Agent skill

Sap Browser Automation

by secondsky in secondsky/sap-skills

A skill your agent uses when an agent must inspect or operate an authenticated SAP web UI through an in-app Browser, Microsoft Edge CDP, or an existing Playwright client, especially when SAP SSO…

GPL-3.0Auto-check passedProductivity & Automation

Install Sap Browser Automation

skills CLI
$ npx skills add secondsky/sap-skills --skill sap-browser-automation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/sap-skills sap-browser-automation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/sap-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/sap-browser-automation/skills/sap-browser-automation .claude/skills/sap-browser-automation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sap-browser-automation
GitHub stars
462
Token cost
~3.3k tokens
SKILL.md length
1,659 words
Files
12 (incl. scripts, references)
Skills in repo
41
Repo updated
First seen
Licence
GPL-3.0

At a glance

A skill your agent uses when an agent must inspect or operate an authenticated SAP web UI through an in-app Browser, Microsoft Edge CDP, or an existing Playwright client, especially when SAP SSO…

  • Works in 6 steps: Classify the task and choose a surface → Authenticate in the in-app Browser → Capture live Edge state, then bootstrap… → …
  • An agent must inspect
  • SKILL.md covers Related Skills, When to Use This Skill, Quick Reference and Requested browser and…, plus 5 more sections
  • Runs JavaScript and PowerShell scripts from its folder; calls codex

What it does

Sap Browser Automation is an agent skill from secondsky/sap-skills. Use when an agent must inspect or operate an authenticated SAP web UI through an in-app Browser, Microsoft Edge CDP, or an existing Playwright client, especially when SAP SSO reuse, isolated Edge profiles, deterministic target selection, screenshots, or browser bootstrap recovery is required.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts and reference files (for example `README.md`, `agents/openai.yaml` and `references/auth-state-bootstrap.md`).

It sits in Productivity & Automation, covering Browser automation, Authentication and Browser testing. It works with Playwright. The repository describes itself as: Production-ready plugins for SAP development with AI coding assistants — BTP, CAP, Fiori, ABAP, HANA, Analytics Cloud, Datasphere, and more. The licence is GPL-3.0.

When your agent uses it

  • An agent must inspect
  • Operate an authenticated SAP web UI through an in-app Browser
  • Microsoft Edge CDP
  • An existing Playwright client

Example prompts

  • “/sap-browser-automation”

Requirements

  • Node.js
  • PowerShell

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Classify the task and choose a surface
  2. Authenticate in the in-app Browser
  3. Capture live Edge state, then bootstrap fresh Edge
  4. Operate the verified target
  5. Verify readiness and perform the domain action
  6. Recover or hand off honestly

What it can do on your machine

Read from SKILL.md and the folder at commit 652a861. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (JavaScript and PowerShell), which the agent can run.

    Shell commands in SKILL.md call:

    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sap Browser Automation loads about 3.3k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 1,659 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from secondsky/sap-skills at commit 652a861, republished under its GPL-3.0 licence (© secondsky). 1,659 words, ~3,313 tokens.

Download SKILL.mdSave it as .claude/skills/sap-browser-automation/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
sap-browser-automation
description
Use when an agent must inspect or operate an authenticated SAP web UI through an in-app Browser, Microsoft Edge CDP, or an existing Playwright client, especially when SAP SSO reuse, isolated Edge profiles, deterministic target selection, screenshots, or browser bootstrap recovery is required.
license
GPL-3.0
metadata.maintainer
Eduard Jiglau
metadata.maintainer_email
hello@sap-ai-skills.com
metadata.website
https://sap-ai-skills.com
metadata.version
2.4.1
metadata.last_verified
2026-07-14
metadata.documentation_source
docs/project/sap-browser-automation-source-review-2026-07-14.md
metadata.status
docs_audited_runtime_pending
metadata.known_issues
In-app Browser authentication is desktop-runtime-dependent and its validation is deferred to Codex or Claude Desktop., SAC and Datasphere SSO, cross-domain…

SAP Browser Automation

Use this skill as the shared browser layer for SAP-specific skills. It owns surface selection, authentication bootstrap, isolated Edge/CDP startup, state reuse, target verification, evidence, recovery, and cleanup. The consuming skill still owns the SAP action boundaries: story edits, planning writeback, model changes, Datasphere deployment, SQL execution, and test acceptance.

  • sap-sac-scripting: SAC story/runtime scripting and reporting-story implementation.
  • sap-sac-test-automation: SAC acceptance, discovery packets, Playwright suites, and evidence.
  • sap-sac-planning: SAC planning models, writeback, versions, data actions, and locks.
  • sap-datasphere: Datasphere modeling, deployment, spaces, connections, and administration.
  • browser:control-in-app-browser: Installed in-app Browser runtime and secure manual authentication.

When to Use This Skill

Use this skill whenever an agent must interact with an authenticated SAP web UI, select or inspect a browser target, start Edge with loopback CDP, reuse an approved Edge profile, transfer scoped browser state to an already-installed compatible client, or recover from browser bootstrap/authentication failure. Do not use it for code-only, API-only, CLI-only, or database-native tasks that do not need visible browser state.

Quick Reference

NeedRoute
Manual SSO in the current browserIn-app Browser, then visible signed-in verification
Enterprise Edge or no Playwright installationFresh isolated Edge with copied profile and loopback CDP
Independent compatible browser contextExisting Playwright plus scoped storageState or CDP state transfer
Missing auth or failed browser bootstrapUser-assisted login, recovery, or specification-only handoff

Requested browser and connection are binding

If the user names Chrome, Edge, Chrome DevTools MCP, CDP, or a local DevTools bridge, use only that browser and connection method. Do not silently switch to the In-app Browser, a ChatGPT browser extension, Playwright, Computer Use, another browser, or shell automation. If the requested surface is not available, report the exact blocker and stop at that boundary.

Operating contract

  • Prefer a connector, API, CLI, or database-native check when it can answer the request without a browser.
  • Use the in-app Browser first only when the user has not named a different browser or connection method.
  • Ask the user to authenticate manually in the in-app Browser when its target redirects to SSO. Use its secure authentication capability; never ask for passwords or OTPs in chat.
  • After in-app verification, use the fresh Edge path for reliable automation when the task needs CDP, enterprise extensions, or a reusable profile.
  • Treat MCP configuration and MCP availability as separate checks. After configuration, verify that the server tools are present in the active tool registry. A successful codex mcp get check alone does not make the MCP usable.
  • Require a live handshake, such as list_pages, and verify that the returned pages belong to the requested browser. If the tools are missing after configuration, ask the user to restart Codex or open a new task before continuing.
  • Ask explicit permission before reusing the user's authenticated normal Edge profile or closing Edge.
  • Copy only after Edge is closed, and copy to an isolated profile path. Treat the copy, cookies, tokens, local storage, and storage-state files as credentials.
  • Bind CDP to 127.0.0.1; never expose the port, WebSocket endpoint, profile, or auth state to a network, repository, log, screenshot, or Oracle review.
  • Verify the tenant, host, path, title, authenticated DOM, and target page before interaction. Never guess the first tab or target ID.
  • Default to read-only actions. The consuming SAP skill must explicitly authorize writes, publishing, deployment, planning, model, permission, or destructive actions.
  • Browser startup, CDP attachment, or a successful login redirect is not evidence that the requested SAP task completed.

Load the focused references only when needed:

  • references/edge-cdp-control.md for Edge launch, CDP discovery, target selection, and recovery.
  • references/auth-state-bootstrap.md for copying an authenticated Edge profile, exporting scoped state when available, and injecting it into compatible clients.
  • references/in-app-browser-auth.md for manual in-app authentication and capability boundaries.
  • Run scripts/edge-profile.ps1 for deterministic profile cloning, launch, status, and stop operations.
  • Run scripts/cdp-agent.mjs for target discovery, inspection, interaction, screenshots, and authentication-state transfer. It requires Node.js 22 or newer and no npm packages.

Standard workflow

1. Classify the task and choose a surface

Record the target application, tenant/host, requested URL, read/write intent, evidence required, and whether the user approved profile reuse. Use this order:

  1. Existing non-browser tool if sufficient.
  2. The explicitly requested browser and connection method, after active-tool and live-handshake checks.
  3. In-app Browser for visible authenticated UI and manual SSO when no other browser or connection was requested.
  4. Fresh isolated Edge with loopback CDP for enterprise browser behavior and reusable authentication.
  5. Already-installed Playwright connected over CDP or using local storage state.
  6. Approved desktop/manual assistance or a specification-only handoff.

Do not install Playwright, browser binaries, MCP servers, or extensions in an enterprise environment unless the user explicitly requests and approves that change. If Playwright is unavailable, Edge/CDP remains the primary automation surface.

2. Authenticate in the in-app Browser

When no other browser or connection was requested, open the target using the installed Browser skill. Inspect visible state. If the page requires SSO, pause for the user to complete the login manually through the supported secure auth flow. Verify a positive signed-in signal on the target domain and retain a screenshot or equivalent evidence when allowed.

Do not extract cookies, local storage, session storage, profile databases, passwords, or tokens from the in-app Browser. Its session is independent from Edge. If it cannot expose an authenticated page after manual login, record the failure and continue to the approved Edge path.

This route runs inside Codex or Claude Desktop. Its runtime validation is deferred to those desktop environments and is not part of the standalone Edge/CDP acceptance tests.

Show full SKILL.md (748 more words)Show less
3. Capture live Edge state, then bootstrap fresh Edge

Before touching the user's normal Edge profile, state the intended scope and ask for confirmation:

I will capture the approved SAP session from the currently authenticated Edge target, close normal Edge, and clone its selected profile into an isolated automation directory. May I continue?

If the user declines, ask them to authenticate once in the isolated profile. If they approve:

  1. Identify the normal Edge user-data root, selected Default or Profile N, target URL, tenant host, target path/title, approved SAP origin, and local temporary state-file path.
  2. While normal Edge is still running and visibly authenticated, open edge://inspect/#remote-debugging and enable Allow remote debugging for this browser instance.
  3. Run scripts/cdp-agent.mjs export-auth against the normal user-data directory. Require host, path, and/or title filters that resolve exactly one approved page. Repeat --origin for approved SAP or identity-provider cookie scopes.
  4. Close normal Edge and verify no msedge.exe process still owns the source profile.
  5. Run scripts/edge-profile.ps1 -Action CloneLaunch with the selected profile name and a new or empty automation root. The helper preserves Profile N, refuses non-empty clone destinations, launches with --remote-debugging-port=0, and verifies the listener discovered through DevToolsActivePort.
  6. Run scripts/cdp-agent.mjs inspect and verify tenant, path, title, visible signed-in state, and page readiness.
  7. If cloning lost volatile state, run scripts/cdp-agent.mjs import-auth against the isolated target, reload, and repeat the authenticated-state inspection.
  8. If authentication still fails, ask the user to log in once in the isolated profile. Reuse it later with scripts/edge-profile.ps1 -Action LaunchExisting; never clone over a populated automation root.

The complete Windows commands, path checks, CDP probes, and recovery matrix are in references/edge-cdp-control.md and references/auth-state-bootstrap.md.

4. Operate the verified target

Use the isolated Edge instance directly. Run scripts/cdp-agent.mjs --help for the complete command surface. The bundled driver supports deterministic targets, inspection/snapshot, navigation, evaluation, selector or coordinate clicks, text entry, key presses, screenshots, and auth-state export/import without Playwright. Use an existing Playwright installation only when the consuming task needs it; do not install it for this workflow.

Authentication transfer uses CDP Storage.getCookies and Storage.setCookies plus page-scoped localStorage and sessionStorage. Recheck SSO redirects, SameSite behavior, certificates, and visible readiness after import. The in-app Browser remains a separate session.

5. Verify readiness and perform the domain action

Before changing anything, verify:

  • tenant and application identity;
  • authenticated state, not merely a non-login URL;
  • correct Story Designer, Modeler, Data Builder, SQL editor, or test target area;
  • visible readiness markers and absence of blocking errors;
  • approved host/path and selected target page;
  • current model/story/widget metadata when the consuming skill requires it.

Capture page-specific evidence and explicit no-data/error states. Do not treat a spinner disappearing, CDP connecting, or a browser window opening as task completion.

6. Recover or hand off honestly

Use the following fallback sequence:

  1. Retry the selected browser using its documented troubleshooting guidance.
  2. Use the Edge/CDP recovery and DevToolsActivePort fallback.
  3. Ask for one-time manual authentication in the isolated Edge profile.
  4. Use approved desktop/manual assistance if the environment supports it.
  5. If no authenticated target can be verified, stop and provide an implementation-ready specification, the exact missing evidence, and the next manual action.

When the user explicitly named a browser or connection method, do not use this sequence to switch to a different surface. Stop when the requested surface is unavailable or its live handshake fails.

Report authentication as verified, missing, expired, blocked, or unknown; never infer success from browser bootstrap alone.

Troubleshooting

Common failures are handled in the shared Edge reference: refused or missing CDP endpoints, 404 discovery responses, wrong targets, SSO redirects, copied profiles that are not authenticated, policy blocks, and runtime/widget errors. When recovery cannot establish a verified authenticated target, stop and hand off the missing evidence rather than guessing or claiming completion.

Sources and Verification

The public-source review and the distinction between documented behavior and unverified tenant behavior are recorded in docs/project/sap-browser-automation-source-review-2026-07-14.md.

Safety and evidence

Profile copies and auth-state files may contain cookies, refresh tokens, saved passwords, history, extensions, and enterprise session data. Keep them in a user-local path with restricted access. Do not place them under the repository, commit them, send them to Oracle, include them in bug reports, or paste their contents into chat. Redact tenant IDs, story IDs, query strings, session-like URL values, cookie values, WebSocket endpoints, and unrelated tabs from evidence.

For any write-capable action, record the approving user, target, intended mutation, before/after verification, and rollback or cleanup status. The consuming SAP skill remains authoritative for whether the action itself is allowed.

© secondsky, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (scripts, references) in plugins/sap-browser-automation/skills/sap-browser-automation of secondsky/sap-skills.

  • SKILL.md
  • README.md
  • agents/openai.yaml
  • references/auth-state-bootstrap.md
  • references/edge-cdp-control.md
  • references/in-app-browser-auth.md
  • scripts/cdp-agent.mjs
  • scripts/edge-profile.ps1
  • scripts/tests/cdp-agent.test.mjs
  • scripts/tests/edge-cdp.integration.test.mjs
  • scripts/tests/edge-profile.test.mjs
  • scripts/tests/skill-contract.test.mjs

Open the folder on GitHubat commit 652a861

Compare with similar skills

Sap Browser Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sap Browser Automation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sap Browser Automation this skillsecondsky/sap-skills462—~3.3kAutomated safety check: PassGPL-3.0
Browser UseQwenLM/qwen-code-examples143—~451Automated safety check: PassNone
Playwright Skilllackeyjb/playwright-skill3.2k—~1.9kAutomated safety check: PassMIT
Playwright Skilltech-leads-club/agent-skills7k—~3.6kAutomated safety check: PassCustom licence
Open BrowserJasonHonKL/Openbrowser114—~1.6kAutomated safety check: PassMIT
Playwright CLIfugazi/test-automation-skills-agents247—~2.2kAutomated safety check: PassMIT

Similar skills

  • Browser Use

    QwenLM/qwen-code-examples

    Control browser pages using the Playwright MCP server. An agent skill from QwenLM/qwen-code-examples.

    143 GitHub stars~451 tokensUpdated 4 mo ago
    Productivity & AutomationAuto-check passed
  • Playwright Skill

    lackeyjb/playwright-skill

    Complete browser automation with Playwright. An agent skill from lackeyjb/playwright-skill.

    3.2k GitHub stars~1.9k tokensUpdated 7 days ago
    Testing & QAAuto-check passed
  • Playwright Skill

    tech-leads-club/agent-skills

    Complete browser automation with Playwright. An agent skill from tech-leads-club/agent-skills.

    7k GitHub stars~3.6k tokensUpdated 18 days ago
    Testing & QAAuto-check passed
  • Open Browser

    JasonHonKL/Openbrowser

    A skill your agent uses whenever the task involves browsing web pages, extracting page content, clicking forms, or completing web workflows.

    114 GitHub stars~1.6k tokensUpdated 5 mo ago
    Testing & QAAuto-check passed
  • Playwright CLI

    fugazi/test-automation-skills-agents

    Drive a live browser from the CLI with playwright-cli to navigate, interact, snapshot, and capture evidence.

    247 GitHub stars~2.2k tokensUpdated 5 days ago
    Testing & QAAuto-check passed
  • Playwright

    magnus919/agent-skills

    Operate Playwright for browser automation end to end: author and debug E2E test suites (robust locators, network interception and mocking, parallel workers, accessibility snapshot checks), wire them…

    113 GitHub stars~3.4k tokensUpdated 2 days ago
    Testing & QAAuto-check: notes

More from secondsky/sap-skills

All 41 skills in this repo
  • Sap Rpt1

    secondsky/sap-skills

    SAP-RPT-1-OSS local tabular prediction workflows for FI/CO prototype datasets.

    462 GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check: notes
  • Dependency Upgrade

    secondsky/sap-skills

    Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout.

    462 GitHub stars~4.8k tokensUpdated 3 days ago
    Auto-check: warnings
  • Sap Abap

    secondsky/sap-skills

    Comprehensive ABAP development skill for SAP systems. An agent skill from secondsky/sap-skills.

    462 GitHub stars~3.9k tokensUpdated 3 days ago
    Auto-check passed
  • Sap Dependency Security

    secondsky/sap-skills

    SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection.

    462 GitHub stars~5.9k tokensUpdated 3 days ago
    Auto-check: warnings
  • Sap Abap Cds

    secondsky/sap-skills

    Comprehensive SAP ABAP CDS (Core Data Services) reference for data modeling, view development, and semantic enrichment.

    462 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • Sap AI Core

    secondsky/sap-skills

    Guides development with SAP AI Core and SAP AI Launchpad for enterprise AI/ML workloads on SAP BTP.

    462 GitHub stars~3.3k tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about Sap Browser Automation

What does Sap Browser Automation do?

A skill your agent uses when an agent must inspect or operate an authenticated SAP web UI through an in-app Browser, Microsoft Edge CDP, or an existing Playwright client, especially when SAP SSO…. Sap Browser Automation is an agent skill from secondsky/sap-skills. Use when an agent must inspect or operate an authenticated SAP web UI through an in-app Browser, Microsoft Edge CDP, or an existing Playwright client, especially when SAP SSO reuse, isolated Edge profiles, deterministic target selection, screenshots, or browser bootstrap recovery is required.

When should I use Sap Browser Automation?

Sap Browser Automation fits situations like: an agent must inspect; operate an authenticated SAP web UI through an in-app Browser; microsoft Edge CDP; an existing Playwright client.

How do I install Sap Browser Automation in Claude Code?

Run `npx skills add secondsky/sap-skills --skill sap-browser-automation -a claude-code`. Or copy the skill folder (plugins/sap-browser-automation/skills/sap-browser-automation in secondsky/sap-skills) into .claude/skills/sap-browser-automation in your project. Claude Code loads it when a task matches its description.

How do I install Sap Browser Automation in Codex?

Run `npx skills add secondsky/sap-skills --skill sap-browser-automation -a codex`. Or copy the skill folder (plugins/sap-browser-automation/skills/sap-browser-automation in secondsky/sap-skills) into .agents/skills/sap-browser-automation in your project. Codex loads it when a task matches its description.

Can I use Sap Browser Automation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/sap-skills --skill sap-browser-automation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sap-browser-automation, .gemini/skills/sap-browser-automation, .github/skills/sap-browser-automation and .opencode/skills/sap-browser-automation in your project.

What does Sap Browser Automation need to run?

Going by SKILL.md and its folder, Sap Browser Automation needs JavaScript and PowerShell for the scripts in its folder and the command-line tools its instructions call (codex). Our summary lists: Node.js; PowerShell.

Does Sap Browser Automation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sap Browser Automation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sap Browser Automation use?

Sap Browser Automation is published under the GPL-3.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sap Browser Automation use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to Sap Browser Automation?

Skills that share tags, products or a category with Sap Browser Automation: Browser Use (QwenLM/qwen-code-examples, 143 stars), Playwright Skill (lackeyjb/playwright-skill, 3.2k stars), Playwright Skill (tech-leads-club/agent-skills, 7k stars) and Open Browser (JasonHonKL/Openbrowser, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sap Browser Automation?

secondsky (a GitHub user) maintains it in secondsky/sap-skills, which has 462 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: secondsky/sap-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.