本文へ移動
cccskills
無料GitHub で公開

chrome-devtools-browser

Bring up a REAL, visible, interactive chromium on the Kali VM that the operator logs into (Smart-ID / Mobile-ID / any manual auth or MFA/CAPTCHA), while the agent drives and observes it live through the chrome-devtools MCP (navigate, DOM snapshot, network capture, screenshots, console, evaluate). Use whenever a target needs a MANUAL login the agent cannot complete headlessly, when you need to capture an authenticated session / the real API calls a page makes, or to confirm/screenshot a DOM-XSS. Triggers - "open a browser", "log in manually", "smart-id / mobile-id / national id login", "mfa / 2fa login", "solve the captcha", "drive the browser", "capture the authenticated session / network".

インストール方法を見る

含まれるファイル(1)

  • SKILL.md4.8 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

chrome-devtools-browser

Headless browser.sh cannot solve a human login. This skill brings up a visible chromium on the Kali desktop (:0) the operator can click and type into, with its DevTools port tunnelled back so the chrome-devtools MCP drives and watches it. Two roles at once: the human authenticates; the agent observes + acts. The VM holds the VPN/egress path, so it reaches both internet and in-scope targets.

1. Bring it up (one command)

bash scripts/browser-visible.sh <login-url> --profile bbtest-<eng>
# e.g. bash scripts/browser-visible.sh https://target.example/ib --profile bbtest-<eng>

It resolves the VM's seat session, unlocks/wakes :0, frees the CDP port, launches chromium as the seat user on :0 in a named tmux session (a dedicated per-engagement profile, so the operator's own profile/cookies stay clean), then reuses scripts/browser.sh to forward CDP to http://127.0.0.1:9222. It prints VISIBLE on :0 when a real on-screen window exists (not merely a listening port). If it prints a no (:N) desktop session message, the VM has no desktop - fall back to scripts/browser.sh (headless).

2. Attach + hand off for login

  • The chrome-devtools MCP attaches to http://127.0.0.1:9222. Confirm with list_pages; navigate_page to the login URL if needed.
  • Stay off the browser while the operator enters credentials. Take a take_screenshot so they can confirm the page, then wait for their "logged in" before you drive again. The operator owns credential entry and the phone approval; the agent never types a personal code / PIN.

3. Drive + observe (chrome-devtools MCP capability map)

NeedMCP tool
List/select tabslist_pages (select the target tab; ignore the operator's other tabs)
Go to a page / back / reloadnavigate_page
Rendered DOM (elements + uids)take_snapshot
Visual PoC / confirm statetake_screenshot -> a web evidence image (hand to Skill(screenshot)/Skill(evidence))
The real API calls the app makeslist_network_requests (add includePreservedRequests:true to span the login redirects); this is the authenticated API map a curl crawl never sees
One request's headers/body/cookiesget_network_request <reqid>
Console / JS errorslist_console_messages
Read client config / globals, confirm DOM-XSSevaluate_script (e.g. __NEXT_DATA__, window.*, fire a payload in the real DOM)

Once authenticated, the captured /… API calls feed the hunt skills: Skill(hunt-idor) / Skill(hunt-api) (BOLA on id-keyed endpoints), Skill(hunt-xss) (DOM-XSS via evaluate_script), business-logic on the authed flows. Load-bearing requests still go to Burp Repeater when reachable (Skill(hunt-burp)).

4. Field notes

  • A 200 {"message":"Unable to login"} with NO Set-Cookie = the server rejected at an account/state check and issued no session -> nothing to pivot (not a bug). A Set-Cookie/JWT issued before such a check is a real authz-bypass lead - test the gated endpoints with that cookie.
  • dbus/GPU errors in the tmux pane are non-fatal VM noise; judge success by VISIBLE on + list_pages.
  • Data minimisation on the authed surface: prove IDOR/BOLA with your own account + stop at the first adjacent-id differential; never pull another customer's real PII.

Safety

  • The CDP port is unauthenticated = total control of the browser (read any tab, lift session cookies). It stays loopback-only + ssh -L; never bind 0.0.0.0 / expose it to the LAN.
  • Named tmux session only (cdpbrowser); never tmux kill-server (the VPN/other work may live in tmux).
  • Dedicated --profile per engagement; the port-free step warns it drops any tabs on that port.

Teardown

bash scripts/browser.sh stop                                   # drop the CDP tunnel
bash /root/vm.sh 'tmux kill-session -t cdpbrowser'             # close the VM browser

Setup / recipe rationale + the dead-ends that shaped this: scripts/browser.sh, scripts/shot.py (seat-session resolution), and the engagement failures.md note.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

arsenal

無料

Wiki-first "what do I use" lookup - pick the automated TOOL (wiki/tools/), then the PAYLOAD/technique (wiki/payloads/ + wiki/cheatsheets/), for a surface/service/vuln-class BEFORE hand-rolling or working from memory. Use for "tool for <service>", "automated tools for web/<service>", "what should I run on <surface>", "which tool for <X>", "payloads for <X>", "payload arsenal", "cheatsheet for <X>", "how do I exploit <tech/class>", "exploit/attack chain for <X>", "arsenal", any SSRF/XSS/SQLi/SSTI/LFI/JWT/XXE/IDOR/NoSQL/deserialization/CSRF/CORS/CRLF/GraphQL/smuggling/web-cache/OAuth/SAML/MFA/crypto/LDAP/XPath/WebAuthn/file-upload/IMDS/prompt-injection/Modbus ask, plus "privesc arsenal", "CVE arsenal", "default creds", "nuclei templates", "sqlmap/hydra/nmap/bloodhound", "password attacks".

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

Autonomous bug-bounty campaign driver. Runs a full programme end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (including which Skill and tool to run) every turn. Use when starting or resuming a bug-bounty engagement, "run the bb workflow", "hunt this program", "9-pass campaign", or when handed a *.scope wildcard to test for TIER1 findings. Single agent, refuter-verified, wiki-first, tool-first.

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

Health check for the bb/pt/ctf workflow driver subsystem - verifies everything is in place so every machine runs the same. Checks vault-content consistency (scripts present, JSON valid, routing wired, all 69 tool pages carry phase:, the tool index resolves, the hook edits are in place) AND per-machine wiring (the three workflow skills symlinked, hooks registered, imports work), then runs a live init->board->next smoke test. Use when setting up the workflow on a new machine, after a vault sync, when the driver misbehaves, or on "bb-health", "campaign health", "is the workflow set up", "check hooks and scripts", "why is the board not working".

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

OFFLINE FALLBACK for the claude-md-management plugin - prefer that plugin when it is installed. Audit and improve CLAUDE.md files - scan for CLAUDE.md files, evaluate quality against templates, output a report, then make targeted updates. Invoke explicitly (/claude-md-improver) when the plugin is unavailable.

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

coverage

無料

Show per-asset vuln-class coverage gaps for the active engagement so nothing in scope is skipped. Use when asked "coverage", "what haven't we tested", "test gaps", "are we thorough", or before calling an engagement done.

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

ctf-box

無料

Boot-to-root methodology for a full machine (THM/HTB/PG/CTF box, "get user.txt+root.txt", "root the box", "foothold to root"). Enforces basic-tool recon (nmap, nc, ffuf, nuclei, dig) before anything custom, wiki-first lookups, and ALWAYS pspy + linpeas/winpeas for privesc. Use when handed a box/IP to own end-to-end.

日本語の概要は準備中です。原文の説明を表示しています。

Encod3d-Sec/TORCH3302026年9月1日 更新

Encod3d-Sec のスキルをすべて見る

このスキルの問題を報告する