Toolin.ai
ego lite

ego lite

Officially listed

A macOS AI agent browser that shares your real logged-in browser state.

views 12favorites 0Free

ego lite

ego (lite) is a macOS desktop GUI browser plus agent driver layer built on Chromium 152 from Citro Labs (CITRO LABS PTE. LIMITED, Singapore/San Francisco). Its purpose is to share "your everyday logged-in browser state" with external AI agents (Claude Code, Codex, Cursor, and others), letting agents run web automation tasks in parallel Spaces without hijacking the tabs you are using. To be clear: it is not a headless runtime and not an MCP server — it is a real browser combined with a driver toolchain.

Core Capabilities and Architecture

  • Custom Chromium 152 core: Deep customization at the browser kernel level (not a JS shim on stock Chrome), centered on semantic snapshots: an accessibility-role semantic tree plus @N refs that, per the vendor, cover cross-origin iframes, shadow DOM, and third-party SDK components (Stripe / Salesforce / Intercom / React portals) where HTML scraping and JS shims tend to fail.
  • Spaces: Parallel workspaces within one browser process, each agent/task with its own tabs and focus, visible, and always takeover-able or killable. Users can run multiple tasks at once (say, Claude Code enriching leads in 10 Spaces while Codex crawls competitors in another 5).
  • ego-browser driver layer: Three interface forms — the native ego-browser CLI (about a 1.9 MB arm64 binary, symlinked into ~/.local/bin/ego-browser), an embedded Node 24 runtime (ego-browser nodejs <<EOF ... EOF), and a custom JS SDK (taskSpace(), page.goto/snapshot/click/fill/evaluate, etc.). The vendor explicitly states the SDK is not Playwright and forbids assumptions like locator()/getByRole()/route().
  • CDP escape hatch: page.cdp() / task.cdp() can send Page/Runtime/DOM/Network/Input/Target/Browser commands; communication with the browser runs over Mojo IPC (ego.mojom.EgoCliBootstrap / EgoCliBridge) — no TCP port, no WebSocket.
  • One-click Chrome migration: Login state, cookies, extensions, bookmarks, history, and multiple profiles migrate in — the vendor stresses "copy, not move", with data stored locally and never uploaded.
  • Human handoff: On captchas/2FA/payment confirmation, the agent calls handOff() to return control to the user, then continues after completion.

Workflow and Integration

  1. Install: Download the DMG (lite.ego.app/download, measured at about 135.7 MB, version 0.5.0.32); or install only the skill with npx skills add citrolabs/ego-lite; or hand the repo link to an agent to self-install. Note ego-browser is not an npm package (npm view ego-browser and @citrolabs/ego-browser both 404).
  2. First launch: The ego-browser skill is written into ~/.agents/skills/, ~/.claude/skills/, and similar skill directories, and the app asks whether to migrate Chrome data. The vendor recommends giving the agent Full access / bypass permissions so the browser can launch local apps past the agent sandbox.
  3. Typical invocation: Trigger from an agent CLI with /ego-browser <natural-language instruction>, e.g. /ego-browser follow @ego_agent on x.com; underneath it is JS batch processing via taskSpace(...) plus page.goto/snapshot/....
  4. Agent support: Claude Code, Codex, Cursor, OpenCode, Gemini CLI, Kimi Code CLI, Warp, Zed, Cline, Antigravity, Continue, and a dozen-plus others, with local model support (Ollama + OpenCode).

Who It's For and Scenarios Aimed at developers, automation engineers, QA, and ops/sales people on macOS who use coding agents heavily. Official scenarios all revolve around "requires login, has no API" websites: social media posting/scraping/monitoring (X, LinkedIn, Reddit, etc.); job/recruiting searches with ATS auto-fill (pausing before submission for confirmation); real estate/finance/shopping filtering and price comparison; flight and hotel booking (stopping at the payment page); SaaS admin report exports/bulk field edits (HubSpot, Salesforce, Stripe, GA4, etc.); and your own admin plus front-end E2E regression.

Versus Playwright/browser-use/Skyvern and other rivals

  • vs Playwright / Puppeteer: They are in-code libraries driving a blank browser with CSS selectors; ego lite is a real browser plus driver layer using semantic refs, JS batch processing, and your real login state. No conflict — they can coexist.
  • vs browser-use: browser-use is an open-source autonomous natural-language task framework requiring your own browser, with login state hard to inherit and a habit of stealing your tabs; ego lite ships the logged-in browser and semantic snapshot driver directly.
  • vs Vercel agent-browser: agent-browser issues CLI actions one at a time; ego lite advocates "one block of JS, one execution" — its main rival on speed claims.
  • vs Stagehand / Browserbase / Steel: Those three are cloud/code SDK browsers aimed at product-grade cloud browser fleets (proxies, stealth, captcha, SOC2); ego lite is a local personal browser running on one machine with no browser-minute billing and no page traffic through the cloud.
  • vs Skyvern / BrowserAct: Those lean toward cloud workflow/enterprise automation platforms; ego lite is a local desktop GUI browser.
  • vs Lightpanda: Lightpanda is a headless browser (server/CI); ego lite is a desktop GUI browser and is officially unsuited to headless CI.

Security and Performance Caveats

  • Spaces do not isolate cookies: The vendor has admitted "a space is not the same as a profile, and spaces do not isolate cookies", and independent testing confirmed cookies/localStorage written in Space A are fully visible in Space B (issues #303/#315/#319). Mitigation: you must use a dedicated profile.
  • Injection risk from privileged runtime + raw CDP: Model-generated JS runs in a privileged Node process with unrestricted page.cdp() and outbound HTTP; prompt injection from a visited page could theoretically read/manipulate every account you are logged into, and the exposure shows no fix (issue #315). The security scanner skills.sh rates the ego-browser skill High Risk.
  • Closed-source binary + full login state: The browser itself cannot be audited, yet it requests Full access and migrates all cookies/passwords/extensions; trust rests on policy text alone. The GitHub repo (citrolabs/ego-lite, about 16k stars, MIT) contains only the skill + docs + spec — the browser is a closed-source free binary.
  • Performance claims deserve a discount: "fastest" and "2.5×/3.45×" come from vendor self-tests (citrolabs/ego-browser-benchmark-framework) with no third-party reproduction; independent testing found its page.snapshot() at 7,823 tokens — actually costlier than agent-browser's 4,742. In full-permission mode the HN task ran about 14% faster and 31% cheaper, but the default permission mode is the slowest because Bash guards block it (measured 194.8s / 30 turns).
  • Other pitfalls: The setup page's "set as default browser / send crash reports / add to Dock" are all checked by default and may silently replace your default browser; with multiple profiles, taskSpace() defaults to Default and can cause false "not logged in" errors; automating X/LinkedIn as yourself may violate platform terms and trigger risk controls.

Editor's Verdict ego (lite) is a genuinely usable, currently downloadable, fast-iterating product that really does solve the pain of "agents can't use real login state and fight users for tabs", for free with no account and broad agent support. But its technical promises need discounting: Spaces' "isolation" fails at the cookie layer, snapshot tokens are not competitive, the speed edge holds only in the vendor's self-tested full-permission mode, and there is an unfixed high-severity injection surface. In one line — excellent but dangerous: "a browser that borrows your identity". Practical advice: create a dedicated profile first, log in only with accounts you "could hand to an intern", and never run untrusted prompts under your everyday Chrome's full login state.

Pricing

### 💰 定价模式:免费(个人版永久免费) **起步价**:$0(无需注册或登录) #### 主要方案 - **ego (lite) 个人版**:$0 永久免费 — macOS App、并行 Spaces(数量仅受本机性能限制)、`ego-browser` skill、复用真实 Chrome 登录态 - **ego (lite) 企业版**:定制报价,官方未公开任何金额或档位表 - **ego(母产品·完整版个人 Agent)**:订阅制,价格未公开,目前仍处 waitlist 预发布阶段 #### 补充信息 - 官方 FAQ 明确:ego (lite) 完全免费,无需登录/注册账号。 - `lite.ego.app/pricing` 为 404,定价信息实际位于 `/enterprise`(标题 “Simple, honest pricing”)。 - 注意:官方未提供任何“免费承诺”的期限或条款文本,第三方分析视 $0 为发布姿态而非合同承诺。 - 平台限制:仅支持 macOS(Apple Silicon M1–M4 与 Intel);Windows/Linux 在路线图,无发布日期。 — Visit website

FAQ

Is ego lite free?

Yes. ego Personal (desktop + mobile + CLI) is permanently free ($0) with no registration or login required; the enterprise edition is custom-quoted with no public price, and the parent product ego is an unreleased subscription product.

What can ego lite do?

It shares your real logged-in browser state with external AI agents, letting agents execute web tasks in parallel Spaces — posting and scraping, ATS form filling, price comparison and ordering, SaaS admin operations, and more — without taking over your current tabs.

Is ego lite a headless browser or an MCP server?

Neither. It is a macOS desktop GUI browser plus an ego-browser CLI, a Node 24 runtime, a custom JS SDK, and a raw CDP driver layer — explicitly not a headless runtime, and it provides no official MCP server.

Which operating systems does ego lite support?

Currently macOS only (native on Apple Silicon M1–M4 and Intel). Windows/Linux are on the roadmap, but the vendor has given no release dates.

How does ego lite differ from Playwright?

Playwright is an in-code library driving a blank browser with CSS selectors; ego lite is a real browser plus driver layer, using semantic snapshot refs and JS batch processing while reusing real login state. The two serve different purposes and can coexist.

How does ego lite differ from browser-use?

browser-use is an open-source autonomous natural-language task framework that requires your own browser, makes login state hard to inherit, and tends to fight users for tabs; ego lite ships a browser with your login state and a semantic snapshot driver layer directly.

Do ego lite's Spaces isolate cookies?

No. The vendor has admitted that a space is not the same as a profile and that spaces do not isolate cookies, and independent testing confirmed cookies are fully visible across Spaces — you must use a dedicated profile to isolate login state.

Is ego lite safe? What are the risks?

There are clear risks: the privileged Node runtime plus unrestricted raw CDP can be exploited by prompt injection from pages, potentially reading every account you are logged into; the skill was rated High Risk by a security scan. Use a dedicated profile and log in only with accounts you can afford to entrust.

Is ego lite's GitHub repository open source?

Partially. The citrolabs/ego-lite repo (about 16k stars, MIT) contains only the skill, docs, and spec; the browser itself is a closed-source free binary whose source cannot be audited.