agentCLAWHUBUnverified

Browser Web Search

一行命令搜遍全网 — 55 个平台 91+ 个命令,头条、知乎、豆瓣、YouTube、GitHub、Reddit、Hacker News 等。专为 OpenClaw 设计,复用浏览器登录态,返回结构化 JSON,天然适配 AI Agent 工具调用。

OpenClaw

Rank

62

Safety

84

Downloads

1.8k

Updated

Oct 10, 2026

Version

0.4.11

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.8K downloadsadoption · observed Oct 10, 2026
Latest release
0.4.11release · observed May 11, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17867zbqf69d0mb2yqzym6nmh83hrxm:browser-web-search
  1. Install using `clawhub skill install s17867zbqf69d0mb2yqzym6nmh83hrxm:browser-web-search` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/sipingme/browser-web-search before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/snapshot"

Documentation

CLAWHUB

148,938 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: browser-web-search
description: 一行命令搜遍全网 — 55 个平台 91+ 个命令,头条、知乎、豆瓣、YouTube、GitHub、Reddit、Hacker News 等。专为 OpenClaw 设计,复用浏览器登录态,返回结构化 JSON,天然适配 AI Agent 工具调用。
version: 0.4.10
versionNotes: |
  0.4.10 — Residual-risk hardening layered on the v0.4.4 sealed-tier model.
  Adds three programmatic responses to the ClawScan May 2026 verdict's
  remaining concern ("core functionality inherently relies on a third-party
  dependency to handle sensitive session data"):

    1. Gate 4 — Platform consent ledger at ~/.bws/consents.json.
       Per (site, pkgVersion, entrySha512) one-time consent via the new
       --accept-platform-consent flag. Any drift in pkgVersion or
       entrySha512 invalidates prior consent for that site.
    2. Transparency block printed to stderr for every sensitive call
       (and for all calls when BWS_TRANSPARENCY=1). Machine-readable JSON
       line naming the third-party package, audited SHA-512, gate path,
       audit log, and consent ledger. Prevents silent invocation by a
       wrapping AI agent.
    3. New launcher-only --dry-run flag that runs all four gates plus
       integrity verification, writes the audit record, and exits
       without importing the package. Useful for CI and agent dispatch.

  Underlying npm package browser-web-search remains pinned at 0.4.3 (no
  change to the SHA-512 integrity gate, ENTRY_EXPECTED_SIZE, or symlink
  rejection). All v0.4.4 gates remain unchanged.
author: Ping Si <[email protected]>
type: cli
requires:
  runtime:
    - name: node
      version: ">=18.0.0"
      description: Node.js 运行时
    - name: npm
      description: Node.js 包管理器(随 Node.js 安装)
  packages:
    - npm: browser-web-search
      global: false
  binaries:
    - name: openclaw
      description: OpenClaw CLI,用于浏览器自动化
install:
  command: npm install -g [email protected]
  riskLevel: medium
  riskReason: 通过 npm 全局安装第三方包,该包会在浏览器页面上下文中执行 JavaScript。安装前请审计源码。
  requiresApproval: true
  source:
    registry: npmjs.com
    package: browser-web-search
    repository: https://github.com/sipingme/browser-web-search
    npm: https://www.npmjs.com/package/browser-web-search
  verification:
    - 安装前请审查 GitHub 仓库代码
    - 检查 npm 包的下载量和维护状态
    - 对比 npm 发布版本与 GitHub 源码是否一致
  note: 用户需先通过 npm install -g 全局安装 browser-web-search,运行时调用本地已安装的 bws 命令
capabilities:
  sensitive:
    - type: browser-session-access
      riskLevel: high
      description: 通过 OpenClaw 在已认证的浏览器标签页中执行 JavaScript
      scope: 按 adapter 域名隔离(如 zhihu.com, xiaohongshu.com)
      access:
        - 当前页面 DOM
        - 当前页面 Session(继承,非提取)
        - 站点认证数据(登录态下的 API 响应)
        - 账户保护页面内容(如私信、收藏、个人资料)
      noAccess:
        - 浏览器 Cookie 文件(不直接读取)
        - 其他域名数据
        - 用户配置目录
      risks:
        - 第三方 npm 包(browser-web-search)在页面上下文中执行,可访问站点认证数据
        - 恶意代码可能窃取 cookies 或页面内容
        - 包代码不包含在此 Skill 中,需独立审计
      mitigations:
        - adapter 脚本开源可审计
        - 按域名隔离,无法跨站访问
        - 不持久化存储任何凭证
  privacyNotice:
    summary: 此 Skill 自动复用浏览器登录

README.md

# Browser Web Search Skill

> **一行命令,搜遍全网** — 55 个平台 91+ 个命令,专为 OpenClaw 与 AI Agent 设计

## 快速开始

```bash
# 安装
npm install -g [email protected]

# 查看所有命令
bws site list

# 搜索示例
bws site toutiao/search "ai search"             # 今日头条
bws site zhihu/search "ai agent" --count 5      # 知乎
bws site hn/search "llm" --sort date            # Hacker News
bws site github/search "ai search" --sort stars # GitHub
bws site youtube/search "ai agent"              # YouTube

# jq 过滤
bws site zhihu/search "ai" --jq '[.items[].url]'
```

## 内置平台(55 个)

### 🇨🇳 国内平台(30 个)

| 平台 | 命令 |
|-----|------|
| **今日头条** | `toutiao/search`, `toutiao/hot`, `toutiao/feed` |
| **微信公众号** | `weixin/search`, `weixin/article` |
| **小红书** | `xiaohongshu/search`, `xiaohongshu/note`, `xiaohongshu/comments`, `xiaohongshu/user_posts`, `xiaohongshu/me`, `xiaohongshu/feed` |
| **知乎** | `zhihu/search`, `zhihu/hot`, `zhihu/question`, `zhihu/me` |
| **微博** | `weibo/search`, `weibo/hot` |
| **Bilibili** | `bilibili/search`, `bilibili/popular`, `bilibili/trending`, `bilibili/ranking`, `bilibili/video`, `bilibili/comments`, `bilibili/history`, `bilibili/me`, `bilibili/feed` |
| **澎湃新闻** | `thepaper/search`, `thepaper/hot` |
| **腾讯新闻** | `qqnews/search`, `qqnews/hot` |
| **网易新闻** | `netease/search`, `netease/hot` |
| **新浪新闻** | `sina/search`, `sina/hot` |
| **36kr** | `36kr/search`, `36kr/newsflash`, `36kr/article` |
| **虎嗅** | `huxiu/search` |
| **华尔街见闻** | `wallstreetcn/search` |
| **东方财富** | `eastmoney/stock`, `eastmoney/news` |
| **雪球** | `xueqiu/search` |
| **掘金** | `juejin/search` |
| **CSDN** | `csdn/search` |
| **博客园** | `cnblogs/search` |
| **V2EX** | `v2ex/search` |
| **BOSS直聘** | `boss/search`, `boss/detail` |
| **Baidu** | `baidu/search` |
| **即刻** | `jike/search` |
| **虎扑** | `hupu/search` |
| **豆瓣** | `douban/search`, `douban/movie`, `douban/movie-hot`, `douban/top250`, `douban/comments` |
| **什么值得买** | `smzdm/search` |
| **起点中文网** | `qidian/search` |
| **有道翻译** | `youdao/translate` |
| **携程** | `ctrip/search` |
| **InfoQ** | `infoq/search` |

### 🌏 国际平台(25 个)

| 平台 | 命令 |
|-----|------|
| **Google** | `google/search` |
| **Bing** | `bing/search` |
| **DuckDuckGo** | `duckduckgo/search` |
| **GitHub** | `github/search` |
| **Hacker News** | `hn/search` |
| **Reddit** | `reddit/search` |
| **X (Twitter)** | `x/search` |
| **The Verge** | `verge/search` |
| **Ars Technica** | `ars/search` |
| **Engadget** | `engadget/search` |
| **LinkedIn** | `linkedin/search` |
| **BBC** | `bbc/news` |
| **Reuters** | `reuters/search` |
| **Stack Overflow** | `stackoverflow/search` |
| **Dev.to** | `devto/search` |
| **npm** | `npm/search` |
| **PyPI** | `pypi/search` |
| **arXiv** | `arxiv/search` |
| **YouTube** | `youtube/search`, `youtube/video`, `youtube/transcript`, `youtube/transcript-by-id`, `youtube/comments`, `youtube/channel`, `youtube/feed` |
| **IMDb** | `imdb/search`, `imdb/movie`, `imdb/top250` |
| **Genius** | `genius/search` |
| **GSMArena** | `gsmarena/search` |
| **Product H

_meta.json

{
  "ownerId": "kn70nwj71rbkzwyvc7pkqs4p6s8222nc",
  "slug": "browser-web-search",
  "version": "0.4.11",
  "publishedAt": 1778465503784
}

SECURITY.md

# Security model — `browser-web-search-skill`

> **Skill version:** 0.4.10 (this launcher + docs + gating policy)
> **Audited upstream:** `[email protected]` (pinned, SHA-512 enforced)
> **Latest external review:** ClawScan, May 2026

This document is the human-readable map between external security reviews
and the file-by-file evidence in this repository. It is intentionally
**code-linked** rather than aspirational: every claim below points at a
specific function or field that anyone can audit.

The launcher does **not** spawn subprocesses, **does not** invoke a shell,
and is the only code that touches the third-party `browser-web-search` npm
package. All hardening described here lives in `scripts/run.js` and
`config.json`.

---

## 1. Threat model in one paragraph

`browser-web-search` is a third-party npm package that executes JavaScript
inside an authenticated OpenClaw browser tab. Once invoked, that JavaScript
inherits the user's full login state for the visited domain (DMs,
favorites, profile, orders) and — depending on browser configuration —
can reach other open tabs in the same profile. This skill's launcher
cannot constrain the package's behavior in-process; it can only:

1. refuse to load the package when its identity or bytes deviate from a
   pinned audit, and
2. interpose deny-by-default policy gates so the package is not invoked
   at all unless an operator has *consciously and recently* authorized
   the specific (site, audited bytes) combination, and
3. record every decision in an append-only audit log so any unauthorized
   call can be detected after the fact.

These three layers are the launcher's entire contribution; the skill
**does not** claim to sandbox the package's runtime behavior.

---

## 2. ClawScan May 2026 verdict — line-by-line

> *Source: ClawScan, analyzed May 11 2026, type "OpenClaw Skill",
> name `browser-web-search`, version 0.4.10.*

### Verdict text (verbatim)

> The skill provides a high-risk capability by executing JavaScript within
> authenticated browser sessions to scrape data from 55+ platforms,
> including private areas like DMs, orders, and profiles. While the
> launcher (`scripts/run.js`) is exceptionally defensive — implementing a
> mandatory SHA-512 integrity check on the 'browser-web-search' npm
> package, rejecting symbolic links, and enforcing a three-tier
> authorization gate that is sealed by default — the core functionality
> inherently relies on a third-party dependency to handle sensitive
> session data. This high-risk access to authenticated browser states,
> despite the robust mitigations and audit logging, warrants a
> suspicious classification.

### Claim ↔ evidence map

| ClawScan claim | Where it lives | Notes |
|---|---|---|
| "executes JavaScript within authenticated browser sessions to scrape data from 55+ platforms" | `SKILL.md` adapter table; `scripts/run.js` `ALWAYS_SENSITIVE_SITES`, `SENSITIVE_SUFFIX_RE`, `PUBLIC_SITES` | The launcher only forwards args; the third-party

skill-card.md

## Description:

Browser Web Search lets agents run unified web-search commands across 55 platforms and return structured JSON, including optional OpenClaw browser-session backed adapters.

This skill is ready for commercial/non-commercial use.

## Publisher:

[sipingme](https://clawhub.ai/user/sipingme)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and agent builders use this skill to retrieve structured search results, trending content, repository data, videos, transcripts, and other public or authenticated site content through a common command interface.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The skill can invoke a third-party npm package inside an OpenClaw browser profile, including contexts that may contain authenticated site data.

Mitigation: Install only when this access is acceptable, keep BWS_PUBLIC_ONLY=1 unless authenticated adapters are intentionally needed, use a dedicated browser profile, and close unrelated logged-in tabs.

Risk: Users may bypass the safer launcher path or safer install flow described by the security evidence.

Mitigation: Use the bws-skill scripts/run.js launcher path rather than direct bws site commands, install [email protected] with --ignore-scripts, and retain the pinned integrity checks.

Risk: Sensitive browser-session calls can expose private page content if authorized accidentally or without current review.

Mitigation: Use the sealed sensitive tier, per-call opt-in, platform consent ledger, transparency output, audit log, and --dry-run preflight before real sensitive calls.

## Reference(s):

- [ClawHub skill page](https://clawhub.ai/sipingme/skills/browser-web-search)
- [browser-web-search-skill repository](https://github.com/sipingme/browser-web-search-skill)
- [browser-web-search core library](https://github.com/sipingme/browser-web-search)
- [browser-web-search npm package](https://www.npmjs.com/package/browser-web-search)
- [Pinned browser-web-search source](https://github.com/sipingme/browser-web-search/blob/v0.4.3/src/index.ts)

## Skill Output:

**Output Type(s):** [text, json, shell commands, configuration, guidance]

**Output Format:** [Structured JSON results with command and configuration guidance]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Adapters may support count, sort, jq filtering, id, limit, and page options; sensitive adapters require explicit runtime gates.]

## Skill Version(s):

0.4.11 (source: server release metadata; artifact frontmatter reports 0.4.10)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 12h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/sipingme/skills/browser-web-search",
      "sourceUrl": "https://clawhub.ai/sipingme/skills/browser-web-search",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:11:07.937Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:11:07.937Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.8K downloads",
      "href": "https://clawhub.ai/sipingme/browser-web-search",
      "sourceUrl": "https://clawhub.ai/sipingme/browser-web-search",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:11:07.937Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.4.11",
      "href": "https://clawhub.ai/sipingme/browser-web-search",
      "sourceUrl": "https://clawhub.ai/sipingme/browser-web-search",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-11T02:11:43.784Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.4.11",
      "description": "**Major hardening release with new residual-risk controls for sensitive session data:** - Adds a Gate 4 platform consent ledger (~/.bws/consents.json); one-time per-site consent now required for sensitive calls (via --accept-platform-consent). - Emits a machine-readable transparency block to stderr on every sensitive call (or all calls with BWS_TRANSPARENCY=1), detailing third-party package and audit info. - New --dry-run flag to exercise all access gates and audit logging without loading untrusted code—ideal for CI workflows. - Underlying npm dependency remains pinned and integrity-verified (0.4.3, unchanged). - SECURITY.md added.",
      "href": "https://clawhub.ai/sipingme/browser-web-search",
      "sourceUrl": "https://clawhub.ai/sipingme/browser-web-search",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-11T02:11:43.784Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to Browser Web Search and adjacent AI workflows.