Agent skill

Sift Project

by agent-labs-dev in agent-labs-dev/fastbrowse

Quality gate, audit evidence, live roots and cleanup boundaries for fastbrowse.

MITAuto-check passedTesting & QA

Install Sift Project

skills CLI
$ npx skills add agent-labs-dev/fastbrowse --skill sift-project -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agent-labs-dev/fastbrowse sift-project --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agent-labs-dev/fastbrowse.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sift-project .claude/skills/sift-project && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sift-project
GitHub stars
113
Token cost
~1.8k tokens
SKILL.md length
770 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Quality gate, audit evidence, live roots and cleanup boundaries for fastbrowse.

  • Works in 5 steps: Tool configuration and documentation. → Reporting scripts and eval… → Clients, adapters and browser indexing. → …
  • Tasks that involve Browser automation
  • SKILL.md covers Gate, Evidence, Live roots and Model-read text, plus 6 more sections
  • Calls uv, npm and npx

What it does

Sift Project is an agent skill from agent-labs-dev/fastbrowse. Quality gate, audit evidence, live roots and cleanup boundaries for fastbrowse. Load before sift audits.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Browser automation, Quality gates and SOC 2 and security compliance. It works with Python. The repository describes itself as: A fast browser agent: Jev picks each action from what is on the page, an LLM reads and plans, and every claim in an answer cites a quote from the page. The licence is MIT.

When your agent uses it

  • Tasks that involve Browser automation
  • Tasks that involve Quality gates
  • Tasks that involve SOC 2 and security compliance

Example prompts

  • “/sift-project”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Tool configuration and documentation.
  2. Reporting scripts and eval infrastructure, preserving versioned grading contracts.
  3. Clients, adapters and browser indexing.
  4. Reading, citation memory and verification.
  5. Run loop, authorization and secret handling.

What it can do on your machine

Read from SKILL.md and the folder at commit 2b881b9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • npm
    • npx
    • uvx
    • git
    • gitleaks
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, npm, npx, uvx and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sift Project loads about 1.8k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 770 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agent-labs-dev/fastbrowse at commit 2b881b9, republished under its MIT licence (© agent-labs-dev). 770 words, ~1,833 tokens.

Download SKILL.mdSave it as .claude/skills/sift-project/SKILL.md (or your agent's skills folder).
name
sift-project
description
Quality gate, audit evidence, live roots and cleanup boundaries for fastbrowse. Load before sift audits.

fastbrowse audit guidance

fastbrowse is a Python 3.13+ package with CLI, MCP, embedding and serve entry points. Two owned JavaScript expressions run inside browser pages through CDP. Python browser tests exercise them against Chrome. packages/sdk is the TypeScript SDK published to npm as fastbrowse. It starts fastbrowse serve --stdio, and its tests run against that server from the uv environment.

Gate

From the repository root, after uv sync --all-extras and npm ci --ignore-scripts:

sh
uv run ruff check .
uv run ruff format --check .
uv run ty check
uv run python scripts/changelog.py --check "$(uv version --short)"
uv run python scripts/npm_versions.py
uv run python scripts/no_slop.py
uv run vale sync
uv run vale README.md CHANGELOG.md AGENTS.md CONTRIBUTING.md docs src scripts tests
uv run pytest -q
npm run check:browser
npm run generate:sdk && git diff --exit-code -- packages/sdk/src/protocol.ts
npm run check:sdk
uv run actionlint
uv run python .sift/agents.py check
uv run python .sift/gate.py --base origin/main

Every command must exit 0. Node.js 22+ is needed only for development. CI retains the required check status, which depends on the Python matrix, secret scan, sift job and SDK job, and on the five binary builds when a change touches what is frozen. The sift job uses the PR base rather than main for its changed-file rules. No ast-grep dependency is needed while there are no rules. The vendored sift helpers are version 0.3.0; do not rewrite their source locally.

Evidence

These commands produce candidates, not blocking verdicts. Run them from the repository root.

sh
uvx vulture==2.16 src tests scripts --min-confidence 80 --sort-by-size
npx --yes jscpd@4.0.8 --silent --reporters json --output .sift/runs/evidence/jscpd src/fastbrowse/*.py src/fastbrowse/clients src/fastbrowse/adapters src/fastbrowse/evals/*.py src/fastbrowse/audit/*.py scripts tests
uvx zizmor==1.30.1 --offline .github/workflows
npx --yes markdownlint-cli2@0.23.3 README.md AGENTS.md CONTRIBUTING.md SECURITY.md 'docs/*.md'
npx --yes -p typescript@7.0.2 tsc --allowJs --checkJs --noEmit --target es2022 --lib es2022,dom,dom.iterable src/fastbrowse/browser/capture.js src/fastbrowse/browser/snapshot.js
gitleaks detect --source . --no-banner --redact
  • Vulture reports six unused context-manager exception parameters. Their protocol signatures are live.
  • Clone detection reports shared test setup and client protocol shapes. Read both contracts before merging them.
  • Zizmor remains advisory in CI: the Jev review executes base code and treats the PR as diff data; the release uses a local reusable site workflow. No ignore markers conceal those warnings.
  • Markdownlint's initial scan reported 1,077 issues, including line length and table layout. Vale remains the prose gate.
  • JavaScript type checking initially reported 156 issues, including DOM narrowing, implicit parameters and the injected window registry. It is evidence until those annotations can be added separately.
  • Gitleaks is pinned to 8.28.0 in CI. No secret or detector baseline is installed.

Live roots

  • fastbrowse.run_task, package exports, public Pydantic models and callback protocols are consumed by embedders.
  • pyproject.toml registers fastbrowse.cli:main and fastbrowse.mcp_server:main console scripts.
  • fastbrowse serve is reached through cli.main; fastbrowse.protocol models are the wire the npm SDK reads.
  • packages/sdk/src/index.ts exports are the npm package's public API. fastbrowse.scripted is named at run time by serve --run-task in the smoke scripts and is a hidden import of the frozen build.
  • scripts/ stand-alone programs are called from ci.yml, binaries.yml and release.yml.
  • MCP registers its browse tool and uses its schema/docstrings as model-visible descriptions.
  • src/fastbrowse/browser/page.py loads snapshot and capture JavaScript by file path; both are wheel assets.
  • CDP event registrations, context-manager methods, pytest fixtures and test discovery call symbols indirectly.
  • Evals and audit modules have python -m entry points; scripts are also called from CI and the justfile.
  • docs/results/summary.json, README and changelog content are consumed by fastbrowse.ai outside this repository.

Model-read text

Prompts in agent, planner, policy, retrieval, verification, safety and shortcut modules, MCP tool descriptions, LLM response schemas, Jev questions and task text are behavior. Never shorten them as cleanup. Validate behavior changes against dev evals; heldout runs are before and after a round and are not debugged. See the evaluation workflow for paid-run prerequisites.

Show full SKILL.md (283 more words)Show less

Zones

PathsZone
src/fastbrowse Python and browser/capture.js, browser/snapshot.jsproduction
packages/sdk/src/ except protocol.tsproduction
packages/sdk/test/test
packages/sdk/src/protocol.tsgenerated
scripts/script
tests/ Pythontest
tests/browser/sites/, evals/fixtures/, audit/fixtures/fixture
docs/results/, src/fastbrowse/evals/versions.jsongenerated
src/fastbrowse/browser/autoconsent/, .sift/gate.py, .sift/agents.pyvendor
.github/, packaging/, tool manifests and lockfilesconfig
Markdown and .agents/skills/docs

Conventions

Keep Python compatible with 3.13, Ruff at 120 columns and typed seam models. Preserve status, authorization, secret-origin and citation invariants. Comments explain the constraint behind code. Use ASCII punctuation. Generated eval tables and versions come from fastbrowse.evals.versions; do not edit them by hand.

Risk order

  1. Tool configuration and documentation.
  2. Reporting scripts and eval infrastructure, preserving versioned grading contracts.
  3. Clients, adapters and browser indexing.
  4. Reading, citation memory and verification.
  5. Run loop, authorization and secret handling.

Settled

  • Context-manager exception arguments are protocol parameters, even when unused: adapters/browser_use_cloud.py.
  • Similar provider client shapes implement different wire protocols: clients/typesafe.py and clients/vercel.py.
  • Browser scripts return CDP-serializable values and use DOM globals; they are not Node.js modules.
  • snapshot.js stays a parenthesized function expression because Python appends its mode arguments. capture.js is embedded inside parentheses and cannot have a leading or trailing semicolon. Their format markers preserve those contracts; JavaScript lint rules still apply, but the formatter cannot enforce the expression bodies without also rewriting their wrappers.

Anti-patterns

None recorded yet.

Project rules and lenses

Existing Ruff rules cover Python style and correctness. Biome lists its JavaScript correctness rules explicitly. Tests already enforce eval fingerprints, generated results, provider contracts, status semantics and safety behavior. The changelog check, no_slop and Vale own release entries and prose. Do not duplicate those in sift rules. No ast-grep rules, script rules or project lenses have been added: the audit found no new mechanical defect shape.

© agent-labs-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/sift-project of agent-labs-dev/fastbrowse.

Open the folder on GitHubat commit 2b881b9

Compare with similar skills

Sift Project next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sift Project compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sift Project this skillagent-labs-dev/fastbrowse113—~1.8kAutomated safety check: PassMIT
SonarqubeDougTrajano/pydantic-ai-skills377—~2.2kAutomated safety check: PassMIT
Checkav1155/houndarr292—~366Automated safety check: PassAGPL-3.0
Anti Detect Browserantibrow/anti-detect-browser-skills914—~9.8kAutomated safety check: WarnMIT
Review Pre Commitopenwpm/OpenWPM1.4k—~788Automated safety check: PassCustom licence
Pump Testingnirholas/pump-fun-sdk133—~706Automated safety check: PassCustom licence

Similar skills

  • Sonarqube

    DougTrajano/pydantic-ai-skills

    Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed…

    377 GitHub stars~2.2k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Check

    av1155/houndarr

    Run Houndarr's full quality gate (ruff lint, ruff format check, mypy, bandit, pytest) and report results in a single table.

    292 GitHub stars~366 tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Anti Detect Browser

    antibrow/anti-detect-browser-skills

    Drive Chromium from standard Playwright APIs with a real-device fingerprint applied in the kernel, one persistent isolated profile per identity, and a per-profile proxy whose exit IP sets timezone…

    914 GitHub stars~9.8k tokensUpdated 1 mo ago
    Testing & QAAuto-check: warnings
  • Review Pre Commit

    openwpm/OpenWPM

    Use as a pre-commit quality gate — review the working diff for stub patterns (TODO/FIXME/unimplemented!()/todo!()), debug leftovers (dbg!, stray console.log/println!, commented-out code), then run…

    1.4k GitHub stars~788 tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Pump Testing

    nirholas/pump-fun-sdk

    Multi-language test infrastructure for the Pump SDK — Rust unit/integration/security/performance tests, TypeScript Jest tests, Python fuzz tests, shell test orchestration, Criterion benchmarks, and…

    133 GitHub stars~706 tokensUpdated 19 days ago
    Testing & QAAuto-check passed
  • Playwright

    secondsky/claude-skills

    Browser automation and E2E testing with Playwright. An agent skill from secondsky/claude-skills.

    227 GitHub stars~3.7k tokensUpdated 9 days ago
    Testing & QAAuto-check: notes

Works with

Categories

Questions about Sift Project

What does Sift Project do?

Quality gate, audit evidence, live roots and cleanup boundaries for fastbrowse. Sift Project is an agent skill from agent-labs-dev/fastbrowse. Quality gate, audit evidence, live roots and cleanup boundaries for fastbrowse.

When should I use Sift Project?

Sift Project fits situations like: tasks that involve Browser automation; tasks that involve Quality gates; tasks that involve SOC 2 and security compliance.

How do I install Sift Project in Claude Code?

Run `npx skills add agent-labs-dev/fastbrowse --skill sift-project -a claude-code`. Or copy the skill folder (.agents/skills/sift-project in agent-labs-dev/fastbrowse) into .claude/skills/sift-project in your project. Claude Code loads it when a task matches its description.

How do I install Sift Project in Codex?

Run `npx skills add agent-labs-dev/fastbrowse --skill sift-project -a codex`. Or copy the skill folder (.agents/skills/sift-project in agent-labs-dev/fastbrowse) into .agents/skills/sift-project in your project. Codex loads it when a task matches its description.

Can I use Sift Project in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agent-labs-dev/fastbrowse --skill sift-project -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sift-project, .gemini/skills/sift-project, .github/skills/sift-project and .opencode/skills/sift-project in your project.

What does Sift Project need to run?

Going by SKILL.md and its folder, Sift Project needs the command-line tools its instructions call (uv, npm, npx, uvx, git and gitleaks). Our summary lists: Python 3; Node.js.

Does Sift Project access the network?

SKILL.md contains no URLs. Its commands use uv, npm, npx, uvx and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sift Project safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sift Project use?

Sift Project is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sift Project use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sift Project?

Skills that share tags, products or a category with Sift Project: Sonarqube (DougTrajano/pydantic-ai-skills, 377 stars), Check (av1155/houndarr, 292 stars), Anti Detect Browser (antibrow/anti-detect-browser-skills, 914 stars) and Review Pre Commit (openwpm/OpenWPM, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sift Project?

agent-labs-dev (a GitHub organization) maintains it in agent-labs-dev/fastbrowse, which has 113 GitHub stars. The repository was last updated on October 6, 2026.

Source: agent-labs-dev/fastbrowse on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.