js-eyes
Install, connect, operate, and troubleshoot the host-neutral JS Eyes browser and Skill Runtime from CLI, MCP, or the optional OpenClaw adapter.
Rank
62
Safety
84
Downloads
3.6k
Updated
Oct 9, 2026
Version
2.10.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 3.6K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 3.6K downloadsadoption · observed Oct 9, 2026
- Latest release
- 2.10.0release · observed Jul 25, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s178deygezkand2ppdrw966d7s840msf:js-eyes- Install using `clawhub skill install s178deygezkand2ppdrw966d7s840msf:js-eyes` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/imjszhang/js-eyes before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-imjszhang-js-eyes/snapshot"
Documentation
CLAWHUB
160,000 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: js-eyes
description: Install, connect, operate, and troubleshoot the host-neutral JS Eyes browser and Skill Runtime from CLI, MCP, or the optional OpenClaw adapter.
version: 2.9.0
metadata: {"openclaw":{"emoji":"\U0001F441","homepage":"https://github.com/imjszhang/js-eyes","os":["darwin","linux","win32"],"requires":{"bins":["node"]}}}
---
# JS Eyes
JS Eyes is a local-first browser capability and site-skill runtime for AI
agents. A browser extension connects to a local JS Eyes server; CLI, MCP, and
OpenClaw are peer host surfaces over the same protocol, policy engine, and
Skill Runtime.
Treat `{baseDir}` as the root of this installed bundle. The optional OpenClaw
adapter is `{baseDir}/openclaw-plugin`.
## Use this Skill when
- The user wants to install or connect JS Eyes.
- An MCP or OpenClaw host cannot see JS Eyes tools.
- The browser extension remains disconnected.
- A local server, token, browser target, or security policy needs diagnosis.
- The user wants to discover, inspect, trust, enable, or call a JS Eyes Skill.
- An external V2 Skill needs to be linked without coupling it to OpenClaw.
## Choose the host surface
Use the smallest surface that fits the request:
1. **CLI** — use `js-eyes` directly for server management, diagnostics, Skill
lifecycle, and one-off Skill calls.
2. **MCP** — use `@js-eyes/mcp-server` for Codex, Claude, Cursor, VS Code, and
other local MCP clients.
3. **OpenClaw** — load `{baseDir}/openclaw-plugin` only when OpenClaw-specific
lifecycle and routing are required.
Do not install the OpenClaw adapter merely to use CLI or MCP.
## Requirements
- Node.js 22 or newer.
- A supported Chrome, Edge, or Firefox extension.
- A local JS Eyes server, normally at `http://localhost:18080`.
- A shared server token unless anonymous compatibility mode was explicitly
selected.
Keep the server bound to loopback unless the user has deliberately configured
and secured remote access.
## Standard standalone setup
Install the public CLI:
```bash
npm install -g js-eyes
```
Initialize a token, register the optional Native Messaging bridge, and start
the server:
```bash
js-eyes server token init
js-eyes native-host install --browser all
js-eyes server start
js-eyes doctor
```
Install or load the browser extension, then use its popup to synchronize the
server URL and token. If Native Messaging is unavailable, reveal the token only
for the local user and paste it into the popup:
```bash
js-eyes server token show --reveal
```
Never place the token in documentation, logs, chat output, command arguments
that will be shared, or a remote URL.
## MCP setup
The MCP facade connects lazily to an existing JS Eyes server:
```json
{
"mcpServers": {
"js-eyes": {
"command": "npx",
"args": ["-y", "@js-eyes/mcp-server"]
}
}
}
```
The default `safe` profile exposes browser status, tab, navigation, page-read,
screenshot, and read-only Skill Runtime tools. Raw JavaScript, CSS injection,
cookie acc_meta.json
{
"ownerId": "kn70g9r4pqpqeckej65c2fznk981vvq3",
"slug": "js-eyes",
"version": "2.10.0",
"publishedAt": 1784964777703
}SECURITY.md
# Security and Network Behavior > **2.9.0 note**: This document covers the runtime security posture (network > behavior, token handling, policy engine, consent ledger, supply-chain > hardening since 2.2.0). For the per-finding response to the > [ClawHub Security Scan](https://clawhub.ai/imjszhang/js-eyes) of v2.6.1, > see [`SECURITY_SCAN_NOTES.md`](./SECURITY_SCAN_NOTES.md); for the one-screen > operator summary (risk item / current default / how to tighten / config > switch / verify) see the [Security Posture table in `README.md`](./README.md#security-posture-280). > A local reproduction of the ClawHub static heuristic is available via > `npm run scan:security` (zero unexpected findings on 2.6.3 — the 2.6.3 > changes are install-time UX only and do not touch the runtime callsites > tracked by the scan). ## Reporting a vulnerability Use GitHub's private vulnerability reporting flow from the repository's **Security** tab. Include the affected component and version or commit, reproduction steps, expected and observed impact, and any known mitigation. Do not open a public issue for a suspected vulnerability or disclose it before a fix or coordinated disclosure plan is available. Routine dependency updates and non-sensitive bugs can use normal GitHub issues. ## Overview JS Eyes is a **local-first** browser automation stack. Its normal runtime loop talks only to the JS Eyes server you configure, which defaults to `localhost:18080`. There are two deployment shapes to keep in mind: - **ClawHub / bundle deployment:** install the JS Eyes bundle, run `npm install` in the bundle root, register `openclaw-plugin`, and allow the plugin tools in OpenClaw. - **Source-repo / development deployment:** clone this repository, run `npm install` in the repo root, point OpenClaw at the repo-root `openclaw-plugin`, and optionally load the unpacked browser extension directly from `extensions/chrome/` or `extensions/firefox/`. Those two modes share the same local runtime behavior, but the source repository also contains release tooling, docs, site assets, and extension source files that reference public URLs for packaging and documentation workflows. ## Complete OpenClaw Deployment Notes A complete local OpenClaw deployment needs all of the following: - `plugins.load.paths` points to the bundle or repo-root `openclaw-plugin` directory. - `plugins.entries["js-eyes"].enabled` is `true`. - `tools.alsoAllow: ["js-eyes"]` or an equivalent `tools.allow` entry is present, because `js-eyes` registers optional plugin tools. - The browser extension is configured to connect to the chosen `serverHost` / `serverPort`. Without the tool allowlist step, the plugin can load successfully while its single `js-eyes` router tool remains unavailable to the model. ## Runtime Network Behavior Base runtime behavior: - **OpenClaw plugin:** connects via WebSocket to `ws://serverHost:serverPort` and uses HTTP only for JS Eyes server endpoints such as `/api/browser/status` and `/api/b
skill-card.md
## Description: Install, connect, operate, and troubleshoot the host-neutral JS Eyes browser and Skill Runtime from CLI, MCP, or the optional OpenClaw adapter. This skill is ready for commercial/non-commercial use. ## Publisher: [imjszhang](https://clawhub.ai/user/imjszhang) ### License/Terms of Use: MIT-0 ## Use Case: Developers and operators use JS Eyes to install, connect, operate, and troubleshoot local browser automation and JS Eyes Skill Runtime integrations across CLI, MCP, and OpenClaw hosts. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Local browser automation and JS Eyes runtime support can expose sensitive browser actions when broader authority is enabled. Mitigation: Use the safe MCP profile where possible, keep raw eval disabled unless the task truly requires it, and require explicit operator intent before enabling sensitive actions. Risk: Skill install and discovery paths include review-worthy unsafe remote install and broad network-fetch behavior. Mitigation: Use the staged skills/plan-install plus CLI approval path, review install plans before approval, and avoid untrusted custom registries. Risk: A local browser automation server can be exposed beyond the intended user if remote binding or anonymous access is enabled. Mitigation: Keep the server on localhost with token authentication, leave anonymous access disabled, and avoid remote binding unless it is deliberately configured and secured. Risk: Native Messaging auto-install and skill directory watchers add local integration surface in hardened environments. Mitigation: Consider disabling Native Messaging auto-install and skill directory watchers where local change monitoring or browser token synchronization is not required. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/imjszhang/skills/js-eyes) - [Project homepage from ClawDIS metadata](https://github.com/imjszhang/js-eyes) - [Artifact skill instructions](artifact/SKILL.md) - [Artifact security documentation](artifact/SECURITY.md) ## Skill Output: **Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance] **Output Format:** [Markdown guidance with JSON and shell command examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Produces setup, diagnosis, and policy-aware operation guidance; it does not produce binary artifacts.] ## Skill Version(s): 2.10.0 (source: server release evidence; artifact frontmatter and package manifests report 2.9.0) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
openclaw-plugin/openclaw.plugin.json
{
"id": "js-eyes",
"activation": {
"onStartup": true
},
"name": "JS Eyes",
"description": "浏览器自动化工具 — 通过 WebSocket 为 AI Agent 提供远程浏览器控制能力(标签页管理、内容获取、脚本执行等)",
"version": "2.9.0",
"contracts": {
"tools": [
"js-eyes"
]
},
"toolMetadata": {
"js-eyes": {
"optional": true
}
},
"configSchema": {
"type": "object",
"additionalProperties": false,
"properties": {
"serverHost": {
"type": "string",
"default": "localhost",
"description": "JS-Eyes 服务器监听地址"
},
"serverPort": {
"type": "number",
"default": 18080,
"description": "JS-Eyes 服务器端口"
},
"autoStartServer": {
"type": "boolean",
"default": true,
"description": "是否随插件加载自动启动内置服务器"
},
"requestTimeout": {
"type": "number",
"default": 1800,
"description": "浏览器操作请求超时(秒),默认 1800(30 分钟)"
},
"skillsRegistryUrl": {
"type": "string",
"default": "https://js-eyes.com/skills.json",
"description": "扩展技能注册表 URL"
},
"skillsDir": {
"type": "string",
"default": "",
"description": "扩展技能安装目录(空值则使用技能包内的 skills/ 目录)"
},
"extraSkillDirs": {
"type": "array",
"items": {
"type": "string"
},
"default": [],
"description": "额外只读技能来源(绝对路径列表)。每条可以是单个 V2/V1 技能目录或父目录(扫描 1 层子目录)。同 id 冲突时 primary 优先;可通过 host security.verifyExtraSkillDirs 启用快照校验。"
},
"skills": {
"type": "object",
"additionalProperties": {
"type": "object"
},
"default": {},
"description": "按技能 ID 配置运行参数;plugins config 覆盖 host config 中的同名技能配置。"
},
"externalSkills": {
"type": "object",
"additionalProperties": false,
"default": {
"policy": "prompt",
"defaultExecution": "worker"
},
"description": "外部技能的发现、信任和执行策略。legacy 保持兼容;prompt 要求批准;strict 还要求 V2 静态 Manifest。",
"properties": {
"policy": {
"type": "string",
"enum": [
"legacy",
"prompt",
"strict"
],
"default": "prompt"
},
"defaultExecution": {
"type": "string",
"enum": [
"in-process",
"worker"
],
"default": "worker"
}
}
},
"watchConfig": {
"type": "boolean",
"default": true,
"description": "通过 chokidar 监听 ~/.js-eyes/config/config.json,配置变更时(含 js-eyes skills link/unlink/enable/disable)零重启热加载技能。"
},
"devWatchSkills": {
"type": "boolean",
"default": true,
"description": "开发模式:监听已发现技能目录的文件变更(默认 ~300ms 防抖),改完 Skill 源文件自动 reload。仅推荐在本地开发用;生产可关闭以减少 fs 监听负载。"
},
"nativeHost": {
"type": "object",
"additionalProperties": false,
"default": {
"aactivepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/imjszhang/skills/js-eyes",
"sourceUrl": "https://clawhub.ai/imjszhang/skills/js-eyes",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T07:26:49.542Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-imjszhang-js-eyes/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-imjszhang-js-eyes/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T07:26:49.542Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "3.6K downloads",
"href": "https://clawhub.ai/imjszhang/js-eyes",
"sourceUrl": "https://clawhub.ai/imjszhang/js-eyes",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T07:26:49.542Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.10.0",
"href": "https://clawhub.ai/imjszhang/js-eyes",
"sourceUrl": "https://clawhub.ai/imjszhang/js-eyes",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-25T07:32:57.703Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-imjszhang-js-eyes/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-imjszhang-js-eyes/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.10.0",
"description": "- **Package boundaries**: install/trust helpers live in `@js-eyes/skill-install`; policy primitives live in `@js-eyes/policy`. Compatibility re-exports under `@js-eyes/protocol/*` and `@js-eyes/client-sdk/policy` are removed. - **V1 skill activation removed**: `createOpenClawAdapter` / `skill.contract.js` loading and `externalSkills.policy=legacy` are gone. Migrate to V2 `skill.manifest.json` + `skill.entry.js`. - **First-class page interact**: `click` / `fill` / `scroll` / `wait_for` no longer require `allowRawEval`; MCP safe profile exposes matching tools. - **Skill scaffold**: official Skills use `@js-eyes/skill-scaffold` and `TOOL_DEFINITIONS` as the tool SSOT. - **Extension staging**: shared runtime is injected into `dist/extensions-stage/{chrome,firefox}` instead of committed browser copies. - **OpenClaw optional peer**: `@js-eyes/openclaw-plugin` no longer pulls OpenClaw into workspace production audits when the peer is absent.",
"href": "https://clawhub.ai/imjszhang/js-eyes",
"sourceUrl": "https://clawhub.ai/imjszhang/js-eyes",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-25T07:32:57.703Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
