The primary risk with these browser agents is prompt injection attacks. Running it locally doesn't help you in that regard.
If each LLM sessions is linked to the domain and restricted just like how we restrict cross domain communication, this problem can be solved? We can have a completely isolated LLM context per each domain.