Browser Web Search
一行命令搜遍全网 — 55 个平台 91+ 个命令,头条、知乎、豆瓣、YouTube、GitHub、Reddit、Hacker News 等。专为 OpenClaw 设计,复用浏览器登录态,返回结构化 JSON,天然适配 AI Agent 工具调用。
Rank
62
Safety
84
Downloads
1.8k
Updated
Oct 10, 2026
Version
0.4.11
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.8K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.4.11release · observed May 11, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17867zbqf69d0mb2yqzym6nmh83hrxm:browser-web-search- Install using `clawhub skill install s17867zbqf69d0mb2yqzym6nmh83hrxm:browser-web-search` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/sipingme/browser-web-search before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/snapshot"
Documentation
CLAWHUB
148,938 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: browser-web-search
description: 一行命令搜遍全网 — 55 个平台 91+ 个命令,头条、知乎、豆瓣、YouTube、GitHub、Reddit、Hacker News 等。专为 OpenClaw 设计,复用浏览器登录态,返回结构化 JSON,天然适配 AI Agent 工具调用。
version: 0.4.10
versionNotes: |
0.4.10 — Residual-risk hardening layered on the v0.4.4 sealed-tier model.
Adds three programmatic responses to the ClawScan May 2026 verdict's
remaining concern ("core functionality inherently relies on a third-party
dependency to handle sensitive session data"):
1. Gate 4 — Platform consent ledger at ~/.bws/consents.json.
Per (site, pkgVersion, entrySha512) one-time consent via the new
--accept-platform-consent flag. Any drift in pkgVersion or
entrySha512 invalidates prior consent for that site.
2. Transparency block printed to stderr for every sensitive call
(and for all calls when BWS_TRANSPARENCY=1). Machine-readable JSON
line naming the third-party package, audited SHA-512, gate path,
audit log, and consent ledger. Prevents silent invocation by a
wrapping AI agent.
3. New launcher-only --dry-run flag that runs all four gates plus
integrity verification, writes the audit record, and exits
without importing the package. Useful for CI and agent dispatch.
Underlying npm package browser-web-search remains pinned at 0.4.3 (no
change to the SHA-512 integrity gate, ENTRY_EXPECTED_SIZE, or symlink
rejection). All v0.4.4 gates remain unchanged.
author: Ping Si <[email protected]>
type: cli
requires:
runtime:
- name: node
version: ">=18.0.0"
description: Node.js 运行时
- name: npm
description: Node.js 包管理器(随 Node.js 安装)
packages:
- npm: browser-web-search
global: false
binaries:
- name: openclaw
description: OpenClaw CLI,用于浏览器自动化
install:
command: npm install -g [email protected]
riskLevel: medium
riskReason: 通过 npm 全局安装第三方包,该包会在浏览器页面上下文中执行 JavaScript。安装前请审计源码。
requiresApproval: true
source:
registry: npmjs.com
package: browser-web-search
repository: https://github.com/sipingme/browser-web-search
npm: https://www.npmjs.com/package/browser-web-search
verification:
- 安装前请审查 GitHub 仓库代码
- 检查 npm 包的下载量和维护状态
- 对比 npm 发布版本与 GitHub 源码是否一致
note: 用户需先通过 npm install -g 全局安装 browser-web-search,运行时调用本地已安装的 bws 命令
capabilities:
sensitive:
- type: browser-session-access
riskLevel: high
description: 通过 OpenClaw 在已认证的浏览器标签页中执行 JavaScript
scope: 按 adapter 域名隔离(如 zhihu.com, xiaohongshu.com)
access:
- 当前页面 DOM
- 当前页面 Session(继承,非提取)
- 站点认证数据(登录态下的 API 响应)
- 账户保护页面内容(如私信、收藏、个人资料)
noAccess:
- 浏览器 Cookie 文件(不直接读取)
- 其他域名数据
- 用户配置目录
risks:
- 第三方 npm 包(browser-web-search)在页面上下文中执行,可访问站点认证数据
- 恶意代码可能窃取 cookies 或页面内容
- 包代码不包含在此 Skill 中,需独立审计
mitigations:
- adapter 脚本开源可审计
- 按域名隔离,无法跨站访问
- 不持久化存储任何凭证
privacyNotice:
summary: 此 Skill 自动复用浏览器登录README.md
# Browser Web Search Skill > **一行命令,搜遍全网** — 55 个平台 91+ 个命令,专为 OpenClaw 与 AI Agent 设计 ## 快速开始 ```bash # 安装 npm install -g [email protected] # 查看所有命令 bws site list # 搜索示例 bws site toutiao/search "ai search" # 今日头条 bws site zhihu/search "ai agent" --count 5 # 知乎 bws site hn/search "llm" --sort date # Hacker News bws site github/search "ai search" --sort stars # GitHub bws site youtube/search "ai agent" # YouTube # jq 过滤 bws site zhihu/search "ai" --jq '[.items[].url]' ``` ## 内置平台(55 个) ### 🇨🇳 国内平台(30 个) | 平台 | 命令 | |-----|------| | **今日头条** | `toutiao/search`, `toutiao/hot`, `toutiao/feed` | | **微信公众号** | `weixin/search`, `weixin/article` | | **小红书** | `xiaohongshu/search`, `xiaohongshu/note`, `xiaohongshu/comments`, `xiaohongshu/user_posts`, `xiaohongshu/me`, `xiaohongshu/feed` | | **知乎** | `zhihu/search`, `zhihu/hot`, `zhihu/question`, `zhihu/me` | | **微博** | `weibo/search`, `weibo/hot` | | **Bilibili** | `bilibili/search`, `bilibili/popular`, `bilibili/trending`, `bilibili/ranking`, `bilibili/video`, `bilibili/comments`, `bilibili/history`, `bilibili/me`, `bilibili/feed` | | **澎湃新闻** | `thepaper/search`, `thepaper/hot` | | **腾讯新闻** | `qqnews/search`, `qqnews/hot` | | **网易新闻** | `netease/search`, `netease/hot` | | **新浪新闻** | `sina/search`, `sina/hot` | | **36kr** | `36kr/search`, `36kr/newsflash`, `36kr/article` | | **虎嗅** | `huxiu/search` | | **华尔街见闻** | `wallstreetcn/search` | | **东方财富** | `eastmoney/stock`, `eastmoney/news` | | **雪球** | `xueqiu/search` | | **掘金** | `juejin/search` | | **CSDN** | `csdn/search` | | **博客园** | `cnblogs/search` | | **V2EX** | `v2ex/search` | | **BOSS直聘** | `boss/search`, `boss/detail` | | **Baidu** | `baidu/search` | | **即刻** | `jike/search` | | **虎扑** | `hupu/search` | | **豆瓣** | `douban/search`, `douban/movie`, `douban/movie-hot`, `douban/top250`, `douban/comments` | | **什么值得买** | `smzdm/search` | | **起点中文网** | `qidian/search` | | **有道翻译** | `youdao/translate` | | **携程** | `ctrip/search` | | **InfoQ** | `infoq/search` | ### 🌏 国际平台(25 个) | 平台 | 命令 | |-----|------| | **Google** | `google/search` | | **Bing** | `bing/search` | | **DuckDuckGo** | `duckduckgo/search` | | **GitHub** | `github/search` | | **Hacker News** | `hn/search` | | **Reddit** | `reddit/search` | | **X (Twitter)** | `x/search` | | **The Verge** | `verge/search` | | **Ars Technica** | `ars/search` | | **Engadget** | `engadget/search` | | **LinkedIn** | `linkedin/search` | | **BBC** | `bbc/news` | | **Reuters** | `reuters/search` | | **Stack Overflow** | `stackoverflow/search` | | **Dev.to** | `devto/search` | | **npm** | `npm/search` | | **PyPI** | `pypi/search` | | **arXiv** | `arxiv/search` | | **YouTube** | `youtube/search`, `youtube/video`, `youtube/transcript`, `youtube/transcript-by-id`, `youtube/comments`, `youtube/channel`, `youtube/feed` | | **IMDb** | `imdb/search`, `imdb/movie`, `imdb/top250` | | **Genius** | `genius/search` | | **GSMArena** | `gsmarena/search` | | **Product H
_meta.json
{
"ownerId": "kn70nwj71rbkzwyvc7pkqs4p6s8222nc",
"slug": "browser-web-search",
"version": "0.4.11",
"publishedAt": 1778465503784
}SECURITY.md
# Security model — `browser-web-search-skill` > **Skill version:** 0.4.10 (this launcher + docs + gating policy) > **Audited upstream:** `[email protected]` (pinned, SHA-512 enforced) > **Latest external review:** ClawScan, May 2026 This document is the human-readable map between external security reviews and the file-by-file evidence in this repository. It is intentionally **code-linked** rather than aspirational: every claim below points at a specific function or field that anyone can audit. The launcher does **not** spawn subprocesses, **does not** invoke a shell, and is the only code that touches the third-party `browser-web-search` npm package. All hardening described here lives in `scripts/run.js` and `config.json`. --- ## 1. Threat model in one paragraph `browser-web-search` is a third-party npm package that executes JavaScript inside an authenticated OpenClaw browser tab. Once invoked, that JavaScript inherits the user's full login state for the visited domain (DMs, favorites, profile, orders) and — depending on browser configuration — can reach other open tabs in the same profile. This skill's launcher cannot constrain the package's behavior in-process; it can only: 1. refuse to load the package when its identity or bytes deviate from a pinned audit, and 2. interpose deny-by-default policy gates so the package is not invoked at all unless an operator has *consciously and recently* authorized the specific (site, audited bytes) combination, and 3. record every decision in an append-only audit log so any unauthorized call can be detected after the fact. These three layers are the launcher's entire contribution; the skill **does not** claim to sandbox the package's runtime behavior. --- ## 2. ClawScan May 2026 verdict — line-by-line > *Source: ClawScan, analyzed May 11 2026, type "OpenClaw Skill", > name `browser-web-search`, version 0.4.10.* ### Verdict text (verbatim) > The skill provides a high-risk capability by executing JavaScript within > authenticated browser sessions to scrape data from 55+ platforms, > including private areas like DMs, orders, and profiles. While the > launcher (`scripts/run.js`) is exceptionally defensive — implementing a > mandatory SHA-512 integrity check on the 'browser-web-search' npm > package, rejecting symbolic links, and enforcing a three-tier > authorization gate that is sealed by default — the core functionality > inherently relies on a third-party dependency to handle sensitive > session data. This high-risk access to authenticated browser states, > despite the robust mitigations and audit logging, warrants a > suspicious classification. ### Claim ↔ evidence map | ClawScan claim | Where it lives | Notes | |---|---|---| | "executes JavaScript within authenticated browser sessions to scrape data from 55+ platforms" | `SKILL.md` adapter table; `scripts/run.js` `ALWAYS_SENSITIVE_SITES`, `SENSITIVE_SUFFIX_RE`, `PUBLIC_SITES` | The launcher only forwards args; the third-party
skill-card.md
## Description: Browser Web Search lets agents run unified web-search commands across 55 platforms and return structured JSON, including optional OpenClaw browser-session backed adapters. This skill is ready for commercial/non-commercial use. ## Publisher: [sipingme](https://clawhub.ai/user/sipingme) ### License/Terms of Use: MIT-0 ## Use Case: Developers and agent builders use this skill to retrieve structured search results, trending content, repository data, videos, transcripts, and other public or authenticated site content through a common command interface. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill can invoke a third-party npm package inside an OpenClaw browser profile, including contexts that may contain authenticated site data. Mitigation: Install only when this access is acceptable, keep BWS_PUBLIC_ONLY=1 unless authenticated adapters are intentionally needed, use a dedicated browser profile, and close unrelated logged-in tabs. Risk: Users may bypass the safer launcher path or safer install flow described by the security evidence. Mitigation: Use the bws-skill scripts/run.js launcher path rather than direct bws site commands, install [email protected] with --ignore-scripts, and retain the pinned integrity checks. Risk: Sensitive browser-session calls can expose private page content if authorized accidentally or without current review. Mitigation: Use the sealed sensitive tier, per-call opt-in, platform consent ledger, transparency output, audit log, and --dry-run preflight before real sensitive calls. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/sipingme/skills/browser-web-search) - [browser-web-search-skill repository](https://github.com/sipingme/browser-web-search-skill) - [browser-web-search core library](https://github.com/sipingme/browser-web-search) - [browser-web-search npm package](https://www.npmjs.com/package/browser-web-search) - [Pinned browser-web-search source](https://github.com/sipingme/browser-web-search/blob/v0.4.3/src/index.ts) ## Skill Output: **Output Type(s):** [text, json, shell commands, configuration, guidance] **Output Format:** [Structured JSON results with command and configuration guidance] **Output Parameters:** [1D] **Other Properties Related to Output:** [Adapters may support count, sort, jq filtering, id, limit, and page options; sensitive adapters require explicit runtime gates.] ## Skill Version(s): 0.4.11 (source: server release metadata; artifact frontmatter reports 0.4.10) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/sipingme/skills/browser-web-search",
"sourceUrl": "https://clawhub.ai/sipingme/skills/browser-web-search",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T02:11:07.937Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T02:11:07.937Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.8K downloads",
"href": "https://clawhub.ai/sipingme/browser-web-search",
"sourceUrl": "https://clawhub.ai/sipingme/browser-web-search",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T02:11:07.937Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.4.11",
"href": "https://clawhub.ai/sipingme/browser-web-search",
"sourceUrl": "https://clawhub.ai/sipingme/browser-web-search",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-11T02:11:43.784Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sipingme-browser-web-search/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.4.11",
"description": "**Major hardening release with new residual-risk controls for sensitive session data:** - Adds a Gate 4 platform consent ledger (~/.bws/consents.json); one-time per-site consent now required for sensitive calls (via --accept-platform-consent). - Emits a machine-readable transparency block to stderr on every sensitive call (or all calls with BWS_TRANSPARENCY=1), detailing third-party package and audit info. - New --dry-run flag to exercise all access gates and audit logging without loading untrusted code—ideal for CI workflows. - Underlying npm dependency remains pinned and integrity-verified (0.4.3, unchanged). - SECURITY.md added.",
"href": "https://clawhub.ai/sipingme/browser-web-search",
"sourceUrl": "https://clawhub.ai/sipingme/browser-web-search",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-11T02:11:43.784Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
