Agent skill

Agent Browser

by oxylabs in oxylabs/agent-skills

Connects to Oxylabs remote agent browsers over the Chrome DevTools Protocol (CDP) with Playwright or Puppeteer.

MITAuto-check passedProductivity & Automation

Install Agent Browser

skills CLI
$ npx skills add oxylabs/agent-skills --skill agent-browser -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install oxylabs/agent-skills agent-browser --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/oxylabs/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-browser .claude/skills/agent-browser && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-browser
GitHub stars
875
Token cost
~3k tokens
SKILL.md length
1,337 words
Files
7 (incl. scripts)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Connects to Oxylabs remote agent browsers over the Chrome DevTools Protocol (CDP) with Playwright or Puppeteer.

  • Works in 7 steps: Connect → Quick start → Sessions and limits → …
  • Tasks that involve Browser automation
  • SKILL.md covers 1. Connect, 2. Quick start, 3. Sessions and limits and 4. Errors, plus 3 more sections
  • Runs JavaScript and Python scripts from its folder; reaches hb.oxylabs.io and ip.oxylabs.io; needs OXY_UNBLOCKER_PASSWORD and OXY_HB_PASSWORD

What it does

Agent Browser is an agent skill from oxylabs/agent-skills. Connects to Oxylabs remote agent browsers over the Chrome DevTools Protocol (CDP) with Playwright or Puppeteer. Built-in anti-detection, residential proxies, geo-targeting, persistent sessions and profiles, session recording and live VNC inspection for debugging. Use instead of WebFetch or a local browser whenever a site renders with JavaScript, blocks bots (DataDome, Cloudflare, Akamai), needs a real browser session, screenshots or PDFs. Covers connection, retries, error recovery and safe scraping of protected…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `errors.md`, `examples.md` and `parameters.md`).

It sits in Productivity & Automation, covering Browser automation, Browser testing and Web scraping. It works with Playwright, Puppeteer, JavaScript and Cloudflare. The repository describes itself as: Official Agent skills of Oxylabs products. The licence is MIT.

When your agent uses it

  • Tasks that involve Browser automation
  • Tasks that involve Browser testing
  • Tasks that involve Web scraping

Example prompts

  • “Use the agent-browser skill to connect to Oxylabs remote agent browsers over the Chrome DevTools Protocol (CDP) with Playwright or Puppeteer”
  • “/agent-browser”

Requirements

  • Python 3
  • Node.js

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Connect
  2. Quick start
  3. Sessions and limits
  4. Errors
  5. Target safety (DataDome and similar)
  6. Operational hygiene
  7. Restricted targets

What it can do on your machine

Read from SKILL.md and the folder at commit a410198. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript and Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • hb.oxylabs.io
    • ip.oxylabs.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OXY_UNBLOCKER_PASSWORD
    • OXY_HB_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent Browser loads about 3k tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 1,337 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from oxylabs/agent-skills at commit a410198, republished under its MIT licence (© oxylabs). 1,337 words, ~3,028 tokens.

Download SKILL.mdSave it as .claude/skills/agent-browser/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
agent-browser
description
Connects to Oxylabs remote agent browsers over the Chrome DevTools Protocol (CDP) with Playwright or Puppeteer. Built-in anti-detection, residential proxies, geo-targeting, persistent sessions and profiles, session recording and live VNC inspection for debugging. Use instead of WebFetch or a local browser whenever a site renders with JavaScript, blocks bots (DataDome, Cloudflare, Akamai), needs a real browser session, screenshots or PDFs. Covers connection, retries, error recovery and safe scraping of protected targets without any human help.

Oxylabs Agent Browser

Remote Chrome sessions with anti-detection, proxy rotation and geo-targeting built in. Nothing runs locally: you connect over a WebSocket, drive the browser with the CDP library you already use, and close the session when done. This file holds the rules; the detail lives next to it: scripts/ (copyable templates), parameters.md, errors.md, examples.md, targets.md.

1. Connect

ItemValue
Endpointwss://USERNAME:PASSWORD@hb.oxylabs.io
CredentialsOXY_UNBLOCKER_USERNAME / OXY_UNBLOCKER_PASSWORD (aliases: OXY_HB_USERNAME / OXY_HB_PASSWORD)
OptionsURL query parameters only, e.g. ?p_cc=US&session_name=job-42 (see parameters.md)
LibrariesPlaywright chromium.connectOverCDP (recommended), Puppeteer puppeteer.connect, any CDP client
Dashboard / supporthttps://hb.oxylabs.io/dashboard · support@oxylabs.io

Rules that prevent the most common 401:

  • Use wss://. Plain ws:// is accepted but sends your password unencrypted.
  • Build the URL by string concatenation with the raw password. Do not pass the finished URL through new URL() or urllib.parse: they percent-encode the password and authentication fails.
  • Use the full username exactly as shown in the dashboard, including any suffix such as _ab12.
  • A password containing : cannot be sent in the URL. Ask for a new password or send the Authorization: Basic header yourself (see examples.md).
  • Authentication is checked before parameters: fix a 401 before looking at anything else.

2. Quick start

Minimal shape (Playwright, JavaScript):

javascript
const { chromium } = require("playwright");
const url = `wss://${process.env.OXY_UNBLOCKER_USERNAME}:${process.env.OXY_UNBLOCKER_PASSWORD}@hb.oxylabs.io?p_cc=US`;
const browser = await chromium.connectOverCDP(url, { timeout: 60000 });
try {
  const page = await browser.contexts()[0].newPage(); // default context: backed by fingerprint, proxy, o_profile
  await page.goto("https://example.com", { waitUntil: "domcontentloaded", timeout: 30000 });
  console.log(await page.content());
} finally {
  await browser.close(); // always: an unclosed session keeps its concurrency slot
}

For real work copy scripts/playwright_scrape.js or scripts/playwright_scrape.py whole instead of reimplementing. They add the five behaviours everything else in this file assumes:

  • Connect with backoff (1 s base, 60 s cap, jitter, 6 attempts) only on retryable errors: 429, 5xx, CDP_SESSION_IN_USE, CDP_NO_BROWSERS_AVAILABLE, CDP_BROWSER_OVERWORKED, CDP_BAD_PROXY, CDP_GENERAL_ERROR, timeouts. 400/401/403 mean the request is wrong: fix, never retry unchanged.
  • Redact the password from every error message before logging; Playwright embeds the connection URL in it.
  • Block image, stylesheet, media, font by default; they cost time and are not needed for data extraction.
  • Register listeners before navigating: the X-Error-Description response header marks an Oxylabs-side error on page traffic.
  • browser.close() in finally, and wrap the job in an overall deadline so a wedged session still gets there.

Puppeteer, Python async, raw CDP, session hand-over, profiles, recording and fan-out: examples.md.

3. Sessions and limits

Limit (account defaults)ValueWhen exceeded
New sessions per second10429 CDP_SESSION_RATE_LIMIT_REACHED (space launches >= 150 ms)
Concurrent sessions100429 CDP_MAX_CONCURRENT_SESSIONS_REACHED
Named (resumable) sessions5429 CDP_MAX_PERSISTENT_SESSIONS_REACHED
Stored profiles (o_profile)5403 profile limit reached (5 profiles maximum)
Recordings10403 recording limit reached (10 recordings maximum)
Concurrent inspection viewers10CDP_VNC_MAX_CONCURRENT_SESSIONS_REACHED
  • session_name (^[A-Za-z0-9-]{3,36}$) makes a session resumable for 10 minutes after disconnect. keep_alive is implied by it; never send keep_alive=true alone (400 keep_alive requires session_name).
  • Reconnecting while the old connection is still attached returns 429 CDP_SESSION_IN_USE: close it first.
  • Any session lives at most 1 hour. Plan long jobs as several sessions.
  • An abandoned session keeps its concurrency slot (about 20 s, or the full 10 min when named) and surfaces later as an unrelated 429 CDP_MAX_CONCURRENT_SESSIONS_REACHED. Closing the Playwright/Puppeteer object is enough.
  • browser.close() wipes open pages and cookies even though a named session stays resumable. To hand a session over use Puppeteer browser.disconnect() (see examples.md, "Resume a named session"). State that must outlive a session (logins, clearance cookies) belongs in o_profile, not keep-alive.
  • Every distinct parameter combination is provisioned separately: keep the set stable across a job.
  • Under load a connection may queue and end with 503 queue timeout after about a minute: back off and retry. Higher limits via support.

4. Errors

Three channels. Handshake: HTTP status plus a short body (Playwright: WebSocket error: <URL with password> <status> then the body; Puppeteer: Unexpected server response: <status>). Post-connect: the WebSocket closes with code 3000 and a CDP_* reason that only raw clients see; Playwright/Puppeteer just report Target closed, so treat any disconnect in the first seconds of a session as retryable. In-page: CDP error 1337 for one refused command. On page traffic, a response with X-Error-Description is an Oxylabs network error (retry); a block page without it is the target's decision (change approach, do not retry).

text
connect failed?
  ├─ 401 ............ fix credentials/scheme, do not retry
  ├─ 400/403/409 .... fix the named parameter, do not retry unchanged (409: wait 30 s+ for the other session)
  ├─ 429 ............ backoff; if MAX_CONCURRENT: hunt for unclosed sessions
  └─ 5xx/503 ........ backoff, up to ~2 min total
session dropped (close 3000)?
  └─ new session with backoff; rotate sticky id on CDP_BAD_PROXY
navigate failed with 1337 Invalid target?
  └─ stop; restricted target (section 7)
page shows block / 403 wall?
  ├─ X-Error-Description present .... Oxylabs network issue: backoff + retry
  └─ absent ......................... target decision: change identity, geo, device, pacing (section 5)

Every message text with cause and fix: errors.md.

Show full SKILL.md (687 more words)Show less

5. Target safety (DataDome and similar)

Default parameter set for most jobs: p_cc, nothing else. Every session already gets a fresh fingerprint and a fresh residential IP, which is what one-shot fetches and fan-outs of independent pages need. Sticky IPs and stored profiles are opt-in tools for a specific need, never a baseline.

Work order for a protected target. First write a plain script and make it pass: one fresh session per page, the right geo and device, human pacing, then the escalation ladder below. Only when that script still fails after the ladder do you recommend persistent profiles to the user (the setup/consumer pattern below, with why it should help and what it costs: a setup step, the profile cap of 5) and implement them only on their go-ahead. Never add a profile or sticky id on your own initiative.

NeedAddNot for
Several connections must look like one visitor (login, cart, a flow that outlives one session)proxy_resi_ses_id + proxy_resi_ses_timeone page per session
Cookies or a login must survive between jobs (DataDome clearance, authenticated scraping)o_profile, prepared once by a setup run, after the user agreeda first attempt; targets that serve without a block
Resume the same browser within 10 minutessession_nameeverything else

When you do use them, the combination is one identity. Keep it consistent:

text
setup, exactly once :  ?o_profile=acme-us-01&o_profile_save=true&p_cc=US&proxy_resi_ses_id=acmeus01&proxy_resi_ses_time=30
consumers, any number:  ?o_profile=acme-us-01&p_cc=US&proxy_resi_ses_id=acmeus01&proxy_resi_ses_time=30
  • A profile is written by one run and read by the others. The setup run is the only connection that ever sends o_profile_save=true: it earns the cookies (clears the entry page, logs in), verifies the page, closes. Consumer runs send o_profile=<name> alone: read-only, no write lock, no 409. Never "top up" a profile from a consumer; when it stops working, run setup again under a new name. In production this is a setup service that prepares and validates profiles and a consumer service that only uses them (examples.md, "Profile setup and consumer runs").
  • proxy_resi_ses_id + proxy_resi_ses_time pin the exit IP (max 1440 min). A pinned id disables automatic proxy retry: on CDP_BAD_PROXY rotate to a new id.
  • Never change p_cc/p_city/p_state for an identity that has cookies. Start a new profile and sticky id.
  • Match interaction to p_device: mobile = taps, small scrolls, no hover; desktop (default) = the opposite. Never set viewport or device metrics yourself; the service owns the fingerprint.
  • Pace like a person: 3 to 8 s between page loads, scroll before clicking, one page at a time per identity. Run parallel identities, not parallel tabs.
  • Escalation when blocked, one rung per fresh connection: fresh session → broader geo (drop p_city) → p_device=mobile → slow down → inspect (section 6) → recommend persistent profiles to the user → stop and report. Repeating an identical request is never a rung.

Block signatures per vendor, do/don't table and starting values for a new protected target: targets.md.

6. Operational hygiene

  • Debugging. Two tools exist, and whenever the user asks how to debug, what the browser is doing, or why a run fails, tell them about both: live inspection (fetch the session id with the CDP command __session_id, open https://hb.oxylabs.io/novnc/?id=<id> and watch the session as it runs) and recordings (record=true& record_name=<job> saves a video of the session to replay later in https://hb.oxylabs.io/dashboard; cap 10, delete old ones there). Both are off by default. Use them yourself after 3 consecutive failures on one target to confirm what the page actually shows. Snippet in examples.md, "Session id, live inspection and recording".
  • Timeouts. Connect 60 s, navigation 30 s, plus an overall job deadline.
  • Logging. Never log the connection URL or a raw error message; log the parameter set and session id.
  • Contexts. Use browser.contexts()[0]. A newContext() is isolated from profile storage and fingerprint tuning.

7. Restricted targets

Blocked by default; access requires a short KYC via your account manager: entertainment and streaming, banking and finance, government sites, gaming platforms, ticketing, webmail, ad networks, third-party IP checkers. Use https://ip.oxylabs.io/location to verify your exit IP and geo. A blocked target fails Page.navigate with CDP error 1337 Invalid target.

See also: scripts/ (full Playwright templates, JS and Python), parameters.md (every parameter and its validation), errors.md (every message), examples.md (Puppeteer, Python async, raw CDP, reconnection, profiles, recording, fan-out), targets.md (block detection, DataDome playbook).

© oxylabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts) in skills/agent-browser of oxylabs/agent-skills.

  • SKILL.md
  • errors.md
  • examples.md
  • parameters.md
  • scripts/playwright_scrape.js
  • scripts/playwright_scrape.py
  • targets.md

Open the folder on GitHubat commit a410198

Compare with similar skills

Agent Browser next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Browser compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Browser this skilloxylabs/agent-skills875—~3kAutomated safety check: PassMIT
Cloudflare Browser Renderingeinverne/dotfiles121—~4.9kAutomated safety check: PassGPL-3.0
Chrome Devtoolseinverne/dotfiles1212 repos~1.6kAutomated safety check: NotesApache-2.0
Cloudflare Browser Renderingsecondsky/claude-skills227—~4kAutomated safety check: PassMIT
Browserjulianromli/opencode-template144—~475Automated safety check: PassNone
Browser Automationdavila7/claude-code-templates32k3 repos~569Automated safety check: PassMIT

Similar skills

  • Guide for implementing Cloudflare Browser Rendering - a headless browser automation API for screenshots, PDFs, web scraping, and testing.

    121 GitHub stars~4.9k tokensUpdated 29 days ago
    Productivity & AutomationAuto-check passed
  • Chrome Devtools

    einverne/dotfiles

    Browser automation, debugging, and performance analysis using Puppeteer CLI scripts.

    121 GitHub starsUsed in 2 repos~1.6k tokens
    Data & AnalyticsAuto-check: notes
  • Cloudflare Browser Rendering

    secondsky/claude-skills

    Cloudflare Browser Rendering with Puppeteer/Playwright. An agent skill from secondsky/claude-skills.

    227 GitHub stars~4k tokensUpdated 10 days ago
    Testing & QAAuto-check passed
  • Browser

    julianromli/opencode-template

    Minimal Chrome DevTools Protocol tools for browser automation and scraping.

    144 GitHub stars~475 tokensUpdated 8 mo ago
    Productivity & AutomationAuto-check passed
  • Browser Automation

    davila7/claude-code-templates

    Browser automation powers web testing, scraping, and AI agent interactions.

    32k GitHub starsUsed in 3 repos~569 tokens
    Productivity & AutomationAuto-check passed
  • Browser Automation

    ynulihao/AgentSkillOS

    Non-testing browser automation - web scraping, form filling, screenshot capture, PDF generation, workflow automation.

    617 GitHub stars~2.2k tokensUpdated 7 mo ago
    Productivity & AutomationAuto-check passed

More from oxylabs/agent-skills

  • Proxies

    oxylabs/agent-skills

    Oxylabs proxy networks: Residential, Mobile, shared Datacenter/ISP, and Dedicated Datacenter/ISP proxies with geo-targeting, IP rotation, session persistence, and port-based sticky IPs.

    875 GitHub stars~1.7k tokensUpdated 7 days ago
    Auto-check passed
  • Video Data

    oxylabs/agent-skills

    YouTube data extraction API and high-bandwidth proxy downloads.

    875 GitHub stars~1.4k tokensUpdated 7 days ago
    Auto-check passed
  • Web Scraper API

    oxylabs/agent-skills

    Production-grade web scraping with automatic anti-bot bypass, structured JSON parsing for 40+ targets, and geo-targeting.

    875 GitHub stars~1.5k tokensUpdated 7 days ago
    Auto-check passed
  • Web Unblocker

    oxylabs/agent-skills

    Bypasses anti-bot protections using Oxylabs Web Unblocker, an AI-powered proxy that handles fingerprinting, JavaScript rendering, and retries automatically.

    875 GitHub stars~865 tokensUpdated 7 days ago
    Auto-check passed

Questions about Agent Browser

What does Agent Browser do?

Connects to Oxylabs remote agent browsers over the Chrome DevTools Protocol (CDP) with Playwright or Puppeteer. Agent Browser is an agent skill from oxylabs/agent-skills. Connects to Oxylabs remote agent browsers over the Chrome DevTools Protocol (CDP) with Playwright or Puppeteer.

When should I use Agent Browser?

Agent Browser fits situations like: tasks that involve Browser automation; tasks that involve Browser testing; tasks that involve Web scraping.

How do I install Agent Browser in Claude Code?

Run `npx skills add oxylabs/agent-skills --skill agent-browser -a claude-code`. Or copy the skill folder (skills/agent-browser in oxylabs/agent-skills) into .claude/skills/agent-browser in your project. Claude Code loads it when a task matches its description.

How do I install Agent Browser in Codex?

Run `npx skills add oxylabs/agent-skills --skill agent-browser -a codex`. Or copy the skill folder (skills/agent-browser in oxylabs/agent-skills) into .agents/skills/agent-browser in your project. Codex loads it when a task matches its description.

Can I use Agent Browser in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add oxylabs/agent-skills --skill agent-browser -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-browser, .gemini/skills/agent-browser, .github/skills/agent-browser and .opencode/skills/agent-browser in your project.

What does Agent Browser need to run?

Going by SKILL.md and its folder, Agent Browser needs JavaScript and Python for the scripts in its folder and credentials named OXY_UNBLOCKER_PASSWORD and OXY_HB_PASSWORD. Our summary lists: Python 3; Node.js.

Does Agent Browser access the network?

SKILL.md names 2 domains. In commands or code: hb.oxylabs.io and ip.oxylabs.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Agent Browser safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Agent Browser use?

Agent Browser is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Browser use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Browser?

Skills that share tags, products or a category with Agent Browser: Cloudflare Browser Rendering (einverne/dotfiles, 121 stars), Chrome Devtools (einverne/dotfiles, 121 stars), Cloudflare Browser Rendering (secondsky/claude-skills, 227 stars) and Browser (julianromli/opencode-template, 144 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Browser?

oxylabs (a GitHub organization) maintains it in oxylabs/agent-skills, which has 875 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 30, 2026.

Source: oxylabs/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.