Agent skill

Cross Origin Iframe Probe

by jumodada in jumodada/Drissionpage-MCP-Server

A skill your agent uses when a drissionpage-mcp task targets an iframe such as a payment widget, challenge, SSO flow, or embedded checkout.

Custom licenceAuto-check passedAgent Workflows

Install Cross Origin Iframe Probe

skills CLI
$ npx skills add jumodada/Drissionpage-MCP-Server --skill cross-origin-iframe-probe -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jumodada/Drissionpage-MCP-Server cross-origin-iframe-probe --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jumodada/Drissionpage-MCP-Server.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cross-origin-iframe-probe .claude/skills/cross-origin-iframe-probe && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cross-origin-iframe-probe
GitHub stars
487
Token cost
~1.2k tokens
SKILL.md length
555 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
Custom licence

At a glance

A skill your agent uses when a drissionpage-mcp task targets an iframe such as a payment widget, challenge, SSO flow, or embedded checkout.

  • Works in 7 steps: Call frame_list and inspect each… → If frame_list does not enumerate the… → Read element_state_get on the iframe… → …
  • A drissionpage-mcp task targets an iframe such as a payment widget
  • SKILL.md covers Decision procedure, Retry discipline and Why this matters for atomic…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cross Origin Iframe Probe is an agent skill from jumodada/Drissionpage-MCP-Server. Use when a drissionpage-mcp task targets an iframe such as a payment widget, challenge, SSO flow, or embedded checkout. Classifies frame document access and outer presentation evidence, then selects a DOM, viewport-coordinate, scroll, keyboard, or parent-page verification path.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers, Authentication and Browser automation. It works with Model Context Protocol. The repository describes itself as: DrissionPage MCP Server · Browser automation for Claude Code, Codex, and MCP clients.

When your agent uses it

  • A drissionpage-mcp task targets an iframe such as a payment widget
  • Embedded checkout

Example prompts

  • “/cross-origin-iframe-probe”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Call frame_list and inspect each candidate's boundary,
  2. If frame_list does not enumerate the widget, use element_find_all with a
  3. Read element_state_get on the iframe selector. The returned geometry is
  4. Branch on presentation.coordinate_actionability before a coordinate
  5. Use element_scroll_into_view.before, after, and scroll_method as the
  6. For an outer_only widget with ready top-level geometry, use physical
  7. Verify from the parent page after every consequential action. Prefer a

What it can do on your machine

Read from SKILL.md and the folder at commit 30e8adf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cross Origin Iframe Probe loads about 1.2k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 555 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 555 words (~1,189 tokens).

“Use this Skill for an authorized iframe workflow. Cross-origin is a security boundary, but it is not by itself proof that DrissionPage cannot inspect the frame document. Make the decision from current capability evidence instead of from the URL or…”

— opening of SKILL.md by jumodada, Custom licence
name
cross-origin-iframe-probe

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/cross-origin-iframe-probe of jumodada/Drissionpage-MCP-Server.

Open the folder on GitHubat commit 30e8adf

Compare with similar skills

Cross Origin Iframe Probe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cross Origin Iframe Probe compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cross Origin Iframe Probe this skilljumodada/Drissionpage-MCP-Server487—~1.2kAutomated safety check: PassCustom licence
MCP Server Builder with mcp-usemcp-use/mcp-use11k—~923Automated safety check: PassApache-2.0
Cao MCP Appsawslabs/cli-agent-orchestrator1.4k—~1.9kAutomated safety check: PassApache-2.0
Unbrowseunbrowse-ai/unbrowse780—~3.3kAutomated safety check: PassMIT
Glance TestDebugBase/glance156—~827Automated safety check: PassMIT
Lightpandalightpanda-io/agent-skill101—~6kAutomated safety check: PassApache-2.0

Similar skills

  • Builds, modifies, debugs, migrates and verifies TypeScript MCP servers and MCP Apps with the mcp-use framework, treating the installed package's types as the source of truth.

    11k GitHub stars~923 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Cao MCP Apps

    awslabs/cli-agent-orchestrator

    Official

    Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman).

    1.4k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Unbrowse

    unbrowse-ai/unbrowse

    Search and call websites through Unbrowse's hosted API or remote MCP, reuse indexed site tools, read pages, and learn missing routes in its cloud browser.

    780 GitHub stars~3.3k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Glance Test

    DebugBase/glance

    Run E2E browser tests on any web application using Glance MCP.

    156 GitHub stars~827 tokensUpdated 5 mo ago
    Testing & QAAuto-check passed
  • Lightpanda

    lightpanda-io/agent-skill

    Lightpanda browser, drop-in replacement for Chrome-based browsing in any AI agent - faster and lighter for tasks without graphical rendering like data retrieval.

    101 GitHub stars~6k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Githits Onboarding

    githits-com/githits-cli

    A skill your agent uses when the user asks to install, connect, configure, sign in to, sign up for, or start using GitHits.

    114 GitHub stars~3.5k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from jumodada/Drissionpage-MCP-Server

  • Turnstile Testing

    jumodada/Drissionpage-MCP-Server

    A skill your agent uses when testing an authorized Cloudflare Turnstile integration or operating an authorized production challenge with drissionpage-mcp.

    487 GitHub stars~1.7k tokensUpdated 25 days ago
    Auto-check passed
  • Xiaohongshu Content Research

    jumodada/Drissionpage-MCP-Server

    A skill your agent uses for authorized, read-only research on public Xiaohongshu content or the local Xiaohongshu-like playground fixture.

    487 GitHub stars~768 tokensUpdated 25 days ago
    Auto-check passed

Questions about Cross Origin Iframe Probe

What does Cross Origin Iframe Probe do?

A skill your agent uses when a drissionpage-mcp task targets an iframe such as a payment widget, challenge, SSO flow, or embedded checkout. Cross Origin Iframe Probe is an agent skill from jumodada/Drissionpage-MCP-Server. Use when a drissionpage-mcp task targets an iframe such as a payment widget, challenge, SSO flow, or embedded checkout.

When should I use Cross Origin Iframe Probe?

Cross Origin Iframe Probe fits situations like: A drissionpage-mcp task targets an iframe such as a payment widget; embedded checkout.

How do I install Cross Origin Iframe Probe in Claude Code?

Run `npx skills add jumodada/Drissionpage-MCP-Server --skill cross-origin-iframe-probe -a claude-code`. Or copy the skill folder (skills/cross-origin-iframe-probe in jumodada/Drissionpage-MCP-Server) into .claude/skills/cross-origin-iframe-probe in your project. Claude Code loads it when a task matches its description.

How do I install Cross Origin Iframe Probe in Codex?

Run `npx skills add jumodada/Drissionpage-MCP-Server --skill cross-origin-iframe-probe -a codex`. Or copy the skill folder (skills/cross-origin-iframe-probe in jumodada/Drissionpage-MCP-Server) into .agents/skills/cross-origin-iframe-probe in your project. Codex loads it when a task matches its description.

Can I use Cross Origin Iframe Probe in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jumodada/Drissionpage-MCP-Server --skill cross-origin-iframe-probe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cross-origin-iframe-probe, .gemini/skills/cross-origin-iframe-probe, .github/skills/cross-origin-iframe-probe and .opencode/skills/cross-origin-iframe-probe in your project.

What does Cross Origin Iframe Probe need to run?

SKILL.md names no scripts, command-line tools or credentials: Cross Origin Iframe Probe is instructions for the agent only.

Does Cross Origin Iframe Probe access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cross Origin Iframe Probe safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cross Origin Iframe Probe use?

Cross Origin Iframe Probe has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Cross Origin Iframe Probe use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cross Origin Iframe Probe?

Skills that share tags, products or a category with Cross Origin Iframe Probe: MCP Server Builder with mcp-use (mcp-use/mcp-use, 11k stars), Cao MCP Apps (awslabs/cli-agent-orchestrator, 1.4k stars), Unbrowse (unbrowse-ai/unbrowse, 780 stars) and Glance Test (DebugBase/glance, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cross Origin Iframe Probe?

jumodada (a GitHub user) maintains it in jumodada/Drissionpage-MCP-Server, which has 487 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 14, 2026.

Source: jumodada/Drissionpage-MCP-Server on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.