Use the browser only as a last resort
On the runtime/LEIA-ME.md, the browser is step 5, computer use. But look at the stability column: it is the only one marked as downloads. Even the local bridge, level 6, is intermediate.
That’s why the R5 recipe opens with a warning: use the browser only when no API, MCP, or CLI exists or export. It's the most fragile approach because the site changes. The only thing below it is reverse engineering, which is for the lab.
🆕 New here? Three words from this module
- Browser for agents — a command-line program that opens pages, reads text, clicks, and fills in forms, taking instructions from the agent instead of the mouse.
- Chromium — Google's open-source foundation for Chrome. The browser for agents uses its own copy, separate from your Chrome.
- Selector — the "address" of a button or field on the page. When the site changes its design, the address changes and the automation gets lost.
How to read the diagram: the bar’s height represents the stability of the LEIA-ME.md gives each step. The step number isn't the order of preference: the browser bar (highlighted) is lower than the local bridge. That's why it's the second-to-last resort.
✓ When using the browser makes sense
- ✓ The vendor’s portal has no API or export button
- ✓ The information appears on only one screen (price table, status)
- ✓ The task is to read and copy, not decide
- ✓ You accept that the site may change one day and need adjustments
✗ When to look for another way
- ✗ The system exports CSV (use the bridge, module 2.3)
- ✗ An official API or MCP server exists
- ✗ The main task is to send or pay
- ✗ The site requires you to solve a “I’m not a robot” challenge
computer use
stability in the README
the bridge wins
the automation gets lost
Install the browser for agents
Recipe R5 uses the agent-browser, a command-line browser built for agents. It is installed via npm, the same installer you used for Claude Code and Codex in module 1.2.
These are two commands: one installs the program, the other downloads the Chromium it uses. The second takes longer because it’s a whole browser.
In the terminal (any folder), one command at a time:
npm i -g agent-browser agent-browser install
Expected result (according to the instructions):
The first command installs the agent-browser; the second one “downloads the Chromium it uses.” The instructions don’t specify a fixed output for the installation: the proof comes in topic 3.
npm complaining about permissions is the same problem you solved when you installed Claude Code.| Option | Which browser it uses | When it makes sense |
|---|---|---|
agent-browser (R5 recipe) | its own clean Chromium, without your logins | public sites, tests, reading tables |
| "Claude in Chrome" extension | your browser, already logged in | when the site requires your login (topic 6) |
What to look for in the table: the two options appear in R5, and the same rules apply to both. The difference is whose browser it is and, therefore, whose accounts are signed in there.
💡 A separate browser is a safeguard
agent-browser's Chromium doesn't have your email, your bank account, or your saved passwords. If the agent gets confused, it gets confused in an empty browser. Always start there.
install the program
downloads Chromium
without your logins
the logged-in alternative
Test reading only
Before handing the browser to the agent, test it yourself. And test it in the safest way possible: open a sample page, read the title, and close it. Nothing is clicked or submitted.
The site example.com exists exactly for this purpose: it is a demo page reserved for examples, with no form or purchase button.
open — opens the page
agent-browser's Chromium loads the address you provided.
get title — reads the title
Purely read-only. It's the kind of action the policy lets the agent perform on its own (N4).
close — closes
Close the browser. Don’t leave a session open for no reason.
In the terminal, one command at a time:
agent-browser open https://example.com agent-browser get title agent-browser close
Result confirmed in CHANGELOG 0.2.0:
agent-browser open https://example.com + get title → Example Domain.
get title returns Example Domain. This is the R5 recipe test.How to read the diagram: only the blue arrow at the top is a clear path. The dashed gray one goes through you first. The red ones aren’t agent paths: the agent prepares and stops. The test in this topic uses only the blue arrow.
opens the page
reads the title
close
the proof
Ask the agent with a written limit
With the proof in hand, the agent can use the browser. The key is in the request: it already says what to do and where to stop. Sônia uses this to copy the supplier’s price table from the portal when it doesn’t offer any export option.
The R5 policy has three tiers, and the request below fits entirely in the first one.
| Action on the site | Level (R5) | What the agent does |
|---|---|---|
| Read a page | N4 | do it automatically, without notifying me |
| Fill in or submit | N2 | asks beforehand, every time |
| Pay | N1 | never: prepares it, and you execute it |
What to look for in the table: is the same per-action ceiling as the POLITICA.md (read N4, send N2, spend money N1), applied to the browser.
Open claude (or codex) in the kit folder and paste the R5 recipe request, replacing <site> with the address:
Use o agent-browser para abrir <site>, ler a tabela de preços e me devolver em CSV. Não clique em botões de envio ou compra: se precisar, pare e me pergunte.
open, readings and close, no clicking submit or purchase.✓ Request with limits
- ✓ Says which site to use and what to read
- ✓ Specifies the delivery format (CSV)
- ✓ Says what not to do (send, purchase)
- ✓ Says what to do when unsure: stop and ask
✗ Request with no limits
- ✗ “Take care of this in the portal for me”
- ✗ “Place this month’s order with the supplier”
- ✗ “Go in there and update the record”
- ✗ No row says where to stop
💡 "Stop and ask me" is the most useful phrase in the request
Websites have surprises: a cookie notice, a “continue” button that actually confirms something. Without this sentence, the agent tends to keep going to finish the task. With it, the surprise becomes a question for you.
pricing table
CSV to use later
sending and purchasing
asks you
Paste the browser rules into AGENTS.md
Writing the limit in every request works, but one day you’ll forget. The solution is to put the rule somewhere the agent reads before for any request: the AGENTS.md.
Codex reads the AGENTS.md directly, and the CLAUDE.md from the kit points to it with @AGENTS.md. One rule, two agents. Recipe R5 has the block ready to use:
Browser: - Read, scroll, take screenshots: allowed. - Fill out a form: show what you’re going to enter and wait for my OK. - Submit, confirm, pay, delete: never on your own. - Login: I do it; you don’t ask for or save the password.
Open claude in the kit folder and paste:
Copy the “Navegador:” block from the “Regras para colar no AGENTS.md” section of runtime/receitas/R5-navegador-com-politica.md to the end of AGENTS.md, without changing any other line. Show the new section before saving.
AGENTS.md. The "Browser:" block appears at the end, with all four lines, and the earlier rules remain unchanged.✓ Rule in AGENTS.md
- ✓ Applies to every request, even one you forgot to limit
- ✓ Applies to Claude and Codex
- ✓ It stays in Git: you can see when it changed
✗ Rule only in the conversation
- ✗ Disappears when the session ends
- ✗ Each agent has a different version
- ✗ No one remembers what was agreed on
💡 Register the site on the map too
O CAPACIDADES.md already includes the example Site do fornecedor | Uso do computador | 5 | navegador automatizado | enviar (N2) | pendente. After testing it with your site, replace "pending" with the date, as in module 2.3.
read before acting
Claude reads the same
one per range
site with a date
Remember, you handle the login
The last line of the block is the most serious: "Login: I’ll handle it; you don’t ask for or store the password." A password doesn’t go in chat, in a project file, or from one tool to another.
A POLITICA.md says the same thing in general: "Never pass a tool’s credentials to another tool." In the browser, this applies twice as much, because the login page is exactly where the password would be at hand.
⚠️ Logged-in browser = your accounts are open
The "Claude in Chrome" extension uses your browser, already logged in. The agent can reach everything you can do in it: email, bank, social networks. R5 warns that the same rules apply. Use the logged-in browser only for sites that require your login, and keep the "Browser:" block in the AGENTS.md.
The agent reaches the login screen
Under the rule, it stops and lets you know. It doesn’t try to guess or ask for the password in chat.
You log in
In your browser, with your own hands. That includes the code that arrives on your phone.
The agent goes back to reading
With the session open, it stays within the same boundaries: reads on its own, asks before filling things out, never submits or pays.
💡 Clara and the agreement portal
Clara wants to check on the agreement website which claims have been approved. She logs in with her own credentials; the agent reads the list and returns it as a CSV. Requesting approval for a new claim is already “sending”: the agent prepares what to fill in and waits for her OK.
Quick test (optional): the agent is on the supplier's portal and finds the "Confirm order" button. What does the R5 rule say?
you do
never in chat
doesn’t pass it on
same rules
🎓 Module summary
Next learning path:
Track 3 — Route and execute (3.1 The right model makes your quota go further)