Install
$ agentstack add skill-kostysh-skills-agent-browser ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
agent-browser
Start here
- Identify the target, requested user-visible result, expected terminal state, and any material limit on external side effects or extraction scope.
- Run
agent-browser --versionand load the installed CLI's version-matched guidance withagent-browser skills get core --full; if unavailable, useagent-browser --help. - Follow the snapshot loop, verify the requested result, and report exactly one status: completed, partial, or blocked.
When to use this skill
- Navigating or interacting with rendered websites and web applications from the terminal.
- Filling forms, taking screenshots, recording evidence, exporting PDFs, or extracting rendered content.
- Running sampled browser smoke or diagnostic scenarios and inspecting page, console, or network behavior.
- Producing SPA evidence while distinguishing real backend paths from intercepted or mocked traffic.
When NOT to use this skill
- Static source inspection or a direct HTTP client can establish the result without a rendered browser.
- The task is to author, maintain, or replace a formal project E2E suite.
- The requested tool is explicitly Playwright or a more specific browser skill owns the target workflow.
Quick start
Use the guidance shipped by the installed CLI instead of a copied command reference:
agent-browser --version
agent-browser skills get core --full
The stable interaction loop is:
agent-browser open
agent-browser snapshot -i
# interact with refs from the current snapshot
# wait for the expected result
agent-browser snapshot -i
agent-browser get url
Refs become stale after navigation and material page changes, so snapshot again before reusing them. If bundled guidance is unavailable, check the root and relevant subcommand help.
What proves completion
- Navigation or interaction: the requested final URL or visible state is
observed.
- Extraction: the requested fields and scope are checked, including pagination
or lazy loading; otherwise report the extracted subset as partial.
- SPA or integration behavior: state whether relevant network calls were real or
intercepted. Mocks prove local UI behavior only.
- Diagnosis: browser requests, responses, console, and page errors are evidence;
another domain owner must establish backend or provider root cause.
A screenshot, snapshot, trace, successful command, or healthy runtime is useful evidence only when it supports the requested result. It is not completion by itself.
Setup boundary
Agent-browser owns its browser runtime. Do not install Playwright packages in the target project to prepare it. Use the installed CLI's diagnostic and install guidance, or report a blocked handoff when environment changes are not in scope.
Do not put secrets in command history or reports. Use the installed CLI's authentication guidance and treat saved state, downloads, screenshots, traces, and recordings as potentially sensitive.
Workflow stages
Workflow stage: Run and verify the browser task
Reach the requested observable result through the rendered page without confusing CLI activity with task completion.
- Apply the governing user, system, and project policies; this skill does not grant authority for additional external side effects.
- Use the installed CLI guidance for command syntax. If the runtime fails, use its help or
agent-browser doctor --offline --quick; use mutating repair commands only when already authorized, and never add Playwright to the target project merely to prepare agent-browser. - Open the target, snapshot before using refs, interact, wait for the expected condition, and re-snapshot after navigation or material page changes.
- Verify the final URL, visible state, or extracted values that establish the requested result; use console, page-error, network, screenshot, or trace evidence only when relevant.
- For extraction, verify the requested fields and scope, including pagination or lazy-loading limits; if completeness is not established, report the observed subset as partial.
- Treat intercepted responses as local UI evidence, not proof of a live API or provider path, and do not infer backend root cause from browser symptoms alone.
Validation:
- The expected terminal state is directly observed, or the exact blocker and strongest supported partial result are recorded.
Workflow stage: Report the browser result
Provide an evidence-bounded outcome instead of a command transcript.
- Report exactly one status: completed, partial, or blocked.
- Name the target and context, main actions, expected and observed terminal state, real or intercepted network mode when relevant, and any unverified scope.
- Do not expose credentials, tokens, cookies, or saved-state contents; report artifacts only when created.
- Close sessions and processes started for the task, or state what remains running and who owns it.
Validation:
- The user can tell what result was achieved, what was not proved, and whether anything remains running.
Interop priority
- Formal browser test suites, fixtures, assertions, coverage, and CI behavior: the project E2E framework and its testing owner. Agent-browser supplies sampled smoke or diagnostic evidence and does not replace suite coverage.
- Explicit Playwright CLI work or persistent interactive browser and Electron QA: playwright or playwright-interactive as requested. Do not silently switch tools when the requested tool or persistent session model is part of the task.
- Static retrieval or backend, security, accessibility, and other conclusions beyond observed browser facts: the relevant source, HTTP, or domain skill. Agent-browser owns rendered browser interaction and observed evidence, not adjacent specialized conclusions.
Gotchas
- high — Use the installed CLI's version-matched guidance and help for command syntax; do not maintain or trust a copied command encyclopedia when they disagree.
- high — A successful command, snapshot, screenshot, trace, or intercepted response does not prove the requested user-visible result by itself.
- high — Keep secrets out of shell history and reports, treat browser artifacts as potentially sensitive, and clean up sessions or processes started for the task.
Policies
Guidance and authority
Governing user, system, and project policies define authority; installed version-matched CLI guidance defines command syntax; this skill does not widen either boundary.
Browser evidence
Match evidence to the claim and report the target, expected and observed terminal state, relevant real or intercepted network mode, and exact limits of partial or blocked results.
Portability rules
- Do not reference machine-specific absolute paths or local files outside this skill folder.
- Keep the stable snapshot workflow and evidence contract inside this skill; external CLI guidance supplies only version-specific command details.
Portability checklist before finishing
- Run the skill-source-compiler check command after regeneration.
- Confirm the copied skill remains understandable when the CLI is unavailable, while clearly reporting execution as blocked or handed off.
Supporting and historical surface
docs/*anddocs/issues/*are non-normative unless explicitly promoted by this file.- Supporting glob:
docs/* - Supporting glob:
docs/logs/*
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: kostysh
- Source: kostysh/skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.