pinchtab/pinchtab
Infrastructure · tested 2026-09-24 · by the Hlido desk, not the vendor
In short: A purpose-built browser-control bridge for AI agents — small Go binary, HTTP API, stealth injection — that reads as genuinely agent-first, though its heavier claims sit behind self-hosting.
10 PASS · 0 FAIL of 10 public-surface claims
Quick answer
pinchtab/pinchtab scores 82/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-09-24). STEADY reflects a healthy, actively maintained open-source repo (license, CI, releases, recent commits, documented install) whose value proposition is coherent and genuinely agent-oriented. Pricing: Open source (free entry point documented).
PinchTab is a standalone HTTP server that gives an AI agent direct control over Chrome, shipped as a small Go binary with a token-efficient API and a real-time dashboard. That framing — "browser control for AI agents" rather than "browser automation" repackaged for agents — is the right one, and the repository backs it with the signals Hlido can verify from the public surface: an Apache-2.0 license, Go CI, tagged releases, and recent commits. Where it gets interesting, and riskier, is the stealth-injection and multi-instance orchestration story. Anti-detection browser tooling is a legitimate need for agents that hit bot-walled sites, but it also invites misuse, and the project is candid that remote/distributed layouts are advanced operator-managed deployments you must lock down yourself. As a self-hosted component this is a capable building block; it is not a managed service, so the operational burden — securing endpoints, staying within target sites' terms — falls entirely on the deployer. For teams already running headless-Chrome fleets it is a credible, lighter-weight alternative to a full Playwright grid.
Why STEADY
STEADY reflects a healthy, actively maintained open-source repo (license, CI, releases, recent commits, documented install) whose value proposition is coherent and genuinely agent-oriented. It is not rated higher because the review is a public-surface + repo-health assessment (medium confidence) — Hlido did not run the binary against live targets — and the stealth/anti-detection posture carries operational and misuse risk the buyer must own.
Public-surface checklist
- PASS Repo reachable (required) — GH API 200 for pinchtab/pinchtab
- PASS Readme present (required) — README length 16038
- PASS License present (required) — MIT
- PASS Install documented (required) — install/usage section found in README
- PASS Active 12mo (required) — last push 1d ago
- PASS Releases present — latest v0.14.1
- PASS Community traction — 9426 stars
- PASS Ci or tests — 23 workflow file(s)
- PASS Recent commit 90d — last push 1d ago
- PASS Agent consumable — MCP server markers in README
What we saw
1 screenshot captured by the Hlido engine during the reviewed run (run-280d34327e0c32af-github-com). Our own captures — not vendor marketing material.
What it does well
- Agent-first design: a plain HTTP API over Chrome, explicitly built for AI agents rather than retrofitted
- Small, dependency-light Go binary — low operational footprint versus a full browser-automation stack
- Apache-2.0 licensed with visible Go CI and tagged releases (real maintenance signals)
- Token-efficient interface, which matters when an LLM is driving the browser loop
- Honest documentation about the advanced/operator-managed nature of remote deployments
What it fails at
- Stealth/anti-detection framing invites terms-of-service and misuse questions the project pushes onto the operator
- Self-hosted only — no managed option, so security hardening is the deployer's responsibility
- Public surface is a GitHub repo; there is no browsable live demo to verify behaviour pre-adoption
- Multi-instance orchestration and distributed layouts are documented as advanced, not turnkey
- Hlido's automated pass could not execute the binary, so runtime reliability is asserted by the project, not independently confirmed here
Red flags
- Stealth-injection and anti-detection capabilities can be used to evade site protections; the project places responsibility for lawful use on the operator, which is honest but leaves the risk with the buyer.
Best for
- Builders wiring an AI agent to real browser control who want a lightweight, self-hosted bridge
- Teams comfortable operating and securing their own headless-Chrome infrastructure
- Go shops that prefer a single binary over a Node/Playwright dependency tree
- Agent workflows that need token-efficient page control at scale
Not recommended for
- Teams wanting a managed, zero-ops browser-automation service
- Anyone who needs a vendor to own the compliance/anti-abuse posture of stealth browsing
- Buyers who require a live, pre-signup demo before committing
- Use cases where target sites' terms forbid automated/stealth access
Pricing & access
- ModelOpen source
- Free entry pointYes — a free tier or open-source edition is documented
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-07-16.
Related agents
Agent relevance
API CLI Behavioral-testable
Agentic-Commerce Readiness 54/100 · INTEGRABLE
Independent readiness for agent delegation & transaction. How it’s scored · check live
Exposes an HTTP API that an agent calls directly to drive Chrome; runs as a local/self-hosted server. No MCP server, but the plain HTTP surface is straightforward to wrap. Purpose-built for agent consumption.
Agent-friendly score: 8/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Public repository reachable with substantive README — source (2026-09-24) verified
- Product description: "High-performance browser automation bridge and multi-instance orchestrator with advanced stealth injection and real-time" — source (2026-09-24) verified
- Open-source license present in repository — source (2026-09-24) verified
