Agent skill

Visible Browser for Manual Login Capture

by Encod3d-Sec in Encod3d-Sec/TORCH

Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

MITAuto-check passedSecurity

Install Visible Browser for Manual Login Capture

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH chrome-devtools-browser --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/chrome-devtools-browser .claude/skills/chrome-devtools-browser && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
chrome-devtools-browser
GitHub stars
329
Token cost
~1.2k tokens
SKILL.md length
516 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

  • Works in 4 steps: Bring it up (one command) → Attach + hand off for login → Drive + observe (chrome-devtools MCP… → …
  • A target login needs a human to enter a code, passkey or CAPTCHA
  • SKILL.md covers 1. Bring it up (one command), 2. Attach + hand off for login, 3. Drive + observe… and 4. Field notes, plus 2 more sections
  • Calls bash and ssh

What it does

This skill solves a specific gap in headless browser automation: a login that needs a human, such as Smart-ID, Mobile-ID, another manual or multi-factor flow, or a CAPTCHA. A script launches a real, on-screen Chromium session on the Kali desktop, tied to a per-engagement browser profile inside a named tmux session, and tunnels its DevTools port back to the agent. The operator signs in on the visible window while the agent stays off the keyboard and mouse during that step, confirming the page with a screenshot and waiting for the operator to say they are logged in.

Once signed in, the agent drives and inspects the same session through the chrome-devtools MCP: listing and selecting tabs, navigating, taking DOM snapshots and screenshots, reading console messages, pulling the network request list (including requests made during the login redirect) and the full detail of any one request, and running scripts in the page to read client state or confirm a DOM-based issue. If the VM has no desktop session, the skill falls back to a headless browser script instead.

When your agent uses it

  • A target login needs a human to enter a code, passkey or CAPTCHA
  • Capturing the authenticated API calls a web app makes after login
  • Confirming and screenshotting a DOM-based issue in a live page

Example prompts

  • “Open a visible browser on the VM so I can log into target.example with Mobile-ID.”
  • “Once I'm logged in, list the network requests the app made during sign-in.”
  • “Check window.__NEXT_DATA__ on this page and screenshot what's rendered.”

Requirements

  • A Kali VM with an active desktop session
  • The chrome-devtools MCP connected to the tunnelled DevTools port
  • tmux

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Bring it up (one command)
  2. Attach + hand off for login
  3. Drive + observe (chrome-devtools MCP capability map)
  4. Field notes

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash
    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Visible Browser for Manual Login Capture loads about 1.2k tokens when it runs. Until then it costs about 181 tokens; SKILL.md has 516 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~181
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 516 words, ~1,228 tokens.

Download SKILL.mdSave it as .claude/skills/chrome-devtools-browser/SKILL.md (or your agent's skills folder).
name
chrome-devtools-browser
description
Bring up a REAL, visible, interactive chromium on the Kali VM that the operator logs into (Smart-ID / Mobile-ID / any manual auth or MFA/CAPTCHA), while the agent drives and observes it live through the chrome-devtools MCP (navigate, DOM snapshot, network capture, screenshots, console, evaluate). Use whenever a target needs a MANUAL login the agent cannot complete headlessly, when you need to capture an authenticated session / the real API calls a page makes, or to confirm/screenshot a DOM-XSS. Triggers - "open a browser", "log in manually", "smart-id / mobile-id / national id login", "mfa / 2fa login", "solve the captcha", "drive the browser", "capture the authenticated session / network".

chrome-devtools-browser

Headless browser.sh cannot solve a human login. This skill brings up a visible chromium on the Kali desktop (:0) the operator can click and type into, with its DevTools port tunnelled back so the chrome-devtools MCP drives and watches it. Two roles at once: the human authenticates; the agent observes + acts. The VM holds the VPN/egress path, so it reaches both internet and in-scope targets.

1. Bring it up (one command)

bash
bash scripts/browser-visible.sh <login-url> --profile bbtest-<eng>
# e.g. bash scripts/browser-visible.sh https://target.example/ib --profile bbtest-<eng>

It resolves the VM's seat session, unlocks/wakes :0, frees the CDP port, launches chromium as the seat user on :0 in a named tmux session (a dedicated per-engagement profile, so the operator's own profile/cookies stay clean), then reuses scripts/browser.sh to forward CDP to http://127.0.0.1:9222. It prints VISIBLE on :0 when a real on-screen window exists (not merely a listening port). If it prints a no (:N) desktop session message, the VM has no desktop - fall back to scripts/browser.sh (headless).

2. Attach + hand off for login

  • The chrome-devtools MCP attaches to http://127.0.0.1:9222. Confirm with list_pages; navigate_page to the login URL if needed.
  • Stay off the browser while the operator enters credentials. Take a take_screenshot so they can confirm the page, then wait for their "logged in" before you drive again. The operator owns credential entry and the phone approval; the agent never types a personal code / PIN.

3. Drive + observe (chrome-devtools MCP capability map)

NeedMCP tool
List/select tabslist_pages (select the target tab; ignore the operator's other tabs)
Go to a page / back / reloadnavigate_page
Rendered DOM (elements + uids)take_snapshot
Visual PoC / confirm statetake_screenshot -> a web evidence image (hand to Skill(screenshot)/Skill(evidence))
The real API calls the app makeslist_network_requests (add includePreservedRequests:true to span the login redirects); this is the authenticated API map a curl crawl never sees
One request's headers/body/cookiesget_network_request <reqid>
Console / JS errorslist_console_messages
Read client config / globals, confirm DOM-XSSevaluate_script (e.g. __NEXT_DATA__, window.*, fire a payload in the real DOM)

Once authenticated, the captured /… API calls feed the hunt skills: Skill(hunt-idor) / Skill(hunt-api) (BOLA on id-keyed endpoints), Skill(hunt-xss) (DOM-XSS via evaluate_script), business-logic on the authed flows. Load-bearing requests still go to Burp Repeater when reachable (Skill(hunt-burp)).

Show full SKILL.md (165 more words)Show less

4. Field notes

  • A 200 {"message":"Unable to login"} with NO Set-Cookie = the server rejected at an account/state check and issued no session -> nothing to pivot (not a bug). A Set-Cookie/JWT issued before such a check is a real authz-bypass lead - test the gated endpoints with that cookie.
  • dbus/GPU errors in the tmux pane are non-fatal VM noise; judge success by VISIBLE on + list_pages.
  • Data minimisation on the authed surface: prove IDOR/BOLA with your own account + stop at the first adjacent-id differential; never pull another customer's real PII.

Safety

  • The CDP port is unauthenticated = total control of the browser (read any tab, lift session cookies). It stays loopback-only + ssh -L; never bind 0.0.0.0 / expose it to the LAN.
  • Named tmux session only (cdpbrowser); never tmux kill-server (the VPN/other work may live in tmux).
  • Dedicated --profile per engagement; the port-free step warns it drops any tabs on that port.

Teardown

bash
bash scripts/browser.sh stop                                   # drop the CDP tunnel
bash /root/vm.sh 'tmux kill-session -t cdpbrowser'             # close the VM browser

Setup / recipe rationale + the dead-ends that shaped this: scripts/browser.sh, scripts/shot.py (seat-session resolution), and the engagement failures.md note.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/workflow/chrome-devtools-browser of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Visible Browser for Manual Login Capture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Visible Browser for Manual Login Capture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Visible Browser for Manual Login Capture this skillEncod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT
Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC133—~3.1kAutomated safety check: PassApache-2.0
Dast Automationhardw00t/ai-security-arsenal104—~2.2kAutomated safety check: PassNone
Moai Ref LLM Securitymodu-ai/moai-adk1.2k—~4.5kAutomated safety check: PassApache-2.0
Securitytelagod/code-abyss244—~907Automated safety check: PassMIT
Browser Testing with Chrome DevToolsaddyosmani/agent-skills102k4 repos~3.5kAutomated safety check: WarnMIT

Similar skills

  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    133 GitHub stars~3.1k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Dast Automation

    hardw00t/ai-security-arsenal

    Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

    104 GitHub stars~2.2k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Moai Ref LLM Security

    modu-ai/moai-adk

    AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and…

    1.2k GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • Security

    telagod/code-abyss

    Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…

    244 GitHub stars~907 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Connects an agent to a real Chrome instance through the Chrome DevTools MCP server, so it can inspect the DOM, read console errors and profile performance directly.

    102k GitHub starsUsed in 4 repos~3.5k tokens
    Testing & QAAuto-check: warnings
  • Release Sample Sweep

    Atmosphere/atmosphere

    Run the pre-release end-to-end sweep of every user-facing surface — the 33 samples under samples/ (booted from their packaged artifacts and driven in a real browser via chrome-devtools MCP), the…

    3.8k GitHub stars~4.2k tokensUpdated yesterday
    MobileAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Hunt Idor

    Encod3d-Sec/TORCH

    IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

    329 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes

Questions about Visible Browser for Manual Login Capture

What does Visible Browser for Manual Login Capture do?

Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP. This skill solves a specific gap in headless browser automation: a login that needs a human, such as Smart-ID, Mobile-ID, another manual or multi-factor flow, or a CAPTCHA. A script launches a real, on-screen Chromium session on the Kali desktop, tied to a per-engagement browser profile inside a named tmux session, and tunnels its DevTools port back to the agent.

When should I use Visible Browser for Manual Login Capture?

Visible Browser for Manual Login Capture fits situations like: A target login needs a human to enter a code, passkey or CAPTCHA; capturing the authenticated API calls a web app makes after login; confirming and screenshotting a DOM-based issue in a live page.

How do I install Visible Browser for Manual Login Capture in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a claude-code`. Or copy the skill folder (skills/workflow/chrome-devtools-browser in Encod3d-Sec/TORCH) into .claude/skills/chrome-devtools-browser in your project. Claude Code loads it when a task matches its description.

How do I install Visible Browser for Manual Login Capture in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a codex`. Or copy the skill folder (skills/workflow/chrome-devtools-browser in Encod3d-Sec/TORCH) into .agents/skills/chrome-devtools-browser in your project. Codex loads it when a task matches its description.

Can I use Visible Browser for Manual Login Capture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chrome-devtools-browser, .gemini/skills/chrome-devtools-browser, .github/skills/chrome-devtools-browser and .opencode/skills/chrome-devtools-browser in your project.

What does Visible Browser for Manual Login Capture need to run?

Going by SKILL.md and its folder, Visible Browser for Manual Login Capture needs the command-line tools its instructions call (bash and ssh). Our summary lists: A Kali VM with an active desktop session; The chrome-devtools MCP connected to the tunnelled DevTools port; tmux.

Does Visible Browser for Manual Login Capture access the network?

SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Visible Browser for Manual Login Capture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Visible Browser for Manual Login Capture use?

Visible Browser for Manual Login Capture is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Visible Browser for Manual Login Capture use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Visible Browser for Manual Login Capture?

Skills that share tags, products or a category with Visible Browser for Manual Login Capture: Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 133 stars), Dast Automation (hardw00t/ai-security-arsenal, 104 stars), Moai Ref LLM Security (modu-ai/moai-adk, 1.2k stars) and Security (telagod/code-abyss, 244 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Visible Browser for Manual Login Capture?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.