HNHacker News
TopNewBestAskShowJobs

simon_luv_pho

91 karma · joined February 27, 2026

submissionscomments
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
After looking into it more, I think PageAgent is actually a very good fit for WebMCP...
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Currently, the extension only has access to the active tab when the task starts (configurable) and any new tabs it opens — all automatically placed into a dedicated tab group. It won’t touch other existing tabs.

Are you looking for something like scoping the agent to a predefined tab group?

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Really appreciate the in-depth feedback.

Iframe and CSP are big problems. For the in-page version, I chose to leave out Shadow DOM, canvas, and iframes. Although I know one of the developers forked a version to control same-origin iframes. I don't think it's practical to try to hack around browser security (and website security) — that's why I built the browser extension. I'm hoping the bridge that lets a page call the extension can cover most use cases.

My original HTML dehydration script was ported from `browser-use`. You're absolutely right that it's getting heavier over time, and it's the key factor influencing the overall task success rate. I'm looking to refactor that part and add an extension system for developers to patch their own sites. Hope it turns out well.

Thank you for the feedback. I'll be extra cautious to keep the dehydration code maintainable.

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
PageAgent operates at the HTML/DOM level with the same privileges as any other JavaScript running on the page and nothing more. The security token concern you're describing applies equally to every third-party script, npm package, or browser extension that runs in-page. It's not unique to PageAgent.

The browser extension can be more risky because it's more privileged. I've designed a simple authorization mechanism so that only pages explicitly approved by the user can call the extension.

That said, I'd welcome more eyes on this. If anyone wants to review the security model, the code is fully open source.

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Details of the testing LLM are listed here. https://github.com/alibaba/page-agent/blob/main/docs/terms-a...

The library does NOT include backend services. This is an open source project. I’m not selling any service here…

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Could you elaborate on what kind of security problems you’re referring to? Like hallucination?
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
This library does not include a LLM services. The one on the homepage is only for demonstration and testing. The npm package and extension requires your own LLM api config. Doc here https://alibaba.github.io/page-agent/docs/features/models
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
I see. The visual effect requires the browser to support webgl2.

The core functionality should not crash because the visual effect crashed. Not a good practice. I will fix that asap.

Thanks for noticing. Btw the video should work now.

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
This is the problem every agent has to face.

PageAgent’s differentiator is that site developers can embed it directly into their own pages. In that scenario, with proper system instructions plus a built-in whitelist/blacklist API for interactive elements, the risk is pretty manageable.

For the general-agent case, operating on pages you don’t control, the risk is definitely higher. I’m currently working on the human-in-the-loop feature so the user can intervene before sensitive actions.

Would love to hear other approaches if anyone has ideas.

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Does the "run" button work?
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Glad it worked well! The Chrome extension is my focus right now. It handles simple tasks pretty reliably and fast, but still has a long way to go for more complex workflows. Lots to improve.
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Currently the only dependency is zod for schema parsing.

I'm intentionally building on a lightweight, in-page JavaScript foundation to carve out some differentiation from the Python-heavy agent ecosystem.

The "protocol" layer of AG-UI does look interesting. I'll look into it to see if I can reuse something, although it seems to be evolving more toward an integration framework rather than an open protocol.

Really glad this resonates with your use case. Lightweight embedding is exactly my priority scenario. Would love to hear how the work goes!

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Confirmed. Have to fix that asap. About other issues. Can you see the homepage? What’s the browser version you use?
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
No and please don’t do that.

If you only use it as a personal assistant. You can connect to your llm service directly.

If you plan to integrate it into your web app. It’s better to have a proxy api for the llm and auth the request with cookie or something.

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
In my plan. Should be easy since I use wxt as the extension framework.
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
WebMCP doesn’t seem to be available for use inside webpages or extensions.
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
That looks great! I also thought about calling the Gemini nano model embedded into Chrome (only extensions can do that). But after some testing on smaller models I found that anything smaller than 9b can’t really handle the complex tool call schema I use.

Qwen3.5 4b is quite good but still gives messy json quite often. But it’s very promising!

Maybe after one more model iteration or some fine-toning we can go fully embedded?

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
It sounds like a network issue or browser compatibility issue. Can you please add an issue on GitHub so I can look into this.

I mean, not even the readme video?

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Is http://0.0.0.0:8080 a OpenAI compatible API?

Even it’s not, it’s not supposed to crash on startup. Can you post some screenshots and details on GitHub issues? I’m looking into this.

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
I haven’t. I don’t think it will work well.

I use a text-based approach. Captchas like “crossroad” usually need a screenshot, a visual model and coordinate-based mouse events.

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Thanks!
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Thanks!
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
I'm 2 years too late for that one...
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Everything happens at runtime, on the HTML level.

It uses a similiar process as `browser-use` but all in the web page. A script parses the live HTML, strips it down to its semantic essentials (HTML dehydration), and indexes every interactive element. That snapshot goes to the LLM, which returns actions referencing elements by index. The agent then simulates mouse/keyboard events on those elements via JS.

This works best on pages with proper semantic HTML and accessibility markup. You can test it right now on any page using the bookmarklet on the homepage (unless that page CSP blocks script injection of course).

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Not yet. Currently focused on the more common interaction patterns. PRs welcome though!
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
I added in the system prompt that it should skip CAPTCHAs and hand control back to the user. Currently working on a proper human-in-the-loop feature. That's actually one of the key advantages of running the agent inside your own browser.
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Thanks!

It supports any OpenAI-compatible API out of the box, so AWS Bedrock, LiteLLM, Ollama, etc. should all work. The free testing LLM is just there for a quick demo. Please bring your own LLM for long-time usage.

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
I'm looking into a European testing endpoint. The legal and compliance requirements are quite hassle, and persuading my company to pay for that infrastructure is gonna be a tough sell.
simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Full transparency: I work at Alibaba and published this under Alibaba's open-source org. I sometines maintain it during work hours, so yes, Alibaba technically pays me for it. That said, this is my project — it's MIT-licensed, includes no backend service, and is open for anyone to audit.

The free testing LLM endpoint is hosted on Alibaba Cloud because I happen to have some company quota to spend, but it's not part of the library. Bring your own LLM and there is zero data transmission to Alibaba or anywhere else you haven't configured yourself.

I highly recommend using it with a local Ollama setup.

simon_luv_pho··on Show HN: PageAgent, A GUI agent that lives inside your web app
Please use your own LLM api instead!

The free testing LLM is Qwen hosted by Aliyun. Qwen and DeepSeek are the only ones I can afford to offer for free. It's just there to lower the try-out barrier; please DO NOT rely on it.

The library itself does NOT include any backend service. Your data only goes to the LLM api you configured.

I tested it on local Ollama models it works fine.

Page 1 of 2Next →