into a shell.
  • Evaluates code at runtime Code that builds and runs code while it executes.

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

4 findings from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment