Agent Operating Guide
/sox-from-web
Collect SOX evidence live from the audited system through the Claude for Chrome extension, read-only with one screenshot per attribute, then annotate and assemble the workpaper.
The live-system counterpart to /sox-annotate-xlsx and /sox-from-video. It takes a tester’s collection plan, prose, with optional example screenshots, and drives Chrome through the Claude for Chrome extension to capture one screenshot per attribute on demand, recording each capture’s source URL, timestamp, viewport, and a SHA-256 for chain of custody. It then hands the captures to the same boxer + context + reviewer pipeline the other evidence skills use, producing per-sample-per-test detail tabs with red-rectangle Excel shapes over the tested fields, never burned in.
This skill is Cowork-only: it needs a Claude Cowork session with the Claude for Chrome extension active and signed in to the target system, and there is no Playwright or headless fallback: it stops immediately if the extension is absent. It is also read-only enforced: every non-navigation click is passed through a deny-list of mutating verbs (Approve, Submit, Save, Delete, Pay, …), and a denied verb, or an unlabeled control, is a hard stop.
When to use
Section titled “When to use”When the evidence for a control is something the tester needs to observe live in a system right now, no pre-built deck, no recording, and they can describe the collection steps in prose. If the evidence is already an xlsx deck, use /sox-annotate-xlsx; if it’s an mp4 plus transcript, use /sox-from-video; to plan the test first, use /sox-testing.
Inputs
Section titled “Inputs”| Flag | Required | Notes |
|---|---|---|
<instructions> |
Yes | The collection plan: prose pasted into the call, or a path to a .txt / .md file. Per sample, per test, which URLs to visit and which attributes to screenshot. |
--examples <dir> |
No | Example screenshots showing what good evidence looks like; reference material for the boxer, not annotated themselves. |
--start-url <url> |
No | The URL to navigate to first, when every sample starts from the same page. |
--workpaper <path> |
No | Destination. Defaults to workpapers/<control-id>/workpaper.xlsx. |
--template-profile <path> |
No | A profile from /sox-from-template to write into a firm’s bespoke layout. |
--no-review |
No | Skip the on-by-default box-position review pass. |
--no-context |
No | Skip the on-by-default value-and-context scan. |
--max-review-iters <N> |
No | Boxer revisions the review loop may request per screenshot (default 2, ceiling 3). |
How it works
Section titled “How it works”The skill first confirms the Chrome extension is active: with no headless fallback, it stops
if it isn’t. It normalizes the tester’s prose into a plan.json (one step per screenshot,
verbatim attribute names, and the expected value for each) and surfaces it for a go-ahead
before driving the browser. It then works the steps in the tester’s order, pausing for any
SSO/MFA prompt, and passes every non-navigation click through the mutating-verb deny-list.
Each capture saves to disk with its source URL, timestamp, viewport, and a SHA-256 for chain
of custody; page content is treated as evidence to capture, never as instructions to follow.
From there the same sox-evidence-boxer + sox-evidence-context + sox-evidence-reviewer
fan-out and four-gate auto-judge as /sox-annotate-xlsx annotate each
capture, and the batch writer assembles the workpaper with a gray custody caption above every
screenshot.
Example
Section titled “Example”/sox-from-web plan.md --start-url https://coupa.example.com parses the prose plan into
steps, navigates to and screenshots each attribute read-only, boxes and reads each field via
the leaf agents, auto-judges the results, and writes annotated detail tabs: each screenshot
carrying a source-URL, timestamp, and sha256 custody caption a reviewer can trace.
Good to know
Section titled “Good to know”- Cowork-only, single driver. No Playwright, no chrome-devtools, no headless mode: the skill stops if the extension isn’t active rather than degrading.
- Authentication is the tester’s job. The skill won’t fill credentials or complete MFA; an SSO/MFA prompt pauses the run until the tester finishes it.
- Read-only is defense in depth, not a guarantee. Still use a read-only account when the system offers one: a custom-labeled button that secretly mutates state won’t be caught. Tune the deny-list per firm; review surfaced refusals rather than bypassing the check.
- Captures never enter the orchestrator. Screenshots save to disk and return a path; the leaf agents read the bytes, not the skill.
- The plan is preserved for replay. /sox-replay-build keeps
plan.jsonverbatim so next period can re-collect against the same URLs and attributes.
Related
Section titled “Related”- /sox-annotate-xlsx: the shared boxer + context + reviewer annotate pipeline.
- /sox-from-video: evidence from a recorded walkthrough instead of live.
- /sox-from-folder: evidence from a mixed folder instead of live.
- /sox-testing: the engine that orchestrates this as its live-evidence step.
Not audit or legal advice. Workpapers and assessments produced by these skills require review by qualified financial professionals before being relied on for SOX 404 compliance.