Skip to content
Back to skills

Dev Browser

ASecurity

Browser automation with persistent page state using the dev-browser CLI. Use when the user mentions browse, open website, click, fill form, screenshot, scrape, automate browser, test website, log into, navigate, web page, or any browser interaction.

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 5, 2026
toolsbashnodedebuggingapi

Works with

  • cursor
  • cli
  • api
  • mcp

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 4 files and shows the line behind each finding

Scanned September 22, 2026

npx -y skills add twikus/claude-configuration --skill dev-browser --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dev Browser?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dev Browser
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/twikus-dev-browser/badge)](https://www.skillsdirectory.com/skills/twikus-dev-browser)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dev-browser
description: Browser automation with persistent page state using the dev-browser CLI. Use when the user mentions browse, open website, click, fill form, screenshot, scrape, automate browser, test website, log into, navigate, web page, or any browser interaction.
allowed-tools:
  - Bash(dev-browser *)
  - Bash(/Applications/Helium.app/Contents/MacOS/Helium *)
---

Drive every browser task with the `dev-browser` CLI. Never use Cursor IDE Browser MCP (`cursor-ide-browser`, `browser_navigate`, `browser_snapshot`, `browser_lock`, `browser_click`, `browser_cdp`, or any `browser_*` tool).

If `dev-browser` is missing: obey the repo's package-manager rules (no `npm install -g` when npm is forbidden). In Codex, prefer the bundled Node/Playwright/Chromium runtime for page-load, screenshot, console, and interaction checks. Install the CLI only when npm is allowed and the task needs persistence or CDP the bundled runtime cannot provide: `npm install -g dev-browser && dev-browser install`. When falling back to Playwright, keep the same proof (URL, title, errors, screenshots, exact steps) and state that the CLI was unavailable.

Write one-thing scripts. Reuse named pages (`browser.getPage("main")`) across runs. End each script by logging JSON state. Commands, flags, Page methods, locators, screenshots, forms, and CDP connect: [api-reference.md](references/api-reference.md). Open that file before inventing a Page method.

File I/O is only `~/.dev-browser/tmp/`. Never pass absolute paths to `saveScreenshot` or `writeFile`; copy out from the returned tmp path.

Helium is not auto-discovered. Launch it with `--remote-debugging-port` and connect with `dev-browser --browser helium --connect http://127.0.0.1:<port>`. An already-running Helium without CDP cannot be attached; if it must not restart, use AppleScript or Computer Use.

On script failure, the page stays put. Reconnect, screenshot, log URL/title, then continue.

Files in this skill

  • SKILL.md6.4 KB
  • agents/openai.yaml285 B
  • assets/codex-icon.svg451 B
  • references/api-reference.md4.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…