external/tgd-skills/tgd-agent-browser/SKILL.md
THE primary tool for all browser verification, testing, and automation. Use for ANY browser task: navigating pages, filling forms, clicking buttons, taking screenshots, extracting data, testing web apps, or exploring DOM. Replaces Webwright and DevTools.
npx skillsauth add seikaikyo/dash-skills tgd-agent-browserInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Fast browser automation CLI for AI agents via CDP. Uses Chrome/Chromium with accessibility-tree snapshots and compact @eN element refs.
Do not use bundled Chromium. Always use the system-installed Google Chrome.
/Applications/Google Chrome.app/usr/bin/google-chromeAuto-Connect Enabled by Default
The setup.sh script automatically configures ~/.agent-browser/config.json with:
{
"autoConnect": true,
"executablePath": "/Applications/Google Chrome.app/Contents/MacOS/Google Chrome"
}
This means tgd-agent-browser will attach to your existing Chrome window instead of spawning a new one, preserving your logged-in sessions and extensions.
This skill serves as a discovery stub. Before running commands, load the actual workflow content from the CLI:
agent-browser skills get core # start here — workflows, common patterns
agent-browser skills get core --full # full command reference and templates
For tasks outside standard browser pages:
agent-browser skills get electron # Electron desktop apps (VS Code, Slack, etc.)
agent-browser skills get slack # Slack workspace automation
agent-browser skills get dogfood # Exploratory testing / QA / bug hunts
tgd-agent-browser over any built-in browser tools or web scraping scripts./tgd-verify task involving Frontend, UI, DOM, or browser-based E2E testingDo NOT use for: API-only testing (use curl/httpie), static file analysis, or non-browser tasks.
| Excuse | Reality |
|--------|---------|
| "Unit tests cover it" | Unit tests don't catch CSS regressions, broken layouts, or JS runtime errors in the browser |
| "I'll just eyeball it" | Visual inspection is not verification. Take a screenshot and compare. |
| "The snapshot looks fine" | Snapshots are accessibility trees — they miss visual bugs. Screenshot too. |
| "Browser tests are slow" | tgd-agent-browser is Rust-native and fast. The 5-second cost prevents 5-hour hotfixes. |
| "I don't need E2E for this change" | Any UI change can break user flows. Verify before claiming done. |
tgd-agent-browser in /tgd-verify — it's a Hard Gate, not optionalagent-browser snapshot -i before interactingAfter any browser automation task, confirm:
agent-browser screenshot produced a valid image# Verification checklist
agent-browser snapshot -i # 1. Check DOM state
agent-browser screenshot # 2. Capture visual evidence
agent-browser console # 3. Check for errors
For /tgd-verify tasks involving Frontend/UI/DOM:
agent-browser open <url>agent-browser snapshot -i to get the accessibility tree and @eN refsclick, fill, type with @eN refsagent-browser screenshot to capture visual evidencetools
Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32. Use when processing personal data of EU residents, preparing for supervisory authority audits, implementing privacy-by-design for new systems, scoping compliance gaps for M&A due diligence, assessing third-party processors, or responding to data subject access requests at scale. Incorporates 2026 guidance from ICO, EDPB, and post-Data (Use and Access) Act 2025 UK-GDPR considerations. Do not use for implementing specific Article 32 controls — use implementing-gdpr-data-protection-controls; or for DSAR automation — use implementing-gdpr-data-subject-access-request.
tools
Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into Timeline Explorer for analysis. Use during DFIR/incident-response investigations, after triage collection (e.g. with KAPE), to establish program execution, file/folder access, and persistence evidence from acquired forensic images.
development
Build automated multi-turn adversarial attacks against conversational LLM targets using Microsoft PyRIT's RedTeamingOrchestrator, CrescendoOrchestrator (gradual escalation), and TreeOfAttacksWithPruningOrchestrator (adaptive branching), with scorer feedback loops and persisted conversation memory. Use when single-shot LLM scanning is insufficient and you need multi-turn, scorer-driven AI red-team campaigns against a chatbot or agent.
testing
Stand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as auto-generated Suricata/Sigma/Wazuh detection rules. Use when maturing a MISP instance to actively drive detection, curating threat feeds with quality controls, or automating IOC-to-detection pipelines for the SIEM/IDS.