AgentSafe is a local-only Manifest V3 Chrome extension for inspecting webpages before they enter AI-agent, browser-assistant, or web-to-LLM workflows. It scans the active page for hidden instructions, encoded payloads, Unicode obfuscation, suspicious metadata, comments, delimiter blocks, and tool-use or data-exfiltration language.
AgentSafe does not use a backend, authentication, telemetry, analytics, remote code, or external AI APIs. All scanning, scoring, sanitizing, and export generation happens on the user's machine. Detection is advisory: it helps surface risk, but it is not a guarantee of safety.
A real scan of a page whose visible text says nothing unusual. Recorded from the packaged build; see Media capture.
Modern AI agents increasingly read webpages, summarize browser content, call tools, and copy page text into model context. A page can contain text that a human never sees but an automated extractor may still collect. AgentSafe makes that hidden AI-facing surface visible, explainable, and exportable.
| Problem | AgentSafe Response |
|---|---|
| Hidden prompt-injection text in comments, metadata, CSS-hidden nodes, or offscreen elements | Detects visibility, extraction likelihood, evidence, selectors, and confidence |
| Obfuscated text using Unicode controls, zero-width characters, or encoded payloads | Normalizes and flags suspicious patterns with rule-specific explanations |
| Large pages that can freeze a side panel or browser tab | Uses worker-based scanning, chunking, progress updates, cancellation, and partial-scan metadata |
| AI workflows that need safer copied content | Exports sanitized Markdown and JSON reports locally |
| Reviewers who need to understand why something is risky | Provides title, verdict, concern, impact, confidence reason, and recommended action per finding |
flowchart LR
User[User clicks Scan] --> Snapshot[Page snapshot via chrome.scripting]
Snapshot --> Adapter[Browser scanner adapter]
Adapter --> Worker[Scan worker]
Worker --> Rules[DOM, CSS, Unicode, metadata, encoded, and instruction rules]
Rules --> Risk[Local risk engine]
Risk --> Findings[Explainable findings]
Findings --> UI[Side panel review]
UI --> Actions[Highlight, reveal, export Markdown, export JSON]
Settings[Local settings and scoped exceptions] --> Adapter
Actions --> Sanitizer[DOM sanitizer]
Sanitizer --> Exporter[Markdown and report exporter]
AgentSafe is a TypeScript and Rust monorepo. The Chrome extension is built with WXT and React. Detection runs in a Rust/WASM scanner inside a Worker; the TypeScript packages handle extraction, chunking, scoring, sanitizing, and export. The production manifest has no static host permissions and no content scripts that run automatically on every page.
flowchart TB
subgraph Extension["apps/extension"]
SidePanel[React side panel]
Background[MV3 background service worker]
end
subgraph Packages["TypeScript packages"]
Adapter["@agentsafe/browser-scanner-adapter"]
Risk["@agentsafe/risk-engine"]
Sanitizer["@agentsafe/dom-sanitizer"]
Exporter["@agentsafe/markdown-exporter"]
Types["@agentsafe/shared-types"]
WasmWrapper["@agentsafe/scanner-wasm"]
end
subgraph Rust["Rust crates"]
Core["agentsafe-core"]
Wasm["agentsafe-wasm"]
end
SidePanel --> Adapter
Adapter --> WasmWrapper
Adapter --> Risk
Adapter --> Types
Risk --> Types
SidePanel --> Sanitizer
Sanitizer --> Exporter
WasmWrapper --> Wasm
Wasm --> Core
| Area | Status | Notes |
|---|---|---|
| Explicit user-triggered scanning | Complete | Scan runs only after user action |
| Worker-based scan execution | Complete | Supports quick, standard, and deep scan modes |
| Large-page handling | Complete | Bounded traversal, chunking, progress, cancellation, and partial results |
| Rule coverage | Complete | Hidden CSS, comments, metadata, Unicode, encoded content, delimiter, tool-use, and exfiltration signals |
| Explainable findings | Complete | Evidence, selector, severity, confidence, verdict, visibility, extraction likelihood, and recommended action |
| Local risk scoring | Complete | Uses multi-signal scoring for stronger high-risk classification |
| Page interaction | Complete | Highlight findings, navigate evidence, and temporarily reveal hidden content |
| Local export | Complete | Sanitized Markdown and JSON report export |
| Privacy posture | Complete | No backend, telemetry, or remote AI calls; nothing written to disk unless the user exports |
| Scoped exceptions | Complete | Rule-scoped local exceptions stored in chrome.storage.local |
| Principle | Implementation |
|---|---|
| Local-first | Page content is scanned in the browser extension context |
| Minimal persistence | Settings live in chrome.storage.local; the latest per-tab scan result is cached in memory-backed chrome.storage.session and cleared when Chrome closes |
| Explicit action | The extension scans only after the user chooses to scan, highlight, or reveal |
| No remote code | The production build uses packaged extension assets |
| No default host access | The manifest avoids broad static host permissions |
| Advisory output | Findings explain risk and confidence without claiming perfect detection |
pnpm install
pnpm test
pnpm --filter @agentsafe/extension dev
pnpm --filter @agentsafe/extension build
pnpm verify:cleanLoad the production build from:
apps/extension/.output/chrome-mv3
To scan local fixture files, open AgentSafe's extension details in Chrome and enable Allow access to file URLs.
The production build must include:
| Asset | Purpose |
|---|---|
apps/extension/.output/chrome-mv3/assets/scan-worker-*.js |
Isolated worker bundle for scan execution |
apps/extension/.output/chrome-mv3/assets/agentsafe_wasm_bg-*.wasm |
Local WASM scanner asset |
Store screenshots and the README GIF are photographs of the running extension, not drawings. Both pipelines load the packaged build in Chromium, scan a real page, and capture the real side panel — a hand-drawn asset drifts from the product the moment the UI changes, and shipping one as a product screenshot misrepresents what a user is installing.
| Command | Output |
|---|---|
pnpm capture:screenshots |
Five 1280x800 store screenshots in docs/chrome-store/assets, each driven into a distinct panel state |
pnpm capture:demo |
docs/media/demo.webm, an untracked recording of a real scan |
pnpm make:gif |
docs/media/demo.gif, encoded from that recording under a 5 MB budget |
Both capture commands need a current build (pnpm --filter @agentsafe/extension build) and run as separate Playwright projects, so an ordinary pnpm e2e never
rewrites a published asset as a side effect.
scripts/make-gif.sh takes --width, --fps, --colors, and --budget. It
refuses a frame rate that does not divide 100 evenly, because GIF stores frame
delays in hundredths of a second and anything else stutters.
| Path | Purpose |
|---|---|
apps/extension |
WXT React side panel and Manifest V3 extension entrypoints |
packages/browser-scanner-adapter |
Browser extraction contracts, worker coordinator, chunking, cancellation, finding mapping, and exception filtering |
packages/scanner-wasm |
TypeScript wrapper around the Rust/WASM scanner package |
packages/risk-engine |
Scoring, severity mapping, and summary aggregation |
packages/dom-sanitizer |
Local DOM cleanup and suspicious-content neutralization |
packages/markdown-exporter |
Readability extraction plus Markdown and JSON report generation |
packages/shared-types |
Shared public data contracts |
crates/agentsafe-core |
Rust scanner primitives and rule evaluation |
crates/agentsafe-wasm |
WASM bindings for browser packaging |
fixtures |
Benign, malicious, scanner, WebMCP, and performance fixtures |
docs |
Architecture, threat model, privacy, Chrome Store, scan lifecycle, and audit documentation |
| Command | What It Verifies |
|---|---|
pnpm test |
JavaScript and TypeScript unit tests |
pnpm typecheck |
Package builds and extension type safety |
pnpm e2e |
Playwright coverage that loads the packaged build in Chromium and scans real pages, plus fixture and side panel smoke checks |
pnpm --filter @agentsafe/extension build |
Production Chrome MV3 extension output |
pnpm verify:clean |
Frozen install, Rust format, clippy, Rust tests, TypeScript checks, JS tests, and production build. Run pnpm e2e separately; it is not part of this script |
| Phase | Goal | Candidate Work |
|---|---|---|
| 0.2 - Reviewer polish | Make findings easier to understand and triage | Rule documentation generated from source, richer evidence grouping, clearer false-positive guidance, and improved report summaries |
| 0.3 - Coverage expansion | Improve detection across real-world page types | More fixtures for CMS pages, docs sites, issue trackers, email-style pages, dashboards, and dynamic apps |
| 0.4 - Packed-extension validation | Test closer to Chrome Web Store behavior | Playwright coverage against a packed MV3 build, install/update smoke tests, and permission regression checks |
| 0.5 - Custom local rules | Let advanced users tune detection locally | Optional local-only rule editor, import/export for rule packs, and per-site rule overrides |
| 0.6 - Performance hardening | Keep scans fast on large and complex pages | Benchmarks for deeply nested DOMs, streaming export improvements, worker memory profiling, and WASM size tracking |
| 0.7 - Enterprise readiness | Support teams that review AI-facing web content | Signed release artifacts, policy templates, audit-friendly reports, and managed configuration guidance |
| Check | Expected Result |
|---|---|
| Manifest review | Permissions match documented use and Chrome Store justification |
| Local verification | pnpm verify:clean passes |
| Extension output | .output/chrome-mv3 contains manifest, side panel, worker, and WASM assets |
| Fixture scan | Benign pages stay low risk and malicious fixtures produce expected findings |
| Privacy review | No telemetry, backend calls, analytics, or persisted page body content |
| Store copy | Listing, screenshots, privacy policy, and permission justification are current |
Start here for deeper detail:
| Document | Topic |
|---|---|
ARCHITECTURE.md |
High-level implementation sequence and package roles |
docs/WORKER_SCANNING_ARCHITECTURE.md |
Worker-based scan architecture |
docs/SCAN_LIFECYCLE.md |
Scan lifecycle and status model |
docs/threat-model/THREAT_MODEL.md |
Threat model |
PRIVACY.md |
Privacy posture |
docs/chrome-store/CHROME_STORE_LISTING.md |
Chrome Store listing copy |
docs/chrome-store/PERMISSION_JUSTIFICATION.md |
Permission rationale |
