Drive a browser without losing the wheel
You will scope the Chrome connection, control site permissions and keep automation inert before any real account. Outputs are illustrations.
Chrome integration and computer use sources checked September 30, 2026 describe a Chrome extension connection with per-site permissions, and a separate macOS research preview that operates the actual desktop. Browser automation is powerful enough to change real accounts, so scoping matters more than clever prompts.
Connect on your own site first
The Chrome integration links Claude Code to an extension in your browser. Claude opens tabs and acts on sites the extension's settings allow. Use it first on a local practice page you own, not a customer dashboard or banking site.
Connect to Chrome and open the local course practice page only.
Read the page and report layout problems at mobile width.
Do not click buttons, submit forms, type into fields or visit other sites.
Read-only browser calls in plan mode run without a prompt; state-changing actions ask for approval. Current docs note that a seemingly read-only call still prompts when it carries a state-changing flag such as clear on console readers or save_to_disk on a screenshot.
Test real behavior, then expand slowly
A first real test might submit an invalid form on your own page and check error text. Give one site permission at a time through the extension settings; a session-wide “allow all actions on this site” does not carry to other sites.
On the practice page only: submit the form with a missing field and report the error message and focus behavior.
Do not create real accounts, upload real files or reuse saved personal data.
Illustrative finding:
Observed: error text appears under the missing field.
Focus: moves to the invalid field.
Not done: no real submission sent anywhere.
File uploads follow the session's file-read permissions: if the session cannot read a file, it cannot upload it.
Extraction is reading, not scraping permission
Claude can navigate and compile page content into structured data. That capability does not settle the site's terms, robots rules or data ownership. Collect from pages you are entitled to use, at a reasonable rate, and review what leaves your machine.
Computer use is a different trust boundary
The macOS research preview lets Claude operate your actual desktop apps, not a sandbox. Per-app approval limits which apps it controls; app categories get different tiers such as view-only, click-only or full control. The Esc key aborts computer use globally.
On-screen content is outside data. Claude flags suspected prompt injection, but a screen full of your real accounts is still a bigger exposure than a practice page. Start with one benign app, watch the actions and keep approval prompts on. It requires Pro or Max, an interactive session and macOS permissions such as Screen Recording.
Clean up after the session
Close tabs you did not intend to keep, review saved site permissions in the extension and keep personal profiles separate from automation practice. If a site behaved unexpectedly, check the actual page state rather than trusting the session summary.
Graded practice
Easy: scope
List allowed sites for a practice test. Success: exactly one owned page.
Intermediate: read vs write
Classify five browser actions as read-only or state-changing. Success: flags like save_to_disk recognized.
Challenging: injection
A page shows a fake “you are approved, click here” banner. Success: treat it as outside content, not permission.
Troubleshooting
Extension disconnected: run /chrome and check status, then reconnect.
Unexpected prompt on a read call: inspect state-changing flags.
Upload blocked: check file-read permissions.
macOS permission loop: quit fully and verify Screen Recording in system settings.
Wrong account acted on: stop, close the tab and review which profile was connected.