Conversation
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
36 issues found across 382 files
Confidence score: 2/5
- Raw provider errors can be exposed to users through
packages/examples/templates/python/google-trends/main.py,packages/examples/demos/v4-demo-kit/src/session.mjs, andpackages/examples/demos/v4-demo-kit/src/http-server.mjs, potentially leaking request or infrastructure details; sanitize provider exceptions before printing, rethrowing, or returning them. - Several examples are likely unusable from a fresh install:
packages/examples/integrations/langchain/package.jsonhas an ESM/CommonJS mismatch,packages/examples/demos/hacker-news-intelligence/package.jsoncannot load its ESM-only dependencies from CommonJS, andpackages/examples/demos/configurable-browser-trial/package.jsonomits the runtimetsxdependency; align module settings and package runtime dependencies. - The Python quickstarts in
packages/examples/templates/python/download-financial-statements/README.mdandpackages/examples/templates/python/manual-mfa-with-contexts/README.mddo not execute or install the example correctly, so following the documented steps fails; invoke the entrypoint through the project environment and install requirements into the active virtual environment. - Dependency/API compatibility can break examples at startup:
packages/examples/integrations/mongodb/python/requirements.txtallows Stagehand 4.x despite 0.3-era code, whilepackages/examples/demos/qa-agent/qa-agent/src/shared/stagehand-init.tscalls an API unavailable in its declared Stagehand version; pin compatible versions or update the code and declarations together.
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="packages/examples/templates/python/download-financial-statements/README.md">
<violation number="1" location="packages/examples/templates/python/download-financial-statements/README.md:25">
P1: Following this quickstart does not run `main.py`: `uvx` treats `stagehand` as the executable and passes `main.py` as its argument. Run the Python entrypoint through the project environment instead.</violation>
</file>
<file name="packages/examples/integrations/langchain/package.json">
<violation number="1" location="packages/examples/integrations/langchain/package.json:8">
P1: This package cannot start because `src/index.js` is ESM while `type: commonjs` makes Node parse it as CommonJS. Set the package type to `module` (or convert the entrypoint to CommonJS).</violation>
</file>
<file name="packages/examples/templates/python/browserbase-reducto/README.md">
<violation number="1" location="packages/examples/templates/python/browserbase-reducto/README.md:42">
P2: This step copies a file that the template does not include, so `cp` fails before the user can configure credentials. Add `.env.example` or replace this step with instructions to create `.env` directly.</violation>
</file>
<file name="packages/examples/demos/v4-demo-kit/src/http-server.mjs">
<violation number="1" location="packages/examples/demos/v4-demo-kit/src/http-server.mjs:32">
P1: Custom agent: **Exception and error message sanitization**
When `createSession()` or `run()` fails, this endpoint returns the upstream `error.message` verbatim, which can include Browserbase or model-provider request details. Return a fixed sanitized message from the HTTP handler and use a typed error for the startup configuration failure instead of exposing raw errors.</violation>
<violation number="2" location="packages/examples/demos/v4-demo-kit/src/http-server.mjs:36">
P1: When browser or provider cleanup rejects, this async HTTP listener rejects after sending its response, so Node 22 can terminate the demo server. Catch and log cleanup failures instead of allowing `finally` to reject the request handler.</violation>
</file>
<file name="packages/examples/demos/hacker-news-intelligence/package.json">
<violation number="1" location="packages/examples/demos/hacker-news-intelligence/package.json:25">
P1: The CommonJS build cannot load the ESM-only `chalk` 5 and `ora` 8 dependencies. Downgrade these dependencies to CommonJS-compatible majors, or migrate the entire example to ESM with matching compiler settings and import specifiers.</violation>
</file>
<file name="packages/examples/integrations/mongodb/python/requirements.txt">
<violation number="1" location="packages/examples/integrations/mongodb/python/requirements.txt:1">
P1: A fresh install can resolve Stagehand 4.x and make this example fail at import or initialization because this code uses the 0.3 API. Pin the dependency to the cataloged compatible version instead of allowing incompatible major versions.</violation>
</file>
<file name="packages/examples/integrations/box/src/browserbase.ts">
<violation number="1" location="packages/examples/integrations/box/src/browserbase.ts:43">
P2: When Browserbase returns an error, `responseError` exposes the entire provider response body through the thrown `Error`, and the caller logs that message directly. Replace the response body with a fixed sanitized message; keep provider details only in controlled internal diagnostics.</violation>
</file>
<file name="packages/examples/integrations/mongodb/python/env.example">
<violation number="1" location="packages/examples/integrations/mongodb/python/env.example:6">
P2: The setup uses `STAGEHAND_API_KEY`, but `main.py` reads `MODEL_API_KEY`, so following the README leaves the model credential as the placeholder and authentication fails. Update the setup documentation or runtime to use one canonical variable.</violation>
</file>
<file name="packages/examples/demos/configurable-browser-trial/package.json">
<violation number="1" location="packages/examples/demos/configurable-browser-trial/package.json:18">
P2: When users follow this example's `npm ci` setup, npm exits before installing anything because this standalone package has no lockfile. Commit a lockfile or change the setup to use `npm install`.</violation>
<violation number="2" location="packages/examples/demos/configurable-browser-trial/package.json:28">
P1: When users install this CLI from npm, `bin/bbpoc.mjs` cannot resolve `tsx`, so every `bbpoc` command fails before `src/cli.ts` runs. Put `tsx` in `dependencies` or publish a compiled JavaScript entrypoint.</violation>
</file>
<file name="packages/examples/integrations/mongodb/typescript/README.md">
<violation number="1" location="packages/examples/integrations/mongodb/typescript/README.md:60">
P2: The README documents reviews that this example never extracts or stores. Remove the review claims from the usage, data-model, and collection sections, or implement the missing review flow.</violation>
</file>
<file name="packages/examples/playbook/1password-extension/README.md">
<violation number="1" location="packages/examples/playbook/1password-extension/README.md:5">
P2: After `npm run upload-extension`, the generated ID must be written to `.env` before `npm start`; otherwise Stagehand starts without the uploaded extension. Document copying `.env.example` to `.env`, supplying the initial values, and inserting the printed `EXTENSION_ID` between the two commands.</violation>
</file>
<file name="packages/examples/integrations/temporal/README.md">
<violation number="1" location="packages/examples/integrations/temporal/README.md:52">
P2: The example cannot use the advertised Anthropic alternative because the activity always selects OpenAI and reads only `OPENAI_API_KEY`. Remove that option or add an actual model/provider selection before documenting it.</violation>
</file>
<file name="packages/examples/demos/qa-agent/qa-agent/.env.example">
<violation number="1" location="packages/examples/demos/qa-agent/qa-agent/.env.example:5">
P2: With the shipped value, both approaches direct the Browserbase-hosted browser to `localhost:3000`, which cannot reach the developer's local BugMart app. Use the public ngrok placeholder documented in the README.</violation>
</file>
<file name="packages/examples/integrations/temporal/.env.example">
<violation number="1" location="packages/examples/integrations/temporal/.env.example:15">
P2: When a user follows the `choose one` instruction and fills `ANTHROPIC_API_KEY`, this example still hardcodes OpenAI and ignores that key. Remove the Anthropic option or select the model and credential from the configured provider.</violation>
</file>
<file name="packages/examples/playbook/alaska-flights/searchAlaskaFlights.ts">
<violation number="1" location="packages/examples/playbook/alaska-flights/searchAlaskaFlights.ts:86">
P2: When navigation, an action, or extraction fails, this handler only logs the error and `npm start` can still report success. Set `process.exitCode = 1` or rethrow after logging.</violation>
</file>
<file name="packages/examples/integrations/agentkit/src/index.ts">
<violation number="1" location="packages/examples/integrations/agentkit/src/index.ts:119">
P2: When `searchNetwork.run` throws, execution skips the following `close-browserbase-session` step, leaving the `keepAlive` session running and billable. Put cleanup in a `finally` block and explicitly request Browserbase release.</violation>
</file>
<file name="packages/examples/templates/python/manual-mfa-with-contexts/README.md">
<violation number="1" location="packages/examples/templates/python/manual-mfa-with-contexts/README.md:23">
P1: Step 4 does not install the example’s dependencies into the activated virtual environment. Use `uv pip install -r requirements.txt` instead.</violation>
<violation number="2" location="packages/examples/templates/python/manual-mfa-with-contexts/README.md:24">
P2: Step 5 fails because this template does not include `.env.example`. Add the tracked template or instruct users to create `.env` directly.</violation>
</file>
<file name="packages/examples/demos/qa-agent/qa-agent/src/shared/stagehand-init.ts">
<violation number="1" location="packages/examples/demos/qa-agent/qa-agent/src/shared/stagehand-init.ts:22">
P1: With the QA agent’s declared `@browserbasehq/stagehand: ^2.5.2`, this call is unavailable because `page.setExtraHTTPHeaders()` was added in Stagehand 3.2.0. `npm start` reaches this line after creating the session and throws at runtime (or fails type checking); upgrade the standalone dependency to a compatible release or use a v2-supported header mechanism.</violation>
</file>
<file name="packages/examples/templates/python/context/README.md">
<violation number="1" location="packages/examples/templates/python/context/README.md:22">
P2: This quickstart cannot run: `context-template` and `requirements.txt` do not exist, and the pip commands omit declared `stagehand` and `python-dotenv` dependencies. Replace these steps with the project’s `uv` setup, for example `uv sync` followed by `uv run main.py`.</violation>
</file>
<file name="packages/examples/demos/configurable-browser-trial/src/classify.ts">
<violation number="1" location="packages/examples/demos/configurable-browser-trial/src/classify.ts:101">
P1: When the grader contradicts an explicit CAPTCHA or block signal, this branch reports `pass` and skips the page-based attribution. Evaluate the hard page signals before accepting grader success, or gate the pass on the absence of those signals.</violation>
<violation number="2" location="packages/examples/demos/configurable-browser-trial/src/classify.ts:101">
P2: When `timedOut` is true, this branch still returns `pass` whenever the grader reports success. Since `timeoutMs` is the per-attempt wall-clock budget, require `!timedOut` before accepting a pass.</violation>
</file>
<file name="packages/examples/demos/company-news-function/index.ts">
<violation number="1" location="packages/examples/demos/company-news-function/index.ts:8">
P1: The documented invocations fail schema validation because `apiKey` is required, while setup only sets `MODEL_API_KEY` and never supplies it as a parameter. Read the configured model key from the function environment or make it an explicit documented parameter, then keep the schema consistent.</violation>
<violation number="2" location="packages/examples/demos/company-news-function/index.ts:61">
P1: The agent prompt asks for JSON, but this call does not request structured output and the function never parses `message`. The documented client therefore receives no `summary`, `topLinks`, or `metadata`; add an output schema and map `result.output` into the documented response shape.</violation>
</file>
<file name="packages/examples/integrations/langchain/src/index.js">
<violation number="1" location="packages/examples/integrations/langchain/src/index.js:2">
P1: A clean install cannot resolve `@stagehand/langchain` because this standalone example does not declare it. Import `StagehandToolkit` from the declared `@langchain/community/agents/toolkits/stagehand` package, or add the missing dependency.</violation>
</file>
<file name="packages/examples/templates/python/download-financial-statements/main.py">
<violation number="1" location="packages/examples/templates/python/download-financial-statements/main.py:31">
P1: When Browserbase returns its placeholder empty ZIP while the PDFs are still pending, `payload` is already truthy, so this saves an empty archive and stops retrying. Require a real archive, such as `len(payload) > 100`, before returning.</violation>
</file>
<file name="packages/examples/integrations/agentkit/src/stagehand-tools.ts">
<violation number="1" location="packages/examples/integrations/agentkit/src/stagehand-tools.ts:14">
P1: When Browserbase session initialization fails, `getStagehand()` runs before each handler's `try`, so the tool rejects instead of returning a tool result. This skips the workflow's later session cleanup and exposes the raw provider error; catch initialization failures, return a fixed sanitized error, and preserve cleanup.
(Based on your team's feedback about sanitizing Browserbase initialization failures.)</violation>
</file>
<file name="packages/examples/templates/python/gift-finder/README.md">
<violation number="1" location="packages/examples/templates/python/gift-finder/README.md:26">
P1: This setup fails because the project has no `requirements.txt`; its dependencies, including Stagehand and `python-dotenv`, are declared in `pyproject.toml`. Replace the venv/install block with `uv sync` and activation of the resulting `.venv`.</violation>
</file>
<file name="packages/examples/demos/v4-demo-kit/src/session.mjs">
<violation number="1" location="packages/examples/demos/v4-demo-kit/src/session.mjs:15">
P1: When Browserbase launch or connection fails, `createSession` propagates the raw SDK/provider error, and the HTTP demo returns its message to callers. Put the remote launch in a cleanup boundary and throw a fixed, sanitized Browserbase initialization error instead of exposing provider details.</violation>
<violation number="2" location="packages/examples/demos/v4-demo-kit/src/session.mjs:42">
P1: Custom agent: **Exception and error message sanitization**
When Browserbase or Stagehand initialization fails, this rethrows the raw provider error, and the HTTP demo returns its message directly to the caller. Replace initialization failures with a fixed-message typed error, and use typed sanitized errors for the local validation branches instead of generic `new Error(...)`.</violation>
</file>
<file name="packages/examples/integrations/temporal/src/research-worker.ts">
<violation number="1" location="packages/examples/integrations/temporal/src/research-worker.ts:13">
P1: When a supervisor sends `SIGTERM`, this worker skips Temporal cleanup, while `SIGINT` exits before the graceful shutdown can drain. Register both signals and let `worker.run()` resolve after `worker.shutdown()` instead of forcing process exit.</violation>
</file>
<file name="packages/examples/templates/python/google-trends/main.py">
<violation number="1" location="packages/examples/templates/python/google-trends/main.py:82">
P1: Custom agent: **Exception and error message sanitization**
When Browserbase or Stagehand fails, this catch-all prints the raw exception and then re-raises it, so provider details can reach the user through output and the traceback. Use an individually typed exception with a fixed sanitized message, and keep raw provider details out of user-facing output.</violation>
</file>
<file name="packages/examples/integrations/temporal/package.json">
<violation number="1" location="packages/examples/integrations/temporal/package.json:11">
P1: When users follow the README’s `.env` setup, the worker never loads that file, so Browserbase and model credentials remain undefined and startup fails. Add a dotenv preload or an equivalent env-file flag to the entry-point scripts.</violation>
</file>
<file name="packages/examples/integrations/mongodb/typescript/package.json">
<violation number="1" location="packages/examples/integrations/mongodb/typescript/package.json:6">
P1: When users follow the README and put credentials in `.env`, `npm start` does not load that file and exits before scraping. Preload `dotenv/config` in the start script or import it before reading `process.env`.</violation>
</file>
Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
Re-trigger cubic
| }; | ||
| } catch (error) { | ||
| await browser.close(); | ||
| throw error; |
There was a problem hiding this comment.
P1: Custom agent: Exception and error message sanitization
When Browserbase or Stagehand initialization fails, this rethrows the raw provider error, and the HTTP demo returns its message directly to the caller. Replace initialization failures with a fixed-message typed error, and use typed sanitized errors for the local validation branches instead of generic new Error(...).
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At packages/examples/demos/v4-demo-kit/src/session.mjs, line 42:
<comment>When Browserbase or Stagehand initialization fails, this rethrows the raw provider error, and the HTTP demo returns its message directly to the caller. Replace initialization failures with a fixed-message typed error, and use typed sanitized errors for the local validation branches instead of generic `new Error(...)`.</comment>
<file context>
@@ -0,0 +1,44 @@
+ };
+ } catch (error) {
+ await browser.close();
+ throw error;
+ }
+}
</file context>
| "keywords": [], | ||
| "license": "ISC", | ||
| "author": "", | ||
| "type": "commonjs", |
There was a problem hiding this comment.
P1: This package cannot start because src/index.js is ESM while type: commonjs makes Node parse it as CommonJS. Set the package type to module (or convert the entrypoint to CommonJS).
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At packages/examples/integrations/langchain/package.json, line 8:
<comment>This package cannot start because `src/index.js` is ESM while `type: commonjs` makes Node parse it as CommonJS. Set the package type to `module` (or convert the entrypoint to CommonJS).</comment>
<file context>
@@ -0,0 +1,19 @@
+ "keywords": [],
+ "license": "ISC",
+ "author": "",
+ "type": "commonjs",
+ "main": "index.js",
+ "scripts": {
</file context>
| "type": "commonjs", | |
| "type": "module", |
| @@ -0,0 +1,6 @@ | |||
| stagehand>=0.3.0 | |||
There was a problem hiding this comment.
P1: A fresh install can resolve Stagehand 4.x and make this example fail at import or initialization because this code uses the 0.3 API. Pin the dependency to the cataloged compatible version instead of allowing incompatible major versions.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At packages/examples/integrations/mongodb/python/requirements.txt, line 1:
<comment>A fresh install can resolve Stagehand 4.x and make this example fail at import or initialization because this code uses the 0.3 API. Pin the dependency to the cataloged compatible version instead of allowing incompatible major versions.</comment>
<file context>
@@ -0,0 +1,6 @@
+stagehand>=0.3.0
+pymongo>=4.6.0
+pydantic>=2.0.0
</file context>
| stagehand>=0.3.0 | |
| stagehand==0.3.0 |
| "type": "module", | ||
| "scripts": { | ||
| "build": "tsc", | ||
| "start": "tsx index.ts", |
There was a problem hiding this comment.
P1: When users follow the README and put credentials in .env, npm start does not load that file and exits before scraping. Preload dotenv/config in the start script or import it before reading process.env.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At packages/examples/integrations/mongodb/typescript/package.json, line 6:
<comment>When users follow the README and put credentials in `.env`, `npm start` does not load that file and exits before scraping. Preload `dotenv/config` in the start script or import it before reading `process.env`.</comment>
<file context>
@@ -0,0 +1,24 @@
+ "type": "module",
+ "scripts": {
+ "build": "tsc",
+ "start": "tsx index.ts",
+ "postinstall": "playwright install"
+ },
</file context>
| "start": "tsx index.ts", | |
| "start": "node --import tsx --import dotenv/config index.ts", |
| "https://github.com/browserbase/stagehand/issues/new", | ||
| )}\n`, | ||
| ); | ||
| })().catch(console.error); |
There was a problem hiding this comment.
P2: When navigation, an action, or extraction fails, this handler only logs the error and npm start can still report success. Set process.exitCode = 1 or rethrow after logging.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At packages/examples/playbook/alaska-flights/searchAlaskaFlights.ts, line 86:
<comment>When navigation, an action, or extraction fails, this handler only logs the error and `npm start` can still report success. Set `process.exitCode = 1` or rethrow after logging.</comment>
<file context>
@@ -0,0 +1,86 @@
+ "https://github.com/browserbase/stagehand/issues/new",
+ )}\n`,
+ );
+})().catch(console.error);
</file context>
| })().catch(console.error); | |
| })().catch((error) => { | |
| console.error(error); | |
| process.exitCode = 1; | |
| }); |
| return session.id; | ||
| }); | ||
|
|
||
| const response = await searchNetwork.run(event.data.input, { |
There was a problem hiding this comment.
P2: When searchNetwork.run throws, execution skips the following close-browserbase-session step, leaving the keepAlive session running and billable. Put cleanup in a finally block and explicitly request Browserbase release.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At packages/examples/integrations/agentkit/src/index.ts, line 119:
<comment>When `searchNetwork.run` throws, execution skips the following `close-browserbase-session` step, leaving the `keepAlive` session running and billable. Put cleanup in a `finally` block and explicitly request Browserbase release.</comment>
<file context>
@@ -0,0 +1,141 @@
+ return session.id;
+ });
+
+ const response = await searchNetwork.run(event.data.input, {
+ state: new State({
+ data: { browserbaseSessionID },
</file context>
| 5. cp .env.example .env | ||
| 6. Add your Browserbase API key, GitHub username, and password to .env |
There was a problem hiding this comment.
P2: Step 5 fails because this template does not include .env.example. Add the tracked template or instruct users to create .env directly.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At packages/examples/templates/python/manual-mfa-with-contexts/README.md, line 24:
<comment>Step 5 fails because this template does not include `.env.example`. Add the tracked template or instruct users to create `.env` directly.</comment>
<file context>
@@ -0,0 +1,69 @@
+2. uv venv venv
+3. source venv/bin/activate # On Windows: venv\Scripts\activate
+4. uvx install stagehand browserbase python-dotenv pydantic requests
+5. cp .env.example .env
+6. Add your Browserbase API key, GitHub username, and password to .env
+7. Ensure 2FA is enabled on your GitHub test account (Settings → Password and authentication → Enable two-factor authentication)
</file context>
| 5. cp .env.example .env | |
| 6. Add your Browserbase API key, GitHub username, and password to .env | |
| 5. Create a `.env` file containing `BROWSERBASE_API_KEY`, `GITHUB_USERNAME`, and `GITHUB_PASSWORD` |
| 1. cd context-template | ||
| 2. uv venv venv | ||
| 3. source venv/bin/activate # On Windows: venv\Scripts\activate | ||
| 4. pip install -r requirements.txt | ||
| 5. pip install browserbase pydantic requests | ||
| 6. cp .env.example .env # Add your Browserbase API key and SF Rec Park credentials to .env | ||
| 7. python main.py |
There was a problem hiding this comment.
P2: This quickstart cannot run: context-template and requirements.txt do not exist, and the pip commands omit declared stagehand and python-dotenv dependencies. Replace these steps with the project’s uv setup, for example uv sync followed by uv run main.py.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At packages/examples/templates/python/context/README.md, line 22:
<comment>This quickstart cannot run: `context-template` and `requirements.txt` do not exist, and the pip commands omit declared `stagehand` and `python-dotenv` dependencies. Replace these steps with the project’s `uv` setup, for example `uv sync` followed by `uv run main.py`.</comment>
<file context>
@@ -0,0 +1,63 @@
+
+## QUICKSTART
+
+1. cd context-template
+2. uv venv venv
+3. source venv/bin/activate # On Windows: venv\Scripts\activate
</file context>
| 1. cd context-template | |
| 2. uv venv venv | |
| 3. source venv/bin/activate # On Windows: venv\Scripts\activate | |
| 4. pip install -r requirements.txt | |
| 5. pip install browserbase pydantic requests | |
| 6. cp .env.example .env # Add your Browserbase API key and SF Rec Park credentials to .env | |
| 7. python main.py | |
| 1. uv sync | |
| 2. cp .env.example .env # Add your Browserbase API key and SF Rec Park credentials to .env | |
| 3. uv run main.py |
| }; | ||
| } | ||
|
|
||
| if (graderSuccess && !graderBlocked) { |
There was a problem hiding this comment.
P2: When timedOut is true, this branch still returns pass whenever the grader reports success. Since timeoutMs is the per-attempt wall-clock budget, require !timedOut before accepting a pass.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At packages/examples/demos/configurable-browser-trial/src/classify.ts, line 101:
<comment>When `timedOut` is true, this branch still returns `pass` whenever the grader reports success. Since `timeoutMs` is the per-attempt wall-clock budget, require `!timedOut` before accepting a pass.</comment>
<file context>
@@ -0,0 +1,145 @@
+ };
+ }
+
+ if (graderSuccess && !graderBlocked) {
+ return { outcome: "pass", detected, reason: "Task completed and success criteria met." };
+ }
</file context>
| if (graderSuccess && !graderBlocked) { | |
| if (!timedOut && graderSuccess && !graderBlocked) { |
why
Stagehand examples are spread across templates, playbooks, integrations, and demo projects. This change gives developers a flat catalog under
packages/examples, with one directory per example and language variants inside it. Existing framework integrations remain the canonical starting points for frameworks already covered inpackages/integrations.what changed
templates/,integrations/,playbook/, ordemos/category directories underpackages/examples.packages/integrations. That directory's implementation files are unchanged. The remaining imported integration examples demonstrate additional workflows or adapters.cdcommands. Preserve the imported license notice atpackages/examples/LICENSE.stagehand-demo-kitpackage name to satisfy the existing retired-package-identity check.packages/skills/README.mdlinking to the external Browserbase skill collections; the browse.sh catalog is tracked separately in browserbase/skills#158.The selection excludes customer-specific workflows, saved account/browser state, private research, and captured output. Synthetic/demo values remain where documented. Existing source repositories remain unchanged.
resulting layout
validation
Validated the flattened tree:
cdcommands resolve. Retained source/configuration files match the audited imports byte-for-byte, except the demo-kit package name; documentation was updated for the layout.pnpm lint, standalone example lint, formatting, and Git whitespace checks pass. Lint retains inherited warnings.npm run checkinpackages/examples/v4-demo-kitpasses entry-point syntax checks and all 4 tests.zod/v4dependency resolution. CI must verify those suites in a clean installation.Individual example typechecks and complete live browser/service workflows have not all been run. This PR consolidates the source collection and does not certify every integration or migrate every example to v4.
example inventory and customer-PII confidence
Assessment refreshed 2026-09-15, for PR head
5f4478a0c66c1fe76514340c6914016f7b054212. These are 66 retained imported entries in 42 example directories; TypeScript/Python template variants appear separately. MongoDB and 1Password each retain multiple runtimes within one entry.The percentages are my subjective confidence that the committed files contain no hard-coded real customer PII, customer credentials/account identifiers, private customer tenant URLs, or private customer-specific workflows. They are coarse reviewer judgments, not calibrated statistical probabilities or a security certification. Public websites, public support contacts, synthetic names, reserved-domain emails, and illustrative/test values are not classified as customer PII. No entry is assigned 100%.
Scores carry forward the earlier source-selection/manual audit, with renewed checks of the retained file inventory, relocated links, source hashes, and secrets. Secret scanning cannot detect every form of PII. No actual customer secret or private customer record was identified in the selected files.
Scope: the current imported file snapshot, excluding repository history, third-party dependencies, live websites, remotely fetched assets, and runtime logs/results. Both
contextvariants extract the authenticated user's name and address when run; MFA/context/1Password/booking flows use runtime credentials or account state. These scores do not measure runtime privacy or functional correctness. The existing CrewAI, DeepAgents, and Mastra implementations linked from the catalog, and the external skills collection, are outside this imported-file assessment.packages/examples