unbrowser
Cheap first-pass web discovery without launching Chrome — fetch SSR pages, run bounded JS, find routes/forms/API endpoints, extract structured data, and detect bot-wall or browser-only escalation points. Skill: unbrowser Owner: protostatis Summary: Cheap first-pass web discovery without launching Chrome — fetch SSR pages, run bounded JS, find routes/forms/API endpoints, extract structured data, and detect bot-wall or browser-only escalation points. Tags: agent:0.0.6, browser:0.0.6, latest:0.0.21, llm:0.0.6, scraping:0.0.6, web:0.0.6 Version history: v0.0.21 | 2026-08-21T22:28:41.824Z | user Discovery latency fix: rou
Rank
62
Safety
84
Downloads
1.8k
Updated
Oct 10, 2026
Version
0.0.21
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.8K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.0.21release · observed Aug 21, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s172e01an0790bheqac1f8wehd85zqad:unbrowser- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-protostatis-unbrowser/snapshot"
Documentation
CLAWHUB
144,779 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
---
name: unbrowser
description: Cheap first-pass web discovery without launching Chrome — fetch SSR pages, run bounded JS, find routes/forms/API endpoints, extract structured data, and detect bot-wall or browser-only escalation points.
version: 0.0.21
tags:
- browser
- web-search
- scraping
- web-automation
- headless
metadata:
openclaw:
requires:
bins:
- unbrowser
homepage: https://github.com/protostatis/unbrowser
---
# unbrowser — Chrome-free first-pass browsing
`unbrowser` is a single static binary that runs page JS in QuickJS and exposes a stateful session over JSON-RPC. It complements OpenClaw's managed browser: use `unbrowser` first for static / SSR / docs / search-result pages, route/form/API discovery, and structured extraction, then **escalate to the managed browser when the page tells you to** (signals below).
## Intended use & non-goals
**Intended use:** first-pass scraping of public web pages, navigation of SSR / static sites, discovery of useful routes/forms/API-like endpoints before extraction, multi-step interaction with simple HTML forms (search boxes, GET workflows), and authenticated tasks against credentials **the user has explicitly provided** — e.g. cookies they exported from their own logged-in browser session.
**Not intended for**, and the agent must refuse:
- Credential harvesting, scraping login forms for user/password pairs, or authenticating as anyone other than the requesting user.
- Mass scraping, denial-of-service-style request volumes, or circumventing per-IP rate limits.
- Anti-detection-as-a-service: the Chrome-aligned TLS/HTTP profile exists so legitimate `unbrowser` requests are **accepted by sites that reject non-browser HTTP libraries**, not to enable abuse of those sites' terms.
- Running arbitrary remote code. `eval` is a diagnostic / extraction tool, not a generic JS runner — see [Operational safety](#operational-safety).
When in doubt about whether a task fits the intended use, surface the action to the user and wait for explicit go-ahead.
## Operational safety
`unbrowser` exposes capabilities that need to be scoped before use: the cookie jar can carry session credentials, page JavaScript runs in QuickJS, and a single process retains state across calls. The skill itself declares **no environment-variable credentials** — the credential surface is entirely the cookies the agent is given at runtime.
### Cookies are credentials
- **Treat any cookie passed to `cookies_set` as a credential.** A session cookie can authenticate as the user who exported it, with no password or 2FA prompt.
- **Scope cookies to the host the user explicitly authorized.** Before calling `cookies_set`, verify the cookie's `domain` field matches the target site you intend to browse. Do not opportunistically replay cookies onto unrelated sites in the same session.
- **Keep challenge-cookie solving local and host-scoped.** If using `unbrowser cookie-service` or `unbrowser router`, keep the serv_meta.json
{
"ownerId": "kn789h172gxgscbdmqsnefvbsx85ztjb",
"slug": "unbrowser",
"version": "0.0.21",
"publishedAt": 1787351321824
}skill-card.md
## Description: Cheap first-pass web discovery without launching Chrome: fetch SSR pages, run bounded JS, find routes, forms, and API endpoints, extract structured data, and detect bot-wall or browser-only escalation points. This skill is ready for commercial/non-commercial use. ## Publisher: [protostatis](https://clawhub.ai/user/protostatis) ### License/Terms of Use: MIT-0 ## Use Case: Developers and agents use this skill to perform inexpensive first-pass web discovery, structured extraction, route/form/API discovery, and simple form workflows before escalating browser-only pages to a managed browser. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill depends on a local browsing binary that makes outbound requests from the user's machine. Mitigation: Install only from trusted pyunbrowser sources and prefer pinned or reviewed package versions in sensitive environments. Risk: Cookies supplied to the tool can act as login credentials for the exporting user. Mitigation: Treat cookies as credentials, scope them to the authorized host, clear them after authenticated use, and require explicit approval before account-changing actions. Risk: Local challenge-cookie services can expose browser cookies if bound or allowed too broadly. Mitigation: Keep cookie services loopback-bound, use host allowlists for private or internal targets, and avoid public interfaces. ## Reference(s): - [unbrowser project homepage](https://github.com/protostatis/unbrowser) - [unbrowser RPC methods](https://github.com/protostatis/unbrowser#rpc-methods) - [ClawHub skill page](https://clawhub.ai/protostatis/skills/unbrowser) ## Skill Output: **Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration] **Output Format:** [Markdown guidance with inline shell, JSON-RPC, and Python examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Includes escalation guidance, host-scoped cookie handling, and no declared environment-variable credentials.] ## Skill Version(s): 0.0.21 (source: SKILL.md frontmatter and server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/protostatis/skills/unbrowser",
"sourceUrl": "https://clawhub.ai/protostatis/skills/unbrowser",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T01:06:20.969Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-protostatis-unbrowser/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-protostatis-unbrowser/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T01:06:20.969Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.8K downloads",
"href": "https://clawhub.ai/protostatis/unbrowser",
"sourceUrl": "https://clawhub.ai/protostatis/unbrowser",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T01:06:20.969Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.0.21",
"href": "https://clawhub.ai/protostatis/unbrowser",
"sourceUrl": "https://clawhub.ai/protostatis/unbrowser",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-21T22:28:41.824Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-protostatis-unbrowser/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-protostatis-unbrowser/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.0.21",
"description": "Discovery latency fix: route_discover no longer burns the 30s watchdog on medium DOMs (quadratic nearestHeading under QuickJS; matrix timeout escalations 7/24 -> 0). Smart-layer routing coherence, shared enrichment deadline, smaller open() bundles. find_binary prefers freshest local builds.",
"href": "https://clawhub.ai/protostatis/unbrowser",
"sourceUrl": "https://clawhub.ai/protostatis/unbrowser",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-21T22:28:41.824Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
