Skip to content
CAI
Software that uses CAICheck a score

vercel-labs/agent-browser

49.6

Weak · 27 September 2026

99.4k

lines of production code

Rust

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Agent-browser is a headless browser automation system built in Rust, designed to provide AI agents with reliable programmatic control over web browsers. It exposes core capabilities such as navigation, interaction, and accessibility snapshotting through a CLI and structured tool extensions, while supporting execution in isolated environments like Vercel Sandboxes. The system includes infrastructure for cross-platform binary distribution, observability dashboards, and comprehensive evaluation suites to validate agent skill integration.

Features

Add agent-browser sandbox example for Vercel

A new example in the \examples/sandbox\ directory demonstrates how to use the \@agent-browser/sandbox\ package with Vercel Sandbox. It includes a Node script (\vercel/snapshot-url.mjs\) that runs browser commands, such as opening a URL and taking a snapshot, within an isolated sandbox environment rather than the serverless function runtime.

examples/sandbox · high confidence

Add daemon benchmark suite for Node.js vs Rust native comparison

A new benchmarking tool has been added to the \benchmarks\ directory to compare the performance of the published Node.js daemon against the new Rust native daemon. The suite runs inside a Vercel Sandbox and measures command latency (navigate, snapshot, screenshot, evaluate, click, fill, agent-loop, and full-workflow) alongside system metrics like cold start time, memory usage (RSS), and distribution size. Users can execute the benchmarks using \pnpm bench\ after configuring Vercel Sandbox credentials in a \.env\ file.

benchmarks · high confidence

Initial open-source release of agent-browser v0.38.1

The project is now open-sourced as agent-browser, providing a headless browser automation CLI for AI agents built in Rust. This release includes the core daemon, CLI commands (open, click, snapshot, screenshot, etc.), and a JSON configuration schema. It introduces features such as conditional screenshots, automatic snapshot deltas, persistent snapshot refs, human-like pointer movement, and recording presentation tools (cursor, contact sheets). It also adds stateful auth vault login, WebMCP catalog updates, and session setup inheritance for new tabs. Bug fixes address recording cursor/mouse timing, CDP transport recovery, and dropdown label matching. Documentation clarifies browser wait strategies and includes Vercel Labs badges.

(repo-wide) · high confidence

Introduce @agent-browser/sandbox package for Vercel sandbox automation

Added the new @agent-browser/sandbox package, which provides utilities to create and manage Vercel sandboxes for running agent-browser. The package includes functions to install agent-browser and its Chromium system dependencies (such as NSS and GTK3) within the sandbox, build shell commands with proper quoting and environment handling, and manage sandbox sessions via the Vercel API. It exports types and helpers for sandbox creation, command execution, and error handling, defaulting to the current sandbox version (0.38.1).

packages/@agent-browser/sandbox/src · high confidence

Introduce new Next.js-based observability dashboard

The dashboard package has been rebuilt as a Next.js application, providing a modern UI for agent-browser observability. This change introduces a new configuration and styling stack, including \next.config.ts\ for API rewrites to the backend, \postcss.config.mjs\ for Tailwind CSS, and a \components.json\ file configuring the shadcn/ui component library with the 'radix-nova' style. The visual identity is updated with new SVG assets for the Lightpanda logo and various provider icons (AgentCore, BrowserUse, BrowserBase, Browserless, Kernel), while the layout establishes a dark-mode-first theme using the Geist font and Jotai for state management.

packages/dashboard · high confidence

Introduces native Rust CLI with embedded dashboard and CDP protocol generation

The CLI has been rewritten in Rust, replacing the previous implementation. This change introduces a new build process (build.rs) that embeds the web dashboard and auto-generates Rust types from the Chrome DevTools Protocol (CDP) JSON definitions. The new CLI includes a built-in \doctor\ command for diagnosing Chrome installations and daemon state, a \chat\ command for AI-assisted interactions, and a \color\ module that respects the \NO\_COLOR\ environment variable for agent-friendly output. It also adds a \ca\_bundle\ module to handle custom CA certificates for proxy trust.

cli · high confidence

New @agent-browser/eve extension for agent browser automation

This release introduces the \@agent-browser/eve\ extension, which provides a comprehensive set of browser automation tools for agents running in an Eve sandbox. By mounting this extension, agents gain access to approximately 20 namespaced tools—including navigation, accessibility snapshots with stable element references, clicking, form filling, semantic element finding, waiting, screenshots, JavaScript evaluation, tab management, and network/console inspection—without needing to write custom tool code. The extension automatically installs the \agent-browser\ CLI and Chromium dependencies on first use if not already present, and supports configuration for safety (domain allowlists, CA certificates), output formatting (content boundaries, max output size), and runtime behavior (session management, proxy settings).

packages/@agent-browser/eve · high confidence

New agent-browser skill documentation and AWS AgentCore support

The skill-data area now includes comprehensive documentation for the agent-browser CLI, organized into a new 'core' skill and a dedicated 'agentcore' skill. The core skill provides a complete reference for browser automation workflows, including snapshot-and-ref interactions, authentication patterns, session management, and proxy configuration. The agentcore skill adds support for running agent-browser on AWS Bedrock AgentCore cloud browsers, detailing credential resolution, persistent profiles, and region selection. These files serve as the authoritative guide for AI agents to correctly invoke agent-browser commands.

skill-data · high confidence

New build, version-sync, and post-install scripts for native binary management

This change introduces a suite of new scripts to streamline the release and installation of the agent-browser native binary. The \build-all-platforms.sh\ script automates cross-compilation for Linux (glibc and musl), Windows, and macOS (x64 and ARM64) using Docker. A new \sync-version.js\ tool ensures the version number remains consistent across \package.json\, \cli/Cargo.toml\, the dashboard, the sandbox, and the Eve extension, while \check-version-sync.js\ validates this consistency in CI. Additionally, \postinstall.js\ now handles downloading the correct platform-specific binary from GitHub releases, detecting the package manager used, and fixing global install shims on Windows and Unix systems to ensure the native binary is executable and directly accessible.

scripts · high confidence

New environments demo for running agent-browser in Vercel Sandboxes

This change adds a new Next.js application in the examples/environments directory that demonstrates running agent-browser inside ephemeral Vercel Sandbox microVMs. The demo provides a UI for taking screenshots and accessibility snapshots of allowed URLs, streaming progress via Server-Sent Events, and includes rate limiting via Upstash Redis. It supports sub-second sandbox startup using pre-built snapshots and handles authentication through either explicit Vercel credentials or automatic OIDC.

examples/environments · high confidence

New eve example app with browser automation capabilities

This change introduces a new example application in the \examples/eve\ directory that demonstrates an agent with full browser automation tools. The app uses the \@agent-browser/eve\ extension to provide tools like navigation, clicking, and screenshotting, which are rendered in the UI with human-readable activity labels and icons. It configures the agent to disable default web search and fetch tools in favor of the browser tools, pre-installs Chromium dependencies in the Vercel Sandbox for performance, and includes a Next.js frontend with a chat interface that supports streaming, reasoning, and tool activity visualization.

examples/eve · high confidence

New multi-platform cross-compilation build infrastructure

The project now provides a Docker-based build environment that enables cross-compiling the agent-browser binary for Linux (x64 and ARM64) and Windows from a single host. This includes a new Dockerfile with necessary toolchains (GCC, MinGW, Zig) and a docker-compose setup that automates the build process, outputting binaries to the bin directory.

docker · high confidence

Removals

Removed legacy src browser automation implementation

The legacy source files in src (actions.ts, browser.ts, client.ts, daemon.ts, index.ts, protocol.ts, types.ts) have been deleted. This removes the previous internal browser management, CLI entry point, and daemon/client communication logic from this location.

src · high confidence

Behavioural changes

Automated version synchronization for CLI components

A pre-commit hook has been added to automatically synchronize the version number between package.json and the CLI's Cargo.toml and Cargo.lock files. This ensures that version consistency is maintained across the JavaScript and Rust-based CLI components before every commit, preventing discrepancies in the project's versioning.

.husky · high confidence

Replaced shell script entry point with cross-platform Node.js CLI wrapper

The package now uses a new JavaScript entry point (bin/agent-browser.js) instead of the previous shell script (bin/veb). This wrapper ensures cross-platform compatibility by automatically detecting the operating system (including Alpine Linux via musl detection) and CPU architecture to select the correct native binary, and it fixes execution permission issues on macOS and Linux by automatically correcting file permissions if they are missing.

bin · high confidence

Test coverage

Added tests for launcher binary selection on ARM64 platforms; Added tests for the agent-browser sandbox package; New evals suite for validating agent-browser skill loading and MCP discovery.

Dependencies

Agent Browser v0.38.1: Native Rust CLI, New Packages, and Dependency Updates

This release introduces the native Rust CLI (agent-browser v0.38.1) defined in cli/Cargo.toml, replacing the previous TypeScript implementation. It adds new workspace packages for the Eve browser extension (packages/@agent-browser/eve) and sandbox runtime helpers (packages/@agent-browser/sandbox), alongside example projects for environments, sandbox, and eve integration. The root package.json is updated to v0.38.1 with Apache-2.0 licensing and new build scripts for native compilation. Dependencies are updated across the workspace, including Next.js to 16.x, React to 19.x, and the AI SDK to v6/v7.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 34 → 50 (+15.6)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 60 → 74 (+13.2)
  • Architecture 93 (new)
  • Maturity 60 → 68 (+7.3)
  • Readiness 14 → 53 (+38.8)
  • Security 47 → 64 (+16.3)
  • Accessibility 36 (new)

Resolved (110)

  • Change coupling: docs-navigation.ts ↔ page-titles.ts (docs/src/lib/docs-navigation.ts)
  • Change coupling: header.tsx ↔ docs-navigation.ts (docs/src/components/header.tsx)
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (benchmarks/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (cli/Cargo.lock)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (cli/Cargo.lock)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (cli/Cargo.lock)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 90 more

New (518)

  • ActionPolicy::check (cognitive 16) (cli/src/native/policy.rs)
  • CdpClient::connect_request (cognitive 51) (cli/src/native/cdp/client.rs)
  • CdpClient::connect_request (cyclomatic 25) (cli/src/native/cdp/client.rs)
  • Change-coupling hub: output.rs → commands.rs, client.rs, docs-navigation.ts (cli/src/output.rs)
  • ClassTooLong: BrowserManager (cli/src/native/browser.rs)
  • Critical vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • DaemonState::apply_drained_events (cognitive 141) (cli/src/native/actions.rs)
  • DaemonState::apply_drained_events (cyclomatic 62) (cli/src/native/actions.rs)
  • DaemonState::drain_cdp_events (cognitive 236) (cli/src/native/actions.rs)
  • DaemonState::drain_cdp_events (cyclomatic 86) (cli/src/native/actions.rs)
  • DaemonState::start_fetch_handler (cognitive 40) (cli/src/native/actions.rs)
  • DaemonState::start_fetch_handler (cyclomatic 20) (cli/src/native/actions.rs)
  • Documentation: no contributor guidance (README.md)
  • Duplicated block (10 lines × 2) (cli/src/commands.rs)
  • Duplicated block (10 lines × 2) (cli/src/commands.rs)
  • Duplicated block (10 lines × 2) (cli/src/commands.rs)
  • Duplicated block (10 lines × 2) (cli/src/native/actions.rs)
  • Duplicated block (10 lines × 2) (cli/src/native/actions.rs)
  • Duplicated block (10 lines × 2) (cli/src/native/element.rs)
  • Duplicated block (10 lines × 2) (cli/src/native/stream/dashboard.rs)
  • …and 498 more

Changes since last survey

  • 52 commits — 34 feature/other, 18 fixes

By area

  • cli/src — 30 commits
  • packages/@agent-browser — 9 commits
  • (root) — 4 commits
  • .github/workflows — 2 commits
  • cli/Cargo.lock — 2 commits
  • examples/eve — 2 commits
  • docs/public — 1 commit
  • scripts/windows-debug — 1 commit
  • skill-data/core — 1 commit

Notable commits

  • fix: Fix Windows ARM64 launcher binary selection (#1725)
  • fix: Fix Windows headless Chrome desktop artifacts (#1498) (#1820)
  • fix: fix(browser-use): use Cloud V4 with bounded session cleanup (#1879)
  • fix: fix(cdp): harden transport parsing and shutdown (#1739)
  • fix: fix(cdp): normalize root WebSocket request paths (#1735)
  • fix: fix(cli): avoid CA config test race (#1707)
  • fix: fix(dashboard): harden origin validation (#1738)
  • fix: fix(deps): update quinn-proto to 0.11.17 (#1720)
  • fix: fix(release): require one approval for npm publishes (#1825)
  • fix: fix(release): restore ARM64 builds (#1716)
  • fix: fix(select): match normalized option labels (#1736)
  • fix: fix(stream): emit active main-frame URL updates (#1682)
  • fix: fix: detect undersized shared memory mounts (#1890)
  • fix: fix: remove obsolete Lightpanda serve timeout (#1750)
  • fix: fix: restore release CI (#1862)
  • fix: fix: synchronize recording cursor and mouse movement timing (#1869)
  • fix: fix: upgrade brace-expansion dependencies (#1752)
  • fix: fix: upgrade rustls-webpki to 0.103.13 (#1723)
  • change: Add Labs status badges to README (#1868)
  • change: Add automatic snapshot deltas (#1811)
  • …and 32 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

vercel-labs/agent-browser was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d01253d9db28d75080e36da3c1c31ef89454731e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.