agentCLAWHUBUnverified

web-browser

Environment-aware browser operations. Detects wmux/cmux/tmux and routes to backend. Topics — ui-test (snapshots, click/fill, shadow DOM), credential-issue (login via backend -> wait sign-in -> issue/refresh token/secret). Use when: "browser", "web-browser", "ui-test", "credential-issue", "playwright", "chrome-devtools", "UI check", "browser test", "screen verify", "Playwright test", "shadow DOM cascade", "::part not working", "CDP trace", "issue token", "service credential", "open login screen", "PAT refresh", "scope expansion", "device-code auth", "browser device-code", "GitHub social login".

OpenClaw

Rank

62

Safety

84

Downloads

1.7k

Updated

Oct 10, 2026

Version

0.2.10

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.7K downloadsadoption · observed Oct 10, 2026
Latest release
0.2.10release · observed Oct 6, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17ay1v6v88r2m102pvvc44gz183qcrm:web-browser
  1. Install using `clawhub skill install s17ay1v6v88r2m102pvvc44gz183qcrm:web-browser` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/drumrobot/web-browser before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-web-browser/snapshot"

Documentation

CLAWHUB

147,879 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: web-browser
metadata:
  author: es6kr
  version: "0.1.0"
description: |
  Environment-aware browser operations. Detects wmux/cmux/tmux and routes to backend. Topics — ui-test (snapshots, click/fill, shadow DOM), credential-issue (login via backend -> wait sign-in -> issue/refresh token/secret). Use when: "browser", "web-browser", "ui-test", "credential-issue", "playwright", "chrome-devtools", "UI check", "browser test", "screen verify", "Playwright test", "shadow DOM cascade", "::part not working", "CDP trace", "issue token", "service credential", "open login screen", "PAT refresh", "scope expansion", "device-code auth", "browser device-code", "GitHub social login".
---

# Web Browser

Environment-aware browser operations skill. Detects the runtime environment and routes to the
appropriate browser backend, then runs one of two workflows: UI testing/verification (`ui-test`) or
browser-login-assisted credential issuance (`credential-issue`).

## Topics

| Topic | Description | Guide |
|-------|-------------|-------|
| ui-test | Snapshot analysis, click/fill/verify, page-state diagnosis | [ui-test.md](./ui-test.md) |
| cdp-trace | CDP-based closed shadow DOM cascade diagnosis (DOM.getDocument pierce:true + CSS.getMatchedStylesForNode) | [cdp-trace.md](./cdp-trace.md) |
| credential-issue | service+command param → open login screen → wait for user login → issue access key/token/secret → hand off to automation | [credential-issue.md](./credential-issue.md) |

## Topic Dependencies

```
web-browser (Step 0: environment detection — shared by all topics)
  ├─→ ui-test (UI verification)
  │     └─→ cdp-trace (extends ui-test for closed shadow DOM)
  └─→ credential-issue (browser-login-assisted token/key issuance)
        └─→ chrome-devtools backend preferred (reuses the user's real logged-in session)
```

- **Step 0 (below) is shared** — every topic detects the backend first, then runs its workflow.
- `ui-test`, `cdp-trace` are the UI-testing family.
- `credential-issue` reuses the same backend routing + the user-visibility rule, generalized into a
  service+command parameterized auth flow.
- **Authentik SSO verification** (`sso-verify`) is **not** included in this skill — it remains in a
  separate local-only `sso-verify` skill (user-environment specific, untracked).

## CRITICAL — capturing a credential-input screen requires an explicit ask (HARD STOP)

**Before capturing a sign-in / credential-input screen — accessibility snapshot, screenshot, or any
full page-content read — call `AskUserQuestion` and get explicit approval.** Applies to every topic
in this skill and to every backend.

The reason is not privacy etiquette, it is a measured leak path: a browser profile's saved-password
autofill populates the password field, and the accessibility tree renders that field's **value in
plaintext**. The capture therefore carries a live credential into the transcript even though nothing
was typed and no screenshot of characters was taken. `document.bo

_meta.json

{
  "ownerId": "kn74k8yfvftx6f062qa8fzyd8h8373jd",
  "slug": "web-browser",
  "version": "0.2.10",
  "publishedAt": 1791273349382
}

cdp-trace.md

# CDP Trace — Closed Shadow DOM Cascade Diagnosis

Extract the computed style + matched CSS rules of elements inside a closed shadow DOM directly via the Chrome DevTools Protocol (CDP). Identifies which stylesheet is the actual carrier and verifies cascade entry when `::part(...)` outer-scope selectors fail to apply.

## When to use

- Outer `::part(<name>) { ... }` rules visually have no effect
- You need the computed style of an element inside a closed shadow DOM
- You need to identify the carrier (outer document vs shadow-root inject)
- You need to verify the cascade for `[part="..."]` direct selectors on a web component

## Mechanism

`DOM.getDocument({ depth: -1, pierce: true })` of the Chrome DevTools Protocol (Playwright `newCDPSession`) returns the full DOM tree **including closed shadow roots**. For each `nodeId`, call `CSS.getComputedStyleForNode` + `CSS.getMatchedStylesForNode` to dump the applied rules and the rules that were ignored.

## Quick Reference

```bash
# 1. Install playwright into .tmp/ and pull headed chromium
cd <repo>/.tmp && npm init -y && npm install playwright@latest
npx playwright install chromium

# 2. Run cdp-trace.js (user-visible browser)
# --parts (canonical, plural) and --part (legacy singular) are both accepted;
# the script tolerates either form to match the historical Quick Reference example.
node scripts/cdp-trace.js --url http://<target>/<path> --parts "app-group,card-wrapper"
```

## Script pattern

```javascript
const { chromium } = require('playwright');

(async () => {
  // headless: false — user-visible (per web-browser SKILL.md Step 0 user-visibility rule)
  const browser = await chromium.launch({ headless: false, slowMo: 800 });
  const page = await browser.newContext({ ignoreHTTPSErrors: true, viewport: null }).then(c => c.newPage());

  await page.goto(URL, { waitUntil: 'domcontentloaded' });
  // (handle login / auth as needed)

  const cdp = await page.context().newCDPSession(page);
  await cdp.send('DOM.enable');
  await cdp.send('CSS.enable');

  // pierce:true — expose closed shadow roots as well
  const { root } = await cdp.send('DOM.getDocument', { depth: -1, pierce: true });

  // Recursive walk — collect every element carrying a part attribute
  function walk(node, found = []) {
    if (!node) return found;
    const attrs = node.attributes || [];
    const partIdx = attrs.findIndex((v, i) => i % 2 === 0 && v === 'part');
    if (partIdx >= 0) {
      found.push({ id: node.nodeId, name: node.nodeName, part: attrs[partIdx + 1] });
    }
    if (node.children) node.children.forEach(c => walk(c, found));
    if (node.shadowRoots) node.shadowRoots.forEach(s => walk(s, found));
    return found;
  }
  const parts = walk(root);

  for (const p of parts.filter(p => TARGET_PARTS.includes(p.part))) {
    const cs = await cdp.send('CSS.getComputedStyleForNode', { nodeId: p.id });
    const matched = await cdp.send('CSS.getMatchedStylesForNode', { nodeId: p.id });

    console.log(`[part="${p.part}"

CHANGELOG.md

# Changelog

## [0.2.10](https://github.com/es6kr/skills/compare/web-browser-v0.2.9...web-browser-v0.2.10) (2026-10-04)


### Bug Fixes

* **web-browser:** resolve host OS layer before backend, scope CDP-hostile table per host ([#571](https://github.com/es6kr/skills/issues/571)) ([1bd3d66](https://github.com/es6kr/skills/commit/1bd3d662c7b29a82322476f36c9aba7dfb485295))

## [0.2.9](https://github.com/es6kr/skills/compare/web-browser-v0.2.8...web-browser-v0.2.9) (2026-09-18)


### Bug Fixes

* **cleanup:** make the session-end report table self-sufficient ([#487](https://github.com/es6kr/skills/issues/487)) ([c4a0255](https://github.com/es6kr/skills/commit/c4a02557fb8de3b32cf337c549f62535dabf824b))

## [0.2.8](https://github.com/es6kr/skills/compare/web-browser-v0.2.7...web-browser-v0.2.8) (2026-08-26)


### Bug Fixes

* accumulate 16 patch-level bug fixes and guard enhancements across skills ([d214e5d](https://github.com/es6kr/skills/commit/d214e5dcc7fac1bc07baf3b6cec62999aea732f0))
* **core:** align workflow steps, next suggestion patterns, and browser topics ([c68d489](https://github.com/es6kr/skills/commit/c68d489d01a79862b8933b4a0542168cf676cd3a))
* promote next-fix batch (consolidate fabrication guard, session rewind, config-driven PR base) ([7ca0ccb](https://github.com/es6kr/skills/commit/7ca0ccbf13cefafedc33a16a7361756c95f8b8f6))

## [0.2.7](https://github.com/es6kr/skills/compare/web-browser-v0.2.6...web-browser-v0.2.7) (2026-08-17)


### Bug Fixes

* promote next-fix staging (30 fixes across 14 skills) ([ee467c0](https://github.com/es6kr/skills/commit/ee467c045d779d7b80d30f160763ec3534a9742b))
* **web-browser:** credential-issue backend routing — session-existence gate + account-mismatch rule ([e5a9098](https://github.com/es6kr/skills/commit/e5a90986812c90b101a24554f3de9038a59906b4))
* **web-browser:** document virtualized table bulk row operation pattern ([c5bc8f0](https://github.com/es6kr/skills/commit/c5bc8f0610263a963e8a75bfd30f36f2a5dafa76))
* **wip:** cross-ref PR-URL and TaskCreate subject repo-qualifier rules ([#186](https://github.com/es6kr/skills/issues/186)) ([4982364](https://github.com/es6kr/skills/commit/49823641a7b08123ebd0325273892bee41bc3280))

## [0.2.6](https://github.com/es6kr/skills/compare/web-browser-v0.2.5...web-browser-v0.2.6) (2026-08-09)


### Bug Fixes

* **consolidate:** address CodeRabbit/Copilot review findings on PR [#270](https://github.com/es6kr/skills/issues/270) ([3b11a73](https://github.com/es6kr/skills/commit/3b11a730b5ad68803d35a8264eda540e48265d75))
* promote accumulated next-fix fixes to main ([95656e9](https://github.com/es6kr/skills/commit/95656e9b551ee0bb77904a0a571d49c53bc01cc9))
* **web-browser:** add revoke command type to credential-issue topic ([306cf63](https://github.com/es6kr/skills/commit/306cf63752638d2cae7b924978cb036467382b00))
* **web-browser:** add revoke command type to credential-issue topic ([cbd7121](https://github.com/es6kr/skills/commit/cbd712145d6faf293409df956706b1afae8ef9

credential-issue.md

# Credential Issue (web-browser topic)

Take a **service** + **command** as parameters, open the service's login screen via the detected
browser backend, wait for the user to sign in, then on a completion signal **issue the requested
access key / token / secret** and hand the result to follow-up automation (aws-cli upload, `gh secret
set`, terraform var injection, etc.).

This generalizes the "open the page + user interaction + collect the result" pattern into a reusable
parameterized flow. It is the credential-issuance counterpart to [ui-test.md](./ui-test.md).

## Parameters

| Param | Meaning | Example |
|-------|---------|---------|
| `service` | The provider whose console issues the credential | `google-forms`, `cloudflare-r2`, `github`, `oci`, `aws`, `authentik` |
| `command` | What to issue / do once logged in | `issue Google API OAuth token`, `issue R2 S3 token`, `issue fine-grained PAT`, `revoke <key-id>` (see "Revoke flow" below) |
| `login-url` | Direct URL to the issuance page (when known) | `https://console.cloud.google.com/apis/credentials`, `https://dash.cloudflare.com/?to=/:account/r2/api-tokens` |
| `handoff` | Follow-up automation to run with the issued credential | `gcloud auth print-access-token`, `aws s3 cp`, `gh secret set` |

## Backend selection (Step 0 + credential-specific preference)

Detect the backend via **SKILL.md Step 0** first. For credential issuance the preference order
differs from ui-test, because the user must **sign in** and reusing their real logged-in session is
fastest:

| Priority | Backend | Why | When |
|----------|---------|-----|------|
| 1 | **chrome-devtools** (real session) | Reuses the user's already-logged-in browser session — often no login needed | `chrome-devtools-mcp` connected **AND the instance actually holds a logged-in session** (see session-existence gate below) |
| 2 | **Default browser** (`Start-Process <url>` / `open <url>`) | Opens the user's real browser (real session, fully interactive) | login-required + chrome-devtools absent |
| 3 | **wmux/cmux panel** | User-visible panel, interactive | `$WMUX` / `$CMUX_SESSION` set |
| 4 | Playwright MCP | **Last resort** — invisible window, user cannot log in interactively | only when a persisted/automated session already exists (no fresh login needed) |

**Session-existence gate (HARD STOP — the priority column is conditional routing, not a fixed
ranking)**: each priority's "Why" is its **applicability condition**. chrome-devtools ranks 1st
*because* it reuses a real logged-in session — an MCP-launched instance whose `list_pages` shows only
`about:blank` (or whose target page redirects to a login screen) has **no session to reuse**, so the
rank-1 rationale is void and a backend that *does* hold a session (e.g., an already-open cmux panel)
outranks it. Before switching backends mid-flow, verify the destination backend actually holds a
logged-in session; if it does not, the switch buys nothing and costs the user a fresh login plus a
second br
Github ReposUpdated 15h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/drumrobot/skills/web-browser",
      "sourceUrl": "https://clawhub.ai/drumrobot/skills/web-browser",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T05:13:16.327Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-web-browser/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-web-browser/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T05:13:16.327Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.7K downloads",
      "href": "https://clawhub.ai/drumrobot/web-browser",
      "sourceUrl": "https://clawhub.ai/drumrobot/web-browser",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T05:13:16.327Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.2.10",
      "href": "https://clawhub.ai/drumrobot/web-browser",
      "sourceUrl": "https://clawhub.ai/drumrobot/web-browser",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-06T07:55:49.382Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-web-browser/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-web-browser/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.2.10",
      "description": "web-browser v0.2.10 - Added explicit privacy gate: always ask for user approval before capturing any credential-input or sign-in screen (accessibility snapshot, screenshot, or full content read). - Clarified self-checks and table guidance for credential field leaks (browser autofill → accessibility tree plaintext). - Condensed and focused top-level skill description for quicker understanding. - Updated documentation for credential-issue: hardened workflow routing and visibility priorities. - Removed obsolete skill-card.md file.",
      "href": "https://clawhub.ai/drumrobot/web-browser",
      "sourceUrl": "https://clawhub.ai/drumrobot/web-browser",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-06T07:55:49.382Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to web-browser and adjacent AI workflows.