據 AlphaMoat 統計,截至 2026-09,Chrome 外掛 AI Browser Guard 使用者數為 21,環比 +31.3%,評分 5(1 人評價),在全部 9,324 款 AI 瀏覽器外掛中排名第 7,292 位,在「通用 AI」分類(2,418 款)中排名第 1,853 位。
Detects AI agents (Playwright, Puppeteer, Selenium, Computer Use) driving your browser, alerts you, and closes tabs they control. BETA — AI Browser Guard is in active development. We are building security infrastructure for the AI agent ecosystem and want your feedback. Report issues or suggest features: https://github.com/opena2a-org/AI-BrowserGuard/issues
AI Browser Guard detects when AI automation frameworks take control of your browser and gives you tools to manage what they can do.
WHAT IT DOES
When an AI agent (Playwright, Puppeteer, Selenium, Anthropic Computer Use, OpenAI Operator, or any WebDriver-based tool) starts controlling your browser, AI Browser Guard:
SCOPE AND LIMITATIONS
External automation frameworks (Playwright, Puppeteer, Selenium, Anthropic Computer Use, OpenAI Operator) drive the browser over the Chrome DevTools Protocol with native input. AI Browser Guard detects and alerts on these agents, and its kill switch closes the tab they control, but it does not block their individual actions and cannot see their clicks, typing, or screenshots in the timeline. A browser extension cannot enforce per-action policy against a framework that owns the tab's debugger slot; the only categorical block is a managed-Chrome policy (RemoteDebuggingAllowed=false), and modern Chrome already blocks remote debugging of your default profile by default. The delegation presets and per-action blocking below apply to IN-PAGE / injected automation only, best-effort. If a session report shows few or no actions for an external agent, that means its actions were not observable, not that nothing happened.
FIVE CORE FEATURES
1. Agent Takeover Detection — identifies automation frameworks without requiring agents to self-identify. WebDriver flag detection, CDP connection scanning, behavioral heuristics (click precision, typing cadence, synthetic events), and framework fingerprinting.
2. Emergency Kill Switch — one-click stop. Revokes delegated permissions, dispatches a page-realm stop to in-page automation, and closes the tabs an agent controls (the real interruption of an in-progress action). It does not terminate an external CDP session -- an extension cannot -- and a persistent external driver can reopen a tab. Keyboard shortcut: Ctrl+Shift+K (Cmd+Shift+K on Mac).
3. Delegation Wizard — define what agents can and cannot do before they connect: Read-Only (navigate and read, no clicking or typing), Limited (specific sites you choose, with time limits 15min / 1hr / 4hr), or Full Access (everything allowed, with logging and alerts).
4. Boundary Violation Alerts — when an IN-PAGE agent attempts a scripted navigation, form submission, click, keystroke, new-tab open, or download outside its delegation scope, the action is blocked (best-effort) and you receive a notification showing what was attempted, which rule blocked it, and the option to allow it once. External CDP frameworks drive via native input these alerts cannot see -- for those, rely on detection and the kill switch. (DOM reads, injected scripts, and screenshots are not blocked; use the kill switch to close the agent's tab.)
5. Session Timeline — chronological log of all agent actions: timestamps, action types, target URLs, element selectors, and whether each action was allowed or blocked. Last 5 sessions retained.
PRIVACY
By default, AI Browser Guard makes zero network requests. All detection, delegation, and session tracking runs locally on your device. There is no analytics, no telemetry, and no tracking. Session logs and settings are stored in chrome.storage.local and are deleted when you uninstall.
The extension also offers four optional features that make network requests and are OFF BY DEFAULT. They only act after you explicitly enable them, and each can be turned off again with one click:
None of these features transmit your URLs, page content, form data, keystrokes, cookies, authentication tokens, or identity. Three of them contact only OpenA2A's own servers (aim.opena2a.org, api.oa2a.org); site safety declarations contacts the website your agent is on, which receives nothing about you but can see that the request was made.
Full privacy policy: https://opena2a.org/aibrowserguard/privacy
PERMISSIONS
AI Browser Guard requests host access to all URLs because AI agents can operate on any website, so the detection content script must run on every page. By default the extension makes no network requests; the only outbound requests are the optional, off-by-default features described under PRIVACY.
ABOUT OPENA2A
AI Browser Guard is built by OpenA2A, an open-source security platform building infrastructure for the AI agent ecosystem. Learn more: https://opena2a.org — Source code: https://github.com/opena2a-org/AI-BrowserGuard
This is a beta release. We are actively improving detection accuracy, adding framework signatures, and expanding delegation controls. Open an issue on GitHub with feedback: https://github.com/opena2a-org/AI-BrowserGuard/issues
ChatGPT, DeepSeek, Gemini, Claude, Grok all in one AI sidebar, for AI search, read, and write.
+ 對比Change default search engine to ChatGPT search.
+ 對比One stop AI Assistant with GPT, Claude, Gemini: Chat, Write, Translate, Search, Summarize, image generator, video generation
+ 對比Summarize YouTube videos, web articles, and PDFs to save time, powered by ChatGPT, Claude, Mistral AI, and Gemini.
+ 對比資料月份:2026-09 · 使用者數與評分來自 Chrome 應用商店公開資料,按月聚合更新。口徑說明見資料方法。