Update SKILL.md with Web Bot Auth browsing instructions#111
Open
nvp-stripe wants to merge 2 commits into
Open
Conversation
danhill-stripe
approved these changes
May 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Updates
skills/create-payment-credential/SKILL.mdso agents know about Web Bot Auth and use it correctly. Three targeted additions to the existing skill file:Step 2: bot protection during browsing: new subsection after the credential-type table explaining what to do when the merchant site returns 403. Agents are told to call
web-bot-auth sign <url>and attach the returnedSignatureandSignature-Inputheaders to their HTTP requests.Step 5:
mpp payauto-bypass: updated description ofmpp payto tell agents that 403 (bot protection) is handled automatically before the 402 flow no manualweb-bot-auth signcall is needed when usingmpp pay.Errors table: two new rows: recovery guidance for (a) 403 during merchant browsing in Step 2, and (b) the
Received 403 before and after Web Bot Auth retryerror frommpp pay, which signals the merchant is blocking for a non-bot-protection reason.Motivation
Without this update, the SKILL.md that agents load has no mention of bot protection. An agent following the current skill would:
mpp payhandles 403 transparently, potentially trying to manually sign and inject headers before callingmpp pay(redundant work).Received 403 before and after Web Bot Auth retryerror frommpp paywith no understanding of what it means or what to do next.The SKILL.md is the canonical source of truth that LLMs use to reason about Link. Code without a skill update ships dead capability: agents won't use what they can't discover.