Bring your own model. Let it work in your real browser—under your control.
A privacy-conscious, multi-model browser agent for Chrome and Microsoft Edge.
English · 简体中文 · Install from Chrome Web Store
TabCtrl is a BYOK (Bring Your Own Key) agentic browser extension. It lets models you choose read and operate task-scoped browser tabs, routes visual and complex reasoning work to specialized model profiles, and pauses for approval before sensitive actions.
There is no developer-operated backend and no telemetry. Model requests go directly from your browser to the endpoints you configure. See the privacy policy for the exact data flow and retention rules.
Task-focused side panel |
BYOK model profiles, capabilities, pricing and budget controls |
| Capability | What it gives you | |
|---|---|---|
| 🧠 | Multi-model routing | Assign primary, vision, reasoning, and fallback roles, then route each step by capability. |
| 🌐 | Real browser tools | Read accessibility trees, click, type, scroll, navigate, manage tabs, capture screenshots, wait for page state, and export structured data. |
| 🧭 | Plan and run control | Review a plan before execution, follow progress, stop work from the page or side panel, inspect run history, and safely retry failed runs. |
| 🛡️ | Layered safeguards | Task-tab isolation, URL and protocol guards, approval gates, sensitive-site policies, download protection, and guarded navigation rules. |
| 🧩 | Reusable knowledge | Import Skills, record parameterized teaching cases, and optionally retain compact execution-memory hints. |
| ⏰ | Local automation | Run notifications or carefully constrained scheduled tasks while the browser is running, with queueing and retry policies. |
- Open TabCtrl in the Chrome Web Store.
- Select Add to Chrome. Chromium-based Microsoft Edge is also supported.
- Open the TabCtrl side panel, then go to Settings → Models.
- Add at least one enabled
primaryprofile withtextandtoolscapabilities. - Open a normal
http://orhttps://page and describe the task you want completed.
Chrome 118 or a compatible Chromium browser is required. The Web Store extension ID is bniefocpdldneagigjlhbllgdjohmeie.
No build step is required for the extension itself.
git clone https://github.com/g1at/TabCtrl.git
cd TabCtrl
npm ciThen open chrome://extensions/, enable Developer mode, choose Load unpacked, and select the repository root. The public manifest.key keeps developer-mode installs on a stable extension ID; the store packaging script removes that field from upload packages.
TabCtrl supports the Anthropic Messages API and OpenAI Chat Completions-compatible endpoints. Typical configurations include:
| Provider | Protocol | Example base URL |
|---|---|---|
| Anthropic | Anthropic Messages | https://api.anthropic.com |
| OpenAI | OpenAI Chat Completions | https://api.openai.com/v1 |
| DeepSeek | OpenAI-compatible | https://api.deepseek.com/v1 |
| Moonshot | OpenAI-compatible | https://api.moonshot.cn/v1 |
| Qwen / DashScope | OpenAI-compatible | https://dashscope.aliyuncs.com/compatible-mode/v1 |
| OpenRouter | OpenAI-compatible | https://openrouter.ai/api/v1 |
| vLLM, Ollama, LM Studio | OpenAI-compatible | Your local /v1 endpoint |
You can combine profiles—for example, use a tool-capable primary model, delegate charts and screenshots to a vision model, and ask a reasoning model for difficult planning decisions. Provider-reported usage can be paired with prices you enter locally to estimate cost and enforce a per-task budget between model turns.
TabCtrl is powerful by design, so it applies several independent controls:
- BYOK and direct requests: API keys stay in Chrome extension storage and requests go directly to your configured provider. TabCtrl does not proxy them through a developer server.
- Task scope: browser tools operate only inside the current TabCtrl task tab group instead of scanning unrelated tabs or browsing history.
- Approval gates: risky, destructive, financial, authentication-related, and policy-sensitive actions are denied or require explicit confirmation.
- Navigation protection: protocol and URL checks plus temporary
declarativeNetRequestrules prevent unreviewed task-tab navigation from leaving the browser. - Restricted sites: identity-provider login pages are hard-blocked; major payment, banking, brokerage, and cryptocurrency sites require per-action approval.
- Local retention controls: recent tasks, run history, queues, schedules, teaching cases, Skills, and optional memory stay in browser storage and can be cleared by the user.
- Native bridge off by default: local CLI access requires an optional host installation and an exact command/path allowlist. Arbitrary shell execution is not supported.
Task prompts, relevant page content, screenshots, tool results, and optional memory or schedule context may be sent to the model endpoint you selected. That provider's privacy and retention terms apply. Read PRIVACY.md before using TabCtrl with sensitive information.
flowchart TB
U["User"] --> SP["Side panel<br/>Chat · Plan · Run center"]
SP <-->|Port| BG["MV3 background service worker<br/>Agent loop · state · schedules"]
BG --> R["Model router<br/>primary · vision · reasoning · fallback"]
R --> EP["User-configured endpoints<br/>Anthropic · OpenAI-compatible"]
BG --> SAFE["Policy and guards<br/>approval · tab isolation · URL/DNR · downloads"]
SAFE --> BT["Browser tools"]
BT --> CS["Content scripts<br/>AX tree · frame refs · click/type/wait/export"]
CS --> TABS["Task-scoped Chrome tab group"]
BG <--> STORE[("Chrome storage / IndexedDB")]
BG -. "optional, disabled by default" .-> NM["Native Messaging host"]
NM --> CLI["Allowlisted local CLI"]
- Plan mode: review, revise, approve, and track a step-by-step plan. Material deviations require confirmation.
- Run center: inspect active work, durable queue items, event timelines, token usage, estimated cost, and retry checkpoints.
- Scheduled tasks: create notification or agent schedules with IANA time zones, preflight checks, busy policies, and bounded retries.
- Reliable page state: stable element refs, cross-frame refs, conditional waits, conservative stale-ref recovery, and snapshot diffs reduce unnecessary context.
- Structured export: serialize supplied rows or bounded page tables as JSON, CSV, or TSV without first copying an unbounded table.
- Teaching cases and Skills: record reusable demonstrations or import folders containing
SKILL.mdinstructions. - Context management: summarize large task histories while preserving the original goal, current progress, important page state, and safety decisions.
- Optional native bridge: invoke explicitly allowlisted local tools on Windows, macOS, or Linux. See the dedicated native documentation before enabling it.
Requirements: Node.js 20+ and Chrome 118+.
npm ci
npm run lint
npm test
npm run eval
npm run smoke:extensionRun the complete Chrome Web Store release gate with:
npm run release:chromeThe release command lints the extension and supporting tools, runs unit and integration tests, performs a real unpacked-extension Chrome smoke test, and writes dist/TabCtrl-<version>.zip. The ZIP contains only manifest.json, icons/, and src/; the package manifest omits key for Web Store upload.
TabCtrl/
├── src/ Extension UI, agent runtime, providers and browser tools
├── icons/ Extension and README artwork
├── tests/ Unit, contract, evaluation and Chrome smoke tests
├── native/ Optional allowlisted Native Messaging bridge
├── agent-control/ Standalone experimental MCP/Chrome control demo
├── scripts/ Store packaging utilities
├── docs/images/ Sanitized product screenshots
├── manifest.json Chrome Manifest V3 definition
└── PRIVACY.md Bilingual privacy policy
agent-control/ is a self-contained experimental demo; it is not part of the main TabCtrl extension runtime.
- TabCtrl currently targets Chrome and Chromium-based Edge; Firefox is not supported.
- Shadow DOM support is limited, and rich editors, online documents, canvas, maps, or heavily visual pages may require a vision model.
- Scheduled tasks require the browser to be running and may be delayed by browser sleep or Manifest V3 scheduling.
- Site adapters provide conservative location and waiting hints, not a promise of compatibility with every future third-party UI change.
- Cost values are local estimates based on provider usage responses and prices entered by the user; provider billing remains authoritative.
- 完整中文说明
- Privacy policy / 隐私政策
- Skill format
- Native Bridge guide · 中文说明
- Agent Control experimental demo
- Contributing · Security policy
Issues and pull requests are welcome. Please read CONTRIBUTING.md, keep changes focused, and include tests for behavioral changes. Do not commit real credentials, browser profiles, machine-generated native manifests, or screenshots from personal accounts.
TabCtrl is released under the MIT License.

