Atlas / Skills / emdash-cms / Agent Browser

Agent BrowserCAUTION

skills/emdash-cms/agent-browser

EmDash is a full-stack TypeScript CMS based on Astro; the spiritual successor to WordPress

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
MIT
Stars
13,442
01

Overview

EmDash is a full-stack TypeScript CMS based on Astro; the spiritual successor to WordPress

Read from source at commit 2e1ca292efe5OBSERVED · 2026-10-07
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: agent-browser
description: Use the agent-browser CLI to exercise web interfaces, inspect rendered accessibility state, verify interactions, and capture screenshots. Use for browser-based UI testing and evidence collection. Do not use as a substitute for deterministic Playwright coverage when an automated regression test is the requested deliverable.
---

# Test interfaces with agent-browser

Use the installed `agent-browser` CLI for rendered, user-facing verification. Load its version-matched instructions before relying on command syntax:

```bash
agent-browser skills get core --full
```

Use a specialized bundled guide when the target requires one. `agent-browser skills list` shows the available guides.

## Verification loop

1. Start or identify the target application and record the exact URL and viewport.
2. Open the page in a named session.
3. Take an accessibility snapshot and identify controls by role, label, or snapshot reference.
4. Perform the user action.
5. Wait for the resulting state, then take a fresh snapshot. References can become stale after navigation or a substantial DOM update.
6. Verify the observable result, console errors, and relevant network behavior.
7. Capture screenshots when visual evidence helps establish the result.

For EmDash admin testing, authenticate through the development bypass rather than attempting to automate passkeys:

```bash
agent-browser open 'http://localhost:4321/_emdash/api/setup/dev-bypass?redirect=/_emdash/admin'
```

Use `auth/dev-bypass` instead when setup is already complete.

## Interaction guidance

- Prefer role and label locators when they express the user-facing control clearly. Use snapshot references for efficient exploration.
- Re-snapshot after a dialog opens, a route changes, or content is replaced.
- Wait for a selector or visible state instead of adding a fixed delay unless timing itself is under test.
- Use a named session for flows that depend on cookies or storage. Close sessions that are no longer needed.
- Check `agent-browser console` and `agent-browser errors` when the UI behaves unexpectedly.
- Use `agent-browser network requests` when the result depends on a request or response boundary.

## Evidence

Record the path tested, inputs, viewport, expected result, actual result, and any console or request failures. For UI changes, capture the rendered result and before-and-after screenshots when the difference is otherwise ambiguous.

Save screenshots inside the task workspace with descriptive filenames. Inspect the saved image before reporting success; a completed screenshot command does not prove that the intended state was visible.

Browser exploration does not replace a regression test when stable automated coverage can protect the behavior. Convert a confirmed defect into the narrowest meaningful automated test when the task includes implementation.
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills
.agents/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
templates/blank/.claude/skills
templates/blank/.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
templates/blog-cloudflare/.claude/skills
templates/blog-cloudflare/.claude/skills
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
.claude/CLAUDE.md
.claude/CLAUDE.md
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 2e1ca292efe5full audit observations/trust-audit/skill/emdash-cms__agent-browser.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-072e1ca292efe5CAUTIONB89first audit
05

Questions

What does the Agent Browser skill do?

EmDash is a full-stack TypeScript CMS based on Astro; the spiritual successor to WordPress

Is Agent Browser safe to install?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Agent Browser access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (2e1ca292efe5), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement