Stealth coverage (the fork's core value was leaking on secondary surfaces): - stealth scripts are registered per CDP session, so new tabs (`tab new`) and cross-origin iframe sessions created after the initial page had NO patches. Extract apply_stealth_via_mgr/apply_stealth_to_session and re-apply on tab_new and on iframe attach. Fixes automation markers (and FullLaunch UA) leaking in new tabs / cross-origin frames. Resource hygiene (temp profiles filled the disk): - ChromeProcess::drop already cleans the temp user-data-dir on normal exit, but a hard kill (kill -9 / version-mismatch restart / crash) skips Drop and leaks ~50MB per session. Add cleanup_orphaned_chrome_profiles() on daemon startup that sweeps agent-browser-chrome-* temp dirs NOT referenced by any live process (so an in-use profile is never deleted).
agent-browser-stealth
Stealth fork of agent-browser — connects to your real Chrome, shares your login sessions, and is undetectable by anti-bot systems.
For basic usage, commands, and API reference, see the upstream documentation.
Why this fork?
agent-browser launches a fresh browser with an empty profile. You need to log in again, and websites can detect it's automated.
agent-browser-stealth connects to your existing Chrome. Your cookies, sessions, and browser fingerprint are all real — because it IS your real browser.
| agent-browser | agent-browser-stealth | |
|---|---|---|
| Browser | Launches new Chrome | Connects to your Chrome |
| Login state | Empty, need to re-login | Your existing sessions |
| Fingerprint | Automation markers present | Your real fingerprint |
| User collaboration | Separate window | Same window, take over anytime |
| CAPTCHA | Agent stuck | You solve it, agent continues |
Install
npm install -g agent-browser-stealth
Install the AI agent skills
The repo ships SKILL.md files for Claude Code, Cursor, etc. Pull them into the current project with skills.sh:
npx skills add leeguooooo/agent-browser-stealth
This drops skills/agent-browser (and the specialized skill-data/{core,electron,slack,dogfood,agentcore,vercel-sandbox}) into your project so your AI agent gets the right usage patterns and pre-approved bash permissions for agent-browser, agent-browser-stealth, and abs.
Setup (one time)
Enable Chrome DevTools Protocol in your Chrome:
- Open
chrome://inspect/#remote-debuggingin Chrome - Toggle the switch on
That's it. This setting persists across Chrome restarts.
Usage
# Connect to your Chrome and navigate
agent-browser open https://example.com
# Everything works through your logged-in browser
agent-browser click "Post"
agent-browser fill "Title" "Hello World"
agent-browser screenshot ./page.png
The agent operates in your Chrome — you'll see tabs opening, pages loading, clicks happening in real time. You can take over at any point (e.g. solve a CAPTCHA), then let the agent continue.
Standalone mode
If you need a separate browser (CI, testing, etc.):
agent-browser --launch open https://example.com
In CI environments, standalone mode is used automatically.
Anti-detection
When connected to your real Chrome, we inject zero JavaScript patches. Your browser's fingerprint is completely genuine.
The only thing we do is call Emulation.setAutomationOverride via CDP to set navigator.webdriver = false at the native Chrome level — undetectable by lie-detection systems like CreepJS.
Test results (connected to real Chrome):
| Test site | Result |
|---|---|
| CreepJS | 0% stealth, 0% headless |
| bot.sannysoft.com | All green |
| Cloudflare Turnstile | Passed |
When using --launch mode (standalone browser), a full suite of 32 stealth patches is applied for headless Chrome.
Differences from upstream
Based on agent-browser v0.27.0. Changes:
- Auto-connect is default —
agent-browser open <url>connects to your Chrome instead of launching a new one - CDP-native stealth —
Emulation.setAutomationOverrideinstead of JS patches - Dual stealth mode — zero patches for real Chrome, full patches for
--launchmode --launch/--newflag — explicitly start a standalone browser- CI auto-detection — standalone mode when
CIenv var is set
All upstream features (commands, snapshots, screenshots, recordings, tabs, sessions, etc.) work the same. See the upstream repo for full documentation.
License
Apache-2.0 (same as upstream)