Auditable sandbox for coding agents. Browser, dependencies, dev server, and workspace in one disposable environment. Local-first. No hosted sandbox. No SaaS account required.
-
Updated
Aug 19, 2026 - Rust
Auditable sandbox for coding agents. Browser, dependencies, dev server, and workspace in one disposable environment. Local-first. No hosted sandbox. No SaaS account required.
Malicious Extension Database
Harden chromium (somewhat) for privacy and security (and performance)
A professional, high-fidelity de-anonymization and vulnerability diagnostic framework. Features a zero-coupling modular architecture for browser-based intelligence gathering, hardware fingerprinting, and security research.
A USB-based script for Ethical hacking with multiple attacks
This browser extension, designed for Qubes OS, blocks and/or redirects non whitelisted URLs to another qube of your choice.
This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one place. The CRX in this Repository are used to train AI Model behind ExterminAI. I hope this will allow others to explore the world of malicious browser extensions and their behaviour!
A modular browser telemetry & fingerprinting research toolkit — explores Web APIs, device metadata, sensors, geolocation, media, and storage. Streams collected data via WebSocket and Telegram. Built for authorised security research and browser API experimentation.
Passive LLM Conversation Capture & Sensitive Data Exposure Research
Proof-of-concept demonstrating browser-native file encryption via the File System Access API. No software installation required - runs entirely within the browser sandbox. Built for authorized red-team assessments.
You've been pinched. Now get unpinched. Find out if PinchTab is running on your host before someone else does.
Security research and exploit development: vulnerability analysis, exploit chain implementation, post-exploitation tradecraft, and defensive assessment tooling. Covers browser engines, persistence mechanisms, credential harvesting, C2 patterns, and AI-accelerated attack automation.
PoC of FileJacking technique with File System API.
Extract stored password(s) and important file(s) from various browser (i.e. Chrome, Brave, Edge, Opera)
hat is a powerful tool designed to provide secure file encryption and decryption directly within your browser. This project, primarily written in JavaScript, ensures that your sensitive data remains private by performing all encryption processes client-side, without the need for server interactions.
Firefox profile decryption tool and master password cracker.
Code for ASE'21 Paper "CorbFuzz: Checking Browser Security Policies with Fuzzing"
A firewall for browser agents. Chrome extension that detects, monitors, and controls AI agents in your browser. Identifies Playwright, Puppeteer, Selenium, Anthropic Computer Use, and OpenAI Operator without the agent identifying itself.
AI-powered Chrome extension for real-time phishing & malware detection using Gemini 1.5 Flash
Add a description, image, and links to the browser-security topic page so that developers can more easily learn about it.
To associate your repository with the browser-security topic, visit your repo's landing page and select "manage topics."