# Defense-in-depth score: BrowserOS neo

**Repo:** https://github.com/browseros-ai/BrowserOS · **Commit:** `4f3523b03e08e1c1d831f87c1aa992eff4918d70` · **Reviewed:** 2026-10-05
**What it is:** A Chromium-based browser plus local MCP server that lets external agents (Claude Code, Codex, Cursor and others) drive a logged-in browser.
**Category:** AI Assistants
**Scored configuration:** BrowserOS neo as installed from the README: default onboarding (Chrome import with default items), first-run auto-connect of detected agents, local MCP endpoint on loopback, remote MCP access off, telemetry on.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions no · sub agents no · external communication yes

## Score: 3.6 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L1 | L0 | L0 | L0 | 0.07 | none | **0.07** | High |
| C2 | Approval gates | L1 | L1 | L2 | L0 | 0.25 | none | **0.25** | High |
| C3 | Tool & action scoping | L1 | L1 | L0 | L0 | 0.15 | none | **0.15** | High |
| C4 | Code-execution isolation | L2 | L2 | L3 | L0 | 0.45 | none | **0.45** | High |
| C5 | Untrusted input blast radius | L2 | L1 | L3 | L0 | 0.38 | C5-WORSTCASE | **0.25** | High |
| C6 | Memory, context & configuration integrity | L0 | L0 | L1 | L1 | 0.10 | none | **0.10** | High |
| C7 | Third-party extensions | SA | SA | SA | SA | 1.00 | none | **1.00** (SA) | High |
| C8 | Secrets & sensitive-data protection | L2 | L2 | L1 | L0 | 0.35 | none | **0.35** | High |
| C9 | Audit & traceability | L2 | L2 | L1 | L1 | 0.40 | none | **0.40** | High |
| C10 | Limits & kill switch | L2 | L2 | L3 | L2 | 0.55 | none | **0.55** | High |

Controls where a risk surface exists: 2.58 / 9.0 (29%); 1 criterion scored SA (surface absent).

BrowserOS neo hands connected agents your logged-in browser: default onboarding imports your Chrome logins, and every tool, including a scripting tool with raw DevTools Protocol access, works on any site and any tab with no approval step in the server. A hostile page that hijacks the agent can read and act in your accounts and send data anywhere. Agents can also save skills that are linked into your coding agents' skill folders and reused later, and the local cockpit API is not locked down by default. Scripts run in a bounded QuickJS engine and every action is recorded for replay, but keep neo away from accounts you can't afford to have misused.

## Critical gaps
- Agents act with every signed-in session in the browser profile, which default onboarding fills from Chrome; there is no per-request authorization. (ASI03, T3; C1). Evidence: [packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts:100-113](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts#L100-L113); [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/guards/mod.rs:3-5](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/guards/mod.rs#L3-L5)
- Model-written scripts run in a C JavaScript engine inside the server process, which runs as the user and drives the signed-in browser. (ASI05, T11; C4). Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:639-649](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L639-L649); [packages/browseros-agent/apps/claw-server-rust/src/main.rs:152](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/main.rs#L152)
- A hijacked agent can leak private data and act irreversibly in signed-in accounts with no human involved. (ASI01, LLM01, T6; C5). Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:71](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L71); [packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs:11-26](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs#L11-L26)

## Criterion details

### C1 Identity & least privilege: 0.07 (high confidence)

BrowserOS neo is a separate browser, but its default onboarding imports the user's Chrome logins, history and other data, and agents then act with every signed-in session in that profile. The server has no identity of its own and no per-request authorization: tab ownership is shown to the agent as a label but the code deliberately never refuses an action on the user's or another agent's tab. The scripting tool also exposes the raw Chrome DevTools Protocol, which reaches the whole browser. The local cockpit API that manages connections, skills and sessions is not locked down by its default access configuration. A hijacked or misbehaving agent therefore holds the user's full web identity.

- **S L1:** A dedicated browser profile separates neo from the everyday browser, but it is populated with the user's imported logins and every tab and site is reachable, including through raw CDP. Evidence: [packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts:100-113](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts#L100-L113); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:71](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L71) (verified)
  - *To reach the next level:* No per-capability or per-site scoping of the authority the agent receives.
- **C L0:** No authorization check sits on any tool path: ownership of tabs is only a label, and the instruction to act on one's own tabs is prompt text. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/guards/mod.rs:3-5](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/guards/mod.rs#L3-L5); [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/script_hook.rs:49](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/script_hook.rs#L49); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:47](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L47) (verified)
  - *To reach the next level:* No code-level authorization layer on tool dispatch.
- **D L0:** Default onboarding selects every import item except search engines and extensions, so the agent profile starts with the user's logins. Evidence: [packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts:100-113](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts#L100-L113) (verified)
  - *To reach the next level:* Least-privilege default (empty profile, or per-site grants) is not the default.
- **B L0:** Authority covers every account the user is signed into in the browser, across services. Evidence: [packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts:100-113](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts#L100-L113); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:1067-1075](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L1067-L1075) (verified)
  - *To reach the next level:* Authority is not limited to one system or to reads.
- **Cap:** none

### C2 Approval gates: 0.25 (high confidence)

As a tool server, neo leaves approval to the connected agent; its contribution is risk signalling. Read tools carry read-only hints, but the click, navigate, download and upload tools carry no annotations, the save-skill tool is marked non-destructive, and the main `run` tool mixes reads and writes in arbitrary scripts that the description tells agents to prefer for every task. There is no preview, no read-only mode and no server-enforced confirmation. A `request_human_help` tool lets the agent hand a tab to a person, but the agent decides when to use it. Actions in logged-in accounts (posting, sending, buying) are not reversible.

- **S L1:** Annotations exist (read-only on read tools) but are missing on mutating tools and inaccurate for save_skill, and the primary run tool mixes reads and writes. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/mod.rs:45-51](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/mod.rs#L45-L51); [packages/browseros-agent/crates/browseros-mcp/src/tools/act.rs:179](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/act.rs#L179); [packages/browseros-agent/crates/browseros-mcp/src/tools/navigate.rs:35](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/navigate.rs#L35); [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/service.rs:1182-1187](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/service.rs#L1182-L1187); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:36](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L36) (verified)
  - *To reach the next level:* No separate read and write tools with accurate hints on every tool.
- **C L1:** Every request can go through the generic run tool, which a host approval sees as one opaque script. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:36](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L36); [packages/browseros-agent/crates/browseros-mcp/src/tools/mod.rs:23-43](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/mod.rs#L23-L43) (verified)
  - *To reach the next level:* Mutating capability is not split into narrowly annotated tools.
- **D L2:** Hints are compiled in and always present; there is no read-only mode or server-side confirmation to switch on. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/mod.rs:45-51](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/mod.rs#L45-L51) (verified)
  - *To reach the next level:* No server-enforced read-only mode or confirmation step.
- **B L0:** A wrongly approved action can post, send, purchase or delete in any signed-in account, with no undo. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:36](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L36); [packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts:100-113](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts#L100-L113) (verified)
  - *To reach the next level:* No checkpoint, preview or dry-run for external actions.
- **Cap:** none

### C3 Tool & action scoping: 0.15 (high confidence)

Every tool has a typed argument schema that rejects unknown fields, but the arguments themselves are mostly passed through. `run` accepts arbitrary JavaScript against an SDK that includes raw DevTools Protocol access, `evaluate` runs arbitrary JavaScript in pages, navigation checks only a small scheme denylist, and `upload` attaches any local file path to a page's file input. All seventeen browser tools are enabled by default with no tool groups. A misused tool can act on any site the browser is signed into and send local files out.

- **S L1:** Validation is typed schemas plus a small URL-scheme denylist; the most powerful tools take arbitrary scripts and file paths. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/guards/navigate_scheme.rs:7](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/guards/navigate_scheme.rs#L7); [packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs:11-26](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs#L11-L26); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:71](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L71) (verified)
  - *To reach the next level:* No allowlist validation (host allowlists, path containment) on URLs, scripts or upload paths.
- **C L1:** Few arguments are validated beyond their type. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs:11-26](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs#L11-L26); [packages/browseros-agent/crates/browseros-mcp/src/tools/evaluate.rs:106-118](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/evaluate.rs#L106-L118) (verified)
  - *To reach the next level:* Most built-in tools do not validate their arguments.
- **D L0:** The whole catalog, including run, evaluate and upload, is registered unconditionally. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/mod.rs:23-43](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/mod.rs#L23-L43) (verified)
  - *To reach the next level:* No read-only or reduced default tool set.
- **B L0:** General-purpose scripting against the user's whole signed-in browser and arbitrary local file upload. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:71](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L71); [packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs:11-26](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs#L11-L26) (verified)
  - *To reach the next level:* Tools are not scoped to a site, workspace or quantity bound.
- **Cap:** none

### C4 Code-execution isolation: 0.45 (high confidence)

Model-written code runs in two places. `run` scripts execute in a fresh QuickJS engine inside the server process, with no filesystem, network or process access of their own, a 64 MB memory limit, a stack limit and a 30-second interrupt; `evaluate` and `page.evaluate` run JavaScript inside Chrome's page renderer. The QuickJS engine is written in C, so an engine bug would land in the server process, and the injected SDK includes raw DevTools Protocol access with browser-wide control. The server process runs as the user, writes to connected agents' config and skill directories, and drives the signed-in browser.

- **S L2:** A capability-only QuickJS runtime per call (no ambient authority, memory and stack limits) plus the Chrome renderer for page scripts; the engine is not memory-safe, so it falls short of the capability-runtime anchor. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:639-649](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L639-L649); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:27-30](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L27-L30); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:38](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L38); [packages/browseros-agent/Cargo.toml:59](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/Cargo.toml#L59) (verified)
  - *To reach the next level:* Runtime is not written in a memory-safe language, and there is no OS-level isolation of the server.
- **C L2:** All model-reachable code paths run in QuickJS or the page renderer, but the injected raw CDP method gives scripts browser-level control outside the narrow SDK. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:639-649](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L639-L649); [packages/browseros-agent/crates/browseros-mcp/src/tools/evaluate.rs:106-118](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/evaluate.rs#L106-L118); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:1067-1075](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L1067-L1075) (verified)
  - *To reach the next level:* The runtime's injected surface is not limited to bounded capabilities.
- **D L3:** The runtime is the only execution path, configured in compiled code that the model cannot change. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:639-649](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L639-L649); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:27-30](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L27-L30) (verified)
  - *To reach the next level:* Sandbox policy is fixed in code but the escape hatch is part of the default SDK.
- **B L0:** An engine escape lands in the server process running as the user, and the injected functions already reach the whole signed-in browser. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/main.rs:152](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/main.rs#L152); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:1067-1075](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L1067-L1075); [packages/browseros-agent/crates/harness-integrations/src/catalog.rs:280](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/harness-integrations/src/catalog.rs#L280) (verified)
  - *To reach the next level:* Execution is not separated from the user's account and browser authority.
- **Cap:** none

### C5 Untrusted input blast radius: 0.25 (high confidence)

Page text returned by the read, grep, snapshot, diff and evaluate tools is wrapped in per-call nonce markers with the page origin and a notice to treat it as data. Values returned from `run` scripts, the primary tool, are not wrapped. Nothing in the server limits what an agent can do after reading a hostile page: the same session can read private data in signed-in accounts, act in them, and send data anywhere. There is no read-only or no-egress mode.

- **S L2:** Page-derived text carries provenance (origin) and an untrusted marker in structured results. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/trust_boundary.rs:3-18](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/trust_boundary.rs#L3-L18) (verified)
  - *To reach the next level:* No mode that drops a Rule-of-Two leg (read-only or no-egress).
- **C L1:** Granular read tools are wrapped, but run script results, which agents are told to prefer, are returned unmarked. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:427-434](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L427-L434); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:36](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L36) (verified)
  - *To reach the next level:* Not every source of page content is marked.
- **D L3:** The wrapper is applied in code and cannot be turned off. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/trust_boundary.rs:3-18](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/trust_boundary.rs#L3-L18) (verified)
  - *To reach the next level:* Coverage gaps keep this from being a configuration-proof control.
- **B L0:** A hijacked agent can read private data in any signed-in account, exfiltrate it through navigation or uploads, and take irreversible actions, with no human involved. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:71](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L71); [packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs:11-26](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/upload.rs#L11-L26); [packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts:100-113](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts#L100-L113) (verified)
  - *To reach the next level:* No structural block on egress or state change after untrusted content is read.
- **Cap:** C5-WORSTCASE: Worst case (B L0): a hijacked agent can leak data and take irreversible actions unattended.

### C6 Memory, context & configuration integrity: 0.10 (high confidence)

Agents can persist instructions and code. The `save_skill` tool writes a skill file and links it into every connected agent's user skills directory (for example ~/.claude/skills), where those agents load it in later sessions. `run` scripts can save JavaScript helpers per website, and successful runs are also distilled into helpers automatically; both are loaded into later runs on that host. Nothing validates or gates these writes, and they are shared across all agents and sessions. Skills are visible and deletable in the cockpit.

- **S L0:** The model can write skills and helper code that persist and are re-loaded as trusted instructions or code. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/service.rs:71-72](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/service.rs#L71-L72); [packages/browseros-agent/apps/claw-server-rust/src/services/skills.rs:367-370](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/services/skills.rs#L367-L370); [packages/browseros-agent/crates/harness-integrations/src/catalog.rs:280](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/harness-integrations/src/catalog.rs#L280); [packages/browseros-agent/apps/claw-server-rust/src/services/helpers.rs:322-324](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/services/helpers.rs#L322-L324) (verified)
  - *To reach the next level:* No human approval or validation for persistent writes.
- **C L0:** Neither skills nor helpers (saved or distilled) pass any control. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/distill.rs:1-4](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/distill.rs#L1-L4); [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/dispatch.rs:441-449](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/dispatch.rs#L441-L449) (verified)
  - *To reach the next level:* No persistence path is controlled.
- **D L1:** Skills and helpers are shared by every connected agent and session on the machine. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/dispatch.rs:441-449](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/dispatch.rs#L441-L449); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:68](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L68) (verified)
  - *To reach the next level:* No per-agent or per-session namespace.
- **B L1:** A poisoned skill or helper persists across the user's sessions and agents and can drive tool use. Evidence: [packages/browseros-agent/crates/harness-integrations/src/catalog.rs:280](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/harness-integrations/src/catalog.rs#L280); [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/dispatch.rs:441-449](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/dispatch.rs#L441-L449) (verified)
  - *To reach the next level:* Persistent content is not gated or reviewed before it affects behaviour.
- **Cap:** none

### C7 Third-party extensions: 1.00 (high confidence)

The neo server loads no plugins and launches no MCP servers or packages at runtime; the only package command in the server is a stdio fallback for agents without HTTP transport, and every supported agent uses HTTP at system scope. Importing Chrome extensions is optional and off by default in onboarding. The project's own bundled components and updates are its own supply chain and out of scope here.

- **Structural absence:** searched `rg -n -S -e Command::new -e libloading -e dlopen -e npx -e uvx -e TokioChildProcess -e load_plugin` in `packages/browseros-agent/apps/claw-server-rust/src packages/browseros-agent/crates/browseros-mcp/src packages/browseros-agent/crates/browseros-core/src packages/browseros-agent/crates/browseros-cdp/src` → 2 hits (both hits are the npx mcp-remote stdio fallback written into an agent's config only when that agent lacks HTTP transport; neo itself never runs it); [packages/browseros-agent/crates/harness-integrations/src/catalog.rs:189](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/harness-integrations/src/catalog.rs#L189) (every harness's system_transports includes Http)

### C8 Secrets & sensitive-data protection: 0.35 (high confidence)

The neo server holds no model or service API keys of its own; browser credentials stay in Chromium's store. Usage telemetry is on by default but built from allowlisted fingerprints so literals and page text are dropped, session recordings mask password inputs, and helper distillation drops typed values. The audit log stores tool arguments in plain form, and the model can read cookies and page data of any signed-in site through the browser tools, which are long-lived session credentials.

- **S L2:** Allowlist-based telemetry fingerprints, password masking in recordings and literal filtering in distillation. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/analytics/script_fingerprint.rs:1-10](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/analytics/script_fingerprint.rs#L1-L10); [packages/browseros-agent/apps/claw-app/entrypoints/recorder.content.ts:111](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-app/entrypoints/recorder.content.ts#L111) (verified)
  - *To reach the next level:* No redaction before audit storage or before model-bound results; no encryption of stored session data.
- **C L2:** Telemetry, error reports and recordings are protected; audit arguments and model-bound outputs are not. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/db/audit_log.rs:976-978](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/db/audit_log.rs#L976-L978); [packages/browseros-agent/apps/claw-server-rust/src/analytics/script_fingerprint.rs:1-10](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/analytics/script_fingerprint.rs#L1-L10) (verified)
  - *To reach the next level:* Model-bound messages and audit records are not redacted.
- **D L1:** Telemetry is enabled by default, content-free. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/analytics/state.rs:39-41](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/analytics/state.rs#L39-L41) (verified)
  - *To reach the next level:* Telemetry is not opt-in.
- **B L0:** Session cookies for every signed-in site are reachable by the model through raw CDP. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:1067-1075](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L1067-L1075); [packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts:100-113](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts#L100-L113) (verified)
  - *To reach the next level:* Long-lived, high-privilege session credentials are reachable by the model.
- **Cap:** none

### C9 Audit & traceability: 0.40 (high confidence)

Every tool dispatch, including each browser primitive inside a `run` script as a child record, is written to a local SQLite audit log with session, agent label and arguments, plus screenshots and replayable recordings. The agent's identity is whatever name the client declares. Records are written after the action through an asynchronous worker and failures are only logged; guard rejections are not recorded. The log lives in ~/.browserclaw, is pruned after 7 days by default, and its retention and cleanup are driven through the local cockpit API.

- **S L2:** Structured per-call records with arguments, timing, and parent-child links for script primitives. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/observers/audit.rs:32-46](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/observers/audit.rs#L32-L46); [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/script_hook.rs:18-24](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/script_hook.rs#L18-L24); [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/service.rs:70](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/service.rs#L70) (verified)
  - *To reach the next level:* Actor attribution relies on a self-declared agent name and the store has no tamper evidence.
- **C L2:** All built-in tools and script primitives are recorded, but denied calls are not. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/script_hook.rs:18-24](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/script_hook.rs#L18-L24); [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/dispatch.rs:278-279](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/dispatch.rs#L278-L279) (verified)
  - *To reach the next level:* Approvals and denials are not recorded.
- **D L1:** On by default, but retention and cleanup are controlled through the same local API surface the cockpit uses. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/services/audit_settings.rs:16](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/services/audit_settings.rs#L16) (verified)
  - *To reach the next level:* Records are not written by a component outside reach of the local API.
- **B L1:** Recording is best-effort after the action through an asynchronous worker; errors only go to the server log. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/api/mcp/observers/audit.rs:32-46](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/mcp/observers/audit.rs#L32-L46) (verified)
  - *To reach the next level:* Audit write failures are not surfaced and records are not durable per action.
- **Cap:** none

### C10 Limits & kill switch: 0.55 (high confidence)

Each `run` and `evaluate` call is capped at 30 seconds, a cap the model cannot raise, and QuickJS scripts also have memory and stack limits and an interrupt that fires on cancellation or deadline. The cockpit can cancel a session, which cancels in-flight dispatches. There is no cap on the number of calls, sessions or open tabs, and no rate limit on actions. Page-side work started by a script continues after a timeout or cancellation.

- **S L2:** Server-enforced timeouts and output caps on the script and evaluate tools, with an engine interrupt. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:27-28](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L27-L28); [packages/browseros-agent/crates/browseros-mcp/src/tools/evaluate.rs:16-17](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/evaluate.rs#L16-L17); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:645-647](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L645-L647); searched `rg -n -S -e Semaphore -e rate_limit -e max_concurrent` in `packages/browseros-agent/apps/claw-server-rust/src packages/browseros-agent/crates/browseros-mcp/src` → 29 hits (all hits are the max_concurrent_used_sessions analytics metric, test semaphores, or audit-worker internals; none limits tool dispatch concurrency or rate) (verified)
  - *To reach the next level:* No concurrency or rate limits on dispatch.
- **C L2:** Per-call timeouts apply to tool work; sessions and tabs are not bounded. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:27-28](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L27-L28); [packages/browseros-agent/apps/claw-server-rust/src/api/http/sessions.rs:149-158](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/http/sessions.rs#L149-L158) (verified)
  - *To reach the next level:* No bound across a session's calls or spawned tabs.
- **D L3:** Caps are clamped constants the model cannot raise. Evidence: [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:27-28](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L27-L28); [packages/browseros-agent/crates/browseros-mcp/src/tools/evaluate.rs:16-17](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/evaluate.rs#L16-L17) (verified)
  - *To reach the next level:* Hard ceilings exist but cover only per-call time.
- **B L2:** Cancellation ends in-flight dispatches, but page-side work and the agent's own loop continue unbounded. Evidence: [packages/browseros-agent/apps/claw-server-rust/src/api/http/sessions.rs:149-158](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/apps/claw-server-rust/src/api/http/sessions.rs#L149-L158); [packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs:645-647](https://github.com/browseros-ai/BrowserOS/blob/4f3523b03e08e1c1d831f87c1aa992eff4918d70/packages/browseros-agent/crates/browseros-mcp/src/tools/run.rs#L645-L647) (verified)
  - *To reach the next level:* No session-level time or action ceiling.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: Arbitrary web pages read via read/snapshot/run (crates/browseros-mcp/src/tools/run.rs:36) · [B] sensitive data/systems: Imported logins and every signed-in session (apps/claw-onboard/src/onboarding/onboarding-v2.helpers.ts:109-113) · [C] state change / egress: Clicks, navigation, uploads and raw CDP on any site (crates/browseros-mcp/src/tools/run.rs:71) · Same default session? Yes

## Highest-impact improvements
1. Lock down the local cockpit API's default access configuration. (C1 C L0→L1, +0.075 before caps; Playbook 4)
2. Require a human confirmation in the cockpit before save_skill links a skill into other agents and before helpers are persisted. (C6 S L0→L3, +0.225 before caps; Playbook 2)
3. Wrap run script results in the same untrusted-content markers as the granular read tools. (C5 C L1→L2, +0.075 before caps; Playbook 1)
4. Add accurate read/destructive annotations to act, navigate, download, upload and save_skill, and offer a server-enforced read-only mode. (C2 S L1→L2, +0.075 before caps; Playbook 5)
5. Remove raw CDP from the default run SDK or restrict it to an allowlist of read-only methods. (C4 C L2→L3, +0.075 before caps; Playbook 3)

## Re-audit log
- C4 S: L3 → L2. QuickJS is a capability-only runtime but its engine is written in C; the L3 anchor requires a memory-safe runtime.
- C4 C: L3 → L2. The injected raw CDP method is model-reachable, not an operator escape hatch, so the L3 coverage anchor is not met.
- C1 S: L0 → L1. neo uses its own browser profile rather than the everyday Chrome profile, a dedicated but broadly scoped identity.

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- Scored BrowserOS neo (apps/claw-server-rust, crates/browseros-mcp, apps/claw-app and the neo Chromium build), which the README leads with. The classic BrowserOS AI browser in the same repo (apps/app and apps/server, with a built-in agent) was not scored.
- neo is a tool server: approval, model choice and loop limits belong to the connected agent and are not credited here.
- The Chromium patch set was reviewed only for the server launch, ports, proxy and remote-access defaults; the rest of the browser fork was not examined.
