All skills
aktsmm avatar

/browser-max-automation

@2e6b12a
by yamapanaktsmm/agent-skills26 stars
4

Visible browser automation using Playwright MCP, CLI, and CDP without interrupting the user's foreground work. Use for navigation, forms, screenshots, durable file downloads, repeatable browser workflows, existing-session reuse, or troubleshooting CDP / iframe / modal / file chooser / passkey (WebAuthn) issues.

Use this Skill: https://skilld.dev/gh/aktsmm/agent-skills/browser-max-automation

This session only. Nothing lands on disk.

referencesinstructionsazure-portal.md

≈331 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Portal Automation Notes

Azure Portal is a hash-routed app with iframe/OOPIF content. Use these notes when deep links or blade operations behave differently from normal pages.

Deep Links

  • If a new tab opens a Portal deep link and falls back to login, reuse an existing logged-in Portal tab first.
  • Verify arrival with URL, title, and visible body text; URL alone is not enough.
  • Subview URLs can land on overview or spin indefinitely. Capture a screenshot before switching paths.

iframe / OOPIF

  • Portal content often renders inside sandbox-*.reactblade.portal.azure.net iframes.
  • If page.evaluate() only sees the outer frame, search page.frames() and evaluate inside the content frame.
  • If Playwright frames do not expose it, CDP Target.getTargets() may show an OOPIF target. Attach with Target.attachToTarget(flatten=true) when needed.
const contentFrame = page.frames().find(frame => frame.url().includes('reactblade.portal.azure.net'));
if (contentFrame) {
  const text = await contentFrame.evaluate(() => document.body.innerText);
}

Trusted Event Boundary

  • Some openBlade() transitions require a trusted user event.
  • If iframe text and handlers are visible but blade open does not fire from JS, switch only that final action to a real click/manual operation.

Source: SKILL.md on GitHub

1 warning4mo4 checks · Risk SAFE
  • Gen Agent Trust Hub4mo

    This skill provides instructions and code for advanced browser automation using Playwright and Chrome DevTools Protocol (CDP). It includes patterns for handling complex web interfaces such as iframes, modals, and virtual scrolls. Security analysis identified a surface for indirect prompt injection common to browser automation tools, as the skill ingests and acts upon untrusted data from external websites.

  • Socket4mo

    No alerts

  • Snyk4mo

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    1/2 files flagged

Signed by skilld at 2e6b12a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 18 hours ago.

Activeupdated 2 days ago
argument-hint
自動化したい URL、操作内容、使いたいモード
user-invocable
true
metadata
{
  "author": "yamapan (https://github.com/aktsmm)"
}

README badge

README badge for aktsmm/agent-skills/browser-max-automation