Invictum Browser Bridge
OfficialInvictum Browser Bridge
AIエージェントのためのオープンソースのブラウザ制御。開発者向けに構築。
Invictum Browser Bridge(IBB。Invictum Browser Gate、IBGとも呼ばれる)は、認可されたAIエージェントがユーザーの既存のGoogle Chromeプロファイルで作業できるようにします。エージェントは、Cookie、パスワード、ブラウザプロファイル、生の認証状態をエクスポートすることなく、サインイン済みのWebアプリケーションを利用できます。
このプロジェクトはMIT Licenseの下でライセンスされています。MCP、CLI、TypeScript SDK、またはループバック制御APIを通じたローカル開発と高度なブラウザワークフロー向けに設計されています。
ビデオデモ

YouTubeでInvictum Browser Bridgeの完全なデモを見ると、AIエージェントが実際のChromeプロファイル内で作業し、公開Webサイトを意味的に理解し、そのコンテンツをナビゲートし、モバイルビューポートをテストし、制御中のタブを表示したまま明示的に予約しながら、全ページおよび注釈付きスクリーンショットを作成する様子を確認できます。
Related MCP server: agent-browser-mcp
なぜ使うのか?
ほとんどのブラウザ自動化は、クリーンなブラウザプロファイルから始めるか、不安定な画面座標に依存しています。IBBは代わりに、ユーザーの実際のChromeプロファイル内で、型付けされた、ポリシー検証済みのアクションを提供します:
意味的なページ読み取りと決定的な要素参照;
ユーザーの作業を妨げないバックグラウンド優先のタブ制御;
WordPress、WHM/cPanelターミナル、Figma向けの専用アダプター;
信頼性の高いフォーム、リッチテキスト/コードエディター、アップロード、ダイアログ、スクリーンショット、デバッグツール;
明示的な認可、タブごとの予約、User Stop、編集済み監査データ、保証されたクリーンアップ。
インストールされた拡張機能は、その正確なランタイム機能を報告します。エージェントは、ドキュメントと読み込まれたChromeビルドが同一であると想定するのではなく、常にsystem.capabilitiesを呼び出す必要があります。
主な機能
ブラウザとページの制御
タブ履歴の一覧表示、開く、閉じる、ナビゲート、アクティブ化、移動。
専用のエージェントウィンドウと、デフォルトではバックグラウンドタブで作業。
URL、タイトル、テキスト、セレクター、DOMの安定性、またはアプリケーションの準備完了を待機。制限付きバックグラウンド待機がフォーカスを必要とすることを証明した場合にのみ、遅延レンダリングされたタブに一度だけフォーカス。
コンパクト、アウトライン、フル、インタラクティブ、またはスコープ付きの意味的スナップショットを読み取り。
クリーンなテキストまたは軽量なMarkdownを抽出し、決定的な自然言語ランキングで要素を検索。
クリック、ダブルクリック、コンテキストクリック、ホバー、フォーカス、タイプ、キー押下、選択、チェック、要素またはドキュメント位置へのスクロール、ドラッグ&ドロップ。
座標クリックはリビジョンに紐付けられたフォールバックとしてのみ使用。
フォーム、エディター、ファイル、認証
ネイティブの入力欄、テキストエリア、セレクト、チェックボックス、ラジオ、contenteditable領域、WYSIWYGエディターを設定。
CodeMirror、Ace、Monaco、Quill、TinyMCE、Gutenberg、および類似の権威あるエディターモデルを同期し、値が送信後も保持されるようにする。
Chromeのネイティブファイル入力APIを通じて1つ以上のローカルファイルを添付。結果や監査ログにパスを公開しない。
必要な認可がある場合にのみフォームを送信。すでに承認されたエージェント指示に対する明示的に認可されたプロンプトなしの経路を含む。
事前入力されたログインフォーム、一時的なHTTP Basic Auth、ネイティブのJavaScript alert、confirm、prompt、
beforeunloadダイアログを専用アクションを通じて使用。
WordPressサポート
IBBは、エージェントに見た目だけのDOM変更や座標ドラッグで即興対応を求めるのではなく、型付けされたWordPressワークフローを提供します:
wp-admin画面、通知、リストテーブル、行、利用可能なアクションを識別;
正確なWordPressアクションキーで行アクションと一括アクションを実行;
GutenbergまたはClassic Editorのコンテンツ、タイトル、抜粋、slug、ステータス、カテゴリー、タグ、アイキャッチ画像メタデータ、その他のサポート対象フィールドを読み取り・更新;
変更を保存とは別に確認し、保存後に権威あるエディターモデルを検証;
クラシックなAppearance > Menusツリーを検査・編集。カスタムリンク、更新、削除、サブツリー全体の移動、ネスト、並び順、保存を含む;
WordPressの未保存の変更プロンプトがナビゲーションをブロックした場合に安全に回復;
プラグイン設定、メディア、ACF類似のコントロール、カスタム管理ページには、一般的なフォーム、アップロード、エディター、DOM、コンソール、同一オリジンAPIツールにフォールバック。
WordPress wp-adminとクラシックメニュー編集を参照してください。
WHM、cPanel、ブラウザターミナル
型付けされたxtermアダプターは、WHM/cPanel Terminalなどのブラウザホスト型ターミナルをサポートします:
WHMのSearch Toolsフィールドではなく、実際のターミナルを検出;
制限付きで編集済みのxtermバッファ、またはアクションローカルなターミナルWebSocketを1つ読み取り;
ターミナルヘルパー入力にのみフォーカスし、バックグラウンドタブで信頼されたテキストまたは特殊キーを送信;
1回のEnterを送信する前に、正確なコマンドをステージングして検証;
フェイルクローズし、Enterを保留し、未検証のドラフトをクリアすることを試行;
プロンプト、テキスト、出力の変化、または静かな状態を待機;
生のコマンドや出力をログに記録せずに、明示的なドラフトと配信の検証を返す。
ターミナル出力はR2、すべてのテキスト/キーアクションはR3です。読み取り専用リクエストがコマンドを認可することはありません。ターミナル自動化を参照してください。
ChromeでのFigma
型付けされたFigmaアクションは、デザインファイル周辺のブラウザUIを検査できます:
期待されるFigma UIアンカーのヘルスチェック;
ファイル名、ページ、現在のモード、現在の選択を読み取り;
レンダリングされたレイヤーツリーの行とインスペクタープロパティを読み取り;
古い行の保護付きでページ、モード、または表示中のレイヤーを選択;
WebGLキャンバスのアートワークにはスクリーンショットを使用。
Figmaはレイヤーツリーを仮想化し、デザインキャンバスをWebGLで描画するため、このアダプターは意図的に完全なドキュメント変更を主張しません。Figmaサポートを参照してください。
開発者向け診断とビジュアル出力
制限付きで編集済みのコンソールキャプチャとメタデータのみのネットワーク診断。
オプションのWordPress nonce処理を備えた同一オリジンのページAPIリクエスト。
元に戻せるモバイルビューポート、向き、DPR、タッチエミュレーション。
ビューポート、要素、領域、全ページのスクリーンショット。
長方形、楕円、矢印、ラベル、自動番号付きセットオブマークオーバーレイを備えたチュートリアルスクリーンショット。
要素/リスナー/ソースの検査、制限付きイベント監視、型付けされたDOMおよびインラインスタイルの変更、元に戻せるCSS注入、制限付きPDFエクスポート。
明示的に認可された生のページJavaScriptをR3の最後の手段として使用。機密、ナビゲーション、送信、無制限ネットワークの各サーフェスは引き続き拒否されます。
ポリシーを維持するシーケンシャルバッチ、ドライラン、冪等性キー、ポストスナップショット、意味的DOMデルタ、検証、古い参照の再配置。
エージェント統合
IBBは4つのローカル開発者向けサーフェスを提供します:
サーフェス | ユースケース |
MCPサーバー | Codex、Cursor、Claude Code、その他のstdio MCPクライアント向けの主要インターフェース |
JSON CLI | PowerShell向きのフォールバック、診断、自動化スクリプト |
TypeScript Agent SDK | アプリケーション統合と |
ループバック制御API |
|
127.0.0.1:47821上のNative Hostトランスポートは、Desktop Authority専用です。エージェントは拡張機能またはそのポートに直接接続してはなりません。
サーバーは現在、54のランタイムブラウザアクションと61のMCPツールを公開しています。この数はリリース時点のスナップショットであり、エージェント契約ではありません。実行時にinvictum_capabilitiesを呼び出してください。
セーフティモデル
Desktop Authorityが単一のポリシーおよび監査境界です。
各アクションはR0-R3に分類されます。機密アクションには、対応する明示的な認可アサーションが必要です。
タブは作業前に予約され、エージェントIDで視覚的にマークされ、
finallyで解放されます。ユーザーはすぐに制御を停止できます。要素参照はドキュメントおよびDOMリビジョンにバインドされます。
スナップショットは機密値を編集します。アップロード、ターミナルコマンド、認証情報、プロンプトテキスト、レスポンスボディは監査ログに書き込まれません。
ブラウザ内部ページ、拡張機能、DevTools、Chrome Web Store、ローカルファイル、その他の制限されたサーフェスは引き続き利用できません。
バックグラウンド作業がデフォルトです。エージェントは、アプリケーションが本当に必要とする場合を除き、フォアグラウンドでのアクティブ化を要求すべきではありません。
デバッガーアクセスはタブスコープかつ制限付きです。永続アダプターは、停止、リセット、ロック解除、ナビゲーション、またはクラッシュクリーンアップ時にリースを解放します。
IBBは、Cookie、保存されたパスワード、自動入力データ、任意のブラウザストレージ、無制限のダウンロード、パッシブなリクエスト/レスポンスボディ、トラフィック傍受、OSレベルの信頼された入力、リモート制御を公開しません。
アクションサーフェスを拡張する前に、SECURITY.mdとPOLICY_CONFIGURATION.mdを読んでください。
アーキテクチャ
AI agent
| MCP / CLI / TypeScript SDK / local control API
v
Desktop Authority :47820
| policy -> validation -> reservation -> audit -> cleanup
v
Native Host -> private loopback WebSocket :47821
v
Chrome MV3 extension -> typed page/CDP adapters -> authorized tab信頼境界とトランスポート契約については、ARCHITECTURE.mdを参照してください。
要件
Windows 11 x64
Google Chrome 120+
Node.js 22+
pnpm 11
Git
リポジトリは現在、署名済みのChrome Web Storeパッケージや本番インストーラーではなく、ソースベースの開発者向けインストールを提供しています。
クイックスタート
git clone https://github.com/invictumhr/ai-invictum-browser-bridge.git
Set-Location .\ai-invictum-browser-bridge
$env:CI = 'true'
pnpm install --frozen-lockfile
pnpm build
pnpm typecheck
pnpm test
pnpm lintchrome://extensionsからapps/extension/distを展開済み拡張機能として読み込み、生成された拡張機能IDをコピーしてから、Native Hostを登録します:
.\scripts\register-native-host-dev.ps1 -ExtensionId "PASTE_EXTENSION_ID"
pnpm browser ping
pnpm browser capabilitiesChromeで拡張機能のサイトへのアクセスをすべてのサイトに設定します。これにより、新しいHTTP(S)オリジンごとの手動ツールバー承認を回避できます。ChromeポリシーとBridge自身の認可モデルは引き続き適用されます。
完全な手順はINSTALL_WINDOWS.mdとEXTENSION_INSTALL.mdにあります。
WindowsでAIエージェントを使ってインストール
以下のプロンプトを、WindowsコンピューターへのPowerShellアクセスを持つ信頼できるAIコーディングエージェントにコピーしてください。エージェントはローカルランタイムをインストールしてビルドできますが、Chromeでは展開済み拡張機能に対していくつかの目に見えるユーザー操作が必要です。そのため、プロンプトはエージェントにいつ一時停止してユーザーをガイドするかを正確に指示します。
Desktop Authorityは、127.0.0.1:47820でエージェントコマンドを受け付けるローカルプロセスです。Native Hostは、Desktop Authorityと127.0.0.1:47821上のChrome拡張機能の間を中継します。サポートされているインストールは、永続的なWindows Serviceを作成しません。MCPとCLIは、必要なときにDesktop Authorityを非表示のローカルデーモンとして起動し、Chromeは登録済みのNative Hostを起動します。どちらのポートも公開したり、ファイアウォールルールを作成したりしないでください。
Install Invictum Browser Bridge from the public repository on this Windows PC:
https://github.com/invictumhr/ai-invictum-browser-bridge.git
Your goal is to install the complete supported local chain:
AI client -> MCP/CLI -> Desktop Authority -> Native Host -> Chrome extension
Work autonomously wherever PowerShell can do the work. Guide me step by step
only for actions Chrome requires me to perform manually. Explain each manual
step in one short message, wait for my confirmation or the extension ID, and
then continue. Do not ask me to execute commands that you can safely execute.
Safety rules:
1. Use only the public repository above and the scripts checked into it.
2. Do not request, copy, print, or store Chrome passwords, cookies, tokens,
browser-profile files, or browsing data.
3. Do not disable Chrome security, install an unrelated extension, expose a
loopback port, create a firewall rule, or bind any service publicly.
4. Do not invent a Windows Service or Scheduled Task. This project intentionally
auto-starts Desktop Authority through MCP/CLI and lets Chrome start the Native
Host.
5. Do not overwrite an existing checkout. If the target directory exists,
inspect its Git remote and working tree first. Continue only if it is this
repository and existing changes are safe; otherwise choose a new directory.
6. Avoid administrator elevation unless a missing prerequisite genuinely
requires it. Native Host registration itself is per-user under HKCU.
7. Never work around a failed test, Chrome permission, or Native Messaging
error. Diagnose it and preserve the security model.
Perform these phases:
PHASE 1 — Preflight
- Use PowerShell.
- Check Windows version and availability/versions of Git, Google Chrome,
Node.js, npm/Corepack, and pnpm.
- Require Node.js 22 or newer and pnpm 11. Use the pnpm version declared in the
repository package.json.
- If a prerequisite is missing, explain what is missing. Install it through an
official source or winget only when installation is within my request; report
any UAC/manual step before continuing.
- Resolve a normal per-user installation directory. Default to
%USERPROFILE%\invictum-browser-bridge unless I already selected another path.
PHASE 2 — Clone, inspect, install, and build
- Clone the repository with:
git clone https://github.com/invictumhr/ai-invictum-browser-bridge.git
- Enter the repository and verify that origin points to that repository.
- Read README.md, INSTALL_WINDOWS.md, EXTENSION_INSTALL.md, SECURITY.md, and
AGENT_USAGE.md before installation.
- Run the repository secret scan before installation.
- Set CI=true for the install and run:
pnpm install --frozen-lockfile
pnpm build
pnpm typecheck
pnpm test
pnpm lint
- Stop and diagnose any failed gate. Do not continue with a partial build.
- Resolve and show me the exact absolute folder I will need in Chrome:
<repository>\apps\extension\dist
- Copy that folder path to the Windows clipboard if possible.
PHASE 3 — Guide me through loading the Chrome extension
Pause and ask me to do exactly this:
1. Open Google Chrome and go to chrome://extensions.
2. Turn on Developer mode in the top-right corner.
3. Click Load unpacked.
4. Select the exact apps\extension\dist folder you resolved above.
5. Confirm that Invictum Browser Controller appears and is enabled.
6. Copy its 32-character extension ID and send only that ID back to you.
Do not guess or hardcode the extension ID. Validate that the value I provide
matches Chrome's unpacked-extension ID format before using it.
PHASE 4 — Register the local Native Host
- From the repository root, run:
.\scripts\register-native-host-dev.ps1 -ExtensionId "THE_ID_I_PROVIDED"
- Confirm that the script created the per-user Native Messaging registration
for com.invictum.browser_bridge and did not expose a network port.
- If the Windows C# compiler needed by the checked-in launcher is unavailable,
report that exact blocker; do not download or execute an unverified launcher.
PHASE 5 — Finish Chrome configuration
Pause and guide me through these steps:
1. Return to chrome://extensions.
2. Click Reload on Invictum Browser Controller once.
3. Open Details for the extension.
4. Set Site access to On all sites.
5. Confirm the extension remains enabled and has no current error.
6. Optionally pin its toolbar icon so the ON/AI status and settings are easy to
see.
Explain that On all sites prevents a new manual approval for every HTTP(S)
domain, but does not bypass Chrome policy, restricted pages, User Stop, or IBB's
own authorization rules. Wait for my confirmation before testing.
PHASE 6 — Start and verify the bridge
- Run pnpm browser health.
- Run pnpm browser ping. The CLI should automatically start Desktop Authority
as a hidden local daemon if it is offline.
- Run pnpm browser capabilities.
- Verify that Desktop Authority is reachable only through 127.0.0.1:47820, the
private Native Host transport uses 127.0.0.1:47821, nativeConnected is true,
and the loaded extension returns its runtime capabilities.
- Treat runtime capabilities as authoritative. The current source expects 54
browser actions and the built MCP server expects 61 tools, but do not hide a
mismatch or force those numbers if the checked-out release differs.
- If the badge briefly shows ON and disconnects, diagnose Desktop Authority,
the HKCU Native Messaging manifest, its allowed extension ID, the built Native
Host paths, and extension errors. Rebuild/reregister/reload only the component
that is stale.
- Do not ask for a second extension reload unless extension files or its Native
Host registration actually changed.
PHASE 7 — Configure AI clients
- Ask whether I want global IBB/IBG discovery for installed AI clients. If yes,
run:
powershell -ExecutionPolicy Bypass -File
.\scripts\install-agent-discovery.ps1
- This should preserve unrelated Codex, Cursor, and Claude configuration.
- Tell me to start a new AI-agent session after MCP registration changes.
- Verify with a harmless request that performs only IBB ping and capabilities;
do not open a browser tab for this verification.
PHASE 8 — Final report
Report:
- repository installation path and checked-out revision;
- Node.js and pnpm versions;
- build/typecheck/test/lint results;
- Chrome extension ID and loaded dist path (the ID is not a secret);
- Native Host registration status;
- Desktop Authority health and nativeConnected state;
- runtime action count and MCP tool count;
- which AI clients were configured;
- whether any manual action or known limitation remains.
Do not claim success until ping and capabilities work through the normal local
authority. Do not use a temporary test harness that takes over port 47821.AIエージェントの設定
pnpm buildの後、サポートされているローカルエージェント用のMCP登録とトリガールールをインストールします:
powershell -ExecutionPolicy Bypass -File .\scripts\install-agent-discovery.ps1use IBB、use IBG、use Invictum Browser Bridge、use Invictum Browser Gateというフレーズ(および対応するクロアチア語のフレーズ)はすべて、このBridgeを選択します。MCP登録を変更した後は、新しいエージェントセッションを開始してください。
MCP設定、エージェントディスカバリー、簡潔なエージェントトリガー契約を参照してください。
推奨されるエージェントワークフロー
ping -> capabilities -> open/navigate in background -> identify agent -> wait
-> outline/snapshot -> find -> typed action -> verify -> unlock in finally型付けされたアクションと意味的な参照を優先してください。視覚的な理解にはスクリーンショットを、座標はフォールバックとしてのみ、生のJavaScriptはユーザーが明示的に認可し、より安全な型付けされたアクションではタスクを解決できない場合にのみ使用してください。
ドキュメント
ドキュメントインデックスから始めてください。重要なガイドは以下のとおりです:
リポジトリ構成
apps/
cli/ JSON CLI and authority auto-start
desktop/ policy/audit authority and loopback control API
extension/ Manifest V3 Chrome controller
mcp/ stdio MCP adapter
native-host/ Native Messaging stdio <-> private local WebSocket
packages/
agent-sdk/ control client and reserved-tab lifecycle helpers
audit-log/ redacted audit contract and development sink
policy-engine/ fail-closed action classification
protocol/ strict IBP schemas and factories
shared-types/ transport-neutral contracts
tests/
fixtures/ deterministic local browser pages
integration/ emulated transport and real-Chrome smoke testsコントリビューション
Issue とプルリクエストを歓迎します。ポリシー、検証、監査、予約、クリーンアップは Desktop Authority パスに維持し、拡張機能に第二の制御経路を追加しないでください。プルリクエストを開く前に完全なローカルゲートを実行し、CONTRIBUTING.md に従ってください。
構造化された GitHub フォームを バグ報告 と 機能リクエスト に使用してください。診断の指針については SUPPORT.md を、参加する前には CODE_OF_CONDUCT.md をお読みください。セキュリティ問題は公開 Issue ではなく、非公開の脆弱性報告 を使用する必要があります。
変更を公開する前に、GIT_PUBLISHING.md のプライベートデータチェックリストを使用してください。
ライセンス
Invictum Browser Bridge は MIT ライセンス の下でライセンスされたオープンソースソフトウェアです。ライセンス条件に従い、コピーの使用、複製、変更、結合、公開、配布、サブライセンス、販売を行うことができます。
制作: invictum.hr
This server cannot be deployed
Maintenance
Related MCP Connectors
AI-powered browser automation — navigate, click, fill forms, and extract data from any website.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants to control and automate your Chrome browser directly, leveraging existing login states and configurations for tasks like content analysis, semantic search across tabs, screenshots, network monitoring, and interactive operations.10MIT
- AlicenseBqualityFmaintenanceEnables AI agents to directly control your real Chrome browser with full context including login sessions, cookies, and open tabs. It provides tools for page scanning, JavaScript execution, CDP control, screenshots, and physical mouse/keyboard input for authentic browser automation.20243MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to securely control a user's existing signed-in Chrome browser through isolated tab groups, with strict per-session ownership and no cookie or token exposure.3 npmISC
- AlicenseNot gradedqualityBmaintenanceEnables AI assistants and terminal users to control a logged-in Chrome browser, performing actions like opening pages, searching, filling forms, and taking screenshots without re-authentication.MIT