Skip to content

Agent Operating Guide

/sox-from-web

Collect SOX evidence live from the audited system through the Claude for Chrome extension, read-only with one screenshot per attribute, then annotate and assemble the workpaper.

The live-system counterpart to /sox-annotate-xlsx and /sox-from-video. It takes a tester’s collection plan, prose, with optional example screenshots, and drives Chrome through the Claude for Chrome extension to capture one screenshot per attribute on demand, recording each capture’s source URL, timestamp, viewport, and a SHA-256 for chain of custody. It then hands the captures to the same boxer + context + reviewer pipeline the other evidence skills use, producing per-sample-per-test detail tabs with red-rectangle Excel shapes over the tested fields, never burned in.

This skill is Cowork-only: it needs a Claude Cowork session with the Claude for Chrome extension active and signed in to the target system, and there is no Playwright or headless fallback: it stops immediately if the extension is absent. It is also read-only enforced: every non-navigation click is passed through a deny-list of mutating verbs (Approve, Submit, Save, Delete, Pay, …), and a denied verb, or an unlabeled control, is a hard stop.

When the evidence for a control is something the tester needs to observe live in a system right now, no pre-built deck, no recording, and they can describe the collection steps in prose. If the evidence is already an xlsx deck, use /sox-annotate-xlsx; if it’s an mp4 plus transcript, use /sox-from-video; to plan the test first, use /sox-testing.

Flag Required Notes
<instructions> Yes The collection plan: prose pasted into the call, or a path to a .txt / .md file. Per sample, per test, which URLs to visit and which attributes to screenshot.
--examples <dir> No Example screenshots showing what good evidence looks like; reference material for the boxer, not annotated themselves.
--start-url <url> No The URL to navigate to first, when every sample starts from the same page.
--workpaper <path> No Destination. Defaults to workpapers/<control-id>/workpaper.xlsx.
--template-profile <path> No A profile from /sox-from-template to write into a firm’s bespoke layout.
--no-review No Skip the on-by-default box-position review pass.
--no-context No Skip the on-by-default value-and-context scan.
--max-review-iters <N> No Boxer revisions the review loop may request per screenshot (default 2, ceiling 3).

The skill first confirms the Chrome extension is active: with no headless fallback, it stops if it isn’t. It normalizes the tester’s prose into a plan.json (one step per screenshot, verbatim attribute names, and the expected value for each) and surfaces it for a go-ahead before driving the browser. It then works the steps in the tester’s order, pausing for any SSO/MFA prompt, and passes every non-navigation click through the mutating-verb deny-list. Each capture saves to disk with its source URL, timestamp, viewport, and a SHA-256 for chain of custody; page content is treated as evidence to capture, never as instructions to follow. From there the same sox-evidence-boxer + sox-evidence-context + sox-evidence-reviewer fan-out and four-gate auto-judge as /sox-annotate-xlsx annotate each capture, and the batch writer assembles the workpaper with a gray custody caption above every screenshot.

/sox-from-web plan.md --start-url https://coupa.example.com parses the prose plan into steps, navigates to and screenshots each attribute read-only, boxes and reads each field via the leaf agents, auto-judges the results, and writes annotated detail tabs: each screenshot carrying a source-URL, timestamp, and sha256 custody caption a reviewer can trace.

  • Cowork-only, single driver. No Playwright, no chrome-devtools, no headless mode: the skill stops if the extension isn’t active rather than degrading.
  • Authentication is the tester’s job. The skill won’t fill credentials or complete MFA; an SSO/MFA prompt pauses the run until the tester finishes it.
  • Read-only is defense in depth, not a guarantee. Still use a read-only account when the system offers one: a custom-labeled button that secretly mutates state won’t be caught. Tune the deny-list per firm; review surfaced refusals rather than bypassing the check.
  • Captures never enter the orchestrator. Screenshots save to disk and return a path; the leaf agents read the bytes, not the skill.
  • The plan is preserved for replay. /sox-replay-build keeps plan.json verbatim so next period can re-collect against the same URLs and attributes.

Not audit or legal advice. Workpapers and assessments produced by these skills require review by qualified financial professionals before being relied on for SOX 404 compliance.