by aindeev
Let your AI agents use your Chrome, signed in as you, in background tabs. By Alexey Indeev · blog: read.aindeev.com · X: @AlexeyIndeev
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
# Add to your Claude Code skills
git clone https://github.com/aindeev/agent-chrome-relayGuides for using ai agents skills like agent-chrome-relay.
See how agent-chrome-relay compares with popular alternatives.
Website: https://agent-chrome-relay.aindeev.com
Lets your coding agents (Claude Code, Codex, Cursor, Paseo) use your everyday Chrome, with your real logins, from the command line, in background tabs: nothing takes focus, no dialogs, ~0.15s per command.
agent-browser --cdp "$(chrome-relay url you@company.com)" open https://app.example.com/
agent-browser snapshot -i # the page's buttons, links and fields, each with a ref like @e5
agent-browser click @e5
agent-browser close
It's opt-in: nothing installs the extension for you, and it only runs on Macs whose owner set it up.
agent-browser (CLI) ──ws──▶ relay (127.0.0.1:9333, LaunchAgent) ──ws──▶ Chrome Relay extension ──chrome.debugger──▶ agent tab
extension/, MV3, one per Chrome profile you load it in): opens each agent tab inactive
in a collapsed "Agents" tab group and runs DevTools commands in it via chrome.debugger. No remote-debugging
port, so Chrome never shows "Allow remote debugging?". Chrome does show "Chrome Relay started debugging this
browser" while agents work.relay/relay.mjs): a DevTools endpoint per agent. Each agent sees and controls only the tabs it
opened; commands that could raise or focus the browser are swallowed.bin/chrome-relay): setup, the connection URL, diagnostics, audit trail.Fastest: paste this prompt into Claude Code, Codex or Cursor and let your agent do it. By hand:
Needs macOS, Google Chrome, Node.js 20+ and agent-browser
(npm i -g agent-browser).
git clone https://github.com/aindeev/agent-chrome-relay
cd agent-chrome-relay
bin/chrome-relay setup # secret, background service, identities, `chrome-relay` on PATH, Claude Code skill
Then, in each Chrome profile agents should use: open chrome://extensions, turn on Developer mode,
Load unpacked, and pick the extension folder of your clone. Check with chrome-relay doctor.
After git pull: chrome-relay update (restarts the relay, reloads the extension in every profile).
To remove: chrome-relay uninstall, then remove the extension in each profile.
Claude Code: setup links the skill (skill/SKILL.md) into ~/.claude/skills/chrome-relay, so every
repo gets it. Codex, Cursor and others: point them at the same file, e.g. a line in your global
~/.codex/AGENTS.md: "For any browser step that needs my logins, follow
<path>/agent-chrome-relay/skill/SKILL.md." A repo's CLAUDE.md/AGENTS.md only needs a
one-line pointer to the skill.
Two checks on every agent connection:
~/.chrome-relay/token (mode 600) and embedded in the URL
that chrome-relay url prints.lsof, ps) and checks the markers those apps set in their child processes
(CLAUDECODE, CODEX_*, CURSOR_*, PASEO_AGENT_ID), then its parent processes.Connections that carry a browser Origin header (a web page) are refused even with the secret. Only this
checkout's extension may connect as the extension: Chrome derives an unpacked extension's ID from its folder,
setup records that ID in ~/.chrome-relay/config.json, the relay checks the connection's
Origin: chrome-extension://<id> (which pages cannot fake), and the connecting process must be Chrome.
This keeps other local tools, web pages and accidents out. It is not a boundary against malware already running as you, which could read the secret and fake the markers.
Agents never type credentials. When a site bounces through Google and the right account is already signed
in, the extension clicks the account and Continue/Allow itself (page scripting, so it works even with
1Password's frame on the page). A password, passkey, 2-step screen or signed-out account stops the hop, and the
agent gets SIGN-IN NEEDED: ... and asks you to sign in in your own window.
Which Google account a site uses comes from ~/.chrome-relay/identities.json (chrome-relay identities):
your Chrome profiles (filled in by setup), optional hand-set sites.rules, and sites.learned, which the
relay fills in after each successful hop. Default: the profile's own account.
Every agent action is recorded in ~/.chrome-relay/audit/YYYY-MM-DD.jsonl; read it with chrome-relay audit:
who connected (app, Claude/Paseo session id, working folder, AGENT_BROWSER_SESSION), pages, clicks with
positions, special keys, the agent's own scripts, screenshots, uploads, popups, sign-in clicks and blocked
pages. Typed text is stored only as a character count, and URLs lose their query string.
target=_blank links open as new hidden tabs owned by the same agent; popup sign-in flows
that postMessage back to the opener and close themselves keep working. Message origins are the ones the relay
saw each tab load (never what the page claims), and targetOrigin is enforced. A safety net adopts any tab an agent
page opens anyway and hands focus back to the tab you were on.cd relay && npm install && npm test # who may connect: secret, allowed apps, Chrome-only extension, audit
Logs: chrome-relay logs (~/.chrome-relay/relay.log). Testing extension changes: edit extension/, then
chrome-relay update. CHROME_RELAY_HOME and CHROME_RELAY_PORT override the data folder and port.
Made by Alexey Indeev, co-founder and CTO of Spare. I write about building more with AI, whether you code or not, at The Leveraged Mind.
Questions, ideas or bugs: open an issue or reach out on X.
MIT. See LICENSE.
agent-chrome-relay is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by aindeev. Let your AI agents use your Chrome, signed in as you, in background tabs. By Alexey Indeev · blog: read.aindeev.com · X: @AlexeyIndeev. It has 54 GitHub stars.
agent-chrome-relay's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/aindeev/agent-chrome-relay" and add it to your Claude Code skills directory (see the Installation section above).
agent-chrome-relay is primarily written in JavaScript. It is open-source under aindeev on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh agent-chrome-relay against similar tools.
No comments yet. Be the first to share your thoughts!