* [codex] Add source-integrated WebMCP skill * fix: address review comments (autofix loop #1) Addresses feedback from Cursor Bugbot and Socket Security * feat: add adversarial verification step and default local runs to headed Step 5 proves a tool is discoverable and that its executor ran, not that it did what it claimed. Add step 6: probe schema closure, required fields, types and constraints, error honesty, annotation honesty, clean rejection, and consequential gating against the live page, then verify the effect in the application rather than trusting the return value. Also: - Default --local validation to headed so the browser is visible; add --headless for CI and unattended runs. - Record that document.modelContext is the live accessor while navigator.modelContext is undefined, so the fallback is load-bearing. - Record that registerTool is idempotent by name with no unregister handle, which is what makes remount and hot reload safe. - Require handlers to read results back from application state instead of echoing the request, including polling asynchronous stores until they settle. * fix: run the scanner when invoked through a symlinked skill path The self-invocation guard compared path.resolve(process.argv[1]) against fileURLToPath(import.meta.url). path.resolve normalizes . and .. but does not resolve symlinks, so when the skill is installed as a link the two paths never match, main() never runs, and the scanner prints nothing and exits 0. That is the default install shape for a Claude Code user, whose skill directory is a symlink to the real one, and step 1 points them at exactly that path. Resolve symlinks on both sides before comparing. Also tell the skill to report what each step found as it goes, rather than saving everything for the final report. * docs: validate against localhost rather than 127.0.0.1 Dev servers commonly bind localhost only, so validating against http://127.0.0.1:PORT discovers zero tools while http://localhost:PORT works. The examples recommended the address that fails, and the symptom is indistinguishable from tools never registering. Point the examples at localhost and say what zero discovered tools usually means.
Browserbase Skills
A set of skills for enabling Claude Code to work with Browserbase through browser automation and the official browse CLI.
Skills
This plugin includes the following skills (see skills/ for details):
| Skill | Description |
|---|---|
| browser | Automate web browser interactions via CLI commands — supports remote Browserbase sessions with Browserbase Identity, Verified browsers, CAPTCHA solving, and residential proxies |
| functions | Deploy serverless browser automation to Browserbase cloud using the browse CLI |
| browser-trace | Capture a full DevTools-protocol trace (CDP firehose, screenshots, DOM dumps) alongside any browser automation, then bisect the stream into per-page searchable buckets |
| browser-to-api | Turn a website's observable HTTP traffic into a best-effort OpenAPI 3.1 spec by analyzing a browser-trace capture |
| autobrowse | Self-improving browser automation — iteratively runs a browsing task, reads the trace, and improves the navigation skill until it reliably passes |
| optimize-agent-prompt | Optimize Browserbase Agent API system prompts through repeated runs, Agent message traces, session logs, scoring, and unchanged confirmation runs |
| safe-browser | Build local Claude Agent SDK browser agents whose only browser capability is a CDP-gated safe_browser tool with domain allowlist enforcement |
| webmcp-gen | Author, compile, and validate site-specific WebMCP init scripts with the Stagehand WebMCP runtime |
| add-webmcp | Analyze an existing web app, add first-party WebMCP tools backed by its routes, forms, actions, and schemas, and validate them through Stagehand |
| cookie-sync | Sync cookies from local Chrome to a Browserbase persistent context so the browse CLI can access authenticated sites |
| fetch | Fetch HTML or JSON from static pages without a browser session — inspect status codes, headers, follow redirects |
| search | Search the web and return structured results (titles, URLs, metadata) without a browser session |
| ui-test | AI-powered adversarial UI testing — analyzes git diffs to test changes, or explores the full app to find bugs |
| browser-use-to-stagehand | Migrate browser-use (Python) automation to Stagehand v3 (TypeScript) on Browserbase — maps features and picks the right determinism level per step |
| agent-experience | Audit how agent-friendly a product, SDK, or docs site is — drops Claude subagents at it with tiny prompts, captures their traces, and scores setup friction, speed, error recovery, and doc quality |
| company-research | Discover target companies matching your ICP using the Browserbase Search API, deep-research each one, and score fit into a research report and CSV |
| event-prospecting | Extract speakers from a conference page, filter their companies against your ICP, and deep-research the best-fit people into a person-first prospecting report |
| competitor-analysis | Auto-discover a company's competitors via the Browserbase Search API, deep-research each across marketing, signal, benchmark, and strategic-diff lanes, and compile a browsable HTML report with an overview, per-competitor deep dives, a feature/pricing matrix, and a mentions feed |
Installation
To install the skill to popular coding agents:
$ npx skills add browserbase/skills
Claude Code
On Claude Code, to add the marketplace, simply run:
/plugin marketplace add browserbase/skills
Then install the plugin:
/plugin install browse@browserbase
If you prefer the manual interface:
- On Claude Code, type
/plugin - Select option
3. Add marketplace - Enter the marketplace source:
browserbase/skills - Press enter to select the
browseplugin - Hit enter again to
Install now - Restart Claude Code for changes to take effect
Usage
Once installed, you can ask Claude to browse or use the Browserbase CLI:
- "Go to Hacker News, get the top post comments, and summarize them "
- "QA test http://localhost:3000 and fix any bugs you encounter"
- "Order me a pizza, you're already signed in on Doordash"
- "Use
browseto list my Browserbase projects and show the output as JSON" - "Initialize a new Browserbase Function with
browse functions initand explain the next commands" - "Use safe-browser to build a Hacker News scraper that only stays on the main site"
Claude will handle the rest.
For local and localhost work, pass --local on the first browser command (for example, browse open http://localhost:3000 --local) to start a clean isolated browser. Use --auto-connect when the agent should reuse your existing local Chrome session, cookies, or login state.
Troubleshooting
Chrome not found
Install Chrome for your platform:
- macOS or Windows: https://www.google.com/chrome/
- Linux:
sudo apt install google-chrome-stable
Profile refresh
To refresh cookies from your main Chrome profile:
rm -rf .chrome-profile