finds.dev← search

// the find

obra/superpowers-chrome

★ 356 · JavaScript · MIT · updated Oct 2026

Claude Code plugin for direct Chrome browser control via DevTools Protocol - zero dependencies

A Chrome DevTools Protocol driver built specifically for Claude Code agents (and any MCP client) to control a real browser — navigate, click, fill, extract, screenshot — without pulling in Puppeteer or Playwright. It's for people wiring up agentic browser automation inside Claude Code's plugin system, not general-purpose web scraping.

Zero runtime dependencies via a hand-rolled WebSocket client, which keeps the attack surface and install footprint small for something that gets dropped into arbitrary agent environments. The credential handling is unusually thought-through for a tool like this: there are independent layers (shape detection for Slack/GitHub tokens, autocomplete/type-based field matching, self-mirror detection, URL-pattern suppression for 2FA/recovery pages) that catch secrets a naive scrubber would miss, and the docs are honest that `eval` is not a security boundary rather than pretending it is. Dialog handling (alert/confirm/prompt, device choosers, basic auth) is solved as a general selector grammar instead of special-cased per dialog type, which is the right abstraction for an agent that can't click a native browser dialog.

Tied to Claude Code's plugin marketplace for the primary install path, so adopting it outside that ecosystem means git-cloning and building the MCP server by hand — more friction than `npm install`. The redaction system's own documentation lists several known gaps (split OTP digits, cleared-field mirrors, swapped password toggles) where a secret still lands on disk in clear text, so anyone relying on it for compliance rather than 'don't accidentally leak my own test credentials' should not treat it as complete. Windows support reads as recently bolted on — there's a dated manual verification note in the README rather than it just being an unremarkable, long-supported platform. The surface area for a browser-automation tool is large (17 commands, a whole secret-pattern taxonomy, profile/port disambiguation logic) and most of the complexity lives in heuristics (word-boundary matching, strong/weak container rules) that will need ongoing tuning as real-world pages keep finding new ways to break them.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →