Agent skill

Tools And Actions

by VectorSpaceLab in VectorSpaceLab/AREX-Skill

Build and debug Browser Use tools/actions: custom Tools/Controller actions, default browser/file actions, ActionResult returns, parameter injection, sensitive data, security guardrails, and…

MITAuto-check passedAI & LLM Engineering

Install Tools And Actions

skills CLI
$ npx skills add VectorSpaceLab/AREX-Skill --skill tools-and-actions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install VectorSpaceLab/AREX-Skill tools-and-actions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/VectorSpaceLab/AREX-Skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/repositories/repo-skills/browser-use/sub-skills/tools-and-actions .claude/skills/tools-and-actions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tools-and-actions
GitHub stars
331
Token cost
~2.1k tokens
SKILL.md length
818 words
Files
6 (incl. scripts, references)
Skills in repo
157
Repo updated
First seen
Licence
MIT

At a glance

Build and debug Browser Use tools/actions: custom Tools/Controller actions, default browser/file actions, ActionResult returns, parameter injection, sensitive data, security guardrails, and…

  • Tasks that involve Browser automation
  • SKILL.md covers Route Here, Route Elsewhere, Safe Defaults and Minimal Custom Tool, plus 6 more sections
  • Runs Python scripts from its folder; calls python and uv
  • Tasks that involve LLM guardrails

What it does

Tools And Actions is an agent skill from VectorSpaceLab/AREX-Skill. Build and debug Browser Use tools/actions: custom Tools/Controller actions, default browser/file actions, ActionResult returns, parameter injection, sensitive data, security guardrails, and validation.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/custom-tools.md`, `references/default-actions.md` and `references/security-and-files.md`).

It sits in AI & LLM Engineering, covering Browser automation and LLM guardrails. The repository describes itself as: A Skill Library for Automated Machine Learning. The licence is MIT.

When your agent uses it

  • Tasks that involve Browser automation
  • Tasks that involve LLM guardrails

Example prompts

  • “/tools-and-actions”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit ac3fe1a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tools And Actions loads about 2.1k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 818 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from VectorSpaceLab/AREX-Skill at commit ac3fe1a, republished under its MIT licence (© VectorSpaceLab). 818 words, ~2,144 tokens.

Download SKILL.mdSave it as .claude/skills/tools-and-actions/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
tools-and-actions
description
Build and debug Browser Use tools/actions: custom Tools/Controller actions, default browser/file actions, ActionResult returns, parameter injection, sensitive data, security guardrails, and validation.
disable-model-invocation
true
metadata.disco-role
operating
license
MIT

Tools and Actions

Use this sub-skill when the user needs Browser Use actions, custom tools, file operations, upload/download handling, sensitive data placeholders, or action validation. Prefer ChatBrowserUse in examples unless the user already chose another model.

Route Here

  • User asks to add @tools.action(...), Tools(), Controller, custom actions, action filters, 2FA helpers, human-in-the-loop actions, deterministic browser helpers, or direct tools.<action>() calls.
  • User asks which default actions exist, how to remove actions, or why an action schema/model is rejected.
  • User asks about ActionResult, extracted_content, long_term_memory, error, is_done, success, attachments/images, or completion semantics.
  • User asks about available_file_paths, write_file, read_file, replace_file, upload_file, downloaded files, or file containment errors.
  • User asks how sensitive_data works, how to use <secret>name</secret>, or how to keep secrets scoped to allowed domains.
  • User hit tool validation, parameter injection, domain filter, file upload, or security guardrail failures.

Route Elsewhere

  • Agent construction, task prompting, run loops, history inspection, callbacks, initial actions, or Python workflow structure: ../agent-programming/SKILL.md.
  • Browser/Profile/CDP/session/proxy/download directory/domain navigation configuration: ../browser-control/SKILL.md.
  • LLM adapters, structured output models, extraction LLMs, cost, fallback models, or provider credentials: ../llm-and-output/SKILL.md.
  • Terminal browser-use / bu CLI sessions and CLI upload commands: ../cli-and-sessions/SKILL.md.
  • Cloud/sandbox/MCP/skills/telemetry/production integrations: ../production-integrations/SKILL.md.

Safe Defaults

  • Import Tools, ActionResult, and BrowserSession from browser_use; Controller is a backwards-compatible alias for Tools.
  • Use Pydantic v2 models for complex custom action input; keep action function parameters explicit and typed.
  • Name injected browser parameters exactly browser_session, page_extraction_llm, file_system, available_file_paths, page_url, cdp_client, has_sensitive_data, extraction_schema, or context.
  • Do not define **kwargs on a custom action; the registry rejects it. Use explicit parameters or a Pydantic param_model.
  • Return ActionResult when the agent needs reasoning context, memory, errors, completion status, files, or attachments; simple strings are accepted but less expressive.
  • Scope dangerous or credentialed custom actions with allowed_domains=[...] when possible.
  • Use Tools(exclude_actions=[...]) or tools.exclude_action(name) to remove defaults that do not fit the task.
  • Pass user-provided upload files through Agent(..., available_file_paths=[...]); never invent local paths.
  • Use sensitive_data placeholders instead of embedding passwords or API keys in tasks.

Minimal Custom Tool

python
from browser_use import ActionResult, Agent, BrowserSession, ChatBrowserUse, Tools

tools = Tools()

@tools.action('Ask the user for a one-line confirmation')
async def ask_user(question: str) -> ActionResult:
    answer = input(f'{question} > ')
    return ActionResult(extracted_content=f'User answered: {answer}')

agent = Agent(task='Ask for confirmation, then continue', llm=ChatBrowserUse(), tools=tools)

For browser-aware actions, use the exact injected name:

python
@tools.action('Read current page URL')
async def current_url(browser_session: BrowserSession) -> ActionResult:
    url = await browser_session.get_current_page_url()
    return ActionResult(extracted_content=url, long_term_memory=f'Current URL: {url}')

Custom Action Patterns

  • Loose parameters: async def fill_field(index: int, text: str, browser_session: BrowserSession); Browser Use auto-generates a Pydantic model for non-special parameters.
  • Pydantic model first: define a model and pass param_model=MyParams, then write async def action(params: MyParams, browser_session: BrowserSession).
  • Domain-filtered action: @tools.action('Use only on billing pages', allowed_domains=['https://billing.example.com']).
  • Sequence-ending action: pass terminates_sequence=True for navigation-like actions where queued multi-actions should stop after execution.
  • Direct call in tests/debugging: many registered actions can be called as await tools.read_file(file_name='x.md', browser_session=session, file_system=fs, available_file_paths=[]).

See references/custom-tools.md for full patterns and validation rules.

Default Actions

Core defaults include:

  • Navigation and tabs: search, navigate, go_back, wait, switch, close.
  • Page interaction: click, input, upload_file, scroll, find_text, send_keys, dropdown actions.
  • Page content: extract, search_page, find_elements, evaluate, screenshot, save_pdf.
  • File operations: write_file, read_file, replace_file.
  • Completion: done or structured done when output_model is configured.

See references/default-actions.md for action parameters, when to exclude defaults, JavaScript evaluation cautions, and file-action behavior.

Show full SKILL.md (341 more words)Show less

File and Secret Guardrails

  • write_file supports text/document outputs such as .txt, .md, .json, .jsonl, .csv, .html, .xml, .pdf, and .docx; it rejects binary/image extensions such as .png and .jpg.
  • replace_file requires exact old_str; read the file first when unsure.
  • read_file can read managed files and user/downloaded files from available_file_paths; large content is summarized in memory but full content is returned for the current step.
  • upload_file accepts paths from available_file_paths, Browser Use downloads, remote-browser paths, or managed FileSystem files; local uploads are checked for existence and nonzero size.
  • Sensitive values are provided as sensitive_data and referenced as <secret>key</secret>; domain-specific secrets are only exposed on matching URLs.
  • Pair sensitive_data with Browser(..., allowed_domains=[...]) for prompt-injection resistance.

See references/security-and-files.md for guardrail details and examples.

Validate Before Shipping

Run the bundled helper after editing tool code or snippets:

bash
python skills/disco/browser-use/sub-skills/tools-and-actions/scripts/validate_custom_tool.py

The helper checks imports, registry schema generation, injected parameter names, validation errors, domain filtering, and ActionResult normalization without launching a browser or making network calls.

Troubleshooting First Moves

  • Import failure: verify package install and use uv pip install browser-use; install Chromium separately when the task needs a live browser.
  • requires browser_session but none provided: use the tool through Agent(..., tools=tools) or pass browser_session in direct tests.
  • conflicts with special argument: rename the parameter or use the required special type, usually BrowserSession.
  • Invalid parameters: inspect the generated Pydantic schema or run validate_custom_tool.py.
  • File upload unavailable: add the path to available_file_paths or write/read through the managed file system first.
  • Secrets not substituted: confirm placeholder spelling, non-empty values, matching domain pattern, and allowed_domains coverage.
  • CDP/browser action timeout: retry, restart the browser/session, or route session setup to ../browser-control/SKILL.md.

See references/troubleshooting.md for symptom-to-fix tables.

Hard Case Prompts This Sub-skill Should Handle

  • Build an authenticated data-entry agent with domain-scoped secrets, a custom 2FA action, file upload from available_file_paths, and structured status messages; route browser profile setup to ../browser-control/SKILL.md and output schema setup to ../llm-and-output/SKILL.md.
  • Debug a failing custom action that uses browser instead of browser_session, has **kwargs, tries to upload ../note.md, and leaks a password in history; produce safe corrected code and validation steps.

© VectorSpaceLab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/repositories/repo-skills/browser-use/sub-skills/tools-and-actions of VectorSpaceLab/AREX-Skill.

  • SKILL.md
  • references/custom-tools.md
  • references/default-actions.md
  • references/security-and-files.md
  • references/troubleshooting.md
  • scripts/validate_custom_tool.py

Open the folder on GitHubat commit ac3fe1a

Compare with similar skills

Tools And Actions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tools And Actions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tools And Actions this skillVectorSpaceLab/AREX-Skill331—~2.1kAutomated safety check: PassMIT
Fable Modemrtooher/fable-mode873—~1kAutomated safety check: PassNone
Browser Toolsyonatangross/orchestkit292—~6.1kAutomated safety check: PassMIT
Aisafetyhotwuyoscar/AISafetyHot-Hub708—~1.4kAutomated safety check: PassCustom licence
ObliteratusRedWoodOG/Hermes-Desktop1775 repos~3.8kAutomated safety check: PassMIT
Lemonade Router Builderamd/skills408—~4kAutomated safety check: PassMIT

Similar skills

  • Fable Mode

    mrtooher/fable-mode

    Enforces staged execution discipline on large tasks: a written stage plan, delegation to named fable agents where the runtime supports it, a failable verification check at each stage, and a…

    873 GitHub stars~1k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Browser Tools

    yonatangross/orchestkit

    Security wrapper over the upstream agent-browser skill, adding URL blocklisting, rate limiting, robots.txt enforcement, and scraping guardrails.

    292 GitHub stars~6.1k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Aisafetyhot

    wuyoscar/AISafetyHot-Hub

    Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.

    708 GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Obliteratus

    RedWoodOG/Hermes-Desktop

    Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…

    177 GitHub starsUsed in 5 repos~3.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Turns a natural-language description of routing intent into a valid Lemonade collection.router policy JSON.

    408 GitHub stars~4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Execution Guardrails

    mrtooher/fable-mode

    Always-on operational guardrails, model-independent. An agent skill from mrtooher/fable-mode.

    873 GitHub stars~1k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed

More from VectorSpaceLab/AREX-Skill

All 157 skills in this repo
  • Agent Lightning

    VectorSpaceLab/AREX-Skill

    Use this repo skill for Agent Lightning package tasks: authoring trainable agents, tracing rewards and spans, running LightningStore/Trainer loops, using agl CLI services, choosing examples, and…

    331 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Agent Tools

    VectorSpaceLab/AREX-Skill

    A skill your agent uses when configuring LiteLLM for MCP tools, A2A agents, Claude Code/Cursor agent gateway traffic, MCP auth/OAuth, tool permissions, semantic filtering, or agent-specific proxy…

    331 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Agents And Awel

    VectorSpaceLab/AREX-Skill

    Build and debug DB-GPT agents, tools, skills, teams, and AWEL workflows, including deterministic local DAG runs and HTTP-trigger topology without assuming an LLM, credential, or external service.

    331 GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Agents And Middleware

    VectorSpaceLab/AREX-Skill

    Work on the actively maintained LangChain v1 agent package: initchatmodel, createagent, structured output, tools, middleware, embeddings initialization, provider routing, and agent runtime…

    331 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Agents Workflows

    VectorSpaceLab/AREX-Skill

    A skill your agent uses for giskard.agents async chat workflows, tools, prompt templates, structured outputs, retries, rate limiting, embeddings, and optional LiteLLM backend.

    331 GitHub stars~500 tokensUpdated 1 mo ago
    Auto-check passed
  • Alphafold3

    VectorSpaceLab/AREX-Skill

    A skill your agent uses for AlphaFold 3 input preparation, prediction command planning, output interpretation, and Python API inspection.

    331 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Tools And Actions

What does Tools And Actions do?

Build and debug Browser Use tools/actions: custom Tools/Controller actions, default browser/file actions, ActionResult returns, parameter injection, sensitive data, security guardrails, and…. Tools And Actions is an agent skill from VectorSpaceLab/AREX-Skill. Build and debug Browser Use tools/actions: custom Tools/Controller actions, default browser/file actions, ActionResult returns, parameter injection, sensitive data, security guardrails, and validation.

When should I use Tools And Actions?

Tools And Actions fits situations like: tasks that involve Browser automation; tasks that involve LLM guardrails.

How do I install Tools And Actions in Claude Code?

Run `npx skills add VectorSpaceLab/AREX-Skill --skill tools-and-actions -a claude-code`. Or copy the skill folder (skills/repositories/repo-skills/browser-use/sub-skills/tools-and-actions in VectorSpaceLab/AREX-Skill) into .claude/skills/tools-and-actions in your project. Claude Code loads it when a task matches its description.

How do I install Tools And Actions in Codex?

Run `npx skills add VectorSpaceLab/AREX-Skill --skill tools-and-actions -a codex`. Or copy the skill folder (skills/repositories/repo-skills/browser-use/sub-skills/tools-and-actions in VectorSpaceLab/AREX-Skill) into .agents/skills/tools-and-actions in your project. Codex loads it when a task matches its description.

Can I use Tools And Actions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VectorSpaceLab/AREX-Skill --skill tools-and-actions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tools-and-actions, .gemini/skills/tools-and-actions, .github/skills/tools-and-actions and .opencode/skills/tools-and-actions in your project.

What does Tools And Actions need to run?

Going by SKILL.md and its folder, Tools And Actions needs Python for the scripts in its folder and the command-line tools its instructions call (python and uv). Our summary lists: Python 3.

Does Tools And Actions access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Tools And Actions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tools And Actions use?

Tools And Actions is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tools And Actions use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.7k tokens, read only when the agent opens those files.

What are the alternatives to Tools And Actions?

Skills that share tags, products or a category with Tools And Actions: Fable Mode (mrtooher/fable-mode, 873 stars), Browser Tools (yonatangross/orchestkit, 292 stars), Aisafetyhot (wuyoscar/AISafetyHot-Hub, 708 stars) and Obliteratus (RedWoodOG/Hermes-Desktop, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tools And Actions?

VectorSpaceLab (a GitHub organization) maintains it in VectorSpaceLab/AREX-Skill, which has 331 GitHub stars. The repository holds 157 skills in this directory. The repository was last updated on September 3, 2026.

Source: VectorSpaceLab/AREX-Skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.