auto-connect resolved the DevToolsActivePort URL by first opening a verification WebSocket (verify_ws_endpoint: connect, Browser.getVersion, close) and only then opening the real connection. On Chrome 136+ the "Allow remote debugging?" consent is granted per-connection, so the user's single Allow click was consumed by the throwaway probe and the real connection (opened afterwards) asked again — surfacing as repeated prompts or a hung command after the user had already clicked Allow. resolve_cdp_from_active_port now gates the direct DevToolsActivePort URL on a consent-free TCP liveness check (tcp_port_alive) instead of a WebSocket probe, so the real connection is the single WebSocket the user consents to. A bare TCP connect does not trigger the consent flow (that fires on the CDP upgrade), and the real connect_async has no client-side timeout, so it waits for the user to click Allow at their own pace. verify_ws_endpoint removed; discovery-order tests updated, plus a guard test that resolution opens no WebSocket. Verified live: single prompt on a real Chrome attach, then open + eval + scroll x2 + eval with zero re-prompts and no freeze.
agent-browser-stealth
Stealth fork of agent-browser — connects to your real Chrome, shares your login sessions, and is undetectable by anti-bot systems.
For basic usage, commands, and API reference, see the upstream documentation.
Why this fork?
agent-browser launches a fresh browser with an empty profile. You need to log in again, and websites can detect it's automated.
agent-browser-stealth connects to your existing Chrome. Your cookies, sessions, and browser fingerprint are all real — because it IS your real browser.
| agent-browser | agent-browser-stealth | |
|---|---|---|
| Browser | Launches new Chrome | Connects to your Chrome |
| Login state | Empty, need to re-login | Your existing sessions |
| Fingerprint | Automation markers present | Your real fingerprint |
| User collaboration | Separate window | Same window, take over anytime |
| CAPTCHA | Agent stuck | You solve it, agent continues |
Install
npm install -g agent-browser-stealth
Install the AI agent skills
The repo ships SKILL.md files for Claude Code, Cursor, etc. Pull them into the current project with skills.sh:
npx skills add leeguooooo/agent-browser-stealth
This drops skills/agent-browser (and the specialized skill-data/{core,electron,slack,dogfood,agentcore,vercel-sandbox}) into your project so your AI agent gets the right usage patterns and pre-approved bash permissions for agent-browser, agent-browser-stealth, and abs.
Setup (one time)
Enable Chrome DevTools Protocol in your Chrome:
- Open
chrome://inspect/#remote-debuggingin Chrome - Toggle the switch on
That's it. This setting persists across Chrome restarts.
Usage
# Connect to your Chrome and navigate
agent-browser open https://example.com
# Everything works through your logged-in browser
agent-browser click "Post"
agent-browser fill "Title" "Hello World"
agent-browser screenshot ./page.png
The agent operates in your Chrome — you'll see tabs opening, pages loading, clicks happening in real time. You can take over at any point (e.g. solve a CAPTCHA), then let the agent continue.
Standalone mode
If you need a separate browser (CI, testing, etc.):
agent-browser --launch open https://example.com
In CI environments, standalone mode is used automatically.
Anti-detection
When connected to your real Chrome, we inject zero JavaScript patches. Your browser's fingerprint is completely genuine.
The only thing we do is call Emulation.setAutomationOverride via CDP to set navigator.webdriver = false at the native Chrome level — undetectable by lie-detection systems like CreepJS.
Test results (connected to real Chrome):
| Test site | Result |
|---|---|
| CreepJS | 0% stealth, 0% headless |
| bot.sannysoft.com | All green |
| Cloudflare Turnstile | Passed |
When using --launch mode (standalone browser), a full suite of 32 stealth patches is applied for headless Chrome.
Differences from upstream
Based on agent-browser v0.27.0. Changes:
- Auto-connect is default —
agent-browser open <url>connects to your Chrome instead of launching a new one - CDP-native stealth —
Emulation.setAutomationOverrideinstead of JS patches - Dual stealth mode — zero patches for real Chrome, full patches for
--launchmode --launch/--newflag — explicitly start a standalone browser- CI auto-detection — standalone mode when
CIenv var is set
All upstream features (commands, snapshots, screenshots, recordings, tabs, sessions, etc.) work the same. See the upstream repo for full documentation.
License
Apache-2.0 (same as upstream)