受限安全瀏覽器

受限安全瀏覽器

建立限制網域存取的本機瀏覽器 Agent。

Browserbase · 官方來源 · 安全

來源狀態

可用來源

資源類型

Skill

與類似 Skill 有什麼不同?

  • 安全最佳實務

    Safe Browser 聚焦瀏覽時的信任邊界與敏感操作;Security Best Practices 檢視程式與框架的安全實作。

來源描述的能力

這些是來源描述的可能操作,不代表 2lus 已授予權限或已測試。

尚未列出能力,請審查原始來源。

這個 Skill 是什麼?

以受限瀏覽器工具與請求攔截示範 allowlist 邊界。

可以做什麼?何時適合使用?

  • 核准網域擷取
  • 跨站封鎖示範
  • 受限工具設計

如何使用

  1. 明列允許的網域與資料。
  2. 在獨立目錄審查範本、SDK 與密鑰設定。
  3. 獲准後檢查允許及拒絕案例,保留去識別化紀錄。

使用前你需要準備

  • 待審查來源與權限
  • 威脅假設及不能操作的範圍

你可以替換:

[scope]、[permissions]

環境與相依需求

  • Node.js 18+、npm、本機 Chromium、Claude Agent SDK;產生的程式需要 ANTHROPIC_API_KEY,可能產生費用。

使用範例與 Prompt

以下是 2lus 撰寫的示範需求;請替換為你有權處理的檔案與專案,不代表已執行或保證結果。

入門

先畫出僅允許 docs.example.com 的請求邊界,不安裝或呼叫 API。

實務

審查範本是否拒絕跨網域重新導向,列出靜態無法確認的事項。

進階

在獲准隔離環境設計允許與拒絕案例,檢查子網域及外部資源,不輸出 API key。

實用提醒

  • 同時檢查重新導向及外部資源請求。

限制與注意事項

  • Skill 文件不是安全沙箱;安全性取決於執行程式與網路控制。

安全注意事項

  • 不要複製私人 .env 或授予原始 shell/CDP;用專用最低權限密鑰,禁止紀錄值。

使用與設定

此條目不提供已確認的通用安裝指令;請依官方文件與 Agent 版本操作。

支援平台

Claude Code — 文件記載,未做實機相容性測試 官方文件 ↗

來源與授權

來源查核日期(非安全認證): 2026-09-29

MIT

原始來源 ↗ 授權條款 ↗ 官方文件 ↗

相關 Skills

使用第三方 Skill 前,請先檢查來源、權限與執行內容。安裝指令只供查看與複製,不會由 2lus 執行。

2lus AI Skills Library 提供 Skill 的整理與使用導覽。第三方 Skill 的內容、授權與可用性以原始來源為準。使用或安裝前,請自行確認其權限與執行內容。

Safe Browser

Build a locally constrained browser agent.

Browserbase · Official source · Security

Source status

Active source

Resource type

Skill

How is this different from similar skills?

  • Security Best Practices

    Safe Browser focuses on browsing trust boundaries and sensitive actions; Security Best Practices reviews code and framework security.

Documented capabilities

These are operations described upstream, not permissions granted or tested by 2lus.

Capabilities not declared here; review the original source.

What is this skill?

Demonstrate domain allowlists through a limited tool and request interception.

Use cases and when to use it

  • Approved-domain extraction
  • Cross-site blocking demonstration
  • Constrained tool design

How to use it

  1. List permitted domains and data.
  2. Review template, SDK and credentials in a separate directory.
  3. With permission, check allow/deny cases and retain redacted logs.

What you need

  • Source and permissions to review
  • Threat assumptions and prohibited actions

You can replace:

[scope], [permissions]

Environment and dependencies

  • Node.js 18+, npm, local Chromium and Claude Agent SDK; generated apps require ANTHROPIC_API_KEY and may incur charges.

Usage and prompt examples

These example requests were written by 2lus. Substitute files and projects you may use; examples are not executed results or guarantees.

Beginner

Diagram a boundary permitting only docs.example.com without installing or calling APIs.

Practical

Review whether the template rejects cross-domain redirects; identify uncertainties needing runtime checks.

Advanced

Design allowed/blocked cases in an approved isolated environment, including subdomains and external resources; never output API keys.

Tips

  • Check redirects and external resource requests too.

Limitations

  • A skill document is not a sandbox; security depends on runtime and network enforcement.

Security notes

  • Do not copy private .env files or grant raw shell/CDP; use scoped dedicated keys and never log values.

Usage and setup

No verified universal installation command is provided for this entry. Follow the official documentation for your agent version.

Supported agents

Claude Code — Documented; not runtime-tested Documentation ↗

Sources and license

Source check date (not a safety certification): 2026-09-29

MIT

Original source ↗ License terms ↗ Documentation ↗

Related skills

Before using a third-party skill, review its source, permissions and executable content. Commands are for viewing and copying only; 2lus does not execute them.

2lus AI Skills Library provides curated educational guides. Third-party content, licenses and availability are governed by their original sources. Review permissions and executable content before use or installation.