Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/oneworks-ai/app/browser-drivernpx skills add oneworks-ai/app --skill browser-drivergit clone --depth 1 https://github.com/oneworks-ai/appWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00031 | $0.00811 |
| Opus 5 | $0.00015 | $0.00405 |
| Sonnet 5 | $0.00006 | $0.00162 |
| Haiku 4.5 | $0.00003 | $0.00081 |
Grade A, and why
browser-driver scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
OneWorks In-App Browser Control
Use this skill for websites shown in the OneWorks internal browser. It does not control external Chrome or native desktop applications.
Prefer execute_in_app_browser_workflow when one page has two or more deterministic steps. When independent work is ready for multiple pages, submit it once with execute_in_app_browser_workflows; pages run concurrently while each page remains serial. Use low-level tools only to inspect, recover from a changed page, or perform a single action.
- Use
in_app_browser_openwhen the requested page is not already open. It reuses the same URL by default; passopen_mode: "new-tab"only when the task needs a separate page instance. Pages open on the right by default; passplacement: "bottom"only when a wide horizontal panel better suits the task. Callin_app_browser_list_pagesonly when you need to discover existing pages. Usein_app_browser_show_pageto reveal an existing page when the user needs to see it; ordinary background operations should continue addressing the page directly bypage_idwithout changing the visible tab. - Call
in_app_browser_snapshotbefore referring to page elements. Keep itspage_idpaired with every returnedref; do not invent CSS selectors or coordinates. Every page operation requires an explicitpage_id, so never rely on an implicit active tab. - A ref can become stale after navigation or DOM updates. If a tool returns
TARGET_NOT_FOUND, take a new snapshot and continue with the new ref. - Prefer
in_app_browser_waitwith an expected text/ref over a fixed delay. Do not add shell sleeps. After an action, request only the cheapest state needed for the next decision; do not take both a snapshot and screenshot by default. - Workflows run serially against an explicit
page_id. Give every step a stablenode_id. Usemissing: "skip"only when absence is an expected exit condition; otherwise keep the defaultstop. Batch only independent page workflows; steps targeting the same page are deliberately queued. - For one to three single-workflow steps, results are returned inline. Longer workflows and all multi-page batches return
run_idand step IDs; callget_in_app_browser_workflow_stepsonly for the details needed. Tab management, history clearing, and paginated history reads remain explicit low-level calls and are not workflow steps. - Use
in_app_browser_get_navigation_statefor the cheap current index/loading/back-forward summary. Callin_app_browser_get_navigation_entriesonly when entry details are needed.in_app_browser_navigate_historyaccepts exactly one ofdirection,offset, orindex. - Treat returned
page.id/replacement_page_idfromin_app_browser_duplicate_pageorin_app_browser_move_pageas authoritative; those actions may recreate the webview. Do not keep usingprevious_page_id. Closing a page is terminal forclosed_page_id. - Before choosing a simulated device, call
in_app_browser_list_device_presets. Usein_app_browser_set_device_modefor the device toolbar and emulation,in_app_browser_set_page_zoomfor native page zoom, andin_app_browser_set_embedded_devtoolsonly when inspection is materially useful. Read the applied state within_app_browser_get_page_view_state. - Use
in_app_browser_screenshotonly when visual verification is material. The tool returns a local PNG path. Usein_app_browser_selectfor native HTML selects instead of simulating popup clicks and arrow keys.
The plugin intentionally does not expose arbitrary JavaScript, raw CDP, cookies, storage, saved passwords, or OneWorks application chrome.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 24 lines · 31 tokens per session scan A 533554300775
browser-driver is a skill published in the GitHub repository oneworks-ai/app (18 stars, last pushed 2d ago), licensed MIT. It adds 31 tokens to every session and 811 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
neo4j-nvl-skill
Neo4j Visualization Library (NVL) — framework-agnostic graph rendering for the browser. Covers @neo4j-nvl/base (NVL class, nodes/relationships, Canvas vs WebGL renderer), @neo4j-nvl/interaction-handlers (ZoomInteraction, PanInteraction, DragNodeInteraction, ClickInteraction, HoverInteraction, BoxSelectInteraction…
lov-app-generator
Use when the user asks for "App生成器", "生成 Web App", "生成 Tauri App", "生成原生 macOS App", "Finder Quick Action", "只创建 web", or to standardize an existing app with branding, CI/CD, native integration, and Lovinsp where applicable.
lov-integrate-lovinsp
幂等集成 lovinsp (click-to-code) 到当前前端项目,并支持从 code-inspector 自动迁移。 Use when the user asks to "装 lovinsp"、"集成 lovinsp"、"接入点击跳转源码"、"click to code"、 "从 code-inspector 迁移",or when scaffolding/upgrading a browser-rendered app that needs click-to-source support. Also trigger when another skill (例如 lov-app-generator) requires…
oneshot-website
Generate immersive, one-shot single-file HTML websites with embedded CSS and JS. No external images. Hostable on CodePen or Vercel. Use for writeup showcases, AI capability demos, and portfolio pieces.
agent-browser
为 Agent 设计的自动化浏览器 CLI 工具,也能操作 Electron 桌面应用。当需要与网站交互(包括页面导航)时使用.
deva-cloak
Drive CloakBrowser stealth Chromium inside the deva cloak container - a headed, anti-detection browser for scraping, automation, or checking a site the way a real browser sees it. Use when the task needs a browser that bypasses bot detection (Cloudflare, FingerprintJS, reCAPTCHA scoring), or when the user asks to…