cli-anything-browser
Browser automation CLI using DOMShell MCP server. Maps Chrome's Accessibility Tree to a virtual filesystem for agent-native navigation.
By hkuds · 518 installs
npx skills add hkuds/cli-anything --skill cli-anything-browser
Source repository · Upstream listing
cli anything browser
A command line interface for browser automation using [DOMShell](https://github.com/apireno/DOMShell)'s MCP server. Navigate web pages using filesystem commands: ls , cd , cat , grep , click .
Installation
Prerequisites
1. Node.js and npx (for DOMShell MCP server):
2. Chrome/Chromium with [DOMShell extension](https://chromewebstore.google.com/detail/domshell browser filesy/okcliheamhmijccjknkkplploacoidnp):
Install extension in Chrome
Ensure Chrome is running before using CLI
3. Python 3.10+
Install CLI
Command Groups
page — Page Navigation
page open <url — Navigate to URL
page reload — Reload current page
page back — Navigate back in history
page forward — Navigate forward in history
page info — Show current page info
fs — Filesystem Commands (Accessibility Tree)
fs ls [path] — List elements at path
fs cd <path — Change directory
fs cat [path] — Read element content
fs grep <pattern [path] — Search for text pattern
fs pwd — Print working directory
act — Action Commands
act click <path — Click an element
act type <path <text — Type text into input
session — Session Management
session status — Show session state
session daemon start — Start persistent daemon mode
session daemon stop — Stop daemon mode
Usage Examples
Basic Navigation
Search and Click
Form Fill
JSON Output
Daemon Mode (Faster Interactive Use)
Interactive REPL
Path Syntax
DOMShell uses a filesystem like path for the Accessibility Tree:
Array indices are 0 based : button[0] is the first button
Use .. to go up one level
Use / for root
Agent Specific Guidance
JSON Output for Parsing
All commands support json flag for machine readable output:
Returns:
Error Handling
The CLI provides clear error messages for common issues:
npx not found : Install Node.js from https://nodejs.org/
DOMShell not found : Run npx @apireno/domshell version
MCP call failed : Install DOMShell Chrome extension
Check is available() return value before running commands.
Daemon Mode for Efficiency
For agent workflows with multiple commands, use daemon mode:
1. Start daemon: cli anything browser session daemon start
2. Run commands: Each command reuses the MCP connection
3. Stop daemon: cli anything browser session daemon stop
This avoids the 1 3 second cold start overhead for each command.
Links
[DOMShell GitHub](https://github.com/apireno/DOMShell)
[CLI Anything](https://github.com/HKUDS/CLI Anything)
[Issue 90](https://github.com/HKUDS/CLI Anything/issues/90)
Security Considerations
IMPORTANT : When using this CLI with AI agents, be aware of the following security considerations:
URL Restrictions
The browser harness validates all URLs before navigation:
Explicit scheme required : URLs must include http:// or https:// scheme (scheme less URLs like example.com are rejected)
Blocked schemes : file:// , javascript:// , data:// , vbscript:// , about:// , chrome:// , and browser internal schemes
Allowed schemes : http:// and https:// only (configurable via CLI ANYTHING BROWSER ALLOWED SCHEMES )
Private network blocking : Optional via CLI ANYTHING BROWSER BLOCK PRIVATE=true (disabled by default)
DOM Content Risks
The Accessibility Tree includes all visible and hidden elements on a page. Malicious websites could:
Craft ARIA labels with manipulative text (e.g., "Ignore previous instructions")
Use aria hidden elements to inject content not visible to users
Create confusing DOM structures that mislead navigation
Mitigation : When interacting with untrusted websites, consider:
1. Using the json flag for structured output that's easier to parse safely
2. Sanitizing or filtering DOM content before including it in prompts
3. Limiting navigation to trusted domains
Private Network Access
By default, the browser can access localhost and private networks (192.168.x.x, 10.x.x.x, etc.). To block:
Session Isolation
Multiple browser sessions share the same Chrome instance. Cookies and authentication state may persist across sessions. For sensitive operations, consider:
1. Using Chrome's guest mode or incognito
2. Clearing cookies between sessions
3. Using separate Chrome profiles for different security contexts