Skip to main content
Glama

browser_macro

Record and replay browser automation macros to repeat discovered workflows without model calls, substituting secrets as placeholders.

Instructions

Record, replay, list, or delete a macro — a discovered path with no model calls.

action="record_start" begin capturing ops (needs the session to be driving the task) action="record_stop" finish and save under name action="run" replay name; params fills {{placeholders}} in text/url action="list" | "inspect" | "delete"

A field the page marks as a secret is never written to the macro: its text is stored as the placeholder {{secret}}, so pass params={"secret": "…"} to replay it. Leaving that out types the placeholder literally, which fails visibly rather than leaking — and the extension's replay panel asks for the same field, because it is an ordinary placeholder.

Replay re-resolves each step by role + name against a fresh observation and refuses to act when the best match is weak or ambiguous.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
goalNo
nameNo
actionYes
paramsNo
sessionNodefault
start_urlNo
thresholdNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.5

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the sparse annotations (readOnlyHint=false, openWorldHint=true, destructiveHint=false), the description discloses that secrets are never written to the macro and are stored as {{secret}} placeholders, that omitting them 'fails visibly rather than leaking', and that replay refuses to act on weak or ambiguous matches. These are meaningful safety and failure-mode disclosures the annotations do not provide.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description front-loads the core purpose and then organizes into action definitions, secret handling, and replay semantics. It runs long, but each sentence adds information, and the secret-handling and weak-match-refusal passages earn their length given their safety importance.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 7-parameter, multi-action tool, the description explains the essential usage contract: actions, placeholder mechanics, and the safety/ambiguity rules. An output schema exists to cover return values, so the main remaining gap is that several parameters (goal, session, start_url, threshold) are left to an input schema with 0% prose coverage.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description carries the burden. It richly documents `action` (five values with their effects), `name` (save/replay target), and `params` (placeholder substitution including the {{secret}} case). It leaves `goal`, `session`, `start_url`, and `threshold` unexplained, though the weak-match refusal partially hints at threshold semantics.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening line 'Record, replay, list, or delete a macro — a discovered path with no model calls' gives specific verbs, a resource, and a defining trait. The 'no model calls' framing distinguishes this from sibling tools like browser_act and browser_observe, which drive live model-mediated interactions.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives per-action context: record_start 'needs the session to be driving the task', run replays a name with params filling placeholders, and list/inspect/delete are enumerated. It doesn't explicitly name sibling alternatives or state when-not-to-use, but 'a discovered path with no model calls' implies the use case that separates this from live-action tools.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.