web-access
Universal web access skill: search, fetch, browser automation via CDP Proxy. Handles login-required sites, anti-scraping bypasses, and complex web interactions. Skill: web-access Owner: eze-is Summary: Universal web access skill: search, fetch, browser automation via CDP Proxy. Handles login-required sites, anti-scraping bypasses, and complex web interactions. Tags: latest:2.5.4 Version history: v2.5.4 | 2026-09-29T10:18:25.332Z | user Sync with eze-is/web-access v2.5.4: CDP Proxy keeps a single long-lived browser connection (one remote-debugging approval), Chrome/Edge brows
Rank
62
Safety
84
Downloads
6.0k
Updated
Oct 9, 2026
Version
2.5.4
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 6K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 6K downloadsadoption · observed Oct 9, 2026
- Latest release
- 2.5.4release · observed Sep 29, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s1722g64sh9m2b0dbwsx9tk4z983w421:web-access- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-eze-is-web-access/snapshot"
Documentation
CLAWHUB
32,323 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: web-access
description: "Universal web access skill: search, fetch, browser automation via CDP Proxy. Handles login-required sites, anti-scraping bypasses, and complex web interactions."
version: 2.5.4
homepage: https://github.com/eze-is/web-access
metadata:
openclaw:
emoji: "🌐"
homepage: https://github.com/eze-is/web-access
requires:
bins: ["node", "curl"]
---
# web-access Skill
## 前置检查
在开始联网操作前,先检查 CDP 模式可用性:
```bash
node "{baseDir}/scripts/check-deps.mjs"
```
**Node.js 22+** 必需(使用原生 WebSocket)。
按脚本输出处理:
- `exit 0` → 继续
- `exit 2` → 需询问用户偏好,写入 `{baseDir}/config.env` 的 `WEB_ACCESS_BROWSER`
- `exit 1` → 按 stdout 错误信息处理。若提示包含「Agent 处理顺序」,按其步骤执行(如先用系统命令打开浏览器后重跑),自动可解则不打扰用户;仍失败再向用户求助
支持参数 `--browser <chrome|edge>` 表达本次临时覆盖(不写 config.env)。
切换浏览器时,proxy 是长驻进程,需先 `pkill -f cdp-proxy.mjs` 再重跑 check-deps。
检查通过后并必须在回复中向用户直接展示以下须知,再启动 CDP Proxy 执行操作:
```
温馨提示:部分站点对浏览器自动化操作检测严格,存在账号封禁风险。已内置防护措施但无法完全避免,Agent 继续操作即视为接受。
```
## 浏览哲学
**像人一样思考,兼顾高效与适应性的完成任务。**
执行任务时不会过度依赖固有印象所规划的步骤,而是带着目标进入,边看边判断,遇到阻碍就解决,发现内容不够就深入——全程围绕「我要达成什么」做决策。这个 skill 的所有行为都应遵循这个逻辑。
**① 拿到请求** — 先明确用户要做什么,定义成功标准:什么算完成了?需要获取什么信息、执行什么操作、达到什么结果?这是后续所有判断的锚点。
**② 选择起点** — 根据任务性质、平台特征、达成条件,选一个最可能直达的方式作为第一步去验证。一次成功当然最好;不成功则在③中调整。比如,需要操作页面、需要登录态、已知静态方式不可达的平台(小红书、微信公众号等)→ 直接 CDP
**③ 过程校验** — 每一步的结果都是证据,不只是成功或失败的二元信号。用结果对照①的成功标准,更新你对目标的判断:路径在推进吗?结果的整体面貌(质量、相关度、量级)是否指向目标可达?发现方向错了立即调整,不在同一个方式上反复重试——搜索没命中不等于"还没找对方法",也可能是"目标不存在";API 报错、页面缺少预期元素、重试无改善,都是在告诉你该重新评估方向。遇到弹窗、登录墙等障碍,判断它是否真的挡住了目标:挡住了就处理,没挡住就绕过——内容可能已在页面 DOM 中,交互只是展示手段。
**④ 完成判断** — 对照定义的任务成功标准,确认任务完成后才停止,但也不要过度操作,不为了"完整"而浪费代价。
## 联网工具选择
- **确保信息的真实性,一手信息优于二手信息**:搜索引擎和聚合平台是信息发现入口。当多次搜索尝试后没有质的改进时,升级到更根本的获取方式:定位一手来源(官网、官方平台、原始页面)。
| 场景 | 工具 |
|------|------|
| 搜索摘要或关键词结果,发现信息来源 | **WebSearch** |
| URL 已知,需要从页面定向提取特定信息 | **WebFetch**(拉取网页内容,由小模型根据 prompt 提取,返回处理后结果) |
| URL 已知,需要原始 HTML 源码(meta、JSON-LD 等结构化字段) | **curl** |
| 非公开内容,或已知静态层无效的平台(小红书、微信公众号等公开内容也被反爬限制) | **浏览器 CDP**(直接,跳过静态层) |
| 需要登录态、交互操作,或需要像人一样在浏览器内自由导航探索 | **浏览器 CDP** |
浏览器 CDP 不要求 URL 已知——可从任意入口出发,通过页面内搜索、点击、跳转等方式找到目标内容。WebSearch、WebFetch、curl 均不处理登录态。
**Jina**(可选预处理层,可与 WebFetch/curl 组合使用,由于其特性可节省 tokens 消耗,请积极在任务合适时组合使用):第三方网络服务,可将网页转为 Markdown,大幅节省 token 但可能有信息损耗。调用方式为 `r.jina.ai/example.com`(URL 前加前缀,不保留原网址 http 前缀),限 20 RPM。适合文章、博客、文档、PDF 等以正文为核心的页面;对数据面板、商品页等非文章结构页面可能提取到错误区块。
进入浏览器层后,`/eval` 就是你的眼睛和手:
- **看**:用 `/eval` 查询 DOM,发现页面上的链接、按钮、表单、文本内容——相当于「看看这个页面有什么」
- **做**:用 `/click` 点击元素、`/scroll` 滚动加载、`/eval` 填表提交——像人一样在页面内自然导航
- **读**:用 `/eval` 提取文字内容,判断图片/视频是否承载核心信息——是则提取媒体 URL 定向读取或 `/screenshot` 视觉识别
浏览网页时,**先了解页面结构,再决定下一步动作**。不需要提前规划所有步骤。
### 页面就绪与完成判断
`/new` 或 `/navigate` 返回,只代表浏览器完成了当前文档的基础加载,不代表用户需要的内容已经出现。HTTP 200、`document.readyState === "complete"`、页面标题出现或导航调用成功,都不能单独作为任务完成标准。
导航后先用 `/eval` 检查目标内容。若目标内容尚未出现,而页面仍是空白、加载态、验证页、登录跳转或其它可能继续变化的中间状态,在默认 15 秒窗口内持续观察 URL、标题和 DOM;页面发生跳转或内容变化后重新判断。只有目标内容已经获取,或观察窗口结束后仍存在明确阻碍,才能继续提取或报告失败。
站点经验可以提供更精确的选择器、等待条件和已知中间状态,但只用于加速判断;即使没有站点经验,也必须遵循上述目标内容就绪规则。
### 补充:本地浏览器资源
用户指向_meta.json
{
"ownerId": "kn74f55swpt9tytwph21yra4qh83x4m9",
"slug": "web-access",
"version": "2.5.4",
"publishedAt": 1790677105332
}references/cdp-api.md
# CDP Proxy API 参考
## 基础信息
- 地址:`http://localhost:3456`
- 启动:`node {baseDir}/scripts/cdp-proxy.mjs &`
- 启动后持续运行,不建议主动停止(重启需 Chrome 重新授权)
- 强制停止:`pkill -f cdp-proxy.mjs`
## API 端点
### GET /health
健康检查,返回连接状态。
```bash
curl -s http://localhost:3456/health
```
### GET /targets
列出所有已打开的页面 tab。返回数组,每项含 `targetId`、`title`、`url`。
```bash
curl -s http://localhost:3456/targets
```
### POST /new
创建新后台 tab。Proxy 会先创建 `about:blank`、完成 CDP attach,再显式导航并等待目标 URL 的 DOM 至少进入 `interactive`,避免把新标签页初始的空白文档误判为目标页面。**URL 通过 POST body 原样传入**,无需 URL-encode、不会因 query 中含 `&` 被切分。返回 `{ targetId }`。
```bash
curl -s -X POST --data-raw 'https://example.com' http://localhost:3456/new
# 含 query 的目标 URL(如带 token 的小红书笔记)也直接原样传:
curl -s -X POST --data-raw 'https://www.xiaohongshu.com/explore/xxx?xsec_source=app_share&xsec_token=ABC&type=normal' http://localhost:3456/new
```
> v2.5.3 起改为 POST。旧的 `GET /new?url=...` 返回 400 + 迁移指引,详见 `migration-2.5.3.md`。
### GET /close?target=ID
关闭指定 tab。
```bash
curl -s "http://localhost:3456/close?target=TARGET_ID"
```
### POST /navigate?target=ID
在已有 tab 中导航到新 URL,自动等待加载。**target 走 query(不带特殊字符的不透明 ID),URL 走 POST body**。
```bash
curl -s -X POST --data-raw 'https://example.com' "http://localhost:3456/navigate?target=ID"
```
> v2.5.3 起改为 POST。旧的 `GET /navigate?target=...&url=...` 返回 400 + 迁移指引,详见 `migration-2.5.3.md`。
> `/new` 和 `/navigate` 的等待是浏览器文档层的基础保证,不是业务内容完成保证。验证页、登录跳转、SPA 异步渲染等仍可能继续变化;调用后必须按主 Skill 的“页面就绪与完成判断”检查目标内容,不能只看 `readyState`。
### GET /back?target=ID
后退一页。
```bash
curl -s "http://localhost:3456/back?target=ID"
```
### GET /info?target=ID
获取页面基础信息(title、url、readyState)。
```bash
curl -s "http://localhost:3456/info?target=ID"
```
### POST /eval?target=ID
执行 JavaScript 表达式,POST body 为 JS 代码。
```bash
curl -s -X POST "http://localhost:3456/eval?target=ID" -d 'document.title'
```
### POST /click?target=ID
JS 层面点击(`el.click()`),POST body 为 CSS 选择器。自动 scrollIntoView 后点击。简单快速,覆盖大多数场景。
```bash
curl -s -X POST "http://localhost:3456/click?target=ID" -d 'button.submit'
```
### POST /clickAt?target=ID
CDP 浏览器级真实鼠标点击(`Input.dispatchMouseEvent`),POST body 为 CSS 选择器。先获取元素坐标,再模拟鼠标按下/释放。算真实用户手势,能触发文件对话框、绕过部分反自动化检测。
```bash
curl -s -X POST "http://localhost:3456/clickAt?target=ID" -d 'button.upload'
```
### POST /setFiles?target=ID
给 file input 设置本地文件路径(`DOM.setFileInputFiles`),完全绕过文件对话框。POST body 为 JSON。
```bash
curl -s -X POST "http://localhost:3456/setFiles?target=ID" -d '{"selector":"input[type=file]","files":["/path/to/file1.png","/path/to/file2.png"]}'
```
### GET /scroll?target=ID&y=3000&direction=down
滚动页面。`direction` 可选 `down`(默认)、`up`、`top`、`bottom`。滚动后自动等待 800ms 供懒加载触发。
```bash
curl -s "http://localhost:3456/scroll?target=ID&y=3000"
curl -s "http://localhost:3456/scroll?target=ID&direction=bottom"
```
### GET /screenshot?target=ID&file=/tmp/shot.png
截图。指定 `file` 参数保存到本地文件;不指定则返回图片二进制。可选 `format=jpeg`。
```bash
curl -s "http://localhost:3456/screenshot?target=ID&file=/tmp/shot.png"
```
## /eval 使用提示
- POST body 为任意 JS 表达式,返回references/migration-2.5.3.md
# v2.5.3 迁移指南:`/new` 和 `/navigate` 改 POST body ## TL;DR ```diff - curl -s "http://localhost:3456/new?url=https://example.com" + curl -s -X POST --data-raw 'https://example.com' http://localhost:3456/new - curl -s "http://localhost:3456/navigate?target=ID&url=https://example.com" + curl -s -X POST --data-raw 'https://example.com' "http://localhost:3456/navigate?target=ID" ``` 旧写法收到 `400` + 包含本文档路径的错误信息后,按下方对照表改写调用。同时把发现的旧写法在源站点经验文件中就地修正。 ## 为什么改 旧版 `/new?url=...` 把目标 URL 塞进 query 参数。当目标 URL 自带 query(如小红书笔记必须携带 `xsec_token`、B 站、微博的分享链接),proxy 用 `URL.searchParams` 解析时,目标 URL 里未编码的 `&` 会被当成 **proxy 自身的** query 分隔符,导致目标 URL 被错误切分、token 等关键参数丢失,页面返回"内容不存在"或被反爬拦截。 例: ``` GET /new?url=https://xhs.com/explore/x?a=1&b=2 ``` proxy 解析结果: - `q.url = "https://xhs.com/explore/x?a=1"` ← 被截断 - `q.b = "2"` ← 被当成 proxy 自己的参数吃掉 根因是用一种"带语法的格式(query string)"承载另一种"也带相同语法的数据(URL)",存在结构性歧义。靠调用方守纪律做 URL-encode 治标不治本:Agent 偶尔忘记就翻车,且增加每次调用的 token 成本。 v2.5.3 把 URL 改为通过 **POST body** 传入。HTTP body 是不透明字节流(边界由 `Content-Length` header 显式声明,与数据本身解耦),不存在任何分隔符歧义,URL 原样传输,零编码负担。 ## 转换对照表 ### `/new` | 场景 | 旧(v2.5.2) | 新(v2.5.3) | |---|---|---| | 简单 URL | `curl ".../new?url=https://example.com"` | `curl -X POST --data-raw 'https://example.com' .../new` | | URL 含 query | `curl ".../new?url=https://xhs.com/explore/x?xsec_token=ABC"` ⚠️ token 丢失 | `curl -X POST --data-raw 'https://xhs.com/explore/x?xsec_token=ABC' .../new` ✓ | | URL 含 `#` fragment | `curl ".../new?url=https://app/page#sec"` ⚠️ fragment 丢失 | `curl -X POST --data-raw 'https://app/page#sec' .../new` ✓ | ### `/navigate` | 旧 | 新 | |---|---| | `curl ".../navigate?target=ID&url=URL"` | `curl -X POST --data-raw 'URL' ".../navigate?target=ID"` | `target` 仍走 query(它是无特殊字符的不透明 ID,没有歧义问题)。 ## Agent 自检 checklist 在迁移后的环境中工作时,遇到任何来源的 web-access 调用,按以下顺序处理: 1. **判断调用是否过时**:搜索字符串 `localhost:3456/new?url=` 或 `localhost:3456/navigate?` 后跟 `&url=`。这两类模式属于 v2.5.2 旧写法。 2. **就地改写**:按上表对照修改成 POST 形式。 3. **更新源文件**:如果旧写法来自 `references/site-patterns/*.md` 中某个站点经验文件,把源文件也一并修正掉(不要只在当前调用上改)—— 这样下次复用同一站点经验时不会再踩坑。 4. **保留 URL 原样**:POST body 是不透明字节流,目标 URL 中的 `?`、`&`、`=`、`#`、`%` 等字符**无需任何转义**,从 DOM/分享链接抓到什么样就传什么样。 ## FAQ **Q: 我用 GET `?url=` 调用会发生什么?** A: 收到 HTTP 400 响应,body 中包含 `error`、`migration` 文档路径、`example` 示例。按提示改 POST 调用即可。 **Q: 为什么不在 proxy 里做兼容(同时支持 GET 和 POST)?** A: 兼容路径会留下永久的"启发式截取 query"代码 + SKILL.md 里"也支持旧写法"的脚注。两条路径长期共存 → Agent 学得不彻底、维护者两套都要测、读代码的人要分辨主路径 vs 兼容路径。把架构债转成了认知债。一次性 breaking change 配合迁移指南,更彻底也更便宜。 **Q: 我自己的脚本/别名/笔记里有大量旧写法,有迁移脚本吗?** A: 没有也不打算提供。站点经验和脚本是人写的文档/代码,掺着说明、注释、上下文判断,正则替换容易误伤。本指南的 Agent 自检 checklist 就是给"Agent 看着内容自己判断怎么改"的,比脚本可靠。 **Q: 还有哪些 endpoint 用 POST body?** A: 一直都有:`/eval`、`/click`、`/clickAt`、`/setFiles` 全是 POST + body。这次 `/new` `/navigate` 加入后,**所有传输"任意字符串载荷"的写操作都统一走 POST body** —— 内部一致性提升。
skill-card.md
## Description: Helps agents search the web, retrieve pages, and interact with sites through a signed-in browser. This skill is ready for commercial/non-commercial use. ## Publisher: [eze-is](https://clawhub.ai/user/eze-is) ### License/Terms of Use: MIT-0 ## Use Case: Developers and other agent users use this skill to find and read web information, navigate interactive sites, and access pages requiring an existing browser login. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Browser automation can access logged-in accounts and perform actions on their behalf. Mitigation: Use a separate browser profile for sensitive accounts and review requested browser actions. Risk: A local browser-control service remains running without strong access controls. Mitigation: Stop the browser-control service after use when it is no longer needed. Risk: Browser history and bookmarks can expose private browsing information. Mitigation: Search history or bookmarks only when needed for the task. Risk: Uploading a local file to an untrusted site can disclose its contents. Mitigation: Do not upload arbitrary local files to untrusted sites. ## Reference(s): - [Project homepage (listed in release metadata)](https://github.com/eze-is/web-access) - [Browser API reference](references/cdp-api.md) - [Version 2.5.3 migration guide](references/migration-2.5.3.md) ## Skill Output: **Output Type(s):** [Text, Markdown, Shell commands, Guidance] **Output Format:** [Text or Markdown, potentially including shell commands and extracted web content] **Output Parameters:** [1D] **Other Properties Related to Output:** [May include content retrieved from sites accessible in the user's browser session.] ## Skill Version(s): 2.5.4 (source: server-resolved release metadata and skill frontmatter) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/eze-is/skills/web-access",
"sourceUrl": "https://clawhub.ai/eze-is/skills/web-access",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T03:35:28.812Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-eze-is-web-access/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-eze-is-web-access/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T03:35:28.812Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "6K downloads",
"href": "https://clawhub.ai/eze-is/web-access",
"sourceUrl": "https://clawhub.ai/eze-is/web-access",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T03:35:28.812Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.5.4",
"href": "https://clawhub.ai/eze-is/web-access",
"sourceUrl": "https://clawhub.ai/eze-is/web-access",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-29T10:18:25.332Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-eze-is-web-access/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-eze-is-web-access/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.5.4",
"description": "Sync with eze-is/web-access v2.5.4: CDP Proxy keeps a single long-lived browser connection (one remote-debugging approval), Chrome/Edge browser discovery with persisted preference (config.env), find-url for bookmarks/history lookup, POST-body /new and /navigate (URL with query/fragment passes intact), and more stable page readiness.",
"href": "https://clawhub.ai/eze-is/web-access",
"sourceUrl": "https://clawhub.ai/eze-is/web-access",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-29T10:18:25.332Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
