Install
$ agentstack add skill-bettyguo-browser-skills-upload-download-file ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Upload / Download File
When to invoke
The user task requires uploading a local file or capturing a download. The agent provides the file path in vars.file_path (uploads) or a target directory in vars.download_dir (downloads).
The matcher hits this skill when an `` is present on the page.
Recipe
Upload mode (vars.mode = "upload" or auto-detected via input[type=file] presence)
- waitforselector selector="input[type='file']" state=attached timeout=5s
- fill selector="input[type='file']" value="$vars.file_path"
- wait extra=300ms
Download mode (vars.mode = "download")
Downloads in headless browsers route through the browser's download API; this skill stubs the recipe for now and defers to the runner's download event handler (M5 wiring).
Success criteria (upload mode)
- assert inputtypefilehasfiles selector="input[type='file']"
When NOT to use
- File-attach widgets that don't use a real `` (proprietary
drag-and-drop). Vision fallback or a per-site bespoke approach.
- Multi-file uploads requiring drag-drop reorder. Not in v0.1.
Known failures
- Sites that gate file inputs behind a click-to-reveal: the input
isn't attached until a wrapper button is clicked. Run a click primitive first; spec your agent to chain.
- Server-side validation of file size / type: the skill submits;
the agent reads validation errors via the form's error-message recipe.
- macOS sandboxing of Playwright file uploads: if Playwright runs
in a security context that can't read ~/Documents, uploads silently fail. Document in the agent's expected setup.
Related skills
fill-multi-step-form— common parent flowverify-page-loaded— run before to ensure the file input has rendered
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: bettyguo
- Source: bettyguo/browser-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.