Skip to main content
Glama

Fill a field

browser_fill
Destructive

Fill an ordinary text field using a snapshot ref. Passwords, one-time codes, and payment details are refused; use browser_handoff instead.

Instructions

Replace the value of an ordinary text field. Never use for passwords, one-time codes or payment details: those fields are refused and the user must fill them (use browser_handoff).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
refYesShort ref such as e3 from that snapshot.
valueYesText to set.
context_idYesContext id from browser_contexts, for example tab:12.
request_idNoStable id for this logical action. Reuse the SAME id to retry or reconcile it; never reuse it for a different action. Omit to have one generated and returned.
observation_idYesobservation_id from the browser_snapshot that produced ref.
browser_instance_idNoOnly needed when several Firefox profiles are connected.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and non-idempotent, but the description adds context annotations cannot: sensitive-field refusal behavior and the required fallback to browser_handoff. "Replace" also signals that any existing value is overwritten. It does not discuss retry/reconciliation, though request_id in the schema partly covers that.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, no filler, and the operative instruction plus the critical safety exclusion are front-loaded. Every clause earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 6-parameter mutation tool with no output schema, the description covers purpose, the sensitive-field refusal path, and the handoff alternative. Return/reconciliation semantics are delegated to the schema's request_id documentation, which is a reasonable division of labor.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and all six parameters are documented in-schema (ref pattern, value maxLength, context_id example, request_id retry semantics). The description adds nothing about parameters, so the baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ("Replace the value of an ordinary text field"), and the word "ordinary" scopes it against siblings like browser_type. It never explicitly contrasts itself with browser_type, so an agent must infer which of the two to pick for a plain text input.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives explicit exclusions (passwords, one-time codes, payment details), states the consequence (fields are refused) and names the correct alternative (browser_handoff, which the user must use instead). This is a complete when/when-not/alternative triad.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.