The primary risk with these browser agents is prompt injection attacks. Running it locally doesn't help you in that regard.
Regardless, giving a remote API access to a browser seems insane. Having had a chance to reflect, I’d be very wary of providing any LLM access to take actions with my personal computer. Sandbox the hell out of these things.