All skills
manaflow-ai avatar

/cmux-browser

@f97f1e9
by manaflow-aimanaflow-ai/cmux28k stars
2,423

End-user browser automation with cmux. Use when you need to open sites, inspect or interact with browser surfaces, wait for page state, and extract data without stealing focus.

Use this Skill: https://skilld.dev/gh/manaflow-ai/cmux/cmux-browser

This session only. Nothing lands on disk.

referencessurface-discovery.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Browser Surface Discovery

Surface-bound existing-surface browser commands need an explicit surface handle. The CLI also has a small, explicit global-verb allowlist (for example identify, devtools, design-mode, zoom, history, and creation/import verbs); those commands may omit a handle according to SKILL.md. Find a surface-bound handle with read-only topology commands; never select or focus a workspace just to make an implicit target work.

Caller workspace

Start with the context of the terminal that launched the agent:

cmux identify --json
if [[ -n "${CMUX_WORKSPACE_ID:-}" ]]; then
  cmux tree --workspace "$CMUX_WORKSPACE_ID" --json
else
  # With no caller anchor, use the server's current context after identify.
  cmux tree --json
fi

CMUX_WORKSPACE_ID is the caller anchor, not necessarily the workspace visible on screen. If it is unavailable, use cmux identify --json and state that the current server context is being used.

For one known workspace, list its panes/surfaces without selecting it:

cmux --json list-pane-surfaces --workspace workspace:N

Browser in any workspace or window

tree --all --json is the non-focus-changing global inventory. The following filter prints only topology refs, not page titles or URLs:

cmux tree --all --json \
  | jq -r '
      .windows[]? as $window
      | $window.workspaces[]? as $workspace
      | $workspace.panes[]? as $pane
      | $pane.surfaces[]?
      | select(.type == "browser")
      | [$window.ref, $workspace.ref, $pane.ref, .ref]
      | @tsv'

Pick the surface by the workspace/pane the user named, or by a URL/title only when the user supplied enough context to disambiguate it. For URL/title-only context, use this exact-match filter; it emits only the unique surface ref and does not print the matched metadata:

MATCH_FIELD="url" # use "title" when matching a page title
MATCH_VALUE="${BROWSER_URL_OR_TITLE:?set BROWSER_URL_OR_TITLE without logging it}"
SURFACE="$(
  cmux tree --all --json |
    jq -r --arg field "$MATCH_FIELD" --arg value "$MATCH_VALUE" '
      [
        .windows[]? as $window
        | $window.workspaces[]? as $workspace
        | $workspace.panes[]? as $pane
        | $pane.surfaces[]?
        | select(.type == "browser")
        | select((if $field == "url" then (.url // "") else (.title // "") end) == $value)
        | .ref
      ] as $matches
      | if ($matches | length) == 1 then $matches[0]
        elif ($matches | length) == 0 then error("no matching browser surface")
        else error("multiple matches; use workspace/pane context")
        end'
)"
if [[ -z "$SURFACE" ]]; then
  printf '%s\n' 'no uniquely matching browser surface; provide workspace/pane context' >&2
  exit 1
fi
cmux browser --surface "$SURFACE" get url

Do not print or store raw authenticated-page metadata unnecessarily.

Inspect the chosen surface

SURFACE="surface:N"
cmux browser --surface "$SURFACE" get url
cmux browser --surface "$SURFACE" get title
cmux browser --surface "$SURFACE" tab list --json
cmux browser --surface "$SURFACE" snapshot --interactive

These inspection commands do not focus the browser or its workspace. Avoid select-workspace, focus-pane, focus-panel, focus-webview, and other focus-intent verbs unless the user explicitly asked to change visible focus.

Stale handles and help drift

Surface refs can change when a tab is closed/replaced or a browser is restored. If a previously valid handle is rejected, run cmux tree --all --json again and reselect from the authoritative topology. Never fall back to a focused surface or a guessed numeric index.

When installed documentation and the binary disagree, stop and refresh the contract before continuing. The installer is pinned to the reviewed skills 1.5.23 release:

cmux browser --help
cmux --version
npx --yes skills@1.5.23 add manaflow-ai/cmux --global --yes --skill cmux-browser --agent claude-code codex --copy

An already-running agent may have cached the old skill; start a fresh session after the install when needed.

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides browser automation capabilities and correctly identifies the sensitivity of browser session data, providing best practices for securing it with restricted permissions and safe credential handling. It includes a mechanism for updates using an installer utility from the author's repository. The primary security consideration is the risk of indirect prompt injection inherent in processing content from arbitrary websites.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    5/11 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at f97f1e9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
  • CLI
  • browser-automation
  • cmux
  • web-scraping
  • form-automation
  • wkwebview
  • macos

README badge

README badge for manaflow-ai/cmux

Automates browser interactions within cmux webviews by opening pages, waiting for state changes, snapshotting the DOM, and performing actions like clicks and form fills using element references. Use this for tasks like form submission, data extraction, and navigation verification in cmux surfaces.

Generated from the current SKILL.md.

Does this skill work with WKWebView, or only Chrome?
It uses WKWebView. Some Chrome/CDP-only features like viewport emulation, network mocking, and trace recording are not supported, but core actions (click, fill, press, scroll, wait, snapshot) work.
How do I handle authentication and preserve login state across browser tasks?
Use the authenticated-session template or follow the authentication reference guide, which covers login flows, OAuth, 2FA patterns, and the save/load state workflow to persist credentials between surfaces.
What should I do if snapshot --interactive fails with a js_error?
Fall back to get url, get text body, or get html body to verify page state. If the issue persists, navigate to a simpler intermediate page and retry the task from there.
Can I run multiple browser tasks in parallel or do I need one surface per task?
Keep one surface per task unless you intentionally switch. Multi-surface isolation and state persistence patterns are covered in the session-management reference.
Does this work with the agent-browser skill or are they separate workflows?
This skill is specific to cmux webviews. It uses cmux CLI commands and surface references; the wait patterns are similar to agent-browser but the execution model is distinct to cmux.

Generated from the current SKILL.md. These answers refresh after source changes.