Give your AI Agent the power to control Safari
Website · Quick Start · Features · FAQ
You want your AI Agent to help with browser tasks — then you discover:
- 🔒 Playwright → Separate browser instance, hijacks your session
- 🧩 Claude for Chrome → Requires Chrome extension, doesn't work with Safari
- 📝 Copy & paste → Manually feeding page content to AI every time
You just want AI to use your Safari, as if you were doing it yourself.
Claude for Safari makes it one command:
npx skills add SDLLL/claude-for-safari
After installing, tell Claude "check what's open in my Safari" — it reads and controls your real browser directly.
If this saves you time, give it a ⭐ — it helps other developers discover the project!
Run this in your terminal:
npx skills add SDLLL/claude-for-safariThen launch Claude Code:
claudeSay "show me what tabs are open in Safari". The agent will guide you through permission setup automatically.
Compatible with any AI Agent that supports Skills: Claude Code, Cursor, Windsurf, etc.
The agent auto-detects and guides you, but you can configure ahead of time:
- System Settings > Privacy & Security > Automation → Allow terminal to control Safari
- Safari > Settings > Advanced → Enable "Show features for web developers"
- Safari > Develop menu → Check "Allow JavaScript from Apple Events"
- (Optional) System Settings > Privacy & Security > Screen Recording → Allow the terminal or agent host (enables reliable background screenshots)
- (Optional) System Settings > Privacy & Security > Accessibility → Required only for System Events clicks and keystrokes
No browser extension, proxy, or persistent daemon. The core uses macOS-native capabilities; optional window helpers require an available Swift toolchain.
| Capability | What the Agent Does | How |
|---|---|---|
| List tabs | List all windows and tabs with title & URL | AppleScript |
| Read pages | Extract text, structured data, simplified DOM | AppleScript + JavaScript |
| Execute JS | Run arbitrary JavaScript in page context | AppleScript do JavaScript |
| Screenshot | Capture Safari window — AI can "see" the page | screencapture |
| Navigate | Open URLs, new tabs, new windows | AppleScript |
| Click | Click elements (React/Vue/Angular compatible) | JavaScript dispatchEvent |
| Type | Fill forms, simulate keyboard input | JavaScript + System Events |
| Safe form filling | Discover fields and fill supported non-sensitive controls with per-field verification | Bundled JavaScript + JXA |
| Network observation | Observe redacted page-level fetch/XHR metadata; bodies are explicit opt-in | Bundled JavaScript |
| Control indicator | Show when an agent is changing a page and clean up afterward | Bundled JavaScript |
| Scroll | Scroll up/down, scroll to element | JavaScript scrollBy/scrollTo |
| Switch tabs | Switch by index or URL keyword | AppleScript |
| Wait for load | Wait until page is fully loaded | JavaScript readyState |
| Mode | Permission Required | Window Switch | Best For |
|---|---|---|---|
| Background | Screen Recording | No switch | Recommended, seamless |
| User-visible | Varies by macOS policy | Yes | Fallback when background capture is unavailable |
Claude Code ──osascript──► Safari (reads/controls your real browser)
│
└──screencapture──► screenshot ──► Claude sees the page
No extensions, proxy servers, or persistent background services.
The skill uses AppleScript, page JavaScript, screencapture, and optional bundled helpers. Page-injected helpers can be detected by websites and are removed after use.
Do I need to install anything?
The core requires no browser extension or separate automation browser. It uses macOS AppleScript and screencapture; compiling the optional multi-window helper requires swiftc/Apple Command Line Tools.
Does it support Chrome / Firefox / Arc?
Safari only. For other browsers, use Playwright MCP or Chrome ACP. Safari is the only macOS browser with full AppleScript automation support.
Is it safe? Will AI do random things?
The skill requires target verification, preserves site confirmation dialogs, excludes sensitive form fields, and asks for authorization before consequential actions. Your agent host's own permission policy still applies.
The window flickers when taking screenshots?
Grant Screen Recording permission to the terminal or agent host for reliable background window capture. Without it, use a user-visible Screenshot workflow and verify the resulting image rather than assuming capture succeeded.
Which AI Agents are compatible?
Any agent supporting Claude Code Skills: Claude Code, Cursor, Windsurf, etc.
- @rrecio contributed the form, control-indicator, window-helper, network-observer, and real-Safari testing ideas in PR #2.
- @jordan-brough contributed permission, dialog, locale, timestamp, and Safari UI measurement findings in PR #3.
Their work informed the maintainer-integrated, safety-hardened implementation.