This is a transparent but very powerful local browser automation skill whose sensitive session features are disclosed and locally guarded, but it should only be used with trusted agents or safer modes enabled.
Install this only for a local, visible browser session where you trust the agent driving it. Use PW_BROWSER_SAFE_MODE=1 for untrusted or semi-trusted callers, and PW_BROWSER_CRED_PERSIST=off if session cookies or localStorage must never be written to disk. Treat exported cookie/storage files like passwords, delete them when done, and avoid using the skill on banking, email, admin, or other high-privilege logged-in sites unless each action is explicitly intended.