# Upload Download File

> Uploads a local file to an HTML5 file input, or triggers a download and captures the resulting path. Composes with multi-step-form for file-attaching workflows.

- **Type:** Skill
- **Install:** `agentstack add skill-bettyguo-browser-skills-upload-download-file`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [bettyguo](https://agentstack.voostack.com/s/bettyguo)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [bettyguo](https://github.com/bettyguo)
- **Source:** https://github.com/bettyguo/browser-skills/tree/main/skills/upload-download-file

## Install

```sh
agentstack add skill-bettyguo-browser-skills-upload-download-file
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Upload / Download File

## When to invoke

The user task requires uploading a local file or capturing a download.
The agent provides the file path in `vars.file_path` (uploads) or a
target directory in `vars.download_dir` (downloads).

The matcher hits this skill when an `` is present
on the page.

## Recipe

### Upload mode (`vars.mode = "upload"` or auto-detected via input[type=file] presence)

1. wait_for_selector selector="input[type='file']" state=attached timeout=5s
2. fill selector="input[type='file']" value="$vars.file_path"
3. wait extra=300ms

### Download mode (`vars.mode = "download"`)

Downloads in headless browsers route through the browser's download
API; this skill stubs the recipe for now and defers to the runner's
download event handler (M5 wiring).

## Success criteria (upload mode)

- assert input_type_file_has_files selector="input[type='file']"

## When NOT to use

- File-attach widgets that don't use a real `` (proprietary
  drag-and-drop). Vision fallback or a per-site bespoke approach.
- Multi-file uploads requiring drag-drop reorder. Not in v0.1.

## Known failures

- **Sites that gate file inputs behind a click-to-reveal:** the input
  isn't `attached` until a wrapper button is clicked. Run a `click`
  primitive first; spec your agent to chain.
- **Server-side validation of file size / type:** the skill submits;
  the agent reads validation errors via the form's error-message
  recipe.
- **macOS sandboxing of Playwright file uploads:** if Playwright runs
  in a security context that can't read `~/Documents`, uploads
  silently fail. Document in the agent's expected setup.

## Related skills

- `fill-multi-step-form` — common parent flow
- `verify-page-loaded` — run before to ensure the file input has rendered

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [bettyguo](https://github.com/bettyguo)
- **Source:** [bettyguo/browser-skills](https://github.com/bettyguo/browser-skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-bettyguo-browser-skills-upload-download-file
- Seller: https://agentstack.voostack.com/s/bettyguo
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
