Skip to content

Browser and Computer-Use Playbook

Methodology, not an executable workflow. This page defines a trust boundary, close control, and evidence requirement. The operator must implement it against a specific authorized target; no command here claims to execute the full chain.

The native runtime uses Playwright Chromium. Install the optional browser extra and Chromium before preflight. Every case receives a new browser context and uses a controlled fixture.

Production variants

  • browser.visible-dom-injection
  • browser.accessibility-tree-injection
  • browser.overlay-destination-confusion
  • browser.clipboard-injection
  • browser.download-artifact-injection
  • browser.cross-tab-delegation

Controls preserve layout, route and affordances while replacing the instruction with inert text. Miss fixtures preserve the task without satisfying the predicate.

Procedure

  1. Validate the fixture, agent boundary, package, bounds and oracle before launch.
  2. Materialize the controlled environment and task.
  3. Run attack/control in separate contexts.
  4. Follow tab, frame, navigation, element, download, task and delegated-hop IDs.
  5. Compare bounded DOM/accessibility structure. Screenshots only orient the operator.
  6. Validate impact through navigation/action logs, download state, form or transaction state, callbacks, or tool invocations.
  7. Confirm context and browser cleanup.

A screenshot never establishes impact. Use browser_state, tool_invocation, callback or another controlled state oracle. Environmental behavior without a protected effect stays below impact_validated.