Nanobrowser turns a sentence into a browsing session. You type a task into its side panel, such as pulling the top headlines from a news site or finding a speaker under $50 with a ten-hour battery, and a Planner agent breaks it into steps while a Navigator agent clicks, types and scrolls through real pages in your own Chrome or Edge window. You watch it work, can ask follow-up questions about the result, and keep a history of past tasks.
It earns its place as a free, open answer to paid browser agents such as OpenAI's Operator. You bring your own model: OpenAI, Anthropic, Gemini, DeepSeek, Grok, OpenRouter, Azure, or a local model through Ollama, and you can give the Planner and Navigator different models to balance cost and accuracy. It builds on ideas from Browser Use and Puppeteer, packaged as a Manifest V3 extension.
The project has about 14,000 stars and is licensed Apache-2.0. Version 0.2.0 was released on October 2, 2026; the Chrome Web Store copy can lag behind GitHub releases while it waits for review.
- Repository: github.com/nanobrowser/nanobrowser
- Licence: Apache-2.0 (Apache License 2.0)
- Language: TypeScript. Stars: 13.9K. Forks: 1,472. Last push: Oct 2, 2026.
- Scan: safe, Oct 2, 2026, commit ad47282
Who it is for
People who repeat the same research, shopping or data-gathering steps across websites and want to delegate them, and developers who want to see how a multi-agent browser agent is put together.
Getting started
1. Install from the Chrome Web Store (Chrome and Edge are supported)
open https://chromewebstore.google.com/detail/nanobrowser/imbddededgmcgfhfpcjmijokokekbkal2. Open the side panel, click Settings, add an API key, and choose models for the Planner and Navigator
# Nanobrowser icon > Settings > add a provider key > pick models3. Or build the latest version yourself (Node.js 24 and pnpm 10), then load dist/ as an unpacked extension
git clone https://github.com/nanobrowser/nanobrowser.git && cd nanobrowser && corepack enable && pnpm install && pnpm buildThe agents act inside your real browser profile, with your logged-in sessions. A page can contain text written to steer an AI agent, so give it tasks on sites you trust, and watch it before letting it near email, banking or anything that spends money. API usage is billed by your model provider.
Safety scan
We cloned nanobrowser/nanobrowser at commit ad47282 on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no pattern hits, no bare-IP URLs and no committed binaries across about 26,000 lines, mostly TypeScript, in 169 files. The two npm hooks are local: postinstall generates translation files and runs wxt prepare, and prepare installs Husky git hooks for contributors.
- We read src/background/services/analytics.ts. It initializes PostHog with autocapture, page views and session recording off and all text masked, and sends task_started, task_completed and task_failed events with durations and an error category, keyed to a random anonymous ID. The setting is checked before PostHog starts and defaults to on; PRIVACY.md says the same.
- Page screenshots and HTML go only to the model provider you configure, which is how the agents decide what to click. Because they run in your real profile with your sessions, a page can contain text written to redirect them; the extension's design does not remove that risk, so supervise it on sensitive sites.
- One known advisory among 627 packages in pnpm-lock.yaml: braces 3.0.3 (high), a glob-matching library used by build tooling.
- There are no GitHub Actions workflows at all, so release builds are made outside public CI and cannot be traced to a workflow run. Security policy, licence and contributing guide present; no Dependabot or CodeQL.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | 2 npm lifecycle scripts |
| Committed binaries | None. |
| CI workflows | No GitHub Actions workflows. |
| Network hosts | 16 distinct hosts referenced from source; most often github.com, my-instance.openai.azure.com, developer.chrome.com, chromewebstore.google.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 1 advisory across 627 pinned packages: 0 critical, 1 high, 0 moderate, 0 low. pnpm-lock.yaml: 627 packages, 1 advisories. |
| Project hygiene | Has security policy, licence file, contributing guide. Missing automated dependency updates, CodeQL. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
npm lifecycle scripts (2)
package.jsonpostinstall:node src/i18n/generate-i18n.mjs && wxt preparepackage.jsonprepare:husky
Worst known vulnerabilities (1 of 1)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-vfj7-8cjw-p6xm | high | braces@3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns |
By the numbers
| Stars | 13.9K |
|---|---|
| Forks | 1,472 |
| Contributors | 27 |
| Commits | 376 |
| Open issues | 48 |
| Open pull requests | 33 |
| Releases | 15 |
| Latest release | v0.2.0 |
| Licence | Apache-2.0 |
| Main language | TypeScript |
| Project age | 1 year |
| Last push | Oct 2, 2026 |
| Tracked files | 169 |
| Lines of code | 25.7K |
| Checkout size | 1 MB |
Lines by language: TypeScript 18.8K, JSON 3,031, JavaScript 1,727, Markdown 1,666, CSS 239, YAML 133.
Questions
Is Nanobrowser free?
Yes. The extension is Apache-2.0 and free, with no subscription. You pay only your model provider for the tokens the agents use, and that cost drops to zero if you run a local model through Ollama, at some loss of reliability on complex tasks.
Which models work best with Nanobrowser?
The README recommends a stronger model for the Planner, which reasons about the task, and a cheaper, faster one for the Navigator, which clicks through pages; for example a Claude Sonnet model to plan and a Claude Haiku model to navigate. Local options it lists include Qwen3-30B-A3B, Mistral Small 24B and Qwen 2.5 Coder 14B.
Does Nanobrowser send my browsing data to its developers?
Not your browsing content. The page screenshots and HTML the agents read go only to the model provider you configure; with a local model, they stay on your machine. Separately, anonymous usage analytics (task start, completion, duration and error category) go to PostHog by default, and can be switched off in the extension's settings.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
