Browser (OpenClaw)
390,823 starsCore built-in OpenClaw plugin (@openclaw/browser-plugin): gives the agent a dedicated managed browser — a separate openclaw profile (orange accent by default) of Chrome/Brave/Edge/Chromium, driven through a loopback-only control service inside the Gateway, with deterministic tab control (list/open/focus/close), actions (click/type/drag/select), snapshots, screenshots, PDFs and managed downloads; a bundled browser-automation skill teaches agents to use it. The built-in user profile mode instead attaches to your real signed-in Chrome (via Chrome DevTools MCP).
- First published:2026-03-26
- data as of:
- 2026-09-30
Host
The agent can visit any site in the managed browser, read all readable page content, click and submit forms, screenshot and download files (into the managed directory after final-URL policy validation). In user profile mode all of this happens inside your real signed-in Chrome session — your cookies and logins become the agent's. The control API binds to loopback only; official Browser security docs cover control-API auth and remote CDP tokens.
It registers into OpenClaw's tools contract and depends on the OpenClaw Gateway's control service, profile management and SSRF/download policies (the official browser docs span nine OpenClaw-specific pages). Other hosts' browser tooling (Hermes' browser settings, DSH's browser-use providers) are separate implementations with no compatibility.
Risk
Same injection surface as any browser tool: arbitrary page content can try to command the agent. User profile mode maximizes the risk — the agent acts wearing your bank/mail/social logins. Downloaded files may carry malicious content. The official docs explicitly warn against letting it interfere with your own Chrome (profile isolation exists for exactly this).
Install prompt
此插件隨 OpenClaw 核心 npm 包內建(官方 inventory 標記 included in OpenClaw),無需另行安裝;按官方 Browser 文件集的 setup 頁啟用,並確認工具政策允許 browser 工具。需要隔離時用預設的 openclaw profile;非必要不要切到接你真實登入態的 user profile。Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.