Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Drive Chrome via the DevTools Protocol from JavaScript. An agent skill from browser-use/browser-harness-js.
$ npx skills add browser-use/browser-harness-js --skill cdp -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install browser-use/browser-harness-js cdp --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cdp" agent skill from https://github.com/browser-use/browser-harness-js/tree/main into .claude/skills/cdp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cdp", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add browser-use/browser-harness-js --skill cdp -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install browser-use/browser-harness-js cdp --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cdp" agent skill from https://github.com/browser-use/browser-harness-js/tree/main into .agents/skills/cdp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cdp", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add browser-use/browser-harness-js --skill cdp -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install browser-use/browser-harness-js cdp --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cdp" agent skill from https://github.com/browser-use/browser-harness-js/tree/main into .cursor/skills/cdp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cdp", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add browser-use/browser-harness-js --skill cdp -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install browser-use/browser-harness-js cdp --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cdp" agent skill from https://github.com/browser-use/browser-harness-js/tree/main into .gemini/skills/cdp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cdp", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install browser-use/browser-harness-js cdpInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add browser-use/browser-harness-js --skill cdp -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cdp" agent skill from https://github.com/browser-use/browser-harness-js/tree/main into .github/skills/cdp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cdp", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add browser-use/browser-harness-js --skill cdp -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install browser-use/browser-harness-js cdp --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cdp" agent skill from https://github.com/browser-use/browser-harness-js/tree/main into .opencode/skills/cdp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cdp", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cdpDrive Chrome via the DevTools Protocol from JavaScript. An agent skill from browser-use/browser-harness-js.
Cdp is an agent skill from browser-use/browser-harness-js. Drive Chrome via the DevTools Protocol from JavaScript. Run JS snippets through the browser-harness-js CLI — it auto-spawns a long-lived bun HTTP server holding a fully-typed CDP Session, and every call (browser-harness-js 'await session.Page.navigate(...)') executes against the same persistent connection. Session, active target, and globals survive across calls. Use when the user wants to automate, script, or inspect a Chrome browser via CDP — single tab or multi-tab, attach to existing Chrome or to a new one…
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 34 other files (for example `README.md`, `interaction-skills/connection.md` and `interaction-skills/cookies.md`).
It sits in Development. It works with JavaScript. The repository describes itself as: Self-healing browser harness that enables LLMs to complete any task. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2d9a5ed. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxosascriptbunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cdp loads about 3.3k tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 1,131 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
# Linux without sudo (ensure ~/.local/bin is on PATH)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from browser-use/browser-harness-js at commit 2d9a5ed, republished under its MIT licence (© browser-use). 1,131 words, ~3,290 tokens.
.claude/skills/cdp/SKILL.md (or your agent's skills folder). This skill also uses 32 other files; get the full folder from GitHub.browser-harness-js skillCustom codegen'd CDP SDK (every method from browser_protocol.json + js_protocol.json gets a typed wrapper) plus a tiny HTTP server that holds one persistent CDP Session. The browser-harness-js CLI auto-starts the server on first use and forwards JS snippets to it.
The SDK lives in the skill's sdk/ directory. In the rest of this doc, <skill-dir> refers to wherever npx skills add installed the skill (Claude Code: ~/.claude/skills/cdp; Cursor: ~/.cursor/skills/cdp; other agents vary). The CLI should be on PATH as browser-harness-js.
npx skills add drops the skill into your agent's skills directory but does NOT put the CLI on PATH. Before the first call, verify it's reachable and symlink it into any directory on your PATH if not:
# macOS (Apple Silicon + Homebrew)
command -v browser-harness-js >/dev/null || ln -sf <skill-dir>/sdk/browser-harness-js /opt/homebrew/bin/browser-harness-js
# macOS (Intel) / most Linux — may need sudo
command -v browser-harness-js >/dev/null || ln -sf <skill-dir>/sdk/browser-harness-js /usr/local/bin/browser-harness-js
# Linux without sudo (ensure ~/.local/bin is on PATH)
command -v browser-harness-js >/dev/null || { mkdir -p ~/.local/bin && ln -sf <skill-dir>/sdk/browser-harness-js ~/.local/bin/browser-harness-js; }The CLI auto-installs bun on first run if it's missing (the server is Bun-native). Set BROWSER_HARNESS_SKIP_BUN_INSTALL=1 to opt out.
Just run browser-harness-js '<JS>'. The first call spawns the server in the background; subsequent calls hit the same process and so reuse the same session, the same WebSocket to Chrome, and any globals you set.
browser-harness-js 'await session.connect()'
browser-harness-js 'await session.Page.navigate({url:"https://example.com"})'
browser-harness-js '(await session.Runtime.evaluate({expression:"document.title",returnByValue:true})).result.value'Output is the raw result content — no {ok,result} envelope.
| Result type | stdout |
|---|---|
| string | bare text, no JSON quotes (e.g. Example Domain) |
| number / boolean | 42, true |
| object / array (non-empty) | compact JSON (e.g. {"frameId":"..."}, [1,2,3]) |
undefined / null / "" / {} / [] | empty (no output) |
Errors go to stderr, exit code 1. The CDP error message and JS stack are printed verbatim, e.g.:
Error: CDP -32602: invalid params
at _call (.../session.ts:117:33)
...Detect failure with if browser-harness-js '...'; then ...; else handle_error; fi or by checking $?.
Multi-line snippets via stdin (heredoc). Important: a multi-statement snippet does NOT auto-return the last expression — write return X explicitly. Single-expression snippets passed as the first argument DO auto-return.
browser-harness-js <<'EOF'
const tabs = await listPageTargets();
globalThis.tid = tabs[0].targetId;
await session.use(globalThis.tid);
return globalThis.tid;
EOF| Command | Behavior |
|---|---|
browser-harness-js '<js>' | Auto-start server if needed, eval the JS, print result. |
browser-harness-js <<EOF…EOF | Same, code from stdin. |
browser-harness-js --status | Print health JSON (uptime, connected, sessionId) or exit 1 if down. |
browser-harness-js --start | Explicit start (no-op if already running). |
browser-harness-js --stop | Graceful shutdown. Drops session state. |
browser-harness-js --restart | Stop + start fresh. |
browser-harness-js --logs | tail -f the server log (/tmp/browser-harness-js.log). |
Env vars: CDP_REPL_PORT (default 9876), CDP_REPL_LOG (default /tmp/browser-harness-js.log).
These globals are pre-loaded — no imports needed:
session — the persistent Session. Has every CDP domain mounted: session.Page, session.DOM, session.Runtime, session.Network, … 56 domains, 652 methods total.listPageTargets() — list real page targets via CDP's Target.getTargets (works on Chrome 144+ too), with chrome:// and devtools:// URLs filtered out. No args — uses the connected session.detectBrowsers() — scan OS-specific profile dirs for running Chromium-based browsers with remote debugging on. Returns [{name, profileDir, port, wsPath, wsUrl, mtimeMs}], sorted by most recently launched.resolveWsUrl(opts) — resolve a WS URL from {wsUrl} | {port, host?} | {profileDir}. For the no-args auto-detect flow, call session.connect() directly instead.CDP — the generated namespaces (CDP.Page, CDP.Runtime, …) for type-name reference.Every method takes a single object argument matching the CDP wire params; it resolves to the typed return value (no result envelope, no id correlation — handled for you).
// no params
await session.DOM.enable()
// required params
await session.Page.navigate({ url: 'https://example.com' })
// all-optional params (object also optional)
await session.Page.captureScreenshot()
await session.Page.captureScreenshot({ format: 'png', quality: 80 })
// returns are stripped to the typed shape
const { root } = await session.DOM.getDocument()
const { nodeId } = await session.DOM.querySelector({ nodeId: root.nodeId, selector: 'h1' })Default: just call session.connect() with no args. It auto-detects running Chromium-based browsers (Chrome, Chromium, Edge, Brave, Arc, Vivaldi, Opera, Comet, Canary) by scanning OS-specific profile dirs for a DevToolsActivePort file, ordered by most-recently-launched, and picks the first one whose WebSocket accepts. OS-agnostic — works on macOS, Linux, Windows.
await session.connect() // auto-detectUse detectBrowsers() first if you want to see what's available (or let the user pick) before connecting:
const found = await detectBrowsers()
// [{ name: 'Google Chrome', profileDir, port, wsPath, wsUrl, mtimeMs }, ...]Explicit forms — use these only when auto-detect picks the wrong browser, or when you already know where to connect:
| Form | When to use |
|---|---|
{ profileDir } | Target a specific browser when several are running. Reads <profileDir>/DevToolsActivePort directly. |
{ wsUrl } | You already have ws://…/devtools/browser/<uuid> (e.g. piped from elsewhere). |
await session.connect({ profileDir: '/Users/<you>/Library/Application Support/Google/Chrome' })
await session.connect({ wsUrl: 'ws://127.0.0.1:9222/devtools/browser/<uuid>' })Profile paths by OS — use these with { profileDir }:
~/Library/Application Support/<Browser> (e.g. Google/Chrome, Comet, BraveSoftware/Brave-Browser, Arc/User Data)~/.config/<browser> (e.g. google-chrome, chromium, BraveSoftware/Brave-Browser)%LOCALAPPDATA%\<Browser>\User Data (e.g. Google\Chrome, Microsoft\Edge, BraveSoftware\Brave-Browser)Per-candidate WS-open timeout defaults to 5s — live browsers answer with open/close within ~100ms, so 5s is already generous. The only case where 5s is too short is when Chrome is showing the Allow popup and waiting on the user to click. If you expect that, pass timeoutMs: 30000:
await session.connect({ profileDir: '/Users/<you>/Library/Application Support/Google/Chrome', timeoutMs: 30_000 })If you see No detected browser accepted a connection — the browsers have DevToolsActivePort files but none are currently serving WS. Most common cause: remote-debugging is enabled but the user hasn't clicked Allow on the prompt yet. Tell them to click Allow, then retry (or bump timeoutMs).
After connect(), call session.use(targetId) once; subsequent page-level calls (Page/DOM/Runtime/Network/etc.) auto-route to that target's sessionId. Browser.* and Target.* calls always hit the browser endpoint.
const tabs = await listPageTargets() // no args; uses the connected session
const sid = await session.use(tabs[0].targetId)
await session.Page.enable()
await session.Page.navigate({ url: 'https://example.com' })listPageTargets() uses CDP's Target.getTargets (not /json), so it works on Chrome 144+ too. It already filters out chrome:// and devtools:// URLs. Equivalent raw call:
const { targetInfos } = await session.Target.getTargets({})
const tabs = targetInfos.filter(t => t.type === 'page' && !t.url.startsWith('chrome://') && !t.url.startsWith('devtools://'))To switch tabs: session.use(otherTargetId). To detach: session.setActiveSession(undefined).
// Subscribe (returns an unsubscribe fn)
const off = session.onEvent((method, params, sessionId) => { ... })
// Or wait for a single matching event with optional predicate + timeout
await session.Network.enable()
const ev = await session.waitFor(
'Page.frameNavigated',
(p) => p.frame.url.includes('example.com'),
10_000
)Each snippet runs inside its own async wrapper, so its let/const declarations vanish when it returns. To carry data forward, attach to globalThis:
browser-harness-js '(await listPageTargets()).forEach((t,i)=>globalThis["tab"+i]=t.targetId)'
browser-harness-js 'await session.use(globalThis.tab0)'
browser-harness-js 'await session.Page.navigate({url:"https://example.com"})'session itself, the active sessionId, and event subscribers are already preserved by the server — globals are only needed for ad-hoc data.
When attaching to the user's already-running browser:
await session.connect() first (no args) — auto-detect handles every Chromium-based browser via DevToolsActivePort. If it returns, you're done.No running browser with remote debugging detected, the user needs to turn it on. Open the inspect page:# macOS — prefer AppleScript over `open -a` (reuses current profile, avoids the profile picker)
osascript -e 'open location "chrome://inspect/#remote-debugging"'
# Linux
google-chrome 'chrome://inspect/#remote-debugging' # or: chromium, google-chrome-stable
# Windows (PowerShell)
Start-Process chrome 'chrome://inspect/#remote-debugging'await detectBrowsers(), then await session.connect({ profileDir: <the one you want> }).session.connect() returns No detected browser accepted a connection, the user has remote-debugging on but hasn't clicked Allow yet. Tell them to click it and retry, or pass timeoutMs: 30000 to wait for the click.listPageTargets() already drops chrome:// and devtools:// URLs. If you call Target.getTargets() directly, filter manually.Target.activateTarget only switches to a known targetId.The full typed surface is in <skill-dir>/sdk/generated.ts (~655 KB, only loaded if you read it). Each method has its CDP description as a JSDoc comment plus typed *Params / *Return interfaces in per-domain namespaces.
grep -n "navigate" <skill-dir>/sdk/generated.ts | headWhen the upstream protocol JSONs change, replace sdk/browser_protocol.json and/or sdk/js_protocol.json and re-run:
cd <skill-dir>/sdk && bun gen.ts
browser-harness-js --restart # pick up the new bindingsAll paths are relative to <skill-dir> (the install path — see top of this doc).
/usr/local/bin/browser-harness-js → <skill-dir>/sdk/browser-harness-js (the CLI)sdk/repl.ts — HTTP server (Bun.serve on 127.0.0.1:9876)sdk/session.ts — Session class (transport, connect, target routing, events)sdk/generated.ts — codegen output: every CDP method as a typed wrappersdk/gen.ts — codegen scriptsdk/{browser,js}_protocol.json — upstream protocol (vendored)© browser-use, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 32 other files in the repository root of browser-use/browser-harness-js.
Open the folder on GitHubat commit 2d9a5ed
Cdp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cdp this skillbrowser-use/browser-harness-js | 489 | — | ~3.3k | Automated safety check: Notes | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| @pierre/diffs Code Renderingpierrecomputer/pierre | 6.2k | 2 repos | ~803 | Automated safety check: Pass | Apache-2.0 | |
| Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop | 5.2k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Generate Release Notesteambit/bit | 18k | — | ~2.2k | Automated safety check: Pass | Custom licence | |
| Pnpm Engineteambit/bit | 18k | — | ~1.9k | Automated safety check: Pass | Custom licence |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
pierrecomputer/pierre
Guides an agent through using @pierre/diffs to render syntax-highlighted files and diffs, and to build editing and review surfaces in React or plain JavaScript.
dmmulroy/anti-slop
Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.
teambit/bit
Generate comprehensive release notes for Bit from git commits and pull requests.
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
TryGhost/Ghost
Moves a legacy internal Ghost package from JavaScript and CommonJS to TypeScript and ESM in three focused commits that keep git file history intact.
Works with
Categories
Drive Chrome via the DevTools Protocol from JavaScript. An agent skill from browser-use/browser-harness-js. Cdp is an agent skill from browser-use/browser-harness-js. Drive Chrome via the DevTools Protocol from JavaScript.
Cdp fits situations like: the user wants to automate; inspect a Chrome browser via CDP — single tab; attach to existing Chrome; A new one launched with --remote-debugging-port.
Run `npx skills add browser-use/browser-harness-js --skill cdp -a claude-code`. Or copy the skill folder (the browser-use/browser-harness-js repository) into .claude/skills/cdp in your project. Claude Code loads it when a task matches its description.
Run `npx skills add browser-use/browser-harness-js --skill cdp -a codex`. Or copy the skill folder (the browser-use/browser-harness-js repository) into .agents/skills/cdp in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add browser-use/browser-harness-js --skill cdp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cdp, .gemini/skills/cdp, .github/skills/cdp and .opencode/skills/cdp in your project.
Going by SKILL.md and its folder, Cdp needs the command-line tools its instructions call (npx, osascript and bun). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Cdp is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cdp: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), @pierre/diffs Code Rendering (pierrecomputer/pierre, 6.2k stars), Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.2k stars) and Generate Release Notes (teambit/bit, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
browser-use (a GitHub organization) maintains it in browser-use/browser-harness-js, which has 489 GitHub stars. The repository was last updated on August 30, 2026.
Source: browser-use/browser-harness-js on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.