Camofox Browser
redf0x1/camofox-browser
Anti-detection browser automation for AI agents. An agent skill from redf0x1/camofox-browser.
Picks the right Skyvern CLI command for a web task, from quick yes/no checks to reusable multi-page workflows, instead of falling back to plain page fetching.
$ npx skills add Skyvern-AI/skyvern --skill skyvern -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Skyvern-AI/skyvern skyvern --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skyvern .claude/skills/skyvern && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "skyvern" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skills/skyvern into .claude/skills/skyvern/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skyvern", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Skyvern-AI/skyvern/tree/main/skills/skyvernType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Skyvern-AI/skyvern --skill skyvern -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Skyvern-AI/skyvern skyvern --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/skyvern .agents/skills/skyvern && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "skyvern" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skills/skyvern into .agents/skills/skyvern/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skyvern", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Skyvern-AI/skyvern --skill skyvern -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Skyvern-AI/skyvern skyvern --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/skyvern .cursor/skills/skyvern && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "skyvern" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skills/skyvern into .cursor/skills/skyvern/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skyvern", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Skyvern-AI/skyvern.git --path skills/skyvern--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Skyvern-AI/skyvern --skill skyvern -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Skyvern-AI/skyvern skyvern --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/skyvern .gemini/skills/skyvern && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "skyvern" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skills/skyvern into .gemini/skills/skyvern/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skyvern", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Skyvern-AI/skyvern skyvernInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Skyvern-AI/skyvern --skill skyvern -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/skyvern .github/skills/skyvern && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "skyvern" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skills/skyvern into .github/skills/skyvern/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skyvern", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Skyvern-AI/skyvern --skill skyvern -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Skyvern-AI/skyvern skyvern --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/skyvern .opencode/skills/skyvern && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "skyvern" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skills/skyvern into .opencode/skills/skyvern/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skyvern", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skyvernPicks the right Skyvern CLI command for a web task, from quick yes/no checks to reusable multi-page workflows, instead of falling back to plain page fetching.
Real websites are the target here, and the agent is told to run the Skyvern CLI through Bash because a plain page fetch cannot handle JavaScript-rendered content, login walls, pop-ups or interactive forms. Its first step is to classify the task, since each class maps to a different command and a different amount of model use.
A yes/no question goes to skyvern browser validate, reading page content goes to extract, a known selector goes to the deterministic click and type commands, a target described in words goes to act, a one-off exploratory attempt goes to run-task, and anything multi-page or recurring becomes a workflow built with workflow create and run. Decision rules push toward the cheapest command that fits, for example using primitives whenever a selector or XPath is supplied.
The folder carries many files, including reference notes on block types, credentials, pagination, prompt writing, common failures and rerunning, plus three example workflows for login and extract, multi-page forms and conditional retry. Separate guidance covers people who use the Skyvern MCP server instead of the CLI.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f5f3f28. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(skyvern:*)From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Skyvern Browser Automation loads about 2.9k tokens when it runs, and up to ~8.6k if it reads all its reference files. Until then it costs about 143 tokens; SKILL.md has 968 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Skyvern-AI/skyvern at commit f5f3f28, republished under its AGPL-3.0 licence (© Skyvern-AI). 968 words, ~2,916 tokens.
.claude/skills/skyvern/SKILL.md (or your agent's skills folder). This skill also uses 22 other files; get the full folder from GitHub.Skyvern uses AI to navigate and interact with websites. Every command below is a runnable skyvern <command> invocation.
| Classification | Signal | CLI Command | Cost | What Happens |
|---|---|---|---|---|
| Quick check (yes/no) | "is the user logged in?" | skyvern browser validate | 1 LLM + screenshots | Lightweight validation (2 steps max), returns boolean. Cheapest AI option. |
| Quick inspection | "what does the page show?" | skyvern browser extract | 1 LLM + screenshots | Dedicated extraction LLM + schema validation + caching. |
| Single action (known target) | "click #submit" | skyvern browser click/type | 0 LLM | Deterministic Playwright. No AI. Fastest. |
| Single action (unknown target) | "click the submit button" | skyvern browser act | 2-3 LLM, no screenshots | No screenshots in reasoning. Economy a11y tree. For visual targets, use hybrid mode (selector + intent). |
| Same-page multi-step | "fill the form and submit" | skyvern browser act or primitive chain | 2-3 LLM or 0 LLM | Use act when labels are clear. Use click/type/select directly when you know selectors. |
| Throwaway autonomous trial | "try this once", "see if this works" | skyvern browser run-task | Higher | One-off autonomous agent for exploration. Do not use for recurring or multi-page production automations. |
| Multi-page or reusable automation | "navigate a multi-page wizard", "set this up", "automate this weekly" | skyvern workflow create + run | N LLM + screenshots | Build a workflow with one block per step. Each block gets visual reasoning, verification, and reusable run history. |
MCP note: if you are using the Skyvern MCP instead of the CLI, prefer observe + execute for same-page multi-step UI work on stdio; refs persist across calls until the next observe, navigation, or page/document context change. On hosted stateless HTTP, prefer selector or intent params; prior-call refs do not resolve, and one execute batch can use refs only when predictable before the call, never adaptively from an inline observe. The CLI does not expose that pair directly.
act.validate -- not extract or act.act or a primitive chain.try this once, see if this works, or clearly wants a one-off exploratory trial, use run-task.set up as automation, use workflow create.skyvern browser login.Every browser command needs a session. Create one first:
# Cloud session (default -- works for public URLs)
skyvern browser session create --timeout 30
# Local session (for localhost URLs or self-hosted mode)
skyvern browser session create --local --timeout 30
# Connect to existing browser via CDP
skyvern browser session connect --cdp "ws://localhost:9222"Session state persists between commands. After session create, subsequent commands auto-attach.
Override with --session pbs_.... Close when done: skyvern browser session close.
skyvern browser validate --prompt "Is the user logged in? Look for a dashboard or avatar."Returns true/false. Cheapest AI option -- prefer over extract or act for boolean checks.
skyvern browser extract \
--prompt "Extract all product names and prices" \
--schema '{"type":"object","properties":{"items":{"type":"array","items":{"type":"object","properties":{"name":{"type":"string"},"price":{"type":"string"}}}}}}'Uses screenshots + dedicated extraction LLM. Better than screenshot+read because Skyvern's LLM interprets the page.
skyvern browser click --selector "#submit-btn"
skyvern browser type --text "user@co.com" --selector "#email"
skyvern browser select --value "US" --intent "the country dropdown"Deterministic. No AI. Three targeting modes:
--intent "the Submit button" (AI finds element)--selector "#submit-btn" (CSS/XPath, deterministic)skyvern browser act --prompt "Click the Sign In button"
skyvern browser act --prompt "Close the cookie banner, then click Sign In"Warning: act has NO screenshots in its LLM reasoning. It uses an economy accessibility tree. Fine for well-labeled elements. For visually complex targets, use MCP observe+execute on stdio (on hosted stateless HTTP prefer selector/intent) or hybrid mode.
skyvern browser act --prompt "Fill the shipping form and click Continue"Use act when the fields and buttons are clearly labeled and the flow stays on one page.
If you need tighter control, break the work into click, type, select, press-key, and wait.
skyvern browser run-task \
--url "https://example.com" \
--prompt "Check whether the checkout flow works end to end and extract the confirmation number"Use run-task to prove feasibility or do one-off exploration. If the task becomes important enough
to rerun, debug, or share, convert it to a workflow.
skyvern workflow create --definition @checkout-workflow.yaml
skyvern workflow run --id wpid_123 --wait
skyvern workflow status --run-id wr_789Each navigation block runs with visual reasoning + verification. Split complex flows into multiple blocks (one per page/step). First run uses AI; subsequent runs replay cached scripts.
skyvern workflow create --definition @workflow.yaml
skyvern workflow run --id wpid_123 --params '{"email":"user@co.com"}'
skyvern workflow status --run-id wr_789Split into one block per step. Use navigation blocks for actions, extraction for data.
First run uses AI; subsequent runs replay a cached script (10-100x faster).
Set --run-with agent to force AI mode for debugging.
Always verify after page-changing actions:
skyvern browser screenshot # visual check
skyvern browser validate --prompt "Was the form submitted successfully?" # boolean assertion
skyvern browser evaluate --expression "document.title" # JS state check| Problem | Fix |
|---|---|
| Action clicked wrong element | Add context to prompt. Use hybrid mode (selector + intent). |
| Extraction returns empty | Wait for content. Relax required fields. Check row count first. |
| Login passes but next step fails | Ensure same session. Add post-login validate check. |
| Element not found | Add wait: skyvern browser wait --selector "#el" --state visible |
| Overloaded prompt | Split into smaller goals -- one intent per command. |
NEVER type passwords through skyvern browser type or act. Always use stored credentials:
skyvern credentials add --name "my-login" --type password --username "user@co.com"
skyvern credential list # find the credential ID
skyvern browser login --url "https://login.example.com" --credential-id cred_123Types: password, credit_card, secret. Also supports bitwarden, 1password, and azure_vault providers.
skyvern workflow create --definition @workflow.yaml # create
skyvern workflow run --id wpid_123 --wait # run and wait
skyvern workflow status --run-id wr_789 # check status
skyvern workflow list --search "invoice" # find workflows
skyvern block schema --type navigation # discover block types
skyvern block validate --block-json @block.json # validate before creatingEngine: known path = 1.0 (default). Dynamic planning = 2.0. Split into multiple 1.0 blocks when in doubt.
Status lifecycle: created -> queued -> running -> completed | failed | canceled | terminated | timed_out
Login flow:
skyvern credential list # find credential ID
skyvern browser session create
skyvern browser navigate --url "https://login.example.com"
skyvern browser login --url "https://login.example.com" --credential-id cred_123
skyvern browser validate --prompt "Is the user logged in?"
skyvern browser screenshotPagination loop:
skyvern browser extract --prompt "Extract all rows"
skyvern browser validate --prompt "Is there a Next button that is not disabled?"
# If true:
skyvern browser act --prompt "Click the Next page button"
# Repeat extraction. Stop when: no next button, duplicate first row, or max page limit.Debugging:
skyvern browser screenshot # visual state
skyvern browser evaluate --expression "document.title"
skyvern browser evaluate --expression "document.querySelectorAll('table tr').length"All commands accept --json for structured output. Set SKYVERN_NON_INTERACTIVE=1 to prevent prompts.
Use skyvern capabilities --json for full command discovery. See references/agent-mode.md.
| Reference | Content |
|---|---|
references/prompt-writing.md | Prompt templates and anti-patterns |
references/engines.md | When to use tasks vs workflows |
references/schemas.md | JSON schema patterns for extraction |
references/pagination.md | Pagination strategy and guardrails |
references/block-types.md | Workflow block type details with examples |
references/parameters.md | Parameter design and variable usage |
references/ai-actions.md | AI action patterns and examples |
references/precision-actions.md | Intent-only, selector-only, hybrid modes |
references/credentials.md | Credential naming, lifecycle, safety |
references/sessions.md | Session reuse and freshness decisions |
references/common-failures.md | Failure pattern catalog with fixes |
references/screenshots.md | Screenshot-led debugging workflow |
references/status-lifecycle.md | Run status states and guidance |
references/rerun-playbook.md | Rerun procedures and comparison |
references/complex-inputs.md | Date pickers, uploads, dropdowns |
references/tool-map.md | Complete tool inventory by outcome |
references/cli-parity.md | CLI/MCP mapping and agent-aware features |
references/quick-start-patterns.md | Quick start examples, common patterns, and workflow templates |
© Skyvern-AI, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 22 other files (references) in skills/skyvern of Skyvern-AI/skyvern.
Open the folder on GitHubat commit f5f3f28
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Skyvern-AI/skyvern, which our catalogue first saw on October 7, 2026.
Skyvern Browser Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Skyvern Browser Automation this skillSkyvern-AI/skyvern | 23k | 1 repos | ~2.9k | Automated safety check: Pass | AGPL-3.0 | |
| Camofox Browserredf0x1/camofox-browser | 412 | — | ~4.6k | Automated safety check: Pass | MIT | |
| Playwright Bowserdisler/bowser | 265 | — | ~1.1k | Automated safety check: Notes | None | |
| Tiered Web Browsing and Scrapingcode-yeongyu/oh-my-openagent | 70k | — | ~2.7k | Automated safety check: Warn | Custom licence | |
| Browser Automationalirezarezvani/claude-skills | 28k | — | ~3.4k | Automated safety check: Notes | MIT | |
| Cloudflare Browser Renderingeinverne/dotfiles | 121 | — | ~4.9k | Automated safety check: Pass | GPL-3.0 |
redf0x1/camofox-browser
Anti-detection browser automation for AI agents. An agent skill from redf0x1/camofox-browser.
disler/bowser
Headless browser automation using Playwright CLI. An agent skill from disler/bowser.
code-yeongyu/oh-my-openagent
Routes a web request through the cheapest tier that can finish it, from headless extraction with WAF bypass up to a real stealth or signed-in browser, with screenshots as proof.
alirezarezvani/claude-skills
A skill your agent uses when the user asks to automate browser tasks, scrape websites, fill forms, capture screenshots, extract structured data from web pages, or build web automation workflows.
einverne/dotfiles
Guide for implementing Cloudflare Browser Rendering - a headless browser automation API for screenshots, PDFs, web scraping, and testing.
sundial-org/awesome-openclaw-skills
Spin up unblocked browser sessions via Browser.cash for web automation.
Skyvern-AI/skyvern
Walks through a Skyvern open-source release bump: update the version, rebuild the Python and TypeScript SDKs with Fern, commit, and open a pull request.
Skyvern-AI/skyvern
Automates websites with Skyvern's AI browser agent to fill forms, extract data, download files, log in and run multi-step workflows through SDKs, REST, MCP or a CLI.
Skyvern-AI/skyvern
Smoke-tests a Skyvern deployment by checking the backend API, frontend rendering, browser session provisioning and workflow execution in sequence.
Skyvern-AI/skyvern
Reads your git diff, writes a handful of happy-path browser smoke tests, runs them with Skyvern or Chrome DevTools MCP and posts screenshot evidence to the PR.
Skyvern-AI/skyvern
Reads your git diff, decides whether the change needs browser QA, API checks or repo tests, runs that validation and reports pass or fail with evidence.
Works with
Picks the right Skyvern CLI command for a web task, from quick yes/no checks to reusable multi-page workflows, instead of falling back to plain page fetching. Real websites are the target here, and the agent is told to run the Skyvern CLI through Bash because a plain page fetch cannot handle JavaScript-rendered content, login walls, pop-ups or interactive forms. Its first step is to classify the task, since each class maps to a different command and a different amount of model use.
Skyvern Browser Automation fits situations like: scraping a dynamic page that a plain fetch cannot render; filling out and submitting a web form automatically; logging into a site and extracting data behind the login; turning a repeated multi-page browser task into a reusable workflow.
Run `npx skills add Skyvern-AI/skyvern --skill skyvern -a claude-code`. Or copy the skill folder (skills/skyvern in Skyvern-AI/skyvern) into .claude/skills/skyvern in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Skyvern-AI/skyvern --skill skyvern -a codex`. Or copy the skill folder (skills/skyvern in Skyvern-AI/skyvern) into .agents/skills/skyvern in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Skyvern-AI/skyvern --skill skyvern -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skyvern, .gemini/skills/skyvern, .github/skills/skyvern and .opencode/skills/skyvern in your project.
SKILL.md names no scripts, command-line tools or credentials: Skyvern Browser Automation is instructions for the agent only. Our summary lists: The skyvern CLI, run through Bash. Its frontmatter pre-approves these tools: Bash(skyvern:*).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Skyvern Browser Automation is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Skyvern Browser Automation: Camofox Browser (redf0x1/camofox-browser, 412 stars), Playwright Bowser (disler/bowser, 265 stars), Tiered Web Browsing and Scraping (code-yeongyu/oh-my-openagent, 70k stars) and Browser Automation (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Skyvern-AI (a GitHub organization) maintains it in Skyvern-AI/skyvern, which has 23,172 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 10, 2026.
Source: Skyvern-AI/skyvern on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.