Skip to content

Latest commit

 

History

82 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Devthink

Devthink is a consent-first browser-agent bridge distributed as a TypeScript library and a Chromium Manifest V3 extension. It turns a user-provided browser objective into a bounded, reviewable plan. The user must start the active-tab session and approve the plan before any page action reaches the browser.

Version: 1.1.62. License: GPL-3.0-only. The repository is wenathlan/extension; the npm-compatible scoped package identifier is @wenathlan/extension.

What it does

Capability Behavior in 1.1.62
Active-tab session The user starts a short-lived session for one HTTPS tab and one origin; the session records its origin grants.
Page observation The extension captures the complete semantic inventory: every interactive element, every form control, every select option and the full page text.
Plan proposal A local plan can be created immediately; an optional user-configured HTTPS endpoint can return a typed plan proposal of any length.
Review gate Every remote proposal starts in pending; it cannot reach the page bridge before explicit approval.
Browser tools Reviewed plans cover three hundred thirty four action kinds: pointer paths and coordinate clicks, text, aria, name, xpath, index and point target resolution, timed typing, key holds, sliders, dates, colors, shadow dom piercing, iframe entry, dialog answering, retry rules, a complete read vocabulary with clickable maps and verification reads, page mutation under review, and browser-level tab, window, zoom, snapshot and download commands.
Forms and data The agent fills forms with review: fillform fills from a structured record of field matches, kinds and values, filllabel and fillplaceholder match controls by label, placeholder or aria label, detectfields reports the form map with field kinds, generatevalues seeds locale aware values per field kind while real looking card numbers and personal identifiers are refused, saveprofiles stores profiles behind origin grants, asksubmit opens the submission prompt with the values diff, submitform submits only under an approved consent ref, readerrors associates inline validation messages with fields, retryform retries with reviewed backoff windows, runwizard, selectchain, picktypeahead and pickdate drive wizards, dependent selects, typeaheads and calendars, attachfile attaches run store artifacts, fillcard, fillcode and consentpassword handle payment and secret fields behind explicit consent, skiphoneypot skips trap fields, detectlogin and detecttemplate flag login, signup and checkout shapes, and handoffcaptcha pauses the plan and hands control back to the user.
Media capture The agent sees the page as evidence: shotview captures the visible viewport in the reviewed format, quality and pixel ratio, shotfullpage stitches viewport tiles on an offscreencanvas with linear overlap blending, fixed header skipping, hidden capture scrollbars and a stitching scroll budget kept inside the reviewed wait window, shotelement crops the pixel ratio scaled element rect with a tiled fallback when the element crosses the viewport edge, shotregion requires the explicit reviewed flag for every reviewed region rectangle and walks scrollable containers in reviewed steps, contactsheet tiles element captures into one labeled grid, annotated captures carry the step number marker, the target outline and a time and url footer, beforeafter capture pairs a before and after shot around every page moving action with the dom snapshot id of the same moment, capture names stamp from run, step, sequence and kind segments with per run counters, and export routing stays consent layered: memory keeps the bytes under the user configured capture retention window while the metadata survives, clipboard export needs clipboardwrite and download export runs through the reviewed download flow.
Documents and moving media The agent captures documents and moving media behind the same gates: capturepdf composes a derived pdf report from page segments with reviewed paper size, margins, scale, landscape orientation and break point pagination named with the capture naming rule, recordscreen and captureaudio are sensitive recordings of user activity that need an approved recording consent prompt per start, run inside the user configured recording window and stop cleanly at run end — deriving an ordered frame sequence and an honest manifest from viewport captures instead of encoded screencast bytes because tabCapture stays outside the manifest — captureframe seeks a video to the reviewed timestamp and grabs the still frame, downloadimages matches a reviewed imagefilter, deduplicates urls and downloads through the reviewed flow, shotcanvas reads 2d and webgl canvas buffers, probestream reports webrtc track details read only, readmedia and readassets extract embedded media sources and page assets, timelapse captures an ordered lapse inside the reviewed wait budget, and convertimage and makethumbs transform stored captures between formats and into reviewed thumbnails.
Network observation The agent speaks to the network with consent: fetchurl retrieves a reviewed HTTPS url from the extension context behind the origin grants with reviewed timeout, retries, backoff and redirect follow limits kept inside the reviewed wait budget, custom header allowlists need a per origin consent that names them (credential bearing headers always), large bodies stream chunk by chunk inside a user configured byte budget, parsejson extracts named fields from stored bodies through dotted json paths with reviewed defaults and honest miss outcomes, parsehtml runs reviewed selectors over fetched markup through the page bridge domparser, and the sensitive callrest and callgraphql kinds run typed endpoint calls with payload schemas, url templating, reviewed success status classes and graphql data and error unwrapping, with stored api key references attaching secrets only inside their origin scope; header values and body bytes never enter the audit trail.
Sockets, streams and page apis The agent listens to the network with consent: opensocket opens a wss websocket channel behind the socket gate with reviewed protocols, reconnect budget and exponential backoff capped at the user configured ceiling, sendmessage publishes a reviewed payload on a named stream of an open channel (sensitive), waitmessage waits on the reviewed stream, json path and match limit filter, subscribesse opens a server sent events stream that resumes from the last event id and cancels on its reviewed path, longpoll walks a reviewed cursor loop that stops on its stop condition, cancellation or plan expiry, watchrequests observes the requests of the run tab derived from the page timing buffers behind the webrequest grant with one correlation id per request and honest error classes, readheaders reads captured headers through a required allowlist and redaction list, capturebodies stores matched bodies inside the reviewed byte ceiling (sensitive when private mime types are listed), mapapi ranks the page api endpoints by frequency, json share and payload stability, and extractapi replays a captured endpoint with reviewed overrides and extraction paths, read only when the replay verb is read; the network view lists every exchange with correlation ids, live channel state, event names and poll cursors, and payload values, header values and body bytes never enter the audit trail.
Network control The agent takes the steering wheel with consent: blockrequest registers reviewed block rules with origin patterns and the explicit reviewed flag behind the blockgate, mockresponse serves reviewed fixtures with their full body, rewriteheaders applies set, append and remove header rules with audited provenance, setcookies, readcookies and clearcookies run behind the cookiegate through the page cookie jar of the granted domain, authflow runs a reviewed oauth flow with a consent tab, code capture on the granted redirect origin, token exchange and refresh behind storage ids, saveapikey stores key entries behind explicit consent with last use timestamps, routeproxy applies a run-scoped route with a bypass list behind the proxygate, and postform and postfiles submit rate limited urlencoded forms and streamed multipart uploads of reviewed files; every rule reverts the moment the run ends, fails or is cancelled, and header values, cookie values, key material, token values and file contents never enter the audit trail.
Run timeline The agent records what pages say and how they misbehave: watchconsole captures console output at every reviewed level through page-injected console hooks with a required redaction pattern list applied before any text leaves the page bridge, object arguments serialize through a reviewed depth bound, spam detection collapses repeats into counts with flagged thresholds and log rotation moves overflow to the reviewed target store without data loss, watcherrors captures javascript errors with stack frames, unhandled rejections with reasons and resource load failures with element context behind the stack gate, and watchtasks observes longtask entries with attribution names and blocking duration per step window; every watch runs read only behind the timeline gate that scopes capture to the run tab with a reviewed window kept inside the reviewed wait budget, console capture prompts once per origin, watchers cancel on run cancel and the killswitch and detach when the tab navigates or closes, failed requests of the run join the timeline, and the console diff view compares two runs into added, removed and repeated lines while level count summaries survive the retention window.
Debugger attach The agent attaches a devtools-style session with consent: attachcdp enables only the reviewed domains of the reviewed domain grammar behind the debuggate and the per origin debugger consent prompt that shows the domain allowlist, every attach carries its reviewed teardown plan of revert steps and resume policy, cdpcmd sends raw reviewed commands of the Domain.method form that serialize per session in send order with duration and error class results (protocol errors fail the step), watchcdp forwards matched domain events into the run timeline for a reviewed lifetime window, setbreakpoint registers reviewed instrumentation hooks with conditions of the reviewed expression grammar behind the user configured breakpoint ceiling, stepcode steps paused probes through stepover, stepinto, stepout and resume while capturing pause states with call frames and the dom snapshot through the page bridge, watchexpr evaluates reviewed expressions at every pause and stores the values with their pause scope, and overridescript applies reviewed page script fixtures on new document evaluation that revert at run end; the debugger permission deliberately stays outside the manifest, so the whole family runs through the page-instrumented harness injected by the scripting api with the honest derivation recorded on every session, every breakpoint and override reverts on run end, failure, cancellation, tab navigation and the user detaching the debugger — which pauses the run for review — and command params, fixture sources and token values never enter any report or the audit trail.
Profiling The agent measures what the run is made of with consent: measureflow marks the start and end of every step of the reviewed flow window and measures navigation, paint, largest contentful paint, first input delay, interaction timings and the blocking time summed per step window from the performance buffers, heapshot snapshots the used and limit heap bytes with the dom node count on demand under the user chosen interval only, trackmemory samples the heap beside every following step, computes the growth trend slope and flags the steps above the reviewed slope with timeline warnings, profilecpu ranks the hot functions of the profiled window by accumulated sampled time, watchshifts records layout shift scores with their impacted selectors, traceload records a trace under the reviewed category list that stops at the reviewed window end and exports through the reviewed download flow under the user configured byte ceiling, annotatetrace aligns step ids and labels with the run timeline so exported traces never lose their annotations, replaytrace renders the stored file offline grouped by category and step, and capturesourcemaps fetches and parses the map files of the loaded same origin scripts behind the per origin consent with stack rewriting through a minimal mapping lookup; every profiling kind runs behind the targetgate with the approved debugger grant of the origin, attachcdp accepts reviewed iframe, worker and service worker targets with flattened sub sessions inside the granted origins, the heavy bytes expire after the user configured profile retention while the counts, hot functions, category lists and annotations survive, and the debugger permission deliberately stays outside the manifest — every derivation is recorded on each record and the changelog says so.
Emulation The agent wears reviewed masks with consent: emulatedevice applies a user curated device preset of width, height, pixel ratio and the mobile flag to the run tab and reloads only when the reviewed plan asks, emulatenetwork applies latency, download and upload bounds and the offline window of the reviewed plan to the traffic the extension itself initiates, emulatelocate overrides navigator geolocation with the reviewed coordinates behind an explicit per origin location consent whose prompt shows the exact latitude and longitude, setuseragent applies the reviewed user agent string, platform and brand list together scoped to the run tab only, overridepermission answers navigator permission queries of the reviewed browser permission set with the granted, denied or prompt state graded by name while the prior state restores at run end, and blackboxscripts marks third party url patterns as blackboxed in traces and hides their frames from captured stack traces, read only; every emulation kind runs behind the emugate (live session on the run tab, approved plan, the explicit reviewed flag and a reviewed revert plan beside every layer), layers stack only while the reviewed plan lists their steps with the last applied winning conflicts, every layer records the prior page state for the exact revert and the whole stack reverts in reverse order at run end, failure, cancellation, tab navigation and tab drop, the emulation state survives service worker restarts through the run record, the device, network, location and agent preset libraries stay user curated data with versioned import and export files through review, and the reverted prior states expire after the user configured retention while the layer history always survives — the debugger, geolocation and notifications permissions deliberately stay outside the manifest, so every mask is a page-injected derivation recorded honestly on each layer and in the changelog.
Session memory Every run becomes survivable with consent: persiststate checkpoints the task state of the run after every completed step with a checksum that detects corruption before any resume and the run resumes from the checkpoint after a service worker or browser restart, capturesession snapshots the full browsing session beyond tabs and windows into per tab scroll positions, non password form state, and the local storage and cookie names of granted origins through the reviewed section toggles, restoresession reopens the saved tabs in their recorded order with the scroll and form state restored behind an explicit restore review that lists every tab, form field and capture first and skips origins whose grants expired with a report, namedsessions files sessions under unique names, folders and tags, diffsessions classifies tab, url, form and storage changes of two saved sessions as read only evidence, searchsessions matches urls, titles, names and captured text inside a reviewed time window, exportsessions packs records into a versioned checksummed session file through the reviewed download flow and importsessions adds records only after the full record review of the known format version — the auto snapshot interval, snapshot count, expiry and retention stay pure user choices with no code ceiling, crash restore prompts stay inside the session consent model, and the manifest permissions stay unchanged.
Workflow engine Steps compose into workflows with consent: composeworkflow validates the name, version, granted HTTPS origins, steps and reusable blocks, expands every nested block before review so no step stays hidden, grades the record by its worst step and freezes it, savetemplate shares one reviewed step across workflows, runworkflow executes the expanded list one step at a time behind the live session, approved plan, origin grants and the explicit run review flag with a checkpoint after every completed step that survives service worker restarts, dryrun evaluates every step read only through per kind projections and refuses mutation steps without one, delay sleeps a seeded jitter window with long delays riding the alarms api when the browser exposes it, waitelement polls a selector until appearance, the reviewed timeout or a clean abort on tab navigation, compute evaluates expressions of arithmetic, comparison, logic, text, contains and length operators with operand coercion, and extractvars stores regex named captures as variables with the no match case reported honestly — typed scopes stack per block with shadowing, bindings link earlier outcomes to named variables, ${name} interpolation substitutes scope values into targets, values and options, and 1.1.51 adds the control flow family: condition evaluates a reviewed boolean expression over the extracted values with no page side effect, branch chooses the first matching path by page state (pageurl, pagetitle and pageready) with a mandatory else path so every branch terminates, loop, repeatuntil, whileloop and foreach iterate lists, convergence conditions, bounded while conditions and matched elements rebinding the deep copied item and index variables per iteration inside user configured safety bounds with no code ceiling, parallel runs branches concurrently in isolated scopes that the join merges under the first, last or fail strategy over conflicting writes with cancel or continue on branch failure, and trycatch wraps fragile steps with a catch handler, rerun option, retry policy of user configured attempts over fixed or exponential seeded backoff and the reviewed error classes, and per step and per run timeout budgets whose aborts carry the cancelled error class — composition validates every control payload, collects every nested child step so no construct hides a step and grades the record by its worst child, single step execution runs one chosen step outside the run loop, pause, resume and cancel record their reasons, runlogs keep under the user configured retention with no code ceiling, control decisions persist for audit, and the manifest permissions stay unchanged.
Triggers and scheduling Reviewed workflows start themselves with consent: visitrule fires on navigations to reviewed HTTPS origins, urlrule matches glob patterns where * spans one path segment and ** spans across segments with explicit ports honored, menurule binds a context menu entry, keyrule binds a keyboard shortcut command, buttonrule binds the toolbar button, cronrule schedules five field cron expressions with named weekdays and months and optional timezones resolved through the runtime database, intervalrule fires every reviewed period with a seeded jitter spread, urllistrule plans one run per url of a reviewed list, webhookrule verifies a shared secret over the entropy floor and a payload schema in constant time before anything persists, and eventrule subscribes to observed page events of the catalog (mutate, focus, banner, console, error, navigate) — every rule arms behind the explicit arm review that renders its match fields and bound workflow first, grades sensitive, and every launch re-passes the live session, approved plan and origin gates through the same run machinery as a reviewed runworkflow step with the triggering url, title and payload as seed variables; cooldown windows, interval periods with jitter and the fire record retention stay user choices with no code ceiling, the dedupe keeps one pending fire per rule while a run is active, the queue holds fires that arrive while the run is busy or the session is paused and drains in arrival order on resume, the manual run step preview renders every expanded step with its control summaries before confirmation, scheduling persists through chrome.storage and opportunistic wakes with the alarms api riding the browser only when exposed without a declared permission, and the manifest permissions stay unchanged.
Workflow editor Reviewed workflows get a visual home with consent: the canvas renders steps as nodes with typed binding sockets and blocks as containers with nested child steps, drag and drop snaps onto the reviewed grid and the nearest block column, the palette lists curated drop blocks across actions, control flow, waits, variables and triggers with search, the step library browses every reviewed kind grouped by category with its option schema, the step inspector edits options, bindings and nested params, the variable inspector lists scopes and values, the mini map projects the full canvas with click navigation and the zoom keeps step labels readable, undo and redo cover every canvas edit, and every save passes the editorsavegate of a live session, an approved plan, unique node ids, forward only edges and the full composeworkflow grammar so no editor artifact bypasses review — breakpoints mark any step for debug runs that pause before it and resume exactly there, version timelines carry change notes with diffs of added, removed and changed steps and rollbacks that grade unreviewed until the rollback review approves them, imports grade unreviewed until the import review approves the expanded step list, exports and share bundles ship as json or yaml with the export content review refusing any secret, token, api key, password or authorization field so secrets never leave the browser, background runs keep executing with the panel closed while every step checkpoints and every worker wake restores them through the same gates, the watchdog recovers stalled runs by the user configured retry, pause or cancel and reaps zombie runs of browser shutdowns with thresholds and windows as pure user choices with no code ceiling, run history keeps outcome, duration and trigger cause under a user configured retention, and per site overrides adjust only the reviewed knobs of loop bounds, step and run timeouts, element wait timeouts and delay bases per https origin pattern or subdomain glob — no new action kinds, the manifest permissions stay unchanged.
Multi agent swarm Several agents work at once over one shared context with consent: each agent binds to its own tab with its own role (planner, worker, observer, critic, verifier or any custom role, one agent per tab), the shared task queue carries user configured lanes, priorities, claims and work stealing inside one approved swarm with lane ownership rules, dead agents release their tasks through claim heartbeat expiry and requeue, agent mailboxes route direct, broadcast and role addressed messages, the blackboard holds the goals, facts, findings and scratch sections every agent reads with the consent class of the source extraction, per agent budgets halt at the user configured token, cost and step ceilings, per agent scopes stay inside the session grants, sub agents spawn under a user configured depth limit, and the killswitch halts every agent at once with no configuration barrier — no agent count, lane or ceiling is hardcoded and every agent proposal passes the same human review.
Multi agent orchestration The swarm organizes itself under consent: a leader worker topology elects its leader by the user rule (first registration or one named agent) with worker, critic and verifier lanes, the leader slices tasks across workers and scales the worker lane by load under the user configured bound with no engine cap, the planner executor split keeps plan drafting and execution in different agents while the executor reports every step outcome back, critics review agent outputs read only with verdicts and required changes, verifiers mark result claims pass or fail with the method they used, tab handoffs move a task between agents mid run from its packaged state while preserving the original session grants, resource locks keyed by one origin and one selector serialize parallel writes with exclusive and shared kinds and expiry sweeps, conflict scans detect overlapping writes with a suggested ordering, parallel results merge into one report under first, last, preferagent or fail rules with provenance for every merged value, escalations lift stalled decisions to the user who alone decides them, arbitration orders competing lock claims by the user rule, consensus rounds carry at the user configured quorum, verified lessons land on the blackboard, shared cost accounting sums the per agent usage, and the progressboard shows every agent at once with the interleaved timeline and replay — coordination never bypasses the review.
Execution environments Every reviewed step names where it runs with consent: the pagecontext keeps dom actions inside the live page because page events only fire there, the isolatedworld runs evaluate steps through the scripting api with reviewed arguments only while page globals stay unreachable from step code, the offscreenworker moves the six heavy parse families (html snapshots, network json payloads, table row reductions, accessibility tree shaping, complex selector evaluation and screenshot stitching) into an offscreen document worker pool behind the optional user granted offscreen capability with an inline fallback inside the page, and the sandboxframe renders untrusted markup inside a sandboxed page with no extension privileges after stripping scripts and event handlers and answering only per render nonces — the environment grants join the origin grants of the session, a keepalive port holds the service worker alive for the whole run of an approved plan with a heartbeat every user configured interval, the persisted run state resumes exactly the pending step after a service worker restart, zombie runs whose heartbeat fell silent reap past the tolerated intervals, a storage level run lock holds one session against concurrent runs, steps sharing one tab serialize across parallel branches, and every navigation lands a url history entry — no pool size, interval or tolerance is hardcoded and no environment ever bypasses the review.
Security foundations Automation runs behind a per origin allowlist under a denydefault posture that refuses every ungranted origin with exact origin matching and no wildcard expansion while the active tab counts as one explicit single origin grant; per site originprofiles grant and deny single action kinds, consentwindows bind every sensitive grant in time with a user chosen duration and a named boundary that never defaults to unlimited (a window past its boundary suspends the run mid step and renews only through a new explicit prompt), revokerun halts the pending step and every queued step as a terminal session event, sensitive kinds classify into the payment, credential, delete and publish classes refined by their options so each class needs one fresh consent prompt per origin, every decision lands in an append only immutablelog whose loghash chains each entry to its predecessor at append time and whose completion seal writes the final hash while the audit accessor verifies the chain and refuses reads of a broken link, and maskinputs keeps typed values, form values and stored values out of every log, observation and export behind the documented password, token, card and secret shapes the user extends.
Security hardening Secrets, messages and money run behind human gates: a secretvault keeps values behind a seam whose persisted records carry labels, scopes, provenance and digests only while the leak scan refuses plaintext secrets in plan texts and step options, redactshots mask sensitive capture regions across viewport, element and stitched captures, schemastrict rejects unknown fields of every registered inbound command with the path and expected shape, origincheck guards every runtime message and port connection while connectallow drops unknown senders from the user managed list that ships empty, ratelimit buckets defer automation commands past their user configured bound until the window resets, confirmpay, confirmdelete and confirmcreds hold payments (amount, payee origin, target), destructive deletions (target, scope, irreversibility) and credential use (label only) until one distinct human action resolves them with no timeout and no batch approval, phishguard blocks login origins whose lookalike distance to a granted origin crosses the user threshold and names the matched origin, safedefaults profile unknown origins as reads only, and the declared transparencypage lists every grant, consent window, sender, permdiff and vault label with a revoke action beside each grant.
Any LLM connection Any model drives the extension with consent: the user connects a gateway, a base url, an api key and any model — nothing is hardcoded, no provider allowlist exists and the openai chat completions, openai responses, anthropic messages and google gemini shapes are protocol styles the user picks; model routes map task kinds to provider and model pairs with user configured fallbacks, a local loopback endpoint keeps sensitive work on the machine, natural language commands parse into intents with entities and confidence, model drafted plans lint against the action grammar and pass the same human review (draft review plus plan review) local plans pass, failed runs replan their tail under a fresh review, executed steps reflect their lessons into the next prompt, cost budgets halt at the user configured token and currency ceilings and ask, the prompt library versions user templates with consent notices, and the guardrails strip code fences, validate model text against the schema, retry and refuse invalid output before anything executes.
Agent protocol The browser becomes a tool server with consent: the mcp server of the agent protocol lists every reviewed browser, workflow, memory and system tool over tools/list with its version, json schema inputs, risk grade and full consent metadata, negotiates capabilities and the per client tool floor with any client the user pairs, frames messages in json rpc with newline delimited and http post envelopes, and answers parse, method, params, internal and consentrefused errors with their codes — read only tools run under the dryrun risk class once the session is approved while every tool with side effects executes exactly the approved plan step it names, so no paired client widens what the human approved; the stdio bridge relays frames for local client processes through the native messaging host manifest with restart on demand, the http listener binds localhost by default with any other bind graded sensitive behind the explicit remote review, the server starts only after the user enables it, and the bind, port, transports, frame size, queue depth and call retention all stay user configured with no code ceiling. Since 1.1.55 the stream http transport opens for remote clients behind the full remote gates: one time pairing codes exchanged for session tokens that persist only as sha-256 digests, token scopes per namespace, a client allowlist with grant history, tls required for any non localhost transport with user configured certificate fingerprints, an ordered frame intake where tls terminates before token verification and namespace checks run before consent checks, auth failures that answer with one fixed message leaking no pairing state, a user configured client ceiling, and approval gates that hold every sensitive remote call with its full arguments (secret fields redacted) until the user decides — refusing by default when the configurable window closes.
Files and downloads The agent moves bytes with review: batchdownload downloads reviewed url lists in waves under a user configured concurrent window with per file states and sequence suffixes for filename conflicts, pausedownload and resumedownload walk the queue through the downloads api, verifydownload compares state, size and checksum against reviewed expectations, interceptmime arms include, exclude and deny default mime filters that reroute matching downloads into quarantine, exportnetlog exports the step correlated network log with every header value redacted, readclipboard needs an approved single use consent prompt per read and never persists the payload text, writeclipboard writes reviewed text through the page bridge with payload hashes for audit, copyscreen copies the visible tab to the clipboard, quarantinedownload and scanvirus keep files outside the downloads folder until a clean scan verdict releases them, namecaptures stamps task, step and sequence filenames with per task counters, and cleanupartifacts sweeps artifacts by reviewed age and kind rules while keeping open review references.
Datasets and exports The agent turns pages into data with audit: scrapetable reads tables into normalized column keys with rowspan and colspan expansion and nested child datasets, paginateextract follows next controls while waiting for fresh rows, mergepages aligns columns across pages, transformvalues applies reviewed expressions with per rule error surfacing, deduperows deduplicates by reviewed keys, stamplerows stamps every row with its source url, timestamp and step ref, previewgrid previews the grid before export, importcsv parses quoted csv with column mappings for fill loops, looprows interpolates {{column}} row variables into the wrapped inner step, exportcsv, exportjson and exportexcel write checksummed artifacts into the task artifact store with provenance records, copytable uses the clipboard under the optional clipboardWrite capability, pushsheets pushes only to a reviewed HTTPS endpoint behind its origin grant and the explicit reviewed flag, streamdisk streams chunk by chunk with backpressure and a persisted resume state, resumeextract continues an interrupted extraction from its stored cursor, and logprovenance logs provenance for audit; exports refuse to leave local memory while the session origin grants do not cover the active origin.
Tabs and windows command The agent commands the whole browser surface with review: querytabs resolves reviewed url, title, id and pattern matchers against the live tab set, closepattern closes matching tabs only under the explicit reviewed flag, pintab, mutetab, movetab, movetabwindow, duplicatetab, reloadtabs, discardtab, zoomin, zoomout and switchtab mutate tabs, grouptabs, colorgroup and collapsegroup keep group registries, savelayout and restorelayout save and restore named tab layouts with window bounds, snapshotsession and reopenrun capture and reopen whole runs, watchtab observes title, activation and closure events, findclones, searchtabs and listaudio enumerate the surface read only, badgetab and attachmeta route task state per tab, and maximizewindow, minimizewindow, restorewindow, focuswindow, scratchwindow and incognitowindow command windows with incognito separated from grant inheritance.
Navigation mastery The agent moves anywhere with review: openlink, openprivate, reopentab, deeplink and openclipboard open reviewed targets in resolved containers, followlink, spanav, spawait, waitload and waiturl navigate pages and single page app routes, rewritequery and setfragment edit the current url, navlist walks a reviewed url list with per entry progress, navprofile applies per site wait profiles, checksafe verifies urls before unreviewed origins open, batchopen opens curated lists with per url safety states, navrate enforces per domain rate limits with user configured windows and ceilings, and the navigation trail, redirect chains and final urls stay recorded for audit.
Observation depth The agent sees the whole page read only: the accessibility tree beside the dom snapshot, reader views, visible text, outlines, selections, open graph and embedded json state, plus detected lists, tables, pagination, infinite scroll, virtualization, lazy images, sticky overlays and scroll locks offered as plan suggestions.
Watch vocabulary watchmutate, watchfocus and watchbanner observe the page across a reviewed lifetime window with batched event records, waitquiet waits for network quiet under a reviewed threshold, diffsnapshots diffs two stored observation versions into added, removed and changed rows, and deriveselector ranks stable selector candidates with stability scores; registrations persist across service worker restarts.
Target resolution Steps address elements through reviewed targetref modes: css selector, visible text, aria role and name, accessible name, xpath, clickable map index or viewport point; ambiguous matches are refused with candidate lists and every resolution returns a matched element summary for review.
Optional capabilities tabs, downloads, clipboardRead and clipboardWrite are optional permissions; browser kinds check their capability, the review panel can request a grant and every grant is audited.
Unlimited by choice Wait durations, plan size, plan expiry, audit retention, outcome retention, zoom steps, the concurrent task tab ceiling, workflow delay bases and jitter windows, element wait timeouts and poll intervals, the workflow runlog retention, loop and repeat until safety bounds, parallel branch counts, retry attempt counts with backoff bases and jitter windows, per step and per run timeout budgets, trigger cooldown windows, interval periods with jitter windows, the trigger fire record retention, the mcp server frame size, request queue depth and tool call record retention carry no code ceilings; every bound is a user choice.
Structured results Step results carry structured JSON details, rendered in the side panel beside each reviewed step.
Session pause The user can pause and resume the active session; a paused session blocks every execution and preview while keeping the reviewed plan alive.
Plan progress Each reviewed step is tracked with its outcome history, completed steps are marked, plans close automatically once every step has executed, and prior history survives plan replacement.
Stop and audit The user can stop the session at any time. Configuration, proposals, decisions and results remain in local extension storage.

The project is deliberately not a hosted control platform. It does not depend on a provider-specific sandbox, server URL or browser profile. A configured endpoint is optional, has to use HTTPS and receives only the session record and bounded observation required to produce a plan.

Security boundary

Devthink never requests broad host access at installation. The user can grant a single HTTPS origin only after entering it in the extension popup, and privileged browser capabilities only as optional permissions requested from the review panel.

The default manifest requests activeTab, storage, scripting and sidePanel, plus optional permissions for tabs, downloads, clipboardRead and clipboardWrite that stay dormant until the user grants them at runtime. It does not request debugger, cookies, history, proxy control, native messaging, web requests, full-time host permissions or credentials. A service worker cannot be relied on for unattended 24-hour agent computation; any such system must be designed, installed and governed separately. 1 2

Browser actions remain blocked if the session is missing, stopped or expired; the tab or origin changed; the plan was not approved; the plan expired; or the tool proposal is not in the local allowlist. The page bridge checks the origin again immediately before it acts.

Install for development

pnpm install
pnpm validate

Then open the Chromium extensions page, enable developer mode, select Load unpacked, and choose extension/dist after a successful build. The popup has three deliberate steps: grant a user-entered endpoint origin if an endpoint is needed, start a session for the active HTTPS tab, and open the side panel to review a plan.

Configure an agent endpoint

The endpoint field intentionally has no default URL. Enter a URL such as https://agent.example/proposal; Chromium will prompt for that origin only. The endpoint receives:

{
  "version": "1.1.62",
  "objective": "User supplied objective",
  "session": { "id": "uuid", "tabid": 1, "origin": "https://example.com" },
  "observation": { "schemaversion": 3, "url": "https://example.com/path", "interactive": [] },
  "capabilities": { "tabs": false, "downloads": false, "clipboardread": false, "clipboardwrite": false }
}

It must return a plan proposal using the same version. Every step needs a human-readable summary and may carry a reviewed JSON options field. Navigation is restricted to the active session origin, and any unknown or malformed proposal is rejected locally. The endpoint is a planner, not an authority to control the browser.

Library use

import { canexecute, normalizeendpoint, parseproposal } from "@wenathlan/extension";

const config = normalizeendpoint("https://agent.example/proposal");
const proposal = parseproposal(agentresponse, "https://example.com");
const decision = canexecute({ session, plan: proposal.plan, step, tabid: 1, origin: "https://example.com" });

The library has no runtime dependency and exposes pure policy, protocol and local-memory contracts. It can be embedded in a browser agent, test harness, CLI or another JavaScript runtime that supplies compatible storage.

Build and package

Command Purpose
pnpm check Strict TypeScript validation.
pnpm test Unit tests for consent, origins, protocol and local audit state.
pnpm build Bundles the library, CLI and unpacked extension.
pnpm validate Runs type check, tests, build and manifest gate.
pnpm package Builds then previews the npm package content without publishing.
node dist/cli.js manifest Rejects a version mismatch, mandatory host permission or disallowed browser capability.

The workflows keep verification, version synchronization, release assembly and registry publication separated. A package.json version change is mirrored to release metadata by a repository workflow. A matching vX.Y.Z tag produces the signed release assets and digest. Registry publication occurs only after a release is published, and npm.js publishing also requires the repository NPM_TOKEN secret or compatible trusted-publishing configuration. Release gates, research evidence and known limitations are in docs/.

Research and clean-room policy

The repository includes public listing research, 58 CRX manifest inventories, static API signals and a 50-project open-source comparison sample. Downloaded artifacts were treated as untrusted, inspected without execution and discarded. Devthink is an original implementation: it does not vendor or derive code, visuals, names or proprietary transport details from reviewed products.

References

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages