Yamak landed on the HN frontpage today as an “open-source AI browser agent.” I clicked through expecting a Playwright wrapper with a license sticker, which is roughly what it is. Source on GitHub. Headless Chrome autoscaling on their backend. Both true at once.

And this is the trick that keeps getting used. Same week, another Show HN for an “open-source autoscaling browser agent” hit the front page. Different repo. Same shape. So the license sells the post, and the architecture is the part nobody puts in the headline.

The license tells you nothing about where Chrome runs

Open source describes who can read the code. But it doesn’t describe where the binary executes. You can fork Yamak tomorrow, audit every line, run the unit tests, and still find that the agent only works by booting Chromium on a server you don’t control. And the cloud browser part is not a bug, it’s the entire product.

But that distinction sounds pedantic until you’re the one trying to use the thing.

Your already-logged-in Chrome is unreachable

Right now you have Gmail open in a tab. LinkedIn in another. Your bank, probably. Some internal admin panel that took fifteen minutes of SSO redirects to reach. But none of that is visible to Yamak, because the Chrome Yamak controls is a fresh ephemeral instance that woke up two seconds ago on AWS with no cookies, no sessions, and no idea who you are.

So Yamak does what every cloud browser agent does. It logs in again. From scratch. Which means your credentials end up in a session on someone else’s machine, and any task that touches an authenticated site forces you to either re-auth in the cloud browser or hand over OAuth tokens the agent stores somewhere on its own infra.

And this is the same problem cloud browser agents have always had, now with a permissive license attached.

Same trick, different repo

I keep seeing the exact same pattern on HN. Different team, different name, identical architecture. “Open-source” is doing all the marketing work in every one of these posts.

Self-hosting doesn’t actually fix anything

Yes, you can run Yamak yourself. But you’ll still need to run the headless browser somewhere. On your laptop, sure. And now you have two browsers running, one for you and one for the agent, neither of which knows the other exists. The agent’s Chrome is still not your Chrome. So self-hosting just moves the autoscaling cluster from AWS to your machine, with all the same isolation between human session and agent session.

Some of the open-source crowd has noticed. There’s a whole conversation about why every new open-source agent ships with its own headless browser infrastructure. And the answer is that nobody wants to write the Chrome extension layer. It’s a different programming model, harder to demo, harder to autoscale, and you can’t put it behind a /pricing page.

The real axis is whose Chrome runs the agent

Two architectures, basically. Either path works for somebody, just not the same somebody.

One: the agent boots a Chrome instance on a server. Open or closed, hosted or self-hosted, the browser is fresh every time. You log in to it manually. Or it can’t do anything. And it scales horizontally because every browser instance is identical and disposable. The autoscaling part is the selling point.

Two: the agent runs inside the Chrome you already have open. Your Gmail tab is its Gmail tab. Your bank session is reachable without re-authenticating. So there’s nothing to autoscale because there’s only one of you. And Dassi sits in this second category. It lives as a Chrome extension in the side panel, sees what you see, uses the sessions you already established. No fresh Chromium instance, no OAuth re-grant, no SSO dance.

Different shapes, different costs, different jobs they handle well. A cloud agent can run 200 tasks in parallel against 200 fresh accounts, which matters if you’re scraping or running tests across throwaway profiles. But a local agent can read the email you just opened, which matters if you’re a person doing your actual job. And the two architectures are not really competing for the same use case at all.

Open source is not the question

Ask whether the agent runs in your Chrome or someone else’s. Ask whether it can see your existing logins or has to re-authenticate from scratch. Ask where the browser memory lives. Because the license is downstream of all that. A closed-source extension running inside your Chrome will, for almost any personal-productivity workflow, beat the hell out of an open-source cloud agent that has to re-log into your bank from scratch.

If you want that second shape, Dassi is on the Chrome Web Store. Bring your own key, or log in with a ChatGPT subscription. And the browser it runs in is the one you’re reading this post in.

Yamak might be excellent at what it does. So might the next three open-source autoscaling agents that ship next month. But none of them, by construction, can see the tab you have open right now.