Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/udecode/plate-template/dev-browsergit clone --depth 1 https://github.com/udecode/plate-templateWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00018 | $0.01350 |
| Opus 5 | $0.00009 | $0.00675 |
| Sonnet 5 | $0.00004 | $0.00270 |
| Haiku 4.5 | $0.00002 | $0.00135 |
Grade A, and why
dev-browser scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -sS http://127.0.0.1:9222/json/version This is a copy
100% identical to dev-browser — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 131 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Dev Browser
Use this only as the fallback browser path when [@browser-use](plugin://browser-use@openai-bundled) is unavailable or blocked.
Do not substitute Puppeteer, standalone Playwright, or raw Chrome DevTools for this fallback path.
Installation
npm install -g dev-browser
dev-browser install
Run dev-browser --help to learn more.
Plate Defaults
- Use
dev-browser --connect http://127.0.0.1:9222by default. Do not preflight9222first. - Only inspect
9222after a directdev-browser --connect http://127.0.0.1:9222attempt fails. - Reuse one persistent debug Chrome on
127.0.0.1:9222. Do not spin up disposable browser instances unless the user asks. - Use a dedicated Chrome
--user-data-dirfor that debug browser, not the user's normal daily Chrome data dir. - Clone the signed-in Chrome profile into the dedicated debug dir, then launch the debug browser from that clone.
- On macOS, launch the debug browser with
open -na "Google Chrome" --args ... --remote-debugging-port=9222so it opens as a separate Chrome instance without hijacking the user's normal window. - Do not close or stop the user's connected debug browser. Leave that debug window open and reuse it. Close named pages only when needed.
- Keep scripts small and direct. Prefer
browser.getPage("persistent-main")for the main app. - Use
dev-browserinstead ofagent-browseror next-devtoolsbrowser_eval. - For Plate registry/browser proof, prefer
/blocks/[id]-demoover docs wrappers when that standalone demo route exists. - If
dev-browsergets blocked by a human prompt or loops on the same step, stop and ask the user to unblock.
Fallback Setup
Use this only after dev-browser --connect http://127.0.0.1:9222 fails because no reusable debug Chrome is available or the CDP endpoint is broken.
Rules
- Prefer one permanent debug browser/profile over disposable automation browsers.
- Treat a custom
--user-data-diras mandatory, not optional. Chrome 136+ expects remote debugging to happen from a dedicated profile. - Keep auth in that profile. Do not fall back to cookie dumps or state files unless the user asks.
- Use a separate signed-in Chrome profile for browser work, like
dev. Do not use the user's normal dailyDefaultprofile as the source profile. - Clone that separate signed-in Chrome profile into the dedicated debug
--user-data-dir; do not point9222straight at the user's daily Chrome data dir. - On macOS, use
open -na "Google Chrome" --args ...for the debug browser. That starts a separate Chrome instance with the dedicated debug profile without touching the user's normal Chrome window.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 131 lines · 18 tokens per session scan A 36196963d49b
dev-browser is a cursor rule published in the GitHub repository udecode/plate-template (59 stars, last pushed 1mo ago), licensed MIT. It adds 18 tokens to every session and 1,350 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). It is 100% identical to dev-browser, differing in 0 lines, and is treated as a copy.
Other cursor rules, from other repositories
dev-browser
Fallback browser automation with persistent Chrome state. Use only when Browser Use is unavailable or blocked.
browser-debug-setup
One-time setup for a persistent debug browser on 127.0.0.1:9222 for dev-browser --connect. Use when browser work is needed but no reusable debug browser is running yet.
agent-browser-issue
Open a concise GitHub follow-up for reusable browser-use limitations. Use when browser automation is blocked by a likely tool-side issue that is worth fixing separately, especially for clicks, dropdowns, file inputs, focus traps, or other repeatable agent/browser failures.
components
React component architecture for creating composable, accessible components with data attributes. Use when creating/updating composable components, not for higher-level feature/page components.
react
React patterns with destructured props, compiler optimization, Effects, and Tailwind v4 syntax. ALWAYS use when using React.
hard-cut
Remove a feature completely with no backward compatibility. Use when the user says "hard cut", "rip it out", "delete it", "unship", "kill this feature", or wants dead code removed instead of deprecated. Delete the surface, callers, tests, docs, comments, fallbacks, and stubs.