agent-browser
Automate Browser Workflows With Agent Refs
Manual browser testing and research slows agents when pages require clicks, forms, or screenshots. This skill gives Claude, Codex, and Claude Code repeatable browser control through belt, element refs, snapshots, and capture tools.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "agent-browser" from https://skillstore.io/skills/halt-catch-fire-agent-browser.md and its manifest at https://skillstore.io/api/skills/halt-catch-fire-agent-browser/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "agent-browser". Review a public pricing page and capture evidence.
Expected outcome:
The page was opened, key navigation elements were listed, a full-page screenshot was captured, and visible pricing text was summarized.
Using "agent-browser". Test a contact form using provided sample data.
Expected outcome:
The form fields were identified from the snapshot, filled with the approved values, submitted, and verified against the final page message.
Using "agent-browser". Record a short browser workflow for documentation.
Expected outcome:
The browser session was recorded with cursor visibility, key steps were completed, and the final video artifact was returned after closing the session.
Security Audit
High RiskMost static findings are Markdown examples, documentation links, or benign shell redirection, and those were marked as false positives. Confirmed risk remains high because the skill enables remote browser automation, screenshots, video recording, authenticated data extraction, arbitrary page JavaScript, file upload, and proxy routing. I found no prompt-injection language in the reviewed skill files.
Confirmed security concerns (6)
Capability review items (56)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (164)
🌐 Network access (54)
📁 Filesystem access (15)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/halt-catch-fire-agent-browser/audits/3?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/halt-catch-fire-agent-browser?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/halt-catch-fire-agent-browser?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/halt-catch-fire-agent-browser/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/halt-catch-fire-agent-browser.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
halt-catch-fire. (2026). agent-browser security audit report (audit version 3) [Author version unspecified]. Skillstore. https://skillstore.io/skills/halt-catch-fire-agent-browser/audits/3BibTeX citation
@techreport{halt-catch-fire-halt-catch-fire-agent-browser-2026,
author = {halt-catch-fire},
title = {agent-browser security audit report (audit version 3)},
institution = {Skillstore},
year = {2026},
number = {3},
url = {https://skillstore.io/skills/halt-catch-fire-agent-browser/audits/3},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "agent-browser security audit report (audit version 3)"
version: "unspecified"
type: report
authors:
- name: "halt-catch-fire"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/halt-catch-fire-agent-browser/audits/3"
identifiers:
- type: other
value: "skillstore:halt-catch-fire-agent-browser:audit:3"
description: "Skillstore immutable audit report identifier"
Compare variants
19 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
supercent-io-agent-browser
2026-08-21
101-skills-agent-browser
2026-08-21
vercel-labs-agent-browser
2026-08-21
qu-skills-agent-browser
2026-08-21
am-will-agent-browser
2026-08-21
tul-sh-agent-browser
2026-08-21
inference-sh-8-agent-browser
2026-08-21
toolshell-agent-browser
2026-08-21
skillssh-agent-browser
2026-08-21
inference-sh-9-agent-browser
2026-08-21
inferen-sh-agent-browser
2026-08-21
inference-shell-agent-browser
2026-08-21
inferencesh-agent-browser
2026-08-21
inference-sh-skills-agent-browser
2026-08-21
inference-sh-0-agent-browser
2026-08-21
infsh-skills-agent-browser
2026-08-21
inf-sh-agent-browser
2026-08-21
inference-skills-agent-browser
2026-08-21
halt-catch-fire-agent-browser
2026-08-21
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Test Interactive Web Flows
Run login, form, and navigation flows while capturing screenshots or video evidence.
Collect Web Page Evidence
Open pages, extract visible text and links, and save screenshots for review.
Document Browser Workflows
Record repeatable browser actions with cursor indicators for support or training materials.
Try These Prompts
Open the target page, summarize the title and visible interactive elements, then close the browser session.
Use the latest snapshot to identify form fields, fill the provided values, submit the form, and report the result.
Open each approved URL, capture a full-page screenshot, extract visible text and links, and list the saved artifacts.
Use the provided credentials and consented target site to log in, re-snapshot after each navigation, complete the task, and avoid recording sensitive pages.
Best Practices
- Use only approved target URLs and close every browser session after the task.
- Re-snapshot after navigation, form submission, modal changes, or dynamic page updates.
- Disable recording and screenshots when credentials or sensitive data are visible.
Avoid
- Do not use proxy rotation to evade rate limits or site access controls.
- Do not print cookies, passwords, TOTP codes, or session tokens in logs.
- Do not upload local files unless the target site and file contents are explicitly approved.
Frequently Asked Questions
What does this skill use to control the browser?
Can it click and fill page elements?
Can it record browser activity?
Does it support authenticated sessions?
What data risk should users understand?
Should agents auto-install this skill?
Developer Details
Author
halt-catch-fireLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
a06681402992ceae98ba04d54cfd4ab004862696
Maintenance freshness
7/18/2026
Usage
2 downloads · 0 views
File structure