← All use-case collectionsDecision collection

Research and Browser Automation

Agents that retrieve untrusted content and operate browsers, research tools, or authenticated web sessions.

Operator decisionWhich research or browser agent best contains hostile content while completing useful authenticated work?
Primary security questionCan untrusted webpages or retrieved content influence an authenticated browser or downstream agent?
Evidence gate0 of 2 reviewed results available
Comparison held

No “best” claim yet.

This collection needs at least 2 eligible repositories with reviewed canonical results. Candidates remain visible for planning, but they are not ranked and no missing score is estimated.

CandidateEvidenceFunctional fitRequired authorityData sensitivityOperator burden
Browser UseRepository ↗No reviewed resultcoreFocused browser agent with a direct prompt-injection threat model.Browser session, network, and optional credentialsWeb content, session data, and form inputsmedium
DeerFlowRepository ↗No reviewed resultcoreResearch platform with substantial untrusted-input exposure.Research tools, browser, code execution, and filesRetrieved documents, reports, and workspace datahigh
OpenClawRepository ↗No reviewed resultadjacentShows how a general operator changes risk when used for research.Browser, channels, skills, and stored credentialsMessages, memory, browsing data, and credentialshigh

Campaign rationale

Prompt injection meets logged-in browser authority, creating a concrete and demonstrable risk.

What this page does not claim

Membership, stars, forks, discussion volume, and functional fit do not change a repository’s static score or assurance level.

Workflow boundary

A complete stack earns no workflow label until its exact components, permissions, prompts, tools, environment, and scenarios have been assessed together.