Agent skill

Gauntlet

by anomalyco in anomalyco/browser-control

Run a real-world navigation and capability gauntlet on Browser Control across live websites, fix general DOM/ARIA/CDP root causes, benchmark speed and token efficiency, and finish with a mandatory…

MITAuto-check passedProductivity & Automation

Install Gauntlet

skills CLI
$ npx skills add anomalyco/browser-control --skill gauntlet -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anomalyco/browser-control gauntlet --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anomalyco/browser-control.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/gauntlet .claude/skills/gauntlet && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gauntlet
GitHub stars
438
Token cost
~1.1k tokens
SKILL.md length
399 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Run a real-world navigation and capability gauntlet on Browser Control across live websites, fix general DOM/ARIA/CDP root causes, benchmark speed and token efficiency, and finish with a mandatory…

  • Works in 4 steps: Gauntlet — Adversarial Real-Site Field… → Autoresearch — Speed, Token & Round-Trip… → Simplify — Mandatory Coherence &… → …
  • Asked to run a gauntlet
  • Calls pnpm; reaches ui.shadcn.com and github.com
  • Dogfood Browser Control on real sites

What it does

Gauntlet is an agent skill from anomalyco/browser-control. Run a real-world navigation and capability gauntlet on Browser Control across live websites, fix general DOM/ARIA/CDP root causes, benchmark speed and token efficiency, and finish with a mandatory simplify pass. Use when asked to run a gauntlet, dogfood Browser Control on real sites, or do an improvement pass.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Browser automation, Root cause analysis and Accessibility. The repository describes itself as: Local browser driver for trusted agents: control your existing Chromium browser through a small extension and local relay. The licence is MIT.

When your agent uses it

  • Asked to run a gauntlet
  • Dogfood Browser Control on real sites
  • Do an improvement pass

Example prompts

  • “/gauntlet”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gauntlet — Adversarial Real-Site Field Pass
  2. Autoresearch — Speed, Token & Round-Trip Check
  3. Simplify — Mandatory Coherence & Compression Pass
  4. Harvest — UI-to-API Promotion (Optional)

What it can do on your machine

Read from SKILL.md and the folder at commit 22c0f77. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • ui.shadcn.com
    • github.com
    • resy.com
    • ubereats.com
    • news.ycombinator.com
    • en.wikipedia.org
    • npmjs.com
    • developer.mozilla.org
    • reddit.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gauntlet loads about 1.1k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 399 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anomalyco/browser-control at commit 22c0f77, republished under its MIT licence (© anomalyco). 399 words, ~1,149 tokens.

Download SKILL.mdSave it as .claude/skills/gauntlet/SKILL.md (or your agent's skills folder).
name
gauntlet
description
Run a real-world navigation and capability gauntlet on Browser Control across live websites, fix general DOM/ARIA/CDP root causes, benchmark speed and token efficiency, and finish with a mandatory simplify pass. Use when asked to run a gauntlet, dogfood Browser Control on real sites, or do an improvement pass.

Gauntlet

Run Browser Control against uncurated live websites, fix general root causes as you hit them, lock each fix in with a minimal offline regression test, and always finish with a Simplify pass so new capabilities never accumulate site-specific hacks or bloated files.

ts
  ┌─────────────────────────────────────────────────────────────────────┐
  │                                                                     │
  ▼                                                                     │
[1. Gauntlet] ──► [2. Autoresearch] ──► [3. Simplify] ──► [4. Harvest] ─┘
 Real-site         Latency, token &      Compress code,    Promote recurring
 field tasks       round-trip profile    remove hacks      UI flows to CLIs

Workflow

1. Gauntlet — Adversarial Real-Site Field Pass
  1. Create a dedicated session (browser-control session new "🧭 gauntlet") and pick 4–6 diverse live sites that stress different web patterns (never perform destructive/irreversible actions like placing an order):
    • Portal UI libraries: https://ui.shadcn.com/docs/components/radix/select (Radix <button role="combobox">, body-portaled [role="listbox"] / [role="option"])
    • Complex web apps: https://github.com/Effect-TS/effect/issues (Primer [role="menu"] / [role="menuitemradio"], filter dialogs, snapshot({ delta: true }))
    • Dense SPAs & e-commerce / booking: https://resy.com, https://www.ubereats.com (top-level <header> search bars, carousels, focus-locked modals, deep card lists)
    • Layout tables & prose: https://news.ycombinator.com, https://en.wikipedia.org, https://www.npmjs.com
    • Web Components & Shadow DOM: https://developer.mozilla.org/en-US/docs/Web/API/ShadowRoot, https://www.reddit.com/r/typescript/
  2. Drive each task through the public agent interface (snapshot(), ref("eN"), screenshotWithLabels(), network).
  3. Whenever a step fails, times out, misses an interactive control, emits duplicate lines, or forces a blind waitForTimeout sleep:
    • Inspect the live DOM in the session to find the general DOM, W3C ARIA, or CDP root cause.
    • Never hardcode site-specific domain names or CSS class names. Express every rule in terms of standard HTML tags, ARIA roles/attributes, computed styles, or DOM structure.
    • Fix the root cause in src/ (or extension/src/), add a minimal offline HTML regression check to scripts/check-snapshot.ts or test/, deploy to /Users/kit/.browser-control/current-runtime (pnpm runtime:prepare + pnpm runtime:select + browser-control relay restart), and re-verify on the live site.
Show full SKILL.md (173 more words)Show less
2. Autoresearch — Speed, Token & Round-Trip Check

Measure across the gauntlet sites:

  • Wall-clock latency (ms) per snapshot() call (target: 15–40 ms on standard pages, < 180 ms on 9,000-node Shadow DOM pages).
  • Token footprint (chars / lines): eliminate duplicate heading + link pairs, redundant listitem / p wrappers, and layout-table noise.
  • Avoidable round-trips & sleeps: prefer event-driven settle (MutationObserver, Emulation.setFocusEmulationEnabled) over manual waitForTimeout padding.
3. Simplify — Mandatory Coherence & Compression Pass

After fixing gauntlet findings, always run a simplify pass before finishing:

  • Remove any ad-hoc branches, dead flags, or overlapping helpers introduced during debugging.
  • Keep module boundaries clean (src/snapshot.ts owns DOM inspection and input helpers; src/execute.ts owns ExecuteSandbox and page recovery).
  • Run the full verification gate:
    bash
    pnpm exec tsx scripts/check-snapshot.ts
    pnpm check:locals && pnpm check:unused && pnpm audit:duplicates
    pnpm test
4. Harvest — UI-to-API Promotion (Optional)

When testing a multi-step workflow (like Uber Eats or Resy), verify that network.start() + network.stop() produces a clean .endpoints digest and that BrowserControlClient.origin(url, { session, headers, handoffOnAuthFailure: true }) can drive the JSON API directly in one turn.

Always delete temporary gauntlet sessions (browser-control session delete "🧭 gauntlet") when finished.

© anomalyco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .opencode/skills/gauntlet of anomalyco/browser-control.

Open the folder on GitHubat commit 22c0f77

Compare with similar skills

Gauntlet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gauntlet compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gauntlet this skillanomalyco/browser-control438—~1.1kAutomated safety check: PassMIT
Preview Rostradpc/rostra110—~2.3kAutomated safety check: PassNone
Kuri Serverjustrach/kuri365—~6.2kAutomated safety check: NotesCustom licence
CLI Anything BrowserHKUDS/CLI-Anything52k—~1.5kAutomated safety check: WarnApache-2.0
Bdgszymdzum/browser-debugger-cli152—~2.5kAutomated safety check: PassMIT
Vitemagnus919/agent-skills111—~1.5kAutomated safety check: NotesMIT

Similar skills

  • Preview Rostra

    dpc/rostra

    Use agent-browser to interact with Rostra's live development UI through accessibility snapshots, semantic controls, text entry, and screenshots.

    110 GitHub stars~2.3k tokensUpdated 13 days ago
    Productivity & AutomationAuto-check passed
  • Kuri Server

    justrach/kuri

    Use kuri-server to automate Chrome via HTTP API — navigate pages, get a11y snapshots, interact with elements, capture network traffic (HAR), extract cookies, and bypass bot protection.

    365 GitHub stars~6.2k tokensUpdated 2 mo ago
    Productivity & AutomationAuto-check: notes
  • CLI Anything Browser

    HKUDS/CLI-Anything

    Browser automation CLI using DOMShell MCP server. An agent skill from HKUDS/CLI-Anything.

    52k GitHub stars~1.5k tokensUpdated 15 days ago
    Productivity & AutomationAuto-check: warnings
  • Bdg

    szymdzum/browser-debugger-cli

    Use bdg CLI to drive and debug a real Chrome via Chrome DevTools Protocol - navigate, click, fill and submit forms, check what an action changed (navigation, new messages, pending requests), inspect…

    152 GitHub stars~2.5k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Vite

    magnus919/agent-skills

    Operate Vite projects: inspect versions and configuration, run bounded development and production builds, diagnose dependency and asset failures, and configure environment-aware frontend delivery.

    111 GitHub stars~1.5k tokensUpdated yesterday
    Frontend & DesignAuto-check: notes
  • Browser QA

    affaan-m/ECC

    Run automated post-deploy UI verification with a browser automation MCP (claude-in-chrome, Playwright, or Puppeteer): console-error and Core Web Vitals smoke checks, form and auth-flow interaction…

    274k GitHub starsUsed in 2 repos~1k tokens
    Frontend & DesignAuto-check passed

More from anomalyco/browser-control

  • Browser Control

    anomalyco/browser-control

    Drive the user's existing Chromium-family browser with deterministic Playwright.

    438 GitHub stars~8.2k tokensUpdated today
    Auto-check passed
  • Self Iteration

    anomalyco/browser-control

    Dogfood a project-owned tool in a realistic user flow and evaluate the agent experience.

    438 GitHub stars~494 tokensUpdated today
    Auto-check passed

Questions about Gauntlet

What does Gauntlet do?

Run a real-world navigation and capability gauntlet on Browser Control across live websites, fix general DOM/ARIA/CDP root causes, benchmark speed and token efficiency, and finish with a mandatory…. Gauntlet is an agent skill from anomalyco/browser-control. Run a real-world navigation and capability gauntlet on Browser Control across live websites, fix general DOM/ARIA/CDP root causes, benchmark speed and token efficiency, and finish with a mandatory simplify pass.

When should I use Gauntlet?

Gauntlet fits situations like: asked to run a gauntlet; dogfood Browser Control on real sites; do an improvement pass.

How do I install Gauntlet in Claude Code?

Run `npx skills add anomalyco/browser-control --skill gauntlet -a claude-code`. Or copy the skill folder (.opencode/skills/gauntlet in anomalyco/browser-control) into .claude/skills/gauntlet in your project. Claude Code loads it when a task matches its description.

How do I install Gauntlet in Codex?

Run `npx skills add anomalyco/browser-control --skill gauntlet -a codex`. Or copy the skill folder (.opencode/skills/gauntlet in anomalyco/browser-control) into .agents/skills/gauntlet in your project. Codex loads it when a task matches its description.

Can I use Gauntlet in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anomalyco/browser-control --skill gauntlet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gauntlet, .gemini/skills/gauntlet, .github/skills/gauntlet and .opencode/skills/gauntlet in your project.

What does Gauntlet need to run?

Going by SKILL.md and its folder, Gauntlet needs the command-line tools its instructions call (pnpm).

Does Gauntlet access the network?

SKILL.md names 9 domains. In commands or code: ui.shadcn.com, github.com, resy.com, ubereats.com, news.ycombinator.com, en.wikipedia.org, npmjs.com, developer.mozilla.org and reddit.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Gauntlet safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gauntlet use?

Gauntlet is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gauntlet use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gauntlet?

Skills that share tags, products or a category with Gauntlet: Preview Rostra (dpc/rostra, 110 stars), Kuri Server (justrach/kuri, 365 stars), CLI Anything Browser (HKUDS/CLI-Anything, 52k stars) and Bdg (szymdzum/browser-debugger-cli, 152 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gauntlet?

anomalyco (a GitHub organization) maintains it in anomalyco/browser-control, which has 438 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: anomalyco/browser-control on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.