New capabilities
Web grounding, page actions, and Codex sign-in in Prompt Paul
Prompt Paul's newer capabilities let you ground answers in live web sources with a cited
Sources section, take carefully bounded actions on the page you are already using, and
connect a ChatGPT subscription through Codex sign-in. Each capability is optional and off
by default.
Start with the side panel
Open Prompt Paul from the toolbar, a context menu, or the Options page. Connect an
compatible model endpoint, or the official Anthropic API format on Anthropic's API domain,
then use the Page, Web, Act,
and More controls as needed.
The composer shows selected text, page content, media, and dropped documents as removable
context chips. Hermes connections use the Hermes gateway's tools. Prompt Paul's custom
HTTP tools are not registered for Hermes runs, and Hermes Act requires gateway client-tool
support.
Quick actions without changing page layout
Enable Top Notch in Options and save the section to show a compact,
top-centered Prompt Paul control on supported web pages. Expand it for Open chat,
All actions, Summarize page, Explain selection,
or Settings. It is off by default, uses an isolated Shadow DOM, and is
limited to the browser page; it is not an OS-wide desktop overlay.
What Act can do
For API-key or Codex connections, or a Hermes gateway with client-tool support, turn on
Act for a run that needs Prompt Paul to inspect a bounded page snapshot,
then click, fill, select, or scroll standard controls on the current tab.
Approved HTTP(S) links can also be followed: same-tab links run through the standard
click action, and indexed new-tab links can open in tabs owned by the extension. Unsafe
schemes and downloads stay blocked, while navigation and unknown destinations remain
policy-gated. One Act lease can own up to twelve tabs, but it cannot control arbitrary
existing tabs.
What stays blocked
State-changing actions ask for approval by default. Passwords, one-time codes, payment
fields, security controls, destructive actions, and arbitrary JavaScript are blocked or
kept behind additional policy checks. Cross-tab work is limited to tabs owned by the
current Act run.
Every change leaves a receipt
Mutations report one of three bounded outcomes: not delivered,
delivered but unverified, or delivered and verified,
each with action-specific evidence. An unverified change is never repeated blindly:
Prompt Paul inspects the page again first, so it never double-submits on an uncertain
result.
Manual steps and mid-run navigation
For safe work only you can do, such as accepting a dialog or solving a check, Prompt Paul shows a
Manual step needed card. Complete the step in the visible tab, then choose
Resume; the old snapshot is discarded and the page is inspected fresh. If the tab navigates
during a run, stale snapshots are discarded the same way: Prompt Paul re-inspects the
current supported page and continues, never acting on outdated targets. Do not enter
passwords, one-time codes, recovery codes, or payment data in chat.
Trusted mode is still bounded
Options includes an optional trusted page-actions mode for allowed low- and medium-risk
actions. It does not enable JavaScript, control arbitrary existing tabs, enter credentials,
handle payments, or perform destructive actions. Act resets after its run and remains
separate from Web.
Beyond media and PDFs, you can drop .txt, .md,
.markdown, .csv, or .json files straight into the
composer. They are read locally as bounded text (up to 200,000 characters per document)
and attached like any other context chip. Media support depends on the provider and
model; Codex connections in this release support text and images, while video and audio
require a compatible API profile. Structured pages get smarter extraction too:
Reddit threads, GitHub repositories, issues, and pull requests, RSS/Atom feeds, and YouTube
transcripts are parsed into clean context instead of raw page noise.
Codex subscription profiles
In Connection settings, choose Codex subscription (ChatGPT) and select
Sign in with ChatGPT. A successful device-code login creates or selects a
local Codex profile, discovers available models, and exposes model-specific thinking levels.
Credential boundary
Codex OAuth credentials stay owned by the background worker and are not included in
backups. If you restore a Codex profile, sign in again. API-key profiles and Hermes
connections continue to use their own setup paths.