dev-browser

Fallback instructions for controlling a persistent Chrome browser when Browser Use is unavailable or blocked. It uses a separate debugging browser profile so saved browser state can be reused.

In plain words
What is it for?
Use it for browser automation as a fallback, connecting to the designated debugging Chrome instance. It covers installation, connection defaults, profile setup, and keeping the browser session open.
Why use it?
It provides a defined browser-automation path and preserves sign-ins and session state between runs. It also helps avoid interfering with the user's normal Chrome profile.

Cursor rule for Codex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/udecode/plate-template/dev-browser
Clone the repo
git clone --depth 1 https://github.com/udecode/plate-template

Made for: Codex.

Per session 18 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,350 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00018 $0.01350
Opus 5 $0.00009 $0.00675
Sonnet 5 $0.00004 $0.00270
Haiku 4.5 $0.00002 $0.00135

Measured yesterday against content hash 36196963d49b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

dev-browser scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

curl -sS http://127.0.0.1:9222/json/version
Origin

This is a copy

100% identical to dev-browser — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.agents/rules/dev-browser.mdc · 131 lines

How it starts

The opening of the file, as written. The whole thing — 131 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Dev Browser

Use this only as the fallback browser path when [@browser-use](plugin://browser-use@openai-bundled) is unavailable or blocked.

Do not substitute Puppeteer, standalone Playwright, or raw Chrome DevTools for this fallback path.

Installation

npm install -g dev-browser
dev-browser install

Run dev-browser --help to learn more.

Plate Defaults

  • Use dev-browser --connect http://127.0.0.1:9222 by default. Do not preflight 9222 first.
  • Only inspect 9222 after a direct dev-browser --connect http://127.0.0.1:9222 attempt fails.
  • Reuse one persistent debug Chrome on 127.0.0.1:9222. Do not spin up disposable browser instances unless the user asks.
  • Use a dedicated Chrome --user-data-dir for that debug browser, not the user's normal daily Chrome data dir.
  • Clone the signed-in Chrome profile into the dedicated debug dir, then launch the debug browser from that clone.
  • On macOS, launch the debug browser with open -na "Google Chrome" --args ... --remote-debugging-port=9222 so it opens as a separate Chrome instance without hijacking the user's normal window.
  • Do not close or stop the user's connected debug browser. Leave that debug window open and reuse it. Close named pages only when needed.
  • Keep scripts small and direct. Prefer browser.getPage("persistent-main") for the main app.
  • Use dev-browser instead of agent-browser or next-devtools browser_eval.
  • For Plate registry/browser proof, prefer /blocks/[id]-demo over docs wrappers when that standalone demo route exists.
  • If dev-browser gets blocked by a human prompt or loops on the same step, stop and ask the user to unblock.

Fallback Setup

Use this only after dev-browser --connect http://127.0.0.1:9222 fails because no reusable debug Chrome is available or the CDP endpoint is broken.

Rules

  • Prefer one permanent debug browser/profile over disposable automation browsers.
  • Treat a custom --user-data-dir as mandatory, not optional. Chrome 136+ expects remote debugging to happen from a dedicated profile.
  • Keep auth in that profile. Do not fall back to cookie dumps or state files unless the user asks.
  • Use a separate signed-in Chrome profile for browser work, like dev. Do not use the user's normal daily Default profile as the source profile.
  • Clone that separate signed-in Chrome profile into the dedicated debug --user-data-dir; do not point 9222 straight at the user's daily Chrome data dir.
  • On macOS, use open -na "Google Chrome" --args ... for the debug browser. That starts a separate Chrome instance with the dedicated debug profile without touching the user's normal Chrome window.

Read the full file on GitHub · 131 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 131 lines · 18 tokens per session scan A 36196963d49b

Subscribe to this mod's changes

dev-browser is a cursor rule published in the GitHub repository udecode/plate-template (59 stars, last pushed 1mo ago), licensed MIT. It adds 18 tokens to every session and 1,350 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). It is 100% identical to dev-browser, differing in 0 lines, and is treated as a copy.

Related

Other cursor rules, from other repositories

dev-browser

Fallback browser automation with persistent Chrome state. Use only when Browser Use is unavailable or blocked.

udecode/plate-playground-template · 18 tokens

browser-debug-setup

One-time setup for a persistent debug browser on 127.0.0.1:9222 for dev-browser --connect. Use when browser work is needed but no reusable debug browser is running yet.

udecode/plate-playground-template · 43 tokens

agent-browser-issue

Open a concise GitHub follow-up for reusable browser-use limitations. Use when browser automation is blocked by a likely tool-side issue that is worth fixing separately, especially for clicks, dropdowns, file inputs, focus traps, or other repeatable agent/browser failures.

udecode/plate-playground-template · 52 tokens

components

React component architecture for creating composable, accessible components with data attributes. Use when creating/updating composable components, not for higher-level feature/page components.

udecode/plate-playground-template · 31 tokens

react

React patterns with destructured props, compiler optimization, Effects, and Tailwind v4 syntax. ALWAYS use when using React.

udecode/plate-playground-template · 25 tokens

hard-cut

Remove a feature completely with no backward compatibility. Use when the user says "hard cut", "rip it out", "delete it", "unship", "kill this feature", or wants dead code removed instead of deprecated. Delete the surface, callers, tests, docs, comments, fallbacks, and stubs.

udecode/plate-playground-template · 64 tokens