CLI tool
Hacker-Valley-Media/Interceptor avatar
Hacker-Valley-Media/Interceptor

Interceptor drives the browser you are already signed into

Agent-driven Chrome extension for full browser control via CLI

481 stars72 forksTypeScriptNOASSERTION

At a glance

What is it?
Interceptor is a Chrome extension, daemon and CLI that hands an agent your real browser session, your native Mac apps and a physical iPhone. The interesting constraints are packaging and permission: three macOS installers, macOS 15 plus for the native bridge, and Safari requiring your own approval.
Who is it for?
Use it when the work depends on being already logged in, on a rich editor that only exists in the page, or on a phone you can hold, because that is what the extension model buys you over launching a clean automated browser. Do not use it expecting headless scale: the default path is one signed-in profile with an extension installed per profile, and macOS binaries only target Apple silicon.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Four verbs cover the common path, and a group owns the tabs

The command surface is deliberately small at the top. `open`, `read`, `act` and `inspect` combine the steps most tasks need, with detailed verbs and agent skills underneath for deeper work. A first task looks like this:

bash
interceptor open "https://example.com" --group first-task
interceptor read --group first-task
interceptor group close first-task

`open` starts the daemon if it is not already running, opens a managed tab in the background, and hands back the page tree and text, so you should see Example Domain without navigating yourself. `read` inspects the same tab again, which is how an agent checks what happened after an action rather than assuming. `group close` removes that task's tabs, which is the piece that keeps repeated runs from piling up windows. Two details are worth memorising. If several browser contexts are connected, `interceptor contexts` lists them and `--context <id>` picks one, with Safari's id being `safari`. And `interceptor status` reports local health without starting the daemon, so a failed check tells you nothing about whether the daemon is up.

Three macOS packages, and only Full carries the native bridge

The download table is the first decision, and picking wrong costs you a reinstall. `Interceptor-Browser-<version>.pkg` gives you the CLI, the daemon and the browser extension files, which is all web work needs. `Interceptor-Full-<version>.pkg` is that package plus the native Mac bridge and the iPhone tooling, and the bridge requires macOS 15 or later. `Interceptor-Safari-<version>.pkg` is only the Safari extension add-on, installed after either core package, so it is not an alternative to Browser or Full but an addition to them. To finish a Safari setup you open `/Applications/InterceptorSafari.app` once and then enable Interceptor and website access under Safari, Settings, Extensions, because Safari requires your approval rather than granting it silently. Platform coverage is uneven by design. The macOS release binaries target Apple silicon. Windows and Linux support browser automation only, and native desktop control plus iPhone setup require a Mac. So the Full package is not available on the platforms that have the least need for it.

The extension is required, and an unpacked copy has its own rules

The local runtime and the browser extension are both required; installing the pkg alone leaves you with a CLI that cannot see a page. In Chrome or Brave you install the extension from the Chrome Web Store listing. For an unpacked copy you enable Developer Mode on the browser's extensions page and load `/Library/Application Support/Interceptor/extension/`, and the rule that follows is one people trip over: keep one copy per profile. A second copy in another profile means a second extension instance with its own state. Store and unpacked installations share an extension ID, which has a practical consequence on updates: store updates arrive only after store review, so an unpacked copy can be ahead of the store build for weeks. On Windows the same extension works in Chrome, Brave and Edge through the Chrome Web Store listing, except that Edge requires you to allow extensions from other stores first. Without the extension, the daemon has nothing to attach to, and every read comes back empty.

Background by default, foreground only when you ask

The default execution model is the one that makes this usable next to a person rather than instead of them. Browser and native Mac operations run in the background so you can keep working while an agent drives; bringing a target forward is an explicit activation rather than a side effect. The behaviour and its exceptions are written up in a reference file inside the skills bundle, at `.agents/skills/interceptor-macos/references/background-first.md`, so the rule is inspectable rather than folklore. The native path has its own prerequisites on the Full package. You grant `interceptor-bridge` the permissions your task actually needs, and `interceptor macos trust --walkthrough` walks you through it. Accessibility access enables native UI control, while screen, microphone and app-automation access are each tied to their own feature, which is why the guidance is to grant narrowly rather than blanket-approve. Underneath, the Mac surface reaches accessibility controls, background input, Apple Events, and even capture of covered windows. Background-first is not a blanket rule either, and the reference file is where the exceptions live: a flow that depends on a native dialog, a drag that needs a real window, or anything where you have to see the result to decide the next step will need the target brought forward explicitly. The design assumption is that a person and an agent are sharing one desktop, so anything that grabs focus without being asked is treated as a bug rather than a convenience.

Linux gets compiled binaries, Windows gets a guide and a new terminal

The two non-Mac platforms are packaged differently, and the Linux path is the more self-contained of the two. Extract the architecture-matched archive and run the installer from its directory:

bash
bash scripts/install.sh --browser-only --brave
# For Chrome, use --chrome instead of --brave.
./dist/interceptor open "https://example.com"

Afterwards you follow the installer's extension-loading instructions. The archive ships compiled binaries, so this release path does not need a separate Bun installation, which is the detail that makes it usable on a machine you do not want to configure. Windows is a different shape: run the architecture-matched installer, install the browser extension, then open a new terminal, because the existing one will not have the CLI on its path. Windows requires version 11 24H2 or later, and there is a separate guide, `docs/windows-install.md`, covering unpacked extensions, silent installation, updates and removal. That division is deliberate: the Linux archive is self-installing, the Windows installer is not, and the documentation picks up the slack.

Skills get adopted into whichever agent runtime you already run

Onboarding an agent takes one of two routes. For a shell-capable agent, `interceptor skills adopt` installs the browser, macOS, iOS and research skills into detected runtimes; the Mac and Windows installers already bundle them, while Linux archive users need a source checkout containing `.agents/skills/` to adopt from. For an MCP client the route is `interceptor mcp`, and the installer detects Claude Code, Codex, Gemini CLI, Cursor and Claude Desktop, after which you register Interceptor and restart the client so it picks the server up. The full MCP documentation lives in `docs/mcp.md`. One point is worth stating plainly because it changes the cost calculation: Interceptor does not require a model API key. It is a tool server, not a model, so the only model spend is whatever your own agent or model already charges. The agents themselves are not a black box either, since the top level carries `.agents/`, `.claude/`, `.codex/` and `.gemini/` directories, and there is an `AGENTS.md` and a `CLAUDE.md` at the root.

Recording a workflow produces replay plans, not just macros

The reuse story is a recording layer rather than a macro recorder. Browser and Mac recording, event timelines and replay-plan export are what turn a demonstrated workflow into reusable commands, which matters because the underlying actions are semantic, not coordinate based. A recorded click becomes an act on an element, so it survives a layout change that would break a screen-scraping macro. That same structural access is what makes the richer cases work. For documents, slides and design work you get rich-editor scenes, canvas input, file uploads and direct capture of the export bytes the page produces, so you save the artefact rather than a screenshot of it. On a real iPhone you get element trees, taps, text entry, screenshots, process telemetry and WebKit inspection, which is a different level of introspection than a browser tab allows. The through-line in all of it is that the agent inspects what happened after an action and uses that as evidence for the next one, rather than firing commands blind and reporting success. Two other research affordances come with the same shell. Browser search and multiple contexts let a task run in a second context without disturbing the one you are reading, and there is a source-ledger research workflow, which is the mechanism behind the claim that you can check where a claim came from instead of trusting a summary.

One package.json holds the CLI, daemon, extension and bridge

The repository is wider than a browser extension, and the manifest shows how wide. The root package is `interceptor` at version 1.0.21, ESM, exposing a single binary, `interceptor`, pointing at `./dist/interceptor`. The source is split across `cli/`, `daemon/`, `extension/`, `interceptor-agent/`, `interceptor-bridge/`, `ios/`, `safari/`, `shared/`, `scripts/`, `patches/`, `test/`, `use-cases/`, `docs/` and a `bench-head-to-head/` directory, with four separate tsconfig files for the host, the extension and the shared base. Scripts are Bun-native: `build` shells to `./scripts/build.sh`, `test` runs `bun test`, `daemon` and `cli` execute their entry TypeScript files directly, and there is an `audit:capability-blind` target. Two dependencies carry most of the weight, `@modelcontextprotocol/sdk` at 1.29 and `tesseract.js` at 7 for OCR, and the MCP SDK is not used as published: it is listed under `patchedDependencies` with a patch file at `patches/@modelcontextprotocol%[email protected]`. Releases are frequent, with 1.0.15, 1.0.17 and 1.0.19 cut between 22 and 26 September 2026.

Editorial conclusion

Use it when the work depends on being already logged in, on a rich editor that only exists in the page, or on a phone you can hold, because that is what the extension model buys you over launching a clean automated browser. Do not use it expecting headless scale: the default path is one signed-in profile with an extension installed per profile, and macOS binaries only target Apple silicon. Three things to settle before you build on it. Pick the package that matches your work, since native Mac control and iPhone setup need the Full installer and macOS 15 or later. Run `interceptor macos trust --walkthrough` on the Full package and grant only what the task needs. And read the licence situation yourself: the manifest declares Elastic-2.0 while the repository carries a LICENSE file whose terms you should confirm before vendoring any of it.

Frequently asked questions

What does Interceptor actually attach to?

To the browser profile you already use. The default browser path uses a Chrome or Brave extension rather than launching a separate automated browser, so the agent works with your existing profiles, cookies and logins. The macOS Full package adds a native bridge for Mac apps and iPhone tooling.

Do I need a model API key to use Interceptor?

No. Interceptor does not require a model API key, and it is a tool server rather than a model. Any cost comes from your own agent or model subscription. You can drive it from any agent that can run shell commands, or through its built-in MCP server.

Can Interceptor control apps on my iPhone?

Yes, but only through the macOS Full package, which bundles the native Mac bridge and iPhone tooling and requires macOS 15 or later. Once installed you get element trees, taps, text entry, screenshots, process telemetry and WebKit inspection. Windows and Linux are browser automation only.

Which macOS package should I download for Interceptor?

Browser for web work only, Full if you also need native Mac control or iPhone setup, and Safari as an addition installed after either core package. Safari also needs you to open /Applications/InterceptorSafari.app once and enable it under Safari, Settings, Extensions.

Does Interceptor work on Windows or Linux with native desktop control?

No. Windows 11 24H2 or later and Linux both support browser automation only, and native desktop control plus iPhone setup require a Mac. The Linux archive ships compiled binaries so no separate Bun install is needed, while Windows uses an architecture-matched installer and then a new terminal.

Official sources

  1. Hacker-Valley-Media/Interceptor on GitHub
  2. Issues
  3. README
  4. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/hacker-valley-media-interceptor.svg)](https://hysenlabs.com/projects/hacker-valley-media-interceptor)