agentCLAWHUBUnverified

MagicBrowse

Browser automation fallback through the magicbrowse CLI with goal-driven act as the default primitive and observe/primitives only for recovery, with changed page state verified by fresh observation.

OpenClaw

Rank

62

Safety

84

Downloads

1.8k

Updated

Oct 10, 2026

Version

0.1.19

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.8K downloadsadoption · observed Oct 10, 2026
Latest release
0.1.19release · observed Aug 20, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s170j1f52qsha0313xn4j1rjsn84bn5f:magicbrowse
  1. Install using `clawhub skill install s170j1f52qsha0313xn4j1rjsn84bn5f:magicbrowse` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/xor777/magicbrowse before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-xor777-magicbrowse/snapshot"

Documentation

CLAWHUB

144,911 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: magicbrowse
description: Browser automation fallback through the magicbrowse CLI with
  goal-driven act as the default primitive and observe/primitives only for
  recovery, with changed page state verified by fresh observation.
homepage: https://www.npmjs.com/package/@nuanu-ai/magicbrowse-cli
metadata:
  openclaw:
    homepage: https://github.com/nuanu-ai/skills/blob/main/docs/magicbrowse/openclaw/marketplace/README.md
    requires:
      bins:
        - magicbrowse
    primaryEnv: MAGICPAY_API_KEY
    install:
      - id: npm
        kind: node
        package: "@nuanu-ai/magicbrowse-cli@latest"
        bins:
          - magicbrowse
        label: Install MagicBrowse CLI (npm)
---

Use `magicbrowse` to reach a target page when your runtime's own
page-control tool cannot do it reliably. "Page-control tool"
means a tool that drives browser pages programmatically and reports page state
back — not the user's desktop browser, and not screen-control of a
browser window. The planner runs two LLM loops per task and is slower
than direct browser control; prefer your own page-control tool
when it suffices. Use `magicbrowse` to *reach* a target page (search, navigation,
traversal through non-sensitive screens). At any login, identity, checkout,
donation, subscription, payment, or human-verification page, stop and surface
to the user — do not invent or type credentials, identity data, payment data,
or any value you do not legitimately have.

For a MagicPay product/payment workflow, use the MagicPay workflow-first
recipe instead of treating a standalone MagicBrowse browser as the product
parent: MagicPay starts the product session, then launches or attaches the
browser as a child resource.

## Fallback Ladder

Try in order. Do not start at layer 4 just because primitives exist.

1. **Your runtime's own page-control tool** — programmatic page
   control owned by your runtime. Screen-control (computer use) of an
   already-open desktop browser does not qualify: takeover needs the
   browser's CDP endpoint, a typical desktop browser starts without one,
   and CDP cannot be enabled on a running browser without a restart. If
   the session may need a MagicBrowse or MagicPay takeover mid-flow,
   start from a browser with a known private CDP endpoint.
2. **`magicbrowse act "<goal>"`** — DOM-only navigator.
3. **`magicbrowse act "<goal>" --use-vision`** — same goal, navigator
   with screenshots. Use only when the user is comfortable sending
   screenshots/page context for this workflow. Vision is a retry mode
   for the same task; keep the granule.
4. **`magicbrowse observe` + primitives** —
   `click <target-id>`, `type <target-id> <text>`,
   `fill <target-id> <value>`, `select <target-id> <option-text>`,
   `press <keys>`. Use only when vision-mode `act` cannot make
   progress, or when single-element precision is required. A primitive
   `completed` result means the direct action ran; it is not a semantic
   proof that the intended page state changed

_meta.json

{
  "ownerId": "kn76jq44xm9vvwz0h4grasjvax84b83f",
  "slug": "magicbrowse",
  "version": "0.1.19",
  "publishedAt": 1787211097089
}

references/commands.md

# MagicBrowse Command Guide

Full reference for the `magicbrowse` CLI. The skill workflow uses
`launch`, `act`, `observe`, `click`/`type`/`fill`/`select`/`press`,
`mark-captcha-resolved`, and `close`. Agent setup uses
`magicbrowse init`, then `doctor`. Everything else is for diagnostics,
compatibility, or one-shot developer use.

The hard rules from `SKILL.md` apply to every command: use a fresh
browser by default, get explicit approval before using an existing
profile/CDP session, stop before consequential actions unless a matching typed
MagicPay approval covers unchanged page facts, and stop at memory fills —
never invent or placeholder Memory data.

## Setup And Readiness

### `magicbrowse init <apiKey> [--api-url <url>]`

Writes the gateway config used by LLM-backed `act`. When `--api-url` is
provided, it also stores the gateway base URL. Omit `--api-url` for normal
setup; pass `--api-url <url>` only for a non-default staging, self-hosted, or
test gateway.

Current CLI compatibility note: the persisted config path and environment
override names still use the existing `~/.magicpay/config.json`,
`MAGICPAY_API_KEY`, and `MAGICPAY_API_URL` names. Treat these as gateway
configuration names, not memory-fill ownership.

Exit codes: `0` on success, `1` if `<apiKey>` is missing.

### `magicbrowse doctor`

Verify the gateway config and reachability. Use this as the preflight
before `launch` and `act`.

Exit codes: `0` if config is healthy, `1` if not.

### `magicbrowse browser-status`

Inspect live browser/page/runtime state. Use for diagnostics only.

Exit code: `0`.

## Session Lifecycle

### `magicbrowse launch [url] [--headful] [--profile <name>]`

Start an owned Chrome session and persist it as the current session.
The URL is **positional and optional**. Headless is the default;
`--headful` is a debug/visible-browser override. Use it only when the
user explicitly asks for a visible browser or a live debugging protocol
requires it; do not add it to normal agent workflows or examples.
Advanced flags (`--user-data-dir`, `--chrome-path`, `--user-agent`)
accept overrides for non-default Chrome layouts.

Prefer a fresh owned profile. Use `--profile` or `--user-data-dir`
only after the user explicitly approves that browser state for the
current task.

Exit code: `0`.

### `magicbrowse attach <cdp-url-or-ws-endpoint>`

Attach to an existing CDP browser as the current session. The
endpoint is **positional**, not a `--cdp-url` flag.

Only attach to a private endpoint that the user provided or explicitly
approved for the current task. Treat CDP endpoints as sensitive because
they inherit the authority of that browser session. Attaching to the
browser child that MagicPay launched inside the current approved product
workflow is the normal in-workflow path and needs no separate approval;
the approval requirement targets external or user-owned browsers.

Exit codes: `0` on success, `1` if the endpoint is missing.

### `magicbrowse close`

Close or detach the cur

references/guardrails.md

# MagicBrowse Guardrails

The Hard Rules from SKILL.md, expanded to long form.

## Consequential Actions

`magicbrowse` can navigate, inspect, draft, and prepare. It must not
silently commit an account-affecting or irreversible action.

Stop and ask the user before:

- submitting a form;
- posting or sending content;
- accepting terms or confirming consent;
- changing account data, account settings, permissions, or privacy
  controls;
- booking, buying, ordering, subscribing, or paying;
- deleting, overwriting, publishing, or otherwise modifying remote
  data.

After approval, re-run `observe` so the target-id and visible state are
fresh, then execute only the exact final action the user approved. If
the page changed meaningfully, ask again rather than widening the
approval.

A successful typed MagicPay approval counts for the exact payment, signing,
or confirmation action it approved. Use it only while the approved page facts
stay unchanged.

When LLM-backed `act` reaches this boundary, it returns
`status: needs_approval`. Treat that as a controlled stop, not a
browser failure.

## Memory Fill Boundary

The `magicbrowse` skill ends at the boundary of any memory fill.
It gets the host *to* the form; it never *into* it. Reach the page,
stop before entering Memory values, and return the handoff to the
orchestrator or MagicPay Memory fill workflow.

**Forbidden field categories.** Do not use `act`, `type`, `fill`, or
`select` on:

- **Login / signup credentials.** Email, username, password, OTP,
  TOTP, magic-link inputs, "remember me" toggles tied to credential
  entry, social-auth connectors that solicit OAuth credentials in the
  same flow.
- **Identity-document fields.** Passport number, national ID number,
  KYC/AML address, date of birth tied to a verified identity,
  document expiry, document-issuing country, machine-readable-zone
  inputs, photo-of-document upload buttons.
- **Payment-card and banking fields.** Cardholder name when bound to
  the PAN, PAN, CVV/CVC, expiry, IBAN, BIC/SWIFT, sort code, routing
  number, account number, billing-address fields when they are part
  of the card form.
- **Vault- or secret-store-sourced values.** Any value whose origin is
  the user's Memory, password manager, or other Memory store, even if
  the field type itself looks generic.
- **Any value you do not legitimately have.** If you do not know it,
  do not guess and do not fabricate.

The planner and navigator already refuse credential entry at the LLM
layer. This guardrail raises that refusal from a probabilistic LLM
behaviour to a host-facing contract: even if the planner *would*
refuse, the host must not attempt it. Stop before entering Memory-managed
values, surface the situation to the user or orchestrator, and never invent
or placeholder Memory values. Be honest about what `magicbrowse` cannot
do.

The narrow exception is **placeholder values to traverse an ordinary
screen during non-committal exploration** (e.g. typing dummy passenger
names to

references/statuses.md

# MagicBrowse Statuses

## `act` Result Shape

`magicbrowse act` returns:

- `status: completed | blocked | needs_handoff | needs_approval |
  failed | max_steps | cancelled`
- `finalUrl: string | undefined` — last URL the navigator observed
- `finalMessage: string` — concise terminal report or stop explanation
- `stepCount: number` — navigator step count
- `blockedReason?: missing_input | item_unavailable | ambiguous | no_path`
  — required when `status` is `blocked`
- `handoff?: { kind, resumeObjective? }` — required when `status` is
  `needs_handoff`

JSON output shape:

```json
{
  "type": "result",
  "status": "needs_handoff",
  "finalUrl": "https://merchant.example/checkout",
  "finalMessage": "CAPTCHA challenge shown before the address form.",
  "handoff": { "kind": "captcha" },
  "stepCount": 14
}
```

Branch on `status`, then on `blockedReason` or `handoff.kind` when
present. Do not parse `finalMessage` to distinguish task success,
missing input, handoff subtype, approval, runtime failure, max steps, or
cancellation. Use `finalMessage` as text to show the user or pass to the
upstream orchestrator.

CLI exit codes:

| `status` | exit code |
| --- | ---: |
| `completed` | `0` |
| `blocked` | `0` |
| `needs_handoff` | `0` |
| `needs_approval` | `0` |
| `failed` | `1` |
| `max_steps` | `2` |
| `cancelled` | `130` |

A non-zero exit code means runtime failure, budget exhaustion, or
cancellation. `blocked`, `needs_handoff`, and `needs_approval` are
controlled browser-task stops and still exit `0`.

## Status Meanings

- `completed` — the delegated browser task reached the requested
  terminal state. Confirm with the visible evidence in `finalMessage`
  when the host needs an extra business-rule check.
- `blocked` — MagicBrowse cannot continue because ordinary
  input is missing, the requested item is unavailable,
  the delegated task is ambiguous, or the page state has no reasonable
  page-control path left inside the task. Read `blockedReason`.
- `needs_handoff` — the task reached Memory data or human
  verification: login, password, OTP, identity/KYC data, payment or
  banking fields, API keys/tokens/secrets, CAPTCHA, or a similar human
  check. Read `handoff.kind`. Surface `finalMessage` to the user and
  stop; do not retry through the barrier and do not invent or
  placeholder Memory values.
- `needs_approval` — the next useful action would commit an external
  side effect such as buy, book, pay, send, post, publish, accept
  terms, delete, or save account settings. Ask for approval before the
  exact final action unless a matching typed MagicPay approval already covers
  the unchanged page facts.
- `failed` — runtime, model, browser, or tool failure. Branch on
  `failureCode` and the `retryable` flag before deciding anything:
  `llm_provider_payment_required`, `llm_provider_auth`,
  `llm_provider_forbidden`, and `llm_request_invalid` are hard stops that
  need an account or configuration fix — do not retry them.
  `max_failures` and `inte
Github ReposUpdated 12h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/xor777/skills/magicbrowse",
      "sourceUrl": "https://clawhub.ai/xor777/skills/magicbrowse",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:38:43.838Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-xor777-magicbrowse/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-xor777-magicbrowse/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:38:43.838Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.8K downloads",
      "href": "https://clawhub.ai/xor777/magicbrowse",
      "sourceUrl": "https://clawhub.ai/xor777/magicbrowse",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:38:43.838Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.1.19",
      "href": "https://clawhub.ai/xor777/magicbrowse",
      "sourceUrl": "https://clawhub.ai/xor777/magicbrowse",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-20T07:31:37.089Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-xor777-magicbrowse/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-xor777-magicbrowse/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.1.19",
      "description": "Release magicbrowse-v0.1.19",
      "href": "https://clawhub.ai/xor777/magicbrowse",
      "sourceUrl": "https://clawhub.ai/xor777/magicbrowse",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-20T07:31:37.089Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to MagicBrowse and adjacent AI workflows.