
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@golproductions/exnos
Advanced tools
Live browser-state verification for AI coding agents. One MCP call, milliseconds, truth. Free to use. Built by GOL Productions. By GOL Productions.
Live browser-state verification for AI coding agents.
Your AI says "done." Exnos is how it knows.
One tool call returns the full state of the Chrome tab you're looking at: every field, every button, every console error, network requests, storage, performance—in milliseconds. Read-only. Local. Free to use. Built by GOL Productions.
By GOL Productions.
AI coding agents edit files and hope for the best. When something breaks:
You: "The button doesn't work"
AI: "Can you check the console for errors?"
You: "It says TypeError something something"
AI: "Can you paste the full error?"
Back and forth. Slow. Frustrating.
You: "The button doesn't work"
AI: [calls exnos_verify]
AI: "Console shows 'TypeError: handleClick is not defined' at line 47.
The handler was renamed to onClick. Fixing now."
Exnos gives your AI eyes. It sees what you see—instantly.
npx @golproductions/exnos@latest setup
That's it. Detects Claude Code, Cursor, and Windsurf—registers with all of them, opens the extension folder, tells you to load it in Chrome. Takes 30 seconds.
1. Connect your agent
{ "mcpServers": { "exnos": { "command": "npx", "args": ["@golproductions/exnos"] } } }
Or for Claude Code:
claude mcp add --scope user exnos -- npx @golproductions/exnos
2. Load the extension
npx @golproductions/exnos@latest path
Open chrome://extensions → Developer mode → Load unpacked → select that folder.
Badge reads ON when connected.
localhost, 127.0.0.1, *.localhost, and local files.| Category | Data |
|---|---|
| Identity | URL, title, ready state |
| Forms | Every visible field with its live value (passwords, API keys, tokens, card numbers and seed phrases masked) |
| Buttons | Text and disabled state |
| Checkboxes | Checked state with labels |
| Alerts | Visible error/success/warning UI |
| Console | Errors (with message and stack), warnings, and failed resource loads since page load, counted separately |
| Network | This site's fetch/XHR: URL, status, short response body. Failures first. Other sites' requests only on request. |
| WebSocket | Sent and received frames |
| Performance | Page load, TTFB, paint timing |
| Focus | Which element has focus |
| Shadow DOM | Pierces web component boundaries |
| Iframes | Same-origin content + cross-origin count |
| Screenshot | Optional PNG capture |
Only when asked: localStorage, sessionStorage and cookies (includeStorage, with tokens, keys and session values redacted), requests to other sites (thirdParty), and window.__* app state (appGlobals).
| Tool | Purpose |
|---|---|
exnos_verify | Full live state. The main tool. |
exnos_tabs | List the tabs Exnos can read. |
exnos_screenshot | PNG screenshot of visible tab. |
exnos_fetch_tabs | Verify multiple tabs at once. |
| Parameter | Description |
|---|---|
tab | Match tab by URL or title substring. Default: active tab. |
selector | CSS selector for deep-dive: text, bounds, computed styles, HTML. |
includeHidden | Include off-screen elements. Default: false. |
thirdParty | Include requests to other sites. Default: false. |
includeStorage | Include storage and cookies, credentials redacted. Default: false. |
appGlobals | Include window.__* app state. Default: false. |
screenshot | Also capture PNG of the visible tab. Returns data URL. |
Pass selector to get the following. If nothing matches, the reply is only selectorFound: false.
selectorText — inner text contentselectorVisible — actually visible?selectorBounds — {top, left, width, height}selectorHTML — outer HTMLselectorStyles — computed: color, backgroundColor, fontSize, fontWeight, fontFamily, padding, margin, border, zIndex, overflow, transform, transitionnpx @golproductions/exnos@latest setup # configure everything
npx @golproductions/exnos@latest uninstall # remove everything Exnos added (run it in each project where you ran init)
npx @golproductions/exnos@latest path # extension folder path
npx @golproductions/exnos@latest init # write rules to agent config
npx @golproductions/exnos@latest rules # print rule text
┌─────────────┐ MCP/stdio ┌─────────────┐ WebSocket ┌─────────────┐
│ AI Agent │ ◄────────────────► │ MCP Server │ ◄──────────────► │ Extension │
│ │ │ :17872 │ │ │
└─────────────┘ └─────────────┘ └──────┬──────┘
│
Chrome APIs
│
┌──────▼──────┐
│ Your Tab │
└─────────────┘
changed: true/false on repeated callsExnos sends nothing to GOL Productions. No account, no telemetry, and no GOL server. Traffic goes from the extension to a local server on 127.0.0.1, which only accepts the Exnos extension and requests from this machine: a web page cannot connect to it.
However: what Exnos returns goes to your AI agent, which forwards it to its model provider. That is why Exnos reads only local pages and the sites you allow, masks passwords and similar fields, and returns storage and cookies only when asked, with credentials redacted. Redaction works by pattern, so it can miss a secret in an unusual place.
Allow the sites you are debugging, not your banking tab.
127.0.0.1:17872. The Chrome extension always connects on this port, so keep it free.GET / returns {"exnos":true,"extension":true|false}chrome://) cannot be inspectedFree to use, personal or commercial, under the GOL Free License. Exnos is built by GOL Productions: you may use it and share unmodified copies with the credit, but not publish changed versions, build your own product from it, or sell it. What you make with it is yours. See LICENSE.
Exnos is part of the GOL Productions toolchain.
FAQs
Live browser-state verification for AI coding agents. One MCP call, milliseconds, truth. Free to use. Built by GOL Productions. By GOL Productions.
We found that @golproductions/exnos demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.