mrkeyoor.com_
Mon 28 Sept 17:34 UTC
Automationevaluationupdated 26 Aug 2026

ego-lite review

ego lite is a macOS Chromium browser built so people and coding agents can work in separate Task Spaces while sharing login state. This repository contains the MIT-licensed `ego-browser` helper and agent skill; the browser application itself is a separate free download.

+175stars / 7d
Verdict

Our ego-browser helper installed 49 packages, passed all 299 tests, and reported 0 known npm vulnerabilities, but that clean result does not cover the separate browser binary or its session boundary. Try it on a dedicated low-privilege Mac profile for supervised work where shared login state saves real time. Do not use it for unattended sensitive accounts until the raw-cookie, cross-profile CDP, and macOS signature reports are resolved and independently verified.

We ran it

Lab card: what happened when we ran ego-liteScreenshot of ego-lite (lite.ego.app)
Install✓ · 20s49 packages · 68 MB
Build✓ · 12s
Tests✓ · 18s299 passed · 0 failed of 299 (node:test)
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo156 files~23,729 lines of source · 2.4 MB · 6 CI workflows · tests dir

Answers from our run

Does ego-lite build from source?

Dependencies installed in 20 seconds (49 packages), and the build succeeded in 12 seconds. We cloned commit 689f71a into a clean Debian container with 3 CPUs and no project-specific setup.

Do ego-lite's tests pass?

Yes: 299 of 299 passed when we ran the project's own test command (node:test). Some failures need services or credentials a bare container does not have.

Does ego-lite have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use ego-lite?

Windows or Linux users who need support today: the README says the browser currently runs only on macOS.

What are the alternatives to ego-lite?

Browser Use, agent-browser, Playwright. Our ego-browser helper installed 49 packages, passed all 299 tests, and reported 0 known npm vulnerabilities, but that clean result does not cover the separate browser binary or its session boundary.

Setup3/5Helper passes; app onboarding and profile migration remain
Docs4/5Detailed task, handoff, helper, and install instructions
Community4/513,686 stars and heavy August 2026 issue activity
Maturity2/5Clean helper tests, but open browser security boundaries are serious

Discussed on

  1. hnShow HN: Ego lite – why our browser agent writes JavaScript not CLI commands12 points

Who it’s for

macOS developers who want Claude Code, Codex, Cursor, or another agent to operate visible authenticated browser tabs.
Human-supervised workflows where the user needs to watch, interrupt, or take over a browser task.
Agent builders who prefer a JavaScript helper runtime over repeated low-level CLI calls.
Testers willing to use a dedicated low-privilege browser profile while the security boundaries mature.

Who it’s NOT for

Windows or Linux users who need support today: the README says the browser currently runs only on macOS.
Anyone comfortable giving an agent only page-level access: open issue 315 reports raw CDP and server-side fetch can expose cookies to model-generated scripts.
Teams relying on Task Spaces as a hard profile boundary: issue 319 reports cross-profile cookie reads and writes through CDP storage methods.
Security-conscious fleets that require verified macOS distribution integrity: issue 292 reports invalid app signatures and an installer that removes quarantine.
Long unattended jobs that cannot restart the browser: issue 329 reports recurring connection drops after sustained use.
Buyers expecting the downloadable browser's full source under MIT: the README says the repository contents are MIT and the browser is a separate download.

Setup reality

Our sandbox installed 49 npm packages in 20 seconds and used 68 MB. The helper build succeeded in 12 seconds, and all 299 Node tests passed in 18 seconds. Npm audit reported 0 known vulnerabilities across critical, high, moderate, and low severities.

Those results cover package/ego-browser/, not the separate Chromium browser binary. Real use needs macOS, the app, its installed skill and command, GUI onboarding, and a choice about Chrome-data migration. Reusing existing sessions avoids new service credentials but gives the agent access to authenticated sites.

Commit 689f71a contained 156 files and about 23,729 source lines in 2.4 MB. The repository has 6 CI workflow files and no Dockerfile. Windows and Linux appear on the roadmap, while the supported browser download is macOS-only today.

Separate Task Spaces solve the tab-collision problem

Browser agents usually start in a blank profile or take over a window the user needs. ego lite takes another route. Its Chromium app gives each agent job a Task Space with separate tabs, while allowing that space to inherit the user's login state. A person can keep browsing, watch the agent's space, take control for a login or judgment call, and later hand control back.

The ego-browser skill targets Claude Code, Codex, Cursor, and other agent CLIs. Its Node helper exposes snapshots, locators, clicking, typing, downloads, screenshots, JavaScript, fetch, Chrome DevTools Protocol access, and task-space ownership calls. A single script can observe and perform several steps before reporting back. That is a sensible interface for agents, which otherwise burn context on a long loop of tiny commands and page dumps.

The MIT repository is not the whole browser product

The open package lives under package/ego-browser/. It bundles agent-facing helpers around a browser-owned runtime, producing one ESM file that the browser invokes. The package documentation says the native browser owns tabs, Task Spaces, CDP transport, snapshots, and events. The top-level README separately states that repository contents use MIT while the ego lite browser is a separate free download.

That distinction affects review and procurement. Source inspection and tests cover the helper layer, but they do not provide the Chromium fork, native bridge, app updater, or macOS distribution as buildable source here. A team can audit the JavaScript calls around the bridge without reproducing the full browser binary. Treat the download as a product dependency with its own integrity, update, privacy, and rollback questions.

What happened when we ran it

Our sandbox entered package/ego-browser/ and installed 49 npm packages in 20 seconds, using 68 MB. The build completed in 12 seconds. Node's test runner finished in 18 seconds with 299 passed and 0 failed out of 299. Npm audit reported 0 known vulnerabilities: 0 critical, 0 high, 0 moderate, and 0 low.

The checkout at commit 689f71a had 156 files, about 23,729 lines of source, and 2.4 MB. It included 6 CI workflow files, a tests directory, and no Dockerfile. Our unprivileged 3-CPU, 8 GB Node 22 container did not install or launch the macOS browser, migrate a Chrome profile, exercise a real Task Space, or test CDP isolation. The green suite applies to the helper package only.

Shared login state is both the convenience and the risk

Importing Chrome data lets an agent use sessions, cookies, extensions, and bookmarks without repeated logins. For supervised research or administration, that can remove the hardest part of browser automation. It also means a bad instruction, compromised skill, or hostile page can act with whatever authority the profile already has. A separate profile with the minimum necessary accounts limits the damage better than a daily personal profile.

Open issue 315 reports that model-generated JavaScript runs with raw CDP access and Node-side HTTP egress, allowing synthetic HttpOnly cookie material to be read and sent away in the reporter's reproduction. The report points to the measured commit 689f71a and asks for filtering in the native bridge. This is an issue report, not our own exploit test, but it targets the exact privilege combination the product advertises.

Task Space isolation has reported browser-global holes

Issue 319 reports that CDP Storage.getCookies and Storage.setCookies from a secondary profile read and write the default profile's cookie jar instead of staying in the caller's context. Its reproduction used a synthetic cookie and ego lite 0.4.7.1. Issue 303 separately reports that Network.clearBrowserCookies from an agent Task Space cleared authenticated sessions in the main Space.

Those reports do not say ordinary page tabs share every cookie. They say low-level browser-global CDP methods can cross the boundary. That matters because the skill exposes a raw cdp() helper to agent-written scripts. Until native scoping or method denial is documented and tested, Task Spaces should be treated as workflow separation, not a security sandbox for accounts with different trust levels.

The macOS install path needs an integrity check

The browser runs on macOS today; Windows and Linux are listed on the roadmap. Users can download a DMG or ask the skill installer to set up the app. Open issue 292 reports that several official Apple Silicon DMGs failed strict code-signature verification even though notarization tickets were present. It also says the agent installer removes macOS quarantine before launch and does not verify a pinned artifact hash.

We did not download those DMGs or reproduce the signature test. The issue includes commands, hashes, versions, and archived artifacts, so security teams have enough detail to verify the current download before approving it. A clean npm audit of 49 packages says nothing about the signed state of a separate application binary. Organizations should require a valid signature and a verifiable download before migration of authenticated browser data.

Activity is high, while the trust model is still settling

GitHub recorded 13,686 stars, 138 combined issues and pull requests, and a push on August 26, 2026. Repository release v1.2.3 shipped August 11 with real-browser regression cases and task-space documentation changes. The browser app has its own 0.4.x version line in current issue reports, another reason not to equate the repository release with the downloadable application build.

Issue 329 also reports the remote connection closing during long automation sessions after 1 to 2 hours, with a full app restart needed before work resumed. The reporter observed it on two 0.4.x app builds. ego lite has a genuinely useful control model and a well-tested helper. For now, use it with human supervision, limited account authority, and an independently checked app binary rather than as an unattended browser holding a person's most sensitive sessions.

Alternatives

ProjectWhat it isPick it when
Browser Use gh↗A Python framework for agents that navigate websites through browser automation.pick this instead when you want a programmable cross-platform agent stack without adopting a daily-use browser.
agent-browser gh↗A command-line browser automation tool designed for coding agents.pick this instead when an isolated automation browser is preferable to sharing a personal browser state.
Playwright gh↗A cross-browser framework for scripted testing and automation.pick this instead when deterministic test code, CI support, and explicit browser contexts matter more than agent convenience.

What people are saying

  1. [github-trending] citrolabs/ego-lite

Sources

  1. ego lite README
  2. ego-browser helper README
  3. ego lite v1.2.3 release
  4. Raw browser credential issue 315
  5. Cross-profile cookie issue 319
  6. macOS signature issue 292
  7. Long-session connection issue 329

More automation reviews

fable-orchestrator · DLSS5-Swapper · runner-images · agent-fleet-manager · kargo · Rose · the whole board →