Research and Browser Automation
Agents that retrieve untrusted content and operate browsers, research tools, or authenticated web sessions.
Comparison held
No “best” claim yet.
This collection needs at least 2 eligible repositories with reviewed canonical results. Candidates remain visible for planning, but they are not ranked and no missing score is estimated.
| Candidate | Evidence | Functional fit | Required authority | Data sensitivity | Operator burden |
|---|---|---|---|---|---|
| Browser UseRepository ↗ | No reviewed result | coreFocused browser agent with a direct prompt-injection threat model. | Browser session, network, and optional credentials | Web content, session data, and form inputs | medium |
| DeerFlowRepository ↗ | No reviewed result | coreResearch platform with substantial untrusted-input exposure. | Research tools, browser, code execution, and files | Retrieved documents, reports, and workspace data | high |
| OpenClawRepository ↗ | No reviewed result | adjacentShows how a general operator changes risk when used for research. | Browser, channels, skills, and stored credentials | Messages, memory, browsing data, and credentials | high |
Campaign rationale
Prompt injection meets logged-in browser authority, creating a concrete and demonstrable risk.
What this page does not claim
Membership, stars, forks, discussion volume, and functional fit do not change a repository’s static score or assurance level.
Workflow boundary
A complete stack earns no workflow label until its exact components, permissions, prompts, tools, environment, and scenarios have been assessed together.