Set up Cloudflare Browser Rendering with the browser skill
The cloudflare-browser skill controls Chrome through Cloudflare Browser Rendering for screenshots, navigation, and video capture.
- Skill Road
- Set up Cloudflare Browser Rendering with the browser skill
Published on 09.09.2026
What the cloudflare-browser skill is and why it's used
According to the vendor, the cloudflare-browser skill originates from the cloudflare/moltworker repository, a proof-of-concept published by Cloudflare itself that demonstrates how a personal AI assistant can run inside a Cloudflare Sandbox. The skill itself is not a standalone product but a set of instructions for an AI agent on how to remote-control a headless Chrome browser through Cloudflare's Browser Rendering service — formerly known under the same name and now also referred to as Browser Run — via the Chrome DevTools Protocol, or CDP. According to Cloudflare, Browser Rendering is a service that provides real, but headless (running without a visible interface) Chrome instances across Cloudflare's global network, reachable over a WebSocket connection. This matters because many automation tasks require a real browser, for example to render JavaScript-heavy pages, generate screenshots, or extract content as Markdown, without having to operate one's own browser infrastructure. The skill wires this capability into an agent, for instance one running in Claude Code or a comparable tool, used within the moltworker project.
Prerequisites
To make meaningful use of the skill, the vendor states that a Cloudflare account with the Browser Rendering service enabled is needed first; it's available on a free entry-level plan as well as on paid plans, and Cloudflare points to its own pricing page for exact quotas and costs. The environment additionally needs a protected CDP secret with which the agent authenticates against the Browser Rendering service, along with a configured browser profile containing the matching CDP address. The example scripts included in the skill assume a Node.js environment, and video production from multiple screenshots additionally requires the ffmpeg tool as a local dependency. Since the overall moltworker project is built on Cloudflare Workers and Cloudflare Sandbox containers, a basic understanding of the Cloudflare Workers platform is also helpful, even though the skill itself only concerns the browser part.
Step-by-step setup
After storing the CDP secret in a secure environment or secrets manager — explicitly not in source code or logs — the agent, per the official examples, first opens a WebSocket connection to the configured CDP address. It then detects a newly created page target in the browser, for which the required CDP domains are activated, for example for page navigation, JavaScript evaluation, or screen capture. After that, a viewport can be set, a target URL opened, and the page allowed to fully render before the actual action runs. For single screenshots, the skill provides a Node.js example script that loads a page and saves the result as an image file. For multi-page video sequences, a series of screenshots is generated and then stitched together into a video file using ffmpeg. Before every run, the actually installed package versions, the worker profile in use, the target URL, and the desired output location should be checked, because small configuration mismatches can lead to blank or faulty results.
Security, privacy, and limitations
Because the browser actually loads web pages and executes JavaScript, any page content retrieved this way counts as untrusted data. The agent should therefore not feed browser results into downstream decisions or automated actions without review, particularly when target pages are unknown or potentially manipulated. The CDP secret is the central security anchor of the whole integration; if it falls into the wrong hands, a third party could abuse the same Cloudflare Browser Rendering access and issue requests at the account owner's expense. For that reason the secret belongs exclusively in a protected secrets manager and must never appear visibly in screenshots, debug logs, or version control. Since the service runs on Cloudflare's global network, loaded page content technically leaves one's own infrastructure; for privacy-sensitive content it's worth checking which Cloudflare region and which data processing terms apply.
Practical example and limitations
A realistic use case is automated visual verification of a web application after a deployment: the agent visits several key pages, takes screenshots, and compares them against a previous state to catch obvious rendering regressions. Another case is documenting a multi-step user flow as a short video, for instance for support tickets or product demos. Limitations arise because a single screenshot or a short sequence is always just a snapshot in time and does not replace a full functional check; dynamic content, wait times, redirects, and responsive layouts must be explicitly handled in the script, or incomplete or misleading results occur. It's also worth noting that the skill is part of an experimental project which, by Cloudflare's own description, is not officially supported and may change without notice — something to factor in for production integrations that need long-term stability.
Frequently asked questions
Does the skill require CDP_SECRET?
According to the provider, yes. Store the secret securely and never place it in code, logs, or catalog copy.
Does the skill replace a local browser?
No. It describes controlling a Cloudflare-provided headless browser through CDP.