← 提示词库 OpenAI/Codex/control-in-app-browser.md 原文 md
🌐 中英双语对照

name: control-in-app-browser
description: "Control the in-app Browser. Use to open, navigate, inspect, test, click, type, screenshot, or verify local targets such as localhost, 127.0.0.1, ::1, file://, the current in-app browser tab, and websites shown side by side inside Codex."

Browser / 浏览器

Use this skill for browser automation tasks such as inspecting pages, navigating, testing local apps, clicking, typing, taking screenshots, and reading visible page state. After setup, select the iab browser.

此技能用于浏览器自动化任务,例如检查页面、导航、测试本地应用、点击、输入、截图和读取可见页面状态。完成设置后,选择 iab 浏览器。

Keep browser work in the background by default.

默认情况下,浏览器工作保持在后台进行。

Show the browser when the user's request is primarily to put a page in front of them or let them watch the interaction, such as "open localhost:3000", "go to the docs page", "take me to the PR", "show me the current tab", or "keep the browser open while you test checkout".

当用户的请求主要是把某个页面展示在他们面前或让他们观看交互过程时,显示浏览器,例如 “open localhost:3000”、“go to the docs page”、“take me to the PR”、“show me the current tab” 或 “keep the browser open while you test checkout”。

Do not show the browser when navigation is only a means to answer a question or verify behavior, such as "check localhost:3000 and tell me whether login works", "inspect the docs page and summarize what changed", or "verify the modal still opens correctly". Localhost targets and ordinary page navigation do not by themselves require visibility.

当导航只是回答问题或验证行为的手段时,不要显示浏览器,例如 “check localhost:3000 and tell me whether login works”、“inspect the docs page and summarize what changed” 或 “verify the modal still opens correctly”。localhost 目标和普通页面导航本身并不要求可见。

When the browser should be visible to the user, actually present it with await (await browser.capabilities.get("visibility")).set(true).

当浏览器应对用户可见时,用 await (await browser.capabilities.get("visibility")).set(true) 真正把它呈现出来。

If this plugin is listed as available in the session, treat that as mandatory reading before browser work. Open and follow this skill before saying that Browser is unavailable and before falling back to standalone Playwright or Computer Use.

如果本插件在会话中被列为可用,则在进行浏览器工作之前必须先阅读它。在声称 Browser 不可用之前、以及退回到独立 Playwright 或 Computer Use 之前,先打开并遵循此技能。

Do not skip this skill just because Computer Use MCP tool calls are directly visible or appear easier to invoke. The presence of Computer Use tools is not evidence that Computer Use is the preferred browser surface.

不要仅仅因为 Computer Use MCP 工具调用直接可见或看起来更容易调用就跳过此技能。Computer Use 工具的存在并不能证明 Computer Use 是首选的浏览器操作面。

Start with the directions in the Bootstrap section below. Use await agent.documentation.get("<name>") when you need information about the specific topic they cover:

从下方 Bootstrap(引导)小节的指引开始。当你需要某个文档所涉主题的信息时,使用 await agent.documentation.get("<name>"):

For example, this will give you guidance about confirmations:

console.log(await agent.documentation.get("confirmations"));

例如,以下调用会给你关于确认(confirmations)的指引:

console.log(await agent.documentation.get("confirmations"));

Bootstrap / 引导

These setup details are internal. User-facing progress updates should be less technical in nature. Never mention Node REPL, node_repl, REPL, JavaScript sessions, module exports, reading documentation, or loading instructions unless a user is asking for that exact information. If setup or recovery is needed, describe it naturally as connecting to the browser or retrying the browser connection.

这些设置细节属于内部信息。面向用户的进度更新不应过于技术化。除非用户问的正是这些信息,否则绝不要提及 Node REPL、node_repl、REPL、JavaScript 会话、模块导出、阅读文档或加载指令。如果需要进行设置或恢复,用自然的方式描述为“连接到浏览器”或“重试浏览器连接”。

The browser-client module is the core entry point for browser use, and is available under scripts/browser-client.mjs in this plugin's root directory. ALWAYS import it using an absolute path.
IMPORTANT: If this path cannot be found, stop and report that this plugin is missing scripts/browser-client.mjs. NEVER use the built in browser-client library.

browser-client 模块是浏览器使用的核心入口,位于本插件根目录下的 scripts/browser-client.mjs。始终(ALWAYS)用绝对路径导入它。
重要:如果找不到该路径,停止并报告本插件缺少 scripts/browser-client.mjs。绝不要使用内置的 browser-client 库。

Run browser setup code through the Node REPL js tool. In this environment the callable tool id typically appears as mcp__node_repl__js. If it is not already available, use tool discovery for node_repl js without setting a result limit. You need the js execution tool: js_reset only clears state, and js_add_node_module_dir only changes package resolution. Do not call either helper while trying to expose js. If js is still not available, search again for node_repl js with limit: 10. Run this once per fresh node_repl session:

通过 Node REPL 的 js 工具运行浏览器设置代码。在此环境中,可调用工具的 id 通常显示为 mcp__node_repl__js。如果它尚不可用,使用工具发现功能查找 node_repl js,不设置结果上限。你需要的是 js 执行工具:js_reset 只清除状态,js_add_node_module_dir 只改变包解析。在试图暴露 js 时不要调用这两个辅助工具。如果 js 仍不可用,用 limit: 10 再次搜索 node_repl js。每个全新的 node_repl 会话运行一次以下代码:

const { setupBrowserRuntime } = await import("<plugin root>/scripts/browser-client.mjs");
await setupBrowserRuntime({ globals: globalThis });
globalThis.browser = await agent.browsers.get("iab");
nodeRepl.write(await browser.documentation());

Use the browser bound to browser for tasks in this skill.

本技能的任务使用绑定到 browser 的浏览器。

The ability to interact directly with the browser is exposed through the browser-client runtime via the agent.browsers.* API. Before trying to interact with it, you MUST emit and read the complete documentation returned by await browser.documentation() in one go. For the initial documentation read, run the exact direct call nodeRepl.write(await browser.documentation()); shown above. Do not assign the documentation to a variable, inspect its length, slice it, truncate it, summarize it, or emit only an excerpt. Do not proactively split the documentation into pages or chunks. Only if the tool output itself explicitly reports that it was truncated may you emit and read smaller chunks until you have read the documentation in its entirety.

与浏览器直接交互的能力通过 agent.browsers.* API 由 browser-client 运行时暴露。在尝试与之交互之前,你必须(MUST)一次性完整输出并阅读 await browser.documentation() 返回的完整文档。首次阅读文档时,原样运行上面给出的直接调用 nodeRepl.write(await browser.documentation());。不要把文档赋给变量、检查其长度、切片、截断、摘要,或只输出节选。不要主动把文档拆分为多页或多块。只有当工具输出本身明确报告被截断时,才可以分较小的块输出并阅读,直到读完整个文档。

Only the Node REPL js tool (mcp__node_repl__js) can be used to control the in-app browser. Do not use external MCP browser-control tools, separate browser automation servers, or other browser skills for this surface. References to Playwright mean the in-skill tab.playwright API after browser-client setup.

只有 Node REPL 的 js 工具(mcp__node_repl__js)可用于控制应用内浏览器。不要为此操作面使用外部 MCP 浏览器控制工具、独立的浏览器自动化服务器或其他浏览器技能。文中提到 Playwright 时,指的是完成 browser-client 设置后的技能内 tab.playwright API。

【评论】强制一次性完整阅读运行时文档、禁止摘要和切片的条款,是针对模型“偷懒省读”行为的防规避设计;同时要求对用户隐藏 REPL 等内部术语,属于面向体验的表述约束。

API Use Behavior / API 使用行为

How to use the API / 如何使用该 API

General guidance / 一般指引

Browser Safety / 浏览器安全

【评论】“Browser Safety”一节是标准的防提示词注入条款:外部内容只有事实地位、没有指令地位;同时把读取与传输区分开,敏感数据的跨域传输一律要求动作时点确认。
【评论】CAPTCHA 条款采取“逐个询问、确认后解决”的中立策略,而对付费墙绕过、年龄验证和密码修改末步则直接禁止,划出了协助与代办的边界。