{"id":"acf738b4-bb7c-4352-b941-158de59ef494","entityType":"agent","slug":"clawhub-wangyin717-testagent-browser-setup","name":"Testagent Browser Setup","canonicalUrl":"https://www.xpersona.co/agent/clawhub-wangyin717-testagent-browser-setup","canonicalPath":"/agent/clawhub-wangyin717-testagent-browser-setup","generatedAt":"2026-10-11T14:13:18.779Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T10:45:28.101Z","emptyReason":null},"description":"One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no ro... Skill: Testagent Browser Setup Owner: wangyin717 Summary: One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no ro... Tags: latest:1.0.10 Version history: v1.0.10 | 2026-07-23T09:56:19.919Z | auto - Version bump to 1.0.10 with no file changes detected. - No updates or modifications to the skill code or documentation i","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s176q06axk4qmw488jvzbydn7188v9dd:testagent-browser-setup","sourceUrl":"https://clawhub.ai/wangyin717/testagent-browser-setup","homepage":"https://clawhub.ai/wangyin717/skills/testagent-browser-setup","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/wangyin717/testagent-browser-setup","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/wangyin717/skills/testagent-browser-setup","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no ro..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T10:45:28.101Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T10:45:28.101Z","emptyReason":null},"stars":null,"forks":null,"downloads":1084,"packageName":null,"latestVersion":"1.0.10","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T10:45:28.089Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T10:45:28.101Z","lastCrawledAt":"2026-10-11T10:45:28.089Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T10:45:28.089Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.10","createdAt":"2026-07-23T09:56:19.919Z","changelog":"- Version bump to 1.0.10 with no file changes detected. - No updates or modifications to the skill code or documentation in this release.","fileCount":6,"zipByteSize":9545},{"version":"1.0.9","createdAt":"2026-07-23T09:51:45.203Z","changelog":"- SKILL.md and TOOLS.md have been updated with full English content and improved clarity. - All main setup instructions, notes, and troubleshooting guidance are now available in English. - Legacy skill-card.md file removed for simplification. - scripts/setup.sh updated (details not specified here).","fileCount":6,"zipByteSize":9481},{"version":"1.0.8","createdAt":"2026-06-24T02:11:20.612Z","changelog":"testagent-browser-setup 1.0.8 - Clarified that configuring the built-in browser via `openclaw.json` is often ineffective; users are advised to immediately switch to CDP direct mode if SSRF errors persist. - Updated configuration and troubleshooting instructions in SKILL.md for greater accuracy and to reflect actual gateway behavior. - Slightly revised execution steps, including improved emphasis on TOOLS.md initialization and updated step numbering. - Removed outdated skill-card.md file.","fileCount":6,"zipByteSize":9627},{"version":"1.0.7","createdAt":"2026-06-23T11:49:45.983Z","changelog":"- 优化 Chromium 安装流程，优先采用系统预装版本，无则自动通过 Playwright 下载。 - setup.sh 安装步骤简化，移除系统库批量提取与 LD_LIBRARY_PATH 配置。 - 更新文档，强调 Chromium 检测逻辑与自动切换机制。 - 移除 skill-card.md 文件，清理冗余文档。","fileCount":6,"zipByteSize":7553},{"version":"1.0.6","createdAt":"2026-06-23T02:45:15.845Z","changelog":"Version 1.0.6 - Updated setup to extract and preload required system libraries without root, enabling Chromium/CDP use in minimal containers. - Added creation of `chrome-cdp` startup script with correct environment setup and launch parameters. - Improved documentation: clarified Playwright MCP's limitations, emphasized Chrome+CDP as the stable path, and updated step-by-step setup guides in SKILL.md. - Removed outdated `skill-card.md` file.","fileCount":6,"zipByteSize":9455},{"version":"1.0.5","createdAt":"2026-06-22T13:10:26.080Z","changelog":"testagent-browser-setup 1.0.5 - 文档（SKILL.md）更新：明确 Playwright MCP 运行环境问题及常见假阳性误区，特别是 `mcp doctor --probe` 检查结果不可直接作为功能可用性依据。 - 增加无 root 权限下的 Playwright MCP 运行失败处理建议，推荐直接 fallback 到内置浏览器 + CDP 截图。 - 其余初始化及配置步骤保持不变。","fileCount":6,"zipByteSize":8796},{"version":"1.0.4","createdAt":"2026-06-22T11:41:22.734Z","changelog":"- Playwright MCP 现在通过 openclaw mcp set 注册，并强调无需 root 权限，系统依赖已由容器提供。 - 核心安装脚本优化：中文字体直接从 GitHub 下载到用户目录，过程幂等。 - 明确 Playwright MCP 与内置浏览器配置（如 noSandbox）的区别，避免混淆。 - Smoke Test 增加截图中文字清晰性和无乱码的验收标准。 - 增强文档说明，优化执行顺序和注意事项，确保流程更清晰。","fileCount":6,"zipByteSize":7709},{"version":"1.0.3","createdAt":"2026-06-22T08:42:49.581Z","changelog":"**Big update: Simplifies setup, removes root requirement, modularizes optional components** - Playwright MCP/browser-use install no longer requires root; fonts handled in user space. - Optional browser-use install split into a new `setup-optional.sh` script. - All instructions updated for non-root, container-first environments. - Removed references to deprecated skill-card.md. - Refined smoke test and troubleshooting guidance for clarity.","fileCount":6,"zipByteSize":7319}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s176q06axk4qmw488jvzbydn7188v9dd:testagent-browser-setup","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T14:13:18.776Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-wangyin717-testagent-browser-setup/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T10:45:28.101Z","emptyReason":null},"readme":"Skill: Testagent Browser Setup\n\nOwner: wangyin717\n\nSummary: One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no ro...\n\nTags: latest:1.0.10\n\nVersion history:\n\nv1.0.10 | 2026-07-23T09:56:19.919Z | auto\n\n- Version bump to 1.0.10 with no file changes detected.\n- No updates or modifications to the skill code or documentation in this release.\n\nv1.0.9 | 2026-07-23T09:51:45.203Z | auto\n\n- SKILL.md and TOOLS.md have been updated with full English content and improved clarity.\n- All main setup instructions, notes, and troubleshooting guidance are now available in English.\n- Legacy skill-card.md file removed for simplification.\n- scripts/setup.sh updated (details not specified here).\n\nv1.0.8 | 2026-06-24T02:11:20.612Z | auto\n\ntestagent-browser-setup 1.0.8\n\n- Clarified that configuring the built-in browser via `openclaw.json` is often ineffective; users are advised to immediately switch to CDP direct mode if SSRF errors persist.\n- Updated configuration and troubleshooting instructions in SKILL.md for greater accuracy and to reflect actual gateway behavior.\n- Slightly revised execution steps, including improved emphasis on TOOLS.md initialization and updated step numbering.\n- Removed outdated skill-card.md file.\n\nv1.0.7 | 2026-06-23T11:49:45.983Z | auto\n\n- 优化 Chromium 安装流程，优先采用系统预装版本，无则自动通过 Playwright 下载。\n- setup.sh 安装步骤简化，移除系统库批量提取与 LD_LIBRARY_PATH 配置。\n- 更新文档，强调 Chromium 检测逻辑与自动切换机制。\n- 移除 skill-card.md 文件，清理冗余文档。\n\nv1.0.6 | 2026-06-23T02:45:15.845Z | auto\n\nVersion 1.0.6\n\n- Updated setup to extract and preload required system libraries without root, enabling Chromium/CDP use in minimal containers.\n- Added creation of `chrome-cdp` startup script with correct environment setup and launch parameters.\n- Improved documentation: clarified Playwright MCP's limitations, emphasized Chrome+CDP as the stable path, and updated step-by-step setup guides in SKILL.md.\n- Removed outdated `skill-card.md` file.\n\nv1.0.5 | 2026-06-22T13:10:26.080Z | auto\n\ntestagent-browser-setup 1.0.5\n\n- 文档（SKILL.md）更新：明确 Playwright MCP 运行环境问题及常见假阳性误区，特别是 `mcp doctor --probe` 检查结果不可直接作为功能可用性依据。\n- 增加无 root 权限下的 Playwright MCP 运行失败处理建议，推荐直接 fallback 到内置浏览器 + CDP 截图。\n- 其余初始化及配置步骤保持不变。\n\nv1.0.4 | 2026-06-22T11:41:22.734Z | auto\n\n- Playwright MCP 现在通过 openclaw mcp set 注册，并强调无需 root 权限，系统依赖已由容器提供。\n- 核心安装脚本优化：中文字体直接从 GitHub 下载到用户目录，过程幂等。\n- 明确 Playwright MCP 与内置浏览器配置（如 noSandbox）的区别，避免混淆。\n- Smoke Test 增加截图中文字清晰性和无乱码的验收标准。\n- 增强文档说明，优化执行顺序和注意事项，确保流程更清晰。\n\nv1.0.3 | 2026-06-22T08:42:49.581Z | auto\n\n**Big update: Simplifies setup, removes root requirement, modularizes optional components**\n\n- Playwright MCP/browser-use install no longer requires root; fonts handled in user space.\n- Optional browser-use install split into a new `setup-optional.sh` script.\n- All instructions updated for non-root, container-first environments.\n- Removed references to deprecated skill-card.md.\n- Refined smoke test and troubleshooting guidance for clarity.\n\nv1.0.2 | 2026-06-17T12:25:50.925Z | auto\n\nVersion 1.0.2\n\n- Added TOOLS.md to provide a browser-use工具使用指南，供 agent 参考\n- 安装脚本（setup.sh）新增：自动复制 TOOLS.md 到项目根目录，覆盖旧版本以保持一致\n- SKILL.md 文档更新，详细说明 TOOLS.md 的初始化步骤\n\nv1.0.1 | 2026-06-17T11:08:29.763Z | auto\n\nVersion 1.1.0 introduces improved browser configuration guidance and startup sequence.\n\n- 新增「配置内置浏览器」步骤，指导直接编辑 `~/.openclaw/openclaw.json` 配置 browser 及 SSRF 防护白名单\n- 强调容器内 `noSandbox: true` 配置和 `allowedHostnames` 的必要性，避免 Chromium 超时和域名拦截问题\n- 明确提出 browser 完整重启流程：`browser stop` → `openclaw gateway restart` → 等待 → `browser start`\n- 安装和注册流程结构化调整，分为四步，更易理解与操作\n- 其他内容无重大变更\n\nv1.0.0 | 2026-06-17T07:34:45.828Z | auto\n\nInitial release of testagent-browser-setup.\n\n- Automates installation and initialization of Playwright MCP and browser-use CLI in new openclaw environments.\n- Adds Chinese font support and configures fontconfig to prevent text rendering issues in screenshots.\n- Supports both ARM64 and x86 architectures for Playwright Chromium setup.\n- Implements automated registration for browser-use using Self-Registration API; stores issued API Key in environment variables.\n- Runs smoke tests for both Playwright MCP and browser-use to ensure setup is successful and outputs error guidance if any validation fails.\n\nArchive index:\n\nArchive v1.0.10: 6 files, 9545 bytes\n\nFiles: scripts/setup-optional.sh (831b), scripts/setup.sh (4679b), skill-card.md (2666b), SKILL.md (2948b), TOOLS.md (9243b), _meta.json (143b)\n\nFile v1.0.10:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 2.2.0\ndescription: One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no root required. Triggered when the user says \"initialize test environment\", \"install browser tools\", \"setup browser\", or when deploying a test agent to a new machine for the first time.\n---\n\n# Browser Setup\n\nOne-time environment initialization, run on a fresh openclaw container. No root required.\n\n## Notes\n\nThe openclaw environment ships with Chromium pre-installed by default; `setup.sh` prefers it and only falls back to downloading via Playwright if it's not found.\n\n**The primary path for screenshots and browser actions is: Chrome + direct CDP.**\nsetup.sh creates a `~/.local/bin/chrome-cdp` launcher script.\n\n**`mcp doctor --probe` gives false positives.**\nIt returning ok only means the MCP server process started — not that Chromium can actually run. The only reliable check is: `playwright__browser_navigate` actually returning page content.\n\n## Execution order\n\n### Step 1: Run the core setup script\n\n```bash\nbash scripts/setup.sh\n```\n\nThe script does three things:\n1. **Chromium detection**: prefers the system-preinstalled Chromium, falling back to a Playwright download if not found\n2. **`chrome-cdp` launcher script**: `~/.local/bin/chrome-cdp`, wrapping the `--headless=new --no-sandbox --remote-allow-origins=*` flags\n3. **Chinese fonts**: downloads WenQuanYi Micro Hei from GitHub into `~/.local/share/fonts/`\n\n### Step 2: Try configuring the built-in browser (optional, often ineffective)\n\nEdit `~/.openclaw/openclaw.json` (`config.patch` refuses to modify protected paths, so the file must be written by hand):\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"your target product domain (e.g. app.example.com)\",\n        \"the corresponding login domain (e.g. xxx.us.auth0.com)\"\n      ]\n    }\n  }\n}\n```\n\nAfter editing: `browser stop → gateway restart → wait 15s → browser start`\n\n> ⚠️ **The SSRF allowlist often doesn't take effect** (the gateway has a runtime cache and doesn't always pick up the file).\n> If `browser navigate` still reports `blocked by policy`, **immediately abandon the built-in browser and switch to direct CDP (see TOOLS.md)** rather than continuing to restart-and-retry.\n\n### Step 4: Initialize TOOLS.md\n\n```bash\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n### Step 6 (optional): Install browser-use\n\n```bash\nbash scripts/setup-optional.sh\n```\n\n### Step 7: Smoke test\n\n```bash\n# Start Chrome CDP\nchrome-cdp &\nsleep 2\n\n# Verify CDP is reachable\ncurl -s http://localhost:9223/json | python3 -m json.tool | head -20\n\n# Verify with a screenshot (see the CDP screenshot flow in REFERENCE.md)\n```\n\nAcceptance criteria: CDP `/json` returns a target list, and Chinese text in screenshots renders cleanly with no mojibake.\n\nFile v1.0.10:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.10\",\n  \"publishedAt\": 1784800579919\n}\n\nFile v1.0.10:skill-card.md\n\n## Description:\n\nOne-time installation and initialization of Chromium, browser dependencies, Chinese fonts, and a Chrome CDP launcher in a fresh OpenClaw environment without root access.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[wangyin717](https://clawhub.ai/user/wangyin717)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and test engineers use this skill to initialize browser automation support in a fresh OpenClaw environment, including Chromium/CDP setup, Chinese font support, Playwright MCP registration, and optional browser-use tooling.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill weakens browser and network safeguards through no-sandbox CDP launch options and SSRF allowlist guidance.\n\nMitigation: Use only in an isolated test container and require explicit authorization before direct CDP is used to work around network policy.\n\nRisk: The setup scripts install mutable third-party tooling and assets from external URLs.\n\nMitigation: Review, pin, and verify third-party installers and downloads before deployment.\n\nRisk: The optional browser-use workflow can reuse local Chrome profiles or real credentials.\n\nMitigation: Do not reuse personal browser profiles or production credentials; use disposable test accounts and isolated browser state.\n\nRisk: Security evidence marks the release suspicious and recommends review before use.\n\nMitigation: Perform security review and scanner review before installing or running the skill.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/wangyin717/skills/testagent-browser-setup)\n- [browser-use repository](https://github.com/browser-use/browser-use)\n- [WenQuanYi Micro Hei font source](https://github.com/anthonyfok/fonts-wqy-microhei/raw/master/wqy-microhei.ttc)\n- [browser-use CLI installer](https://browser-use.com/cli/install.sh)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration, Guidance, Code]\n\n**Output Format:** [Markdown guidance with shell commands, JSON configuration snippets, and JavaScript CDP examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces setup and testing guidance for an agent; setup scripts may install browser tooling and create local configuration files.]\n\n## Skill Version(s):\n\n1.0.10 (source: server release metadata; artifact frontmatter reports 2.2.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.0.10:TOOLS.md\n\n# TOOLS.md — Browser Tools Guide\n\n## Comparison of the three browser tools\n\n| | OpenClaw built-in browser | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **Invocation** | `browser` tool (snapshot/act/screenshot) | `playwright__browser_*` tool family | `exec` calling the `browser-use` command |\n| **Browser engine** | Local Chromium | Local Chromium | Local Chromium / cloud browser |\n| **State retrieval** | accessibility snapshot (text tree) | snapshot (text tree) | `state` (indexed element list) |\n| **Element targeting** | ref (e.g. e36) | ref + selector | numeric index (e.g. click 5) |\n| **Screenshot output** | AI analysis text (❌ not shareable) | PNG file (✅ shareable) | saved path (✅ shareable) |\n| **JS execution** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **Keyboard events** | ⚠️ doesn't work on React controlled components | ✅ works well | ✅ `keys \"Enter\"` |\n| **Cloud browser** | ❌ | ❌ | ✅ `cloud connect` |\n| **Reuse login session** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **Anti-bot/CAPTCHA** | ❌ | ❌ | ✅ built into the cloud browser |\n| **Residential proxy** | ❌ | ❌ | ✅ 195+ countries |\n| **Internal network tunnel** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **Parallel multi-session** | limited (tabs) | limited (tabs) | ✅ `--session NAME` |\n| **Command chaining** | not supported | not supported | ✅ chainable with `&&` |\n| **Persisted login state** | ✅ persists within the same tab | ✅ persists within the same page | ✅ kept alive by a daemon, persists across commands |\n\n## Choosing a tool for the task\n\n### → Use the OpenClaw built-in browser (default choice)\n- Routine functional testing and page interaction\n- Actions within an already-logged-in session\n- When screenshots don't need to be shared with the user\n- **Advantage**: tightly integrated tooling, gets things done in one step\n\n### → Use Playwright MCP\n- Need to share a screenshot with the user (bug screenshots, state confirmation)\n- Precise interaction with React/Vue controlled components (good keyboard event support)\n- Need precise selector-based element targeting\n- **Advantage**: most precise element targeting, screenshots are usable\n\n### → Use browser-use CLI\n- Need a cloud browser (anti-bot, CAPTCHA, residential proxy)\n- Need to reuse the user's local Chrome login session\n- Internal services need to be reached via a tunnel (`tunnel <port>`)\n- Fast exploration of a new product (efficient with `&&` command chains)\n- Parallel testing across multiple products (`--session` multi-session)\n- **Advantage**: strongest browser capabilities, full coverage across cloud + local + tunnel\n\n## Typical testing workflow\n\n1. **First-time exploration of a new product** → browser-use CLI (cloud browser + command chains for a quick survey)\n2. **Regression testing on a familiar product** → OpenClaw built-in (fast) or Playwright MCP (precise)\n3. **Need a screenshot to document a bug** → Playwright MCP or browser-use CLI\n4. **Sites with restricted login sessions** → browser-use CLI (`--profile` to reuse login)\n5. **Sites with strict anti-bot measures** → browser-use CLI (`cloud connect`)\n\n## Correct screenshot workflow\n\n```\n1. playwright__browser_take_screenshot → filename=\"/tmp/screenshot.png\"\n2. cp /tmp/screenshot.png /root/.openclaw/workspace/<description>.png\n3. Attach in the reply: MEDIA:/root/.openclaw/workspace/<description>.png\n```\n\n- The built-in browser's `browser screenshot` only returns AI analysis text — it **cannot** be shared via `MEDIA:`\n- `MEDIA:` only renders inside chat replies; writing it into a `.md` file will not display the image\n\n## Direct CDP connection (the primary path when the built-in browser's SSRF check blocks you)\n\nThe built-in browser's SSRF allowlist configuration often doesn't take effect (the gateway has a runtime cache, and writing to the file alone doesn't help). **As soon as `browser navigate` reports `blocked by policy`, switch immediately to direct CDP rather than continuing to restart-and-retry.**\n\n### Start\n\n```bash\nchrome-cdp &          # ~/.local/bin/chrome-cdp, headless + CDP port 9223\nsleep 2\ncurl -s http://localhost:9223/json   # verify it's reachable\n```\n\n### Node.js CDP login template\n\n```javascript\n// login.js — requires the ws package (already installed by setup.sh)\nconst WebSocket = require('ws');\n\nasync function cdp(ws, method, params = {}) {\n  return new Promise((resolve, reject) => {\n    const id = Date.now();\n    ws.send(JSON.stringify({ id, method, params }));\n    ws.once('message', d => {\n      const r = JSON.parse(d);\n      r.error ? reject(r.error) : resolve(r.result);\n    });\n  });\n}\n\nasync function waitForElement(ws, selector, timeout = 10000) {\n  const start = Date.now();\n  while (Date.now() - start < timeout) {\n    const { result } = await cdp(ws, 'Runtime.evaluate', {\n      expression: `!!document.querySelector('${selector}') && document.querySelector('${selector}').offsetParent !== null`,\n      returnByValue: true,\n    });\n    if (result.value) return;\n    await new Promise(r => setTimeout(r, 500));\n  }\n  throw new Error(`Timeout waiting for ${selector}`);\n}\n\nasync function fillInput(ws, selector, value) {\n  // Use nativeInputValueSetter to trigger React's state update\n  await cdp(ws, 'Runtime.evaluate', {\n    expression: `\n      const el = document.querySelector('${selector}');\n      const setter = Object.getOwnPropertyDescriptor(HTMLInputElement.prototype, 'value').set;\n      setter.call(el, '');                                     // clear first\n      el.dispatchEvent(new Event('input', { bubbles: true }));\n      setter.call(el, ${JSON.stringify(value)});               // then fill the value\n      el.dispatchEvent(new Event('input', { bubbles: true }));\n      el.dispatchEvent(new Event('change', { bubbles: true }));\n    `,\n  });\n}\n\n(async () => {\n  const targets = await (await fetch('http://localhost:9223/json')).json();\n  const ws = new WebSocket(targets[0].webSocketDebuggerUrl);\n  await new Promise(r => ws.on('open', r));\n\n  await cdp(ws, 'Page.navigate', { url: 'https://your-app.example.com/login' });\n  await cdp(ws, 'Page.loadEventFired');  // wait for the page to finish loading\n\n  // Fill in the email (Auth0 identifier-first flow)\n  await waitForElement(ws, 'input[type=\"email\"], input[name=\"email\"]');\n  await fillInput(ws, 'input[type=\"email\"], input[name=\"email\"]', 'user@example.com');\n  await cdp(ws, 'Runtime.evaluate', { expression: `document.querySelector('[type=\"submit\"], button[name=\"action\"]').click()` });\n\n  // Wait for the password field to appear (Auth0: the URL stays the same, only the DOM updates) — don't rely on the URL\n  await waitForElement(ws, 'input[type=\"password\"]');\n  await fillInput(ws, 'input[type=\"password\"]', 'your-password');\n  await cdp(ws, 'Runtime.evaluate', { expression: `document.querySelector('[type=\"submit\"], button[name=\"action\"]').click()` });\n\n  // Wait for the post-login redirect\n  await cdp(ws, 'Page.loadEventFired');\n  console.log('Login done');\n  ws.close();\n})();\n```\n\nRun: `node login.js`\n\n---\n\n## Common pitfalls\n\n### React form filling: `input.value = 'xxx'` doesn't work\n\nReact controlled components intercept `input.value`; a direct assignment doesn't trigger a state update, so the form submits an empty value.\n\n**You must use nativeInputValueSetter** (see the `fillInput` function above). Don't use a plain assignment, and don't use Playwright's `fill()` (it doesn't work in the direct-CDP scenario).\n\n### Auth0 multi-step login: don't rely on URL changes to detect steps\n\nAuth0's identifier-first flow: enter the email → click Continue → the URL **stays the same** (still `/u/login/identifier`), but the DOM updates internally to the password page. The password field starts out `hidden` and only becomes visible after the email is submitted.\n\n**Judge by whether `input[type=\"password\"]` is visible** (offsetParent !== null), polling for up to 10 seconds. Don't wait for a URL change.\n\n### Clear old values before filling\n\nEvery `fillInput` call must first do `setter.call(el, '')` plus fire an input event — otherwise, if the field already has a value, the new value gets appended instead of replacing it.\n\n### No pip in the Python container — use Node.js for CDP scripts\n\nThe container's Python has no `pip`, so `websockets` can't be installed. Use Node.js with the `ws` package instead (already installed by `setup.sh`).\n\n### Keyboard events don't work on React/Vue controlled components\nShortcuts like `keyboard.press('Control+Enter')` may not trigger on controlled components.\n\nFix: find the page's actual submit button and click it via JS:\n```javascript\ndocument.querySelector('[aria-label=\"Send\"]').click()\n```\n\n### Mojibake (□□□) in screenshots for Chinese text\nRun `setup.sh` from the `testagent-browser-setup` skill, which automatically installs Chinese fonts and configures fontconfig.\n\n### Config changes not taking effect\nAfter editing `~/.openclaw/openclaw.json`, you must run the full sequence:\n```\nbrowser stop → openclaw gateway restart → wait 15s → browser start\n```\nRestarting only the gateway, or only the browser, is not enough. **Even if the SSRF allowlist file write succeeds, it may still not take effect due to the runtime cache.**\n\nArchive v1.0.9: 6 files, 9481 bytes\n\nFiles: scripts/setup-optional.sh (831b), scripts/setup.sh (4679b), skill-card.md (2556b), SKILL.md (2948b), TOOLS.md (9243b), _meta.json (142b)\n\nFile v1.0.9:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 2.2.0\ndescription: One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no root required. Triggered when the user says \"initialize test environment\", \"install browser tools\", \"setup browser\", or when deploying a test agent to a new machine for the first time.\n---\n\n# Browser Setup\n\nOne-time environment initialization, run on a fresh openclaw container. No root required.\n\n## Notes\n\nThe openclaw environment ships with Chromium pre-installed by default; `setup.sh` prefers it and only falls back to downloading via Playwright if it's not found.\n\n**The primary path for screenshots and browser actions is: Chrome + direct CDP.**\nsetup.sh creates a `~/.local/bin/chrome-cdp` launcher script.\n\n**`mcp doctor --probe` gives false positives.**\nIt returning ok only means the MCP server process started — not that Chromium can actually run. The only reliable check is: `playwright__browser_navigate` actually returning page content.\n\n## Execution order\n\n### Step 1: Run the core setup script\n\n```bash\nbash scripts/setup.sh\n```\n\nThe script does three things:\n1. **Chromium detection**: prefers the system-preinstalled Chromium, falling back to a Playwright download if not found\n2. **`chrome-cdp` launcher script**: `~/.local/bin/chrome-cdp`, wrapping the `--headless=new --no-sandbox --remote-allow-origins=*` flags\n3. **Chinese fonts**: downloads WenQuanYi Micro Hei from GitHub into `~/.local/share/fonts/`\n\n### Step 2: Try configuring the built-in browser (optional, often ineffective)\n\nEdit `~/.openclaw/openclaw.json` (`config.patch` refuses to modify protected paths, so the file must be written by hand):\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"your target product domain (e.g. app.example.com)\",\n        \"the corresponding login domain (e.g. xxx.us.auth0.com)\"\n      ]\n    }\n  }\n}\n```\n\nAfter editing: `browser stop → gateway restart → wait 15s → browser start`\n\n> ⚠️ **The SSRF allowlist often doesn't take effect** (the gateway has a runtime cache and doesn't always pick up the file).\n> If `browser navigate` still reports `blocked by policy`, **immediately abandon the built-in browser and switch to direct CDP (see TOOLS.md)** rather than continuing to restart-and-retry.\n\n### Step 4: Initialize TOOLS.md\n\n```bash\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n### Step 6 (optional): Install browser-use\n\n```bash\nbash scripts/setup-optional.sh\n```\n\n### Step 7: Smoke test\n\n```bash\n# Start Chrome CDP\nchrome-cdp &\nsleep 2\n\n# Verify CDP is reachable\ncurl -s http://localhost:9223/json | python3 -m json.tool | head -20\n\n# Verify with a screenshot (see the CDP screenshot flow in REFERENCE.md)\n```\n\nAcceptance criteria: CDP `/json` returns a target list, and Chinese text in screenshots renders cleanly with no mojibake.\n\nFile v1.0.9:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.9\",\n  \"publishedAt\": 1784800305203\n}\n\nFile v1.0.9:skill-card.md\n\n## Description: <br>\nOne-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh OpenClaw environment without root access. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[wangyin717](https://clawhub.ai/user/wangyin717) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and test agents use this skill to prepare a fresh OpenClaw environment for browser-based testing, screenshots, direct CDP control, and Chinese text rendering. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The setup enables broad local browser control through headless Chromium and direct CDP. <br>\nMitigation: Use it only in a disposable or tightly controlled environment and review the setup scripts before execution. <br>\nRisk: The optional browser-use installer pulls and runs an upstream installer and skill from external sources. <br>\nMitigation: Skip the optional installer unless the upstream source is trusted and separately reviewed. <br>\nRisk: Reusing personal browser profiles or bypassing network policy through direct CDP can expose sensitive sessions or violate environment controls. <br>\nMitigation: Do not reuse personal Chrome profiles, and use direct CDP only with explicit authorization for the target environment. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/wangyin717/skills/testagent-browser-setup) <br>\n- [Browser tools guide](artifact/TOOLS.md) <br>\n- [browser-use repository](https://github.com/browser-use/browser-use) <br>\n- [WenQuanYi Micro Hei font source](https://github.com/anthonyfok/fonts-wqy-microhei/raw/master/wqy-microhei.ttc) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Configuration, Code, Guidance] <br>\n**Output Format:** [Markdown with inline shell commands, JSON configuration, and JavaScript examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Produces local setup guidance and scripts for Chromium, CDP, Playwright MCP, Chinese fonts, and optional browser-use installation.] <br>\n\n## Skill Version(s): <br>\n1.0.9 (source: server release metadata; artifact frontmatter reports 2.2.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.9:TOOLS.md\n\n# TOOLS.md — Browser Tools Guide\n\n## Comparison of the three browser tools\n\n| | OpenClaw built-in browser | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **Invocation** | `browser` tool (snapshot/act/screenshot) | `playwright__browser_*` tool family | `exec` calling the `browser-use` command |\n| **Browser engine** | Local Chromium | Local Chromium | Local Chromium / cloud browser |\n| **State retrieval** | accessibility snapshot (text tree) | snapshot (text tree) | `state` (indexed element list) |\n| **Element targeting** | ref (e.g. e36) | ref + selector | numeric index (e.g. click 5) |\n| **Screenshot output** | AI analysis text (❌ not shareable) | PNG file (✅ shareable) | saved path (✅ shareable) |\n| **JS execution** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **Keyboard events** | ⚠️ doesn't work on React controlled components | ✅ works well | ✅ `keys \"Enter\"` |\n| **Cloud browser** | ❌ | ❌ | ✅ `cloud connect` |\n| **Reuse login session** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **Anti-bot/CAPTCHA** | ❌ | ❌ | ✅ built into the cloud browser |\n| **Residential proxy** | ❌ | ❌ | ✅ 195+ countries |\n| **Internal network tunnel** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **Parallel multi-session** | limited (tabs) | limited (tabs) | ✅ `--session NAME` |\n| **Command chaining** | not supported | not supported | ✅ chainable with `&&` |\n| **Persisted login state** | ✅ persists within the same tab | ✅ persists within the same page | ✅ kept alive by a daemon, persists across commands |\n\n## Choosing a tool for the task\n\n### → Use the OpenClaw built-in browser (default choice)\n- Routine functional testing and page interaction\n- Actions within an already-logged-in session\n- When screenshots don't need to be shared with the user\n- **Advantage**: tightly integrated tooling, gets things done in one step\n\n### → Use Playwright MCP\n- Need to share a screenshot with the user (bug screenshots, state confirmation)\n- Precise interaction with React/Vue controlled components (good keyboard event support)\n- Need precise selector-based element targeting\n- **Advantage**: most precise element targeting, screenshots are usable\n\n### → Use browser-use CLI\n- Need a cloud browser (anti-bot, CAPTCHA, residential proxy)\n- Need to reuse the user's local Chrome login session\n- Internal services need to be reached via a tunnel (`tunnel <port>`)\n- Fast exploration of a new product (efficient with `&&` command chains)\n- Parallel testing across multiple products (`--session` multi-session)\n- **Advantage**: strongest browser capabilities, full coverage across cloud + local + tunnel\n\n## Typical testing workflow\n\n1. **First-time exploration of a new product** → browser-use CLI (cloud browser + command chains for a quick survey)\n2. **Regression testing on a familiar product** → OpenClaw built-in (fast) or Playwright MCP (precise)\n3. **Need a screenshot to document a bug** → Playwright MCP or browser-use CLI\n4. **Sites with restricted login sessions** → browser-use CLI (`--profile` to reuse login)\n5. **Sites with strict anti-bot measures** → browser-use CLI (`cloud connect`)\n\n## Correct screenshot workflow\n\n```\n1. playwright__browser_take_screenshot → filename=\"/tmp/screenshot.png\"\n2. cp /tmp/screenshot.png /root/.openclaw/workspace/<description>.png\n3. Attach in the reply: MEDIA:/root/.openclaw/workspace/<description>.png\n```\n\n- The built-in browser's `browser screenshot` only returns AI analysis text — it **cannot** be shared via `MEDIA:`\n- `MEDIA:` only renders inside chat replies; writing it into a `.md` file will not display the image\n\n## Direct CDP connection (the primary path when the built-in browser's SSRF check blocks you)\n\nThe built-in browser's SSRF allowlist configuration often doesn't take effect (the gateway has a runtime cache, and writing to the file alone doesn't help). **As soon as `browser navigate` reports `blocked by policy`, switch immediately to direct CDP rather than continuing to restart-and-retry.**\n\n### Start\n\n```bash\nchrome-cdp &          # ~/.local/bin/chrome-cdp, headless + CDP port 9223\nsleep 2\ncurl -s http://localhost:9223/json   # verify it's reachable\n```\n\n### Node.js CDP login template\n\n```javascript\n// login.js — requires the ws package (already installed by setup.sh)\nconst WebSocket = require('ws');\n\nasync function cdp(ws, method, params = {}) {\n  return new Promise((resolve, reject) => {\n    const id = Date.now();\n    ws.send(JSON.stringify({ id, method, params }));\n    ws.once('message', d => {\n      const r = JSON.parse(d);\n      r.error ? reject(r.error) : resolve(r.result);\n    });\n  });\n}\n\nasync function waitForElement(ws, selector, timeout = 10000) {\n  const start = Date.now();\n  while (Date.now() - start < timeout) {\n    const { result } = await cdp(ws, 'Runtime.evaluate', {\n      expression: `!!document.querySelector('${selector}') && document.querySelector('${selector}').offsetParent !== null`,\n      returnByValue: true,\n    });\n    if (result.value) return;\n    await new Promise(r => setTimeout(r, 500));\n  }\n  throw new Error(`Timeout waiting for ${selector}`);\n}\n\nasync function fillInput(ws, selector, value) {\n  // Use nativeInputValueSetter to trigger React's state update\n  await cdp(ws, 'Runtime.evaluate', {\n    expression: `\n      const el = document.querySelector('${selector}');\n      const setter = Object.getOwnPropertyDescriptor(HTMLInputElement.prototype, 'value').set;\n      setter.call(el, '');                                     // clear first\n      el.dispatchEvent(new Event('input', { bubbles: true }));\n      setter.call(el, ${JSON.stringify(value)});               // then fill the value\n      el.dispatchEvent(new Event('input', { bubbles: true }));\n      el.dispatchEvent(new Event('change', { bubbles: true }));\n    `,\n  });\n}\n\n(async () => {\n  const targets = await (await fetch('http://localhost:9223/json')).json();\n  const ws = new WebSocket(targets[0].webSocketDebuggerUrl);\n  await new Promise(r => ws.on('open', r));\n\n  await cdp(ws, 'Page.navigate', { url: 'https://your-app.example.com/login' });\n  await cdp(ws, 'Page.loadEventFired');  // wait for the page to finish loading\n\n  // Fill in the email (Auth0 identifier-first flow)\n  await waitForElement(ws, 'input[type=\"email\"], input[name=\"email\"]');\n  await fillInput(ws, 'input[type=\"email\"], input[name=\"email\"]', 'user@example.com');\n  await cdp(ws, 'Runtime.evaluate', { expression: `document.querySelector('[type=\"submit\"], button[name=\"action\"]').click()` });\n\n  // Wait for the password field to appear (Auth0: the URL stays the same, only the DOM updates) — don't rely on the URL\n  await waitForElement(ws, 'input[type=\"password\"]');\n  await fillInput(ws, 'input[type=\"password\"]', 'your-password');\n  await cdp(ws, 'Runtime.evaluate', { expression: `document.querySelector('[type=\"submit\"], button[name=\"action\"]').click()` });\n\n  // Wait for the post-login redirect\n  await cdp(ws, 'Page.loadEventFired');\n  console.log('Login done');\n  ws.close();\n})();\n```\n\nRun: `node login.js`\n\n---\n\n## Common pitfalls\n\n### React form filling: `input.value = 'xxx'` doesn't work\n\nReact controlled components intercept `input.value`; a direct assignment doesn't trigger a state update, so the form submits an empty value.\n\n**You must use nativeInputValueSetter** (see the `fillInput` function above). Don't use a plain assignment, and don't use Playwright's `fill()` (it doesn't work in the direct-CDP scenario).\n\n### Auth0 multi-step login: don't rely on URL changes to detect steps\n\nAuth0's identifier-first flow: enter the email → click Continue → the URL **stays the same** (still `/u/login/identifier`), but the DOM updates internally to the password page. The password field starts out `hidden` and only becomes visible after the email is submitted.\n\n**Judge by whether `input[type=\"password\"]` is visible** (offsetParent !== null), polling for up to 10 seconds. Don't wait for a URL change.\n\n### Clear old values before filling\n\nEvery `fillInput` call must first do `setter.call(el, '')` plus fire an input event — otherwise, if the field already has a value, the new value gets appended instead of replacing it.\n\n### No pip in the Python container — use Node.js for CDP scripts\n\nThe container's Python has no `pip`, so `websockets` can't be installed. Use Node.js with the `ws` package instead (already installed by `setup.sh`).\n\n### Keyboard events don't work on React/Vue controlled components\nShortcuts like `keyboard.press('Control+Enter')` may not trigger on controlled components.\n\nFix: find the page's actual submit button and click it via JS:\n```javascript\ndocument.querySelector('[aria-label=\"Send\"]').click()\n```\n\n### Mojibake (□□□) in screenshots for Chinese text\nRun `setup.sh` from the `testagent-browser-setup` skill, which automatically installs Chinese fonts and configures fontconfig.\n\n### Config changes not taking effect\nAfter editing `~/.openclaw/openclaw.json`, you must run the full sequence:\n```\nbrowser stop → openclaw gateway restart → wait 15s → browser start\n```\nRestarting only the gateway, or only the browser, is not enough. **Even if the SSRF allowlist file write succeeds, it may still not take effect due to the runtime cache.**\n\nArchive v1.0.8: 6 files, 9627 bytes\n\nFiles: scripts/setup-optional.sh (831b), scripts/setup.sh (4725b), skill-card.md (2465b), SKILL.md (2614b), TOOLS.md (8162b), _meta.json (142b)\n\nFile v1.0.8:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 2.2.0\ndescription: 在新的 openclaw 环境中安装并初始化 Chromium、系统依赖、中文字体和 CDP 启动脚本，无需 root 权限。当用户说「初始化测试环境」「安装浏览器工具」「setup browser」或在新机器首次部署测试 agent 时触发。\n---\n\n# Browser Setup\n\n一次性环境初始化，在新 openclaw 容器上执行。不需要 root 权限。\n\n## 说明\n\nopenclaw 环境默认已预装 Chromium，`setup.sh` 会优先使用它。若未找到则自动通过 Playwright 下载。\n\n**截图和浏览器操作的主路径是：Chrome + CDP 直连。**\nsetup.sh 会创建 `~/.local/bin/chrome-cdp` 启动脚本。\n\n**`mcp doctor --probe` 是假阳性。**\n返回 ok 只说明 MCP server 进程启动，不代表 Chromium 能实际运行。唯一可信的验证：`playwright__browser_navigate` 真正返回页面内容。\n\n## 执行顺序\n\n### 第一步：运行核心安装脚本\n\n```bash\nbash scripts/setup.sh\n```\n\n脚本完成三件事：\n1. **Chromium 检测**：优先用系统预装 Chromium，未找到则通过 Playwright 下载\n2. **`chrome-cdp` 启动脚本**：`~/.local/bin/chrome-cdp`，封装 `--headless=new --no-sandbox --remote-allow-origins=*` 参数\n3. **中文字体**：从 GitHub 下载 WenQuanYi Micro Hei 到 `~/.local/share/fonts/`\n\n### 第二步：尝试配置内置浏览器（可选，经常无效）\n\n编辑 `~/.openclaw/openclaw.json`（`config.patch` 拒绝修改受保护路径，只能手动写文件）：\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"你的目标产品域名（如 app.example.com）\",\n        \"对应的登录域名（如 xxx.us.auth0.com）\"\n      ]\n    }\n  }\n}\n```\n\n改完后：`browser stop → gateway restart → 等 15 秒 → browser start`\n\n> ⚠️ **SSRF 白名单经常不生效**（gateway 有运行时缓存，不以文件为准）。\n> 若 `browser navigate` 仍然报 `blocked by policy`，**立即放弃内置浏览器，改用 CDP 直连（见 TOOLS.md）**，不要继续重启验证。\n\n### 第四步：初始化 TOOLS.md\n\n```bash\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n### 第六步（可选）：安装 browser-use\n\n```bash\nbash scripts/setup-optional.sh\n```\n\n### 第七步：Smoke Test\n\n```bash\n# 启动 Chrome CDP\nchrome-cdp &\nsleep 2\n\n# 验证 CDP 可访问\ncurl -s http://localhost:9223/json | python3 -m json.tool | head -20\n\n# 截图验证（见 REFERENCE.md 的 CDP 截图流程）\n```\n\n验收标准：CDP `/json` 能返回 target 列表，截图中中文清晰无乱码。\n\nFile v1.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.8\",\n  \"publishedAt\": 1782267080612\n}\n\nFile v1.0.8:skill-card.md\n\n## Description: <br>\nSets up Chromium browser tooling, Chinese font support, Playwright MCP registration, and CDP launch helpers for new OpenClaw test-agent environments. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[wangyin717](https://clawhub.ai/user/wangyin717) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and test-agent operators use this skill to initialize browser automation dependencies in a new OpenClaw environment and choose between built-in browser tooling, Playwright MCP, CDP direct mode, and optional browser-use workflows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill enables broad browser-control, CDP, profile/session, proxy, tunnel, policy-bypass, and remote-install capabilities. <br>\nMitigation: Review before installation, run only in an isolated test environment, and avoid using CDP fallback to bypass network or SSRF controls without explicit authorization. <br>\nRisk: Optional browser-use installation pulls and installs upstream code at runtime. <br>\nMitigation: Skip the optional installer unless the upstream source is trusted and pinned for the deployment environment. <br>\nRisk: Browser profile reuse can expose real sessions or credentials. <br>\nMitigation: Use disposable browser profiles and avoid reusing a real Chrome profile. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/wangyin717/skills/testagent-browser-setup) <br>\n- [browser-use upstream skill](https://github.com/browser-use/browser-use) <br>\n- [WenQuanYi Micro Hei font source](https://github.com/anthonyfok/fonts-wqy-microhei/raw/master/wqy-microhei.ttc) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Configuration, Code, Markdown, Guidance] <br>\n**Output Format:** [Markdown guidance with Bash, JSON, and JavaScript snippets plus setup scripts] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Creates local browser setup artifacts such as a chrome-cdp launcher and user-level font configuration.] <br>\n\n## Skill Version(s): <br>\n1.0.8 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.8:TOOLS.md\n\n# TOOLS.md — 浏览器工具使用指南\n\n## 三个浏览器工具对比\n\n| | OpenClaw 内置浏览器 | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **调用方式** | `browser` 工具（snapshot/act/screenshot） | `playwright__browser_*` 系列工具 | `exec` 调用 `browser-use` 命令 |\n| **浏览器引擎** | 本地 Chromium | 本地 Chromium | 本地 Chromium / 云端浏览器 |\n| **状态获取** | accessibility snapshot（文本树） | snapshot（文本树） | `state`（元素索引列表） |\n| **元素定位** | ref（如 e36） | ref + selector | 数字索引（如 click 5） |\n| **截图返回** | AI 分析文本（❌ 不可分享） | PNG 文件（✅ 可分享） | 保存路径（✅ 可分享） |\n| **JS 执行** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **键盘事件** | ⚠️ React 受控组件不生效 | ✅ 支持良好 | ✅ `keys \"Enter\"` |\n| **云浏览器** | ❌ | ❌ | ✅ `cloud connect` |\n| **复用登录态** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **反爬/CAPTCHA** | ❌ | ❌ | ✅ 云浏览器内置 |\n| **住宅代理** | ❌ | ❌ | ✅ 195+ 国家 |\n| **内网隧道** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **多会话并行** | 有限（tabs） | 有限（tabs） | ✅ `--session NAME` |\n| **命令链** | 不支持 | 不支持 | ✅ `&&` 链式执行 |\n| **登录态保持** | ✅ 同一 tab 内保持 | ✅ 同一 page 内保持 | ✅ daemon 保活，跨命令保持 |\n\n## 使用场景选择\n\n### → 用 OpenClaw 内置浏览器（默认首选）\n- 常规功能测试和页面交互\n- 已登录的会话内操作\n- 不需要截图分享给用户时\n- **优势**：工具集成度高，一步到位\n\n### → 用 Playwright MCP\n- 需要截图分享给用户（bug 截图、状态确认）\n- React/Vue 受控组件的精确交互（键盘事件支持好）\n- 需要精确 selector 定位元素\n- **优势**：元素定位最精确，截图可用\n\n### → 用 browser-use CLI\n- 需要云浏览器（反爬、CAPTCHA、住宅代理）\n- 需要复用用户本地 Chrome 登录态\n- 内网服务需通过隧道访问（`tunnel <port>`）\n- 新产品快速探索（命令链 `&&` 高效）\n- 多产品并行测试（`--session` 多会话）\n- **优势**：浏览器能力最强，云+本地+隧道全覆盖\n\n## 典型测试流程\n\n1. **新产品首次探索** → browser-use CLI（云浏览器 + 命令链快速摸底）\n2. **已熟悉产品回归测试** → OpenClaw 内置（快）或 Playwright MCP（精）\n3. **需要截图记录 Bug** → Playwright MCP 或 browser-use CLI\n4. **登录态受限的网站** → browser-use CLI（`--profile` 复用登录）\n5. **反爬严格的网站** → browser-use CLI（`cloud connect`）\n\n## 截图正确流程\n\n```\n1. playwright__browser_take_screenshot → filename=\"/tmp/screenshot.png\"\n2. cp /tmp/screenshot.png /root/.openclaw/workspace/<描述>.png\n3. 回复中附加: MEDIA:/root/.openclaw/workspace/<描述>.png\n```\n\n- 内置浏览器的 `browser screenshot` 只返回 AI 分析文本，**无法**用 `MEDIA:` 分享\n- `MEDIA:` 只在聊天回复中渲染，写进 `.md` 文件里不会显示图片\n\n## CDP 直连（内置浏览器 SSRF 被拦时的主路径）\n\n内置浏览器的 SSRF 白名单配置经常不生效（gateway 运行时缓存，文件写入不起作用）。**一旦 `browser navigate` 报 `blocked by policy`，立即切换到 CDP 直连，不要继续重启验证。**\n\n### 启动\n\n```bash\nchrome-cdp &          # ~/.local/bin/chrome-cdp，headless + CDP port 9223\nsleep 2\ncurl -s http://localhost:9223/json   # 验证可访问\n```\n\n### Node.js CDP 登录模板\n\n```javascript\n// login.js — 需要 ws 包（setup.sh 已预装）\nconst WebSocket = require('ws');\n\nasync function cdp(ws, method, params = {}) {\n  return new Promise((resolve, reject) => {\n    const id = Date.now();\n    ws.send(JSON.stringify({ id, method, params }));\n    ws.once('message', d => {\n      const r = JSON.parse(d);\n      r.error ? reject(r.error) : resolve(r.result);\n    });\n  });\n}\n\nasync function waitForElement(ws, selector, timeout = 10000) {\n  const start = Date.now();\n  while (Date.now() - start < timeout) {\n    const { result } = await cdp(ws, 'Runtime.evaluate', {\n      expression: `!!document.querySelector('${selector}') && document.querySelector('${selector}').offsetParent !== null`,\n      returnByValue: true,\n    });\n    if (result.value) return;\n    await new Promise(r => setTimeout(r, 500));\n  }\n  throw new Error(`Timeout waiting for ${selector}`);\n}\n\nasync function fillInput(ws, selector, value) {\n  // 用 nativeInputValueSetter 触发 React state 更新\n  await cdp(ws, 'Runtime.evaluate', {\n    expression: `\n      const el = document.querySelector('${selector}');\n      const setter = Object.getOwnPropertyDescriptor(HTMLInputElement.prototype, 'value').set;\n      setter.call(el, '');                                     // 先清空\n      el.dispatchEvent(new Event('input', { bubbles: true }));\n      setter.call(el, ${JSON.stringify(value)});               // 再填值\n      el.dispatchEvent(new Event('input', { bubbles: true }));\n      el.dispatchEvent(new Event('change', { bubbles: true }));\n    `,\n  });\n}\n\n(async () => {\n  const targets = await (await fetch('http://localhost:9223/json')).json();\n  const ws = new WebSocket(targets[0].webSocketDebuggerUrl);\n  await new Promise(r => ws.on('open', r));\n\n  await cdp(ws, 'Page.navigate', { url: 'https://your-app.example.com/login' });\n  await cdp(ws, 'Page.loadEventFired');  // 等页面加载完\n\n  // 填邮箱（Auth0 identifier-first 流程）\n  await waitForElement(ws, 'input[type=\"email\"], input[name=\"email\"]');\n  await fillInput(ws, 'input[type=\"email\"], input[name=\"email\"]', 'user@example.com');\n  await cdp(ws, 'Runtime.evaluate', { expression: `document.querySelector('[type=\"submit\"], button[name=\"action\"]').click()` });\n\n  // 等密码框出现（Auth0：URL 不变，DOM 更新）— 不要用 URL 判断\n  await waitForElement(ws, 'input[type=\"password\"]');\n  await fillInput(ws, 'input[type=\"password\"]', 'your-password');\n  await cdp(ws, 'Runtime.evaluate', { expression: `document.querySelector('[type=\"submit\"], button[name=\"action\"]').click()` });\n\n  // 等登录跳转\n  await cdp(ws, 'Page.loadEventFired');\n  console.log('Login done');\n  ws.close();\n})();\n```\n\n运行：`node login.js`\n\n---\n\n## 常见踩坑\n\n### React 表单填充：input.value = 'xxx' 不生效\n\nReact 受控组件劫持了 `input.value`，直接赋值不触发 state 更新，表单提交时值为空。\n\n**必须用 nativeInputValueSetter**（见上方 `fillInput` 函数）。不要用简单赋值，不要用 Playwright 的 `fill()`（它在 CDP 直连场景不可用）。\n\n### Auth0 分步登录：不要用 URL 变化判断步骤\n\nAuth0 identifier-first 流程：输入邮箱 → 点 Continue → URL **不变**（仍是 `/u/login/identifier`），但 DOM 内部更新为密码页。密码框一开始是 `hidden`，邮箱提交后才显示。\n\n**判断依据：`input[type=\"password\"]` 是否 visible**（offsetParent !== null），用轮询等待，最多 10 秒。不要等 URL 变化。\n\n### 填充前先清空旧值\n\n每次 `fillInput` 前必须先 `setter.call(el, '')` + 触发 input 事件，否则若输入框有残留值，新值会被追加而非覆盖。\n\n### Python 缺 pip，CDP 脚本用 Node.js\n\n容器 Python 无 `pip`，无法装 `websockets`。用 Node.js + `ws` 包（`setup.sh` 已预装）。\n\n### React/Vue 受控组件键盘事件不生效\n`keyboard.press('Control+Enter')` 等快捷键在受控组件中可能无法触发。\n\n解决：找页面上的实际提交按钮，用 JS 点击：\n```javascript\ndocument.querySelector('[aria-label=\"发送\"]').click()\n```\n\n### 截图中文乱码（□□□）\n运行 `testagent-browser-setup` skill 中的 `setup.sh`，会自动安装中文字体并配置 fontconfig。\n\n### 配置修改后不生效\n改 `~/.openclaw/openclaw.json` 后必须完整执行：\n```\nbrowser stop → openclaw gateway restart → 等 15 秒 → browser start\n```\n仅 restart gateway 或仅重启浏览器均不够。**SSRF 白名单即使文件写入成功，也可能因运行时缓存不生效。**\n\nArchive v1.0.7: 6 files, 7553 bytes\n\nFiles: scripts/setup-optional.sh (831b), scripts/setup.sh (4515b), skill-card.md (2492b), SKILL.md (2520b), TOOLS.md (3849b), _meta.json (142b)\n\nFile v1.0.7:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 2.2.0\ndescription: 在新的 openclaw 环境中安装并初始化 Chromium、系统依赖、中文字体和 CDP 启动脚本，无需 root 权限。当用户说「初始化测试环境」「安装浏览器工具」「setup browser」或在新机器首次部署测试 agent 时触发。\n---\n\n# Browser Setup\n\n一次性环境初始化，在新 openclaw 容器上执行。不需要 root 权限。\n\n## 说明\n\nopenclaw 环境默认已预装 Chromium，`setup.sh` 会优先使用它。若未找到则自动通过 Playwright 下载。\n\n**截图和浏览器操作的主路径是：Chrome + CDP 直连。**\nsetup.sh 会创建 `~/.local/bin/chrome-cdp` 启动脚本。\n\n**`mcp doctor --probe` 是假阳性。**\n返回 ok 只说明 MCP server 进程启动，不代表 Chromium 能实际运行。唯一可信的验证：`playwright__browser_navigate` 真正返回页面内容。\n\n## 执行顺序\n\n### 第一步：运行核心安装脚本\n\n```bash\nbash scripts/setup.sh\n```\n\n脚本完成三件事：\n1. **Chromium 检测**：优先用系统预装 Chromium，未找到则通过 Playwright 下载\n2. **`chrome-cdp` 启动脚本**：`~/.local/bin/chrome-cdp`，封装 `--headless=new --no-sandbox --remote-allow-origins=*` 参数\n3. **中文字体**：从 GitHub 下载 WenQuanYi Micro Hei 到 `~/.local/share/fonts/`\n\n### 第二步：配置内置浏览器\n\n编辑 `~/.openclaw/openclaw.json`（`config.patch` 无法修改，受保护路径）：\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"你的目标产品域名（如 app.example.com）\",\n        \"对应的登录域名（如 xxx.us.auth0.com）\"\n      ]\n    }\n  }\n}\n```\n\n- `noSandbox: true`：容器 seccomp 限制，内置浏览器必须设置\n- `allowedHostnames`：SSRF 防护，未列入的域名报 `blocked by policy`\n\n### 第三步：重启 Gateway（让配置生效）\n\n按顺序执行：\n\n```\nbrowser stop\ngateway restart\n# 等待约 15 秒\nbrowser start\n```\n\n### 第四步：初始化 TOOLS.md\n\n```bash\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n### 第五步（可选）：安装 browser-use\n\n```bash\nbash scripts/setup-optional.sh\n```\n\n### 第六步：Smoke Test\n\n```bash\n# 启动 Chrome CDP\nchrome-cdp &\nsleep 2\n\n# 验证 CDP 可访问\ncurl -s http://localhost:9223/json | python3 -m json.tool | head -20\n\n# 截图验证（见 REFERENCE.md 的 CDP 截图流程）\n```\n\n验收标准：CDP `/json` 能返回 target 列表，截图中中文清晰无乱码。\n\nFile v1.0.7:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.7\",\n  \"publishedAt\": 1782215385983\n}\n\nFile v1.0.7:skill-card.md\n\n## Description: <br>\nTestagent Browser Setup initializes Chromium, Playwright MCP, Chinese font support, and a CDP launcher for browser testing in a new OpenClaw environment without root access. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[wangyin717](https://clawhub.ai/user/wangyin717) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and test engineers use this skill to prepare a fresh OpenClaw test agent for Chromium-based browser automation, CDP access, screenshots, Chinese font rendering, and browser configuration. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The optional browser-use setup runs unverified remote code and installs another skill from GitHub. <br>\nMitigation: Use the optional installer only after independently reviewing and trusting browser-use.com, the GitHub skill source, and the npm commands it invokes; consider pinning versions. <br>\nRisk: The skill creates durable browser automation setup with headless Chromium, no-sandbox flags, CDP access, and browser configuration changes. <br>\nMitigation: Run it in an isolated OpenClaw environment, keep CDP local, restrict SSRF allowed hostnames to required targets, and keep backups of existing TOOLS.md and OpenClaw configuration. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/wangyin717/skills/testagent-browser-setup) <br>\n- [browser-use CLI Installer](https://browser-use.com/cli/install.sh) <br>\n- [browser-use GitHub Skill Source](https://github.com/browser-use/browser-use) <br>\n- [WenQuanYi Micro Hei Font Source](https://github.com/anthonyfok/fonts-wqy-microhei/raw/master/wqy-microhei.ttc) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with shell commands and JSON configuration snippets.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The skill can guide setup of local browser automation files and commands, including an optional browser-use installer path.] <br>\n\n## Skill Version(s): <br>\n1.0.7 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.7:TOOLS.md\n\n# TOOLS.md — 浏览器工具使用指南\n\n## 三个浏览器工具对比\n\n| | OpenClaw 内置浏览器 | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **调用方式** | `browser` 工具（snapshot/act/screenshot） | `playwright__browser_*` 系列工具 | `exec` 调用 `browser-use` 命令 |\n| **浏览器引擎** | 本地 Chromium | 本地 Chromium | 本地 Chromium / 云端浏览器 |\n| **状态获取** | accessibility snapshot（文本树） | snapshot（文本树） | `state`（元素索引列表） |\n| **元素定位** | ref（如 e36） | ref + selector | 数字索引（如 click 5） |\n| **截图返回** | AI 分析文本（❌ 不可分享） | PNG 文件（✅ 可分享） | 保存路径（✅ 可分享） |\n| **JS 执行** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **键盘事件** | ⚠️ React 受控组件不生效 | ✅ 支持良好 | ✅ `keys \"Enter\"` |\n| **云浏览器** | ❌ | ❌ | ✅ `cloud connect` |\n| **复用登录态** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **反爬/CAPTCHA** | ❌ | ❌ | ✅ 云浏览器内置 |\n| **住宅代理** | ❌ | ❌ | ✅ 195+ 国家 |\n| **内网隧道** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **多会话并行** | 有限（tabs） | 有限（tabs） | ✅ `--session NAME` |\n| **命令链** | 不支持 | 不支持 | ✅ `&&` 链式执行 |\n| **登录态保持** | ✅ 同一 tab 内保持 | ✅ 同一 page 内保持 | ✅ daemon 保活，跨命令保持 |\n\n## 使用场景选择\n\n### → 用 OpenClaw 内置浏览器（默认首选）\n- 常规功能测试和页面交互\n- 已登录的会话内操作\n- 不需要截图分享给用户时\n- **优势**：工具集成度高，一步到位\n\n### → 用 Playwright MCP\n- 需要截图分享给用户（bug 截图、状态确认）\n- React/Vue 受控组件的精确交互（键盘事件支持好）\n- 需要精确 selector 定位元素\n- **优势**：元素定位最精确，截图可用\n\n### → 用 browser-use CLI\n- 需要云浏览器（反爬、CAPTCHA、住宅代理）\n- 需要复用用户本地 Chrome 登录态\n- 内网服务需通过隧道访问（`tunnel <port>`）\n- 新产品快速探索（命令链 `&&` 高效）\n- 多产品并行测试（`--session` 多会话）\n- **优势**：浏览器能力最强，云+本地+隧道全覆盖\n\n## 典型测试流程\n\n1. **新产品首次探索** → browser-use CLI（云浏览器 + 命令链快速摸底）\n2. **已熟悉产品回归测试** → OpenClaw 内置（快）或 Playwright MCP（精）\n3. **需要截图记录 Bug** → Playwright MCP 或 browser-use CLI\n4. **登录态受限的网站** → browser-use CLI（`--profile` 复用登录）\n5. **反爬严格的网站** → browser-use CLI（`cloud connect`）\n\n## 截图正确流程\n\n```\n1. playwright__browser_take_screenshot → filename=\"/tmp/screenshot.png\"\n2. cp /tmp/screenshot.png /root/.openclaw/workspace/<描述>.png\n3. 回复中附加: MEDIA:/root/.openclaw/workspace/<描述>.png\n```\n\n- 内置浏览器的 `browser screenshot` 只返回 AI 分析文本，**无法**用 `MEDIA:` 分享\n- `MEDIA:` 只在聊天回复中渲染，写进 `.md` 文件里不会显示图片\n\n## 常见踩坑\n\n### React/Vue 受控组件键盘事件不生效\n`keyboard.press('Control+Enter')` 等快捷键在受控组件中可能无法触发。\n\n解决：找页面上的实际提交按钮，用 JS 点击：\n```javascript\ndocument.querySelector('[aria-label=\"发送\"]').click()\n// 或用 evaluate / dispatchEvent\n```\n\n### 截图中文乱码（□□□）\n运行 `testagent-browser-setup` skill 中的 `setup.sh`，会自动安装 `fonts-noto-cjk` + `fonts-wqy-zenhei` 并配置 fontconfig。\n\n### 配置修改后不生效\n改 `~/.openclaw/openclaw.json` 后必须完整执行：\n```\nbrowser stop → openclaw gateway restart → 等 15 秒 → browser start\n```\n仅 restart gateway 或仅重启浏览器均不够。\n\nArchive v1.0.6: 6 files, 9455 bytes\n\nFiles: scripts/setup-optional.sh (831b), scripts/setup.sh (8191b), skill-card.md (2566b), SKILL.md (2953b), TOOLS.md (3849b), _meta.json (142b)\n\nFile v1.0.6:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 2.2.0\ndescription: 在新的 openclaw 环境中安装并初始化 Chromium、系统依赖、中文字体和 CDP 启动脚本，无需 root 权限。当用户说「初始化测试环境」「安装浏览器工具」「setup browser」或在新机器首次部署测试 agent 时触发。\n---\n\n# Browser Setup\n\n一次性环境初始化，在新 openclaw 容器上执行。不需要 root 权限。\n\n## ⚠️ 重要前提\n\n**最小容器下 Playwright MCP 基本不可用。**\nPlaywright MCP 在启动时检查系统库路径（`/usr/lib`、`/lib`），不尊重 `LD_LIBRARY_PATH`。最小容器缺少 ~75 个 `.so` 依赖，无 root 无法 `apt install` 到系统路径。\n\n**截图和浏览器操作的主路径是：Chrome + CDP 直连。**\nsetup.sh 会创建 `~/.local/bin/chrome-cdp` 启动脚本，包含正确的 LD_LIBRARY_PATH 和启动参数。\n\n**`mcp doctor --probe` 是假阳性。**\n返回 ok 只说明 MCP server 进程启动，不代表 Chromium 能实际运行。唯一可信的验证：`playwright__browser_navigate` 真正返回页面内容。\n\n## 执行顺序\n\n### 第一步：运行核心安装脚本\n\n```bash\nbash scripts/setup.sh\n```\n\n脚本完成四件事：\n1. **Playwright Chromium 下载**（幂等，已存在则跳过；后台下载避免超时）\n2. **系统库提取**：`apt-get download`（无需 root）+ `dpkg-deb -x` 解压约 75 个包到 `~/.local/lib/<arch>-linux-gnu/`，并写入 `openclaw.json env.vars.LD_LIBRARY_PATH`（gateway 自动重载）\n3. **`chrome-cdp` 启动脚本**：`~/.local/bin/chrome-cdp`，封装了正确的 LD_LIBRARY_PATH 和 `--headless=new --no-sandbox --remote-allow-origins=*` 参数\n4. **中文字体**：从 GitHub 下载 WenQuanYi Micro Hei 到 `~/.local/share/fonts/`\n\n### 第二步：配置内置浏览器\n\n编辑 `~/.openclaw/openclaw.json`（`config.patch` 无法修改，受保护路径）：\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"你的目标产品域名（如 app.example.com）\",\n        \"对应的登录域名（如 xxx.us.auth0.com）\"\n      ]\n    }\n  }\n}\n```\n\n- `noSandbox: true`：容器 seccomp 限制，内置浏览器必须设置\n- `allowedHostnames`：SSRF 防护，未列入的域名报 `blocked by policy`\n\n### 第三步：重启 Gateway（让配置生效）\n\n按顺序执行：\n\n```\nbrowser stop\ngateway restart\n# 等待约 15 秒\nbrowser start\n```\n\n### 第四步：初始化 TOOLS.md\n\n```bash\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n### 第五步（可选）：安装 browser-use\n\n```bash\nbash scripts/setup-optional.sh\n```\n\n### 第六步：Smoke Test\n\n```bash\n# 启动 Chrome CDP\nchrome-cdp &\nsleep 2\n\n# 验证 CDP 可访问\ncurl -s http://localhost:9223/json | python3 -m json.tool | head -20\n\n# 截图验证（见 REFERENCE.md 的 CDP 截图流程）\n```\n\n验收标准：CDP `/json` 能返回 target 列表，截图中中文清晰无乱码。\n\nFile v1.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1782182715845\n}\n\nFile v1.0.6:skill-card.md\n\n## Description: <br>\nInstalls and initializes Chromium, required system libraries, Chinese fonts, and a Chrome CDP launcher for browser automation in a new OpenClaw environment without root access. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[wangyin717](https://clawhub.ai/user/wangyin717) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and testing agents use this skill to prepare a minimal OpenClaw container for Chromium-based browser testing, screenshots, and CDP-driven workflows. It provides setup commands, browser configuration guidance, and tool-selection guidance for OpenClaw, Playwright MCP, and optional browser-use flows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Persistent OpenClaw environment changes can affect browser and MCP behavior after installation. <br>\nMitigation: Review setup scripts before installing and confirm changes to ~/.openclaw/openclaw.json, ~/.local/bin, LD_LIBRARY_PATH, and MCP server registration are acceptable and reversible. <br>\nRisk: Optional browser-use setup executes external installation flows and adds an external skill. <br>\nMitigation: Skip optional browser-use setup unless needed, or install it through a pinned and verifiable method. <br>\nRisk: Browser automation can expose user sessions or route activity through modes that are not local-only. <br>\nMitigation: Prefer local-only browser modes and avoid personal Chrome profiles unless that access is explicitly approved. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/wangyin717/testagent-browser-setup) <br>\n- [TOOLS.md](TOOLS.md) <br>\n- [browser-use project](https://github.com/browser-use/browser-use) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with shell commands, JSON configuration snippets, and setup guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May create local browser setup scripts, configuration guidance, and smoke-test commands for the agent to run.] <br>\n\n## Skill Version(s): <br>\n1.0.6 (source: server release metadata; artifact frontmatter lists 2.2.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.6:TOOLS.md\n\n# TOOLS.md — 浏览器工具使用指南\n\n## 三个浏览器工具对比\n\n| | OpenClaw 内置浏览器 | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **调用方式** | `browser` 工具（snapshot/act/screenshot） | `playwright__browser_*` 系列工具 | `exec` 调用 `browser-use` 命令 |\n| **浏览器引擎** | 本地 Chromium | 本地 Chromium | 本地 Chromium / 云端浏览器 |\n| **状态获取** | accessibility snapshot（文本树） | snapshot（文本树） | `state`（元素索引列表） |\n| **元素定位** | ref（如 e36） | ref + selector | 数字索引（如 click 5） |\n| **截图返回** | AI 分析文本（❌ 不可分享） | PNG 文件（✅ 可分享） | 保存路径（✅ 可分享） |\n| **JS 执行** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **键盘事件** | ⚠️ React 受控组件不生效 | ✅ 支持良好 | ✅ `keys \"Enter\"` |\n| **云浏览器** | ❌ | ❌ | ✅ `cloud connect` |\n| **复用登录态** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **反爬/CAPTCHA** | ❌ | ❌ | ✅ 云浏览器内置 |\n| **住宅代理** | ❌ | ❌ | ✅ 195+ 国家 |\n| **内网隧道** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **多会话并行** | 有限（tabs） | 有限（tabs） | ✅ `--session NAME` |\n| **命令链** | 不支持 | 不支持 | ✅ `&&` 链式执行 |\n| **登录态保持** | ✅ 同一 tab 内保持 | ✅ 同一 page 内保持 | ✅ daemon 保活，跨命令保持 |\n\n## 使用场景选择\n\n### → 用 OpenClaw 内置浏览器（默认首选）\n- 常规功能测试和页面交互\n- 已登录的会话内操作\n- 不需要截图分享给用户时\n- **优势**：工具集成度高，一步到位\n\n### → 用 Playwright MCP\n- 需要截图分享给用户（bug 截图、状态确认）\n- React/Vue 受控组件的精确交互（键盘事件支持好）\n- 需要精确 selector 定位元素\n- **优势**：元素定位最精确，截图可用\n\n### → 用 browser-use CLI\n- 需要云浏览器（反爬、CAPTCHA、住宅代理）\n- 需要复用用户本地 Chrome 登录态\n- 内网服务需通过隧道访问（`tunnel <port>`）\n- 新产品快速探索（命令链 `&&` 高效）\n- 多产品并行测试（`--session` 多会话）\n- **优势**：浏览器能力最强，云+本地+隧道全覆盖\n\n## 典型测试流程\n\n1. **新产品首次探索** → browser-use CLI（云浏览器 + 命令链快速摸底）\n2. **已熟悉产品回归测试** → OpenClaw 内置（快）或 Playwright MCP（精）\n3. **需要截图记录 Bug** → Playwright MCP 或 browser-use CLI\n4. **登录态受限的网站** → browser-use CLI（`--profile` 复用登录）\n5. **反爬严格的网站** → browser-use CLI（`cloud connect`）\n\n## 截图正确流程\n\n```\n1. playwright__browser_take_screenshot → filename=\"/tmp/screenshot.png\"\n2. cp /tmp/screenshot.png /root/.openclaw/workspace/<描述>.png\n3. 回复中附加: MEDIA:/root/.openclaw/workspace/<描述>.png\n```\n\n- 内置浏览器的 `browser screenshot` 只返回 AI 分析文本，**无法**用 `MEDIA:` 分享\n- `MEDIA:` 只在聊天回复中渲染，写进 `.md` 文件里不会显示图片\n\n## 常见踩坑\n\n### React/Vue 受控组件键盘事件不生效\n`keyboard.press('Control+Enter')` 等快捷键在受控组件中可能无法触发。\n\n解决：找页面上的实际提交按钮，用 JS 点击：\n```javascript\ndocument.querySelector('[aria-label=\"发送\"]').click()\n// 或用 evaluate / dispatchEvent\n```\n\n### 截图中文乱码（□□□）\n运行 `testagent-browser-setup` skill 中的 `setup.sh`，会自动安装 `fonts-noto-cjk` + `fonts-wqy-zenhei` 并配置 fontconfig。\n\n### 配置修改后不生效\n改 `~/.openclaw/openclaw.json` 后必须完整执行：\n```\nbrowser stop → openclaw gateway restart → 等 15 秒 → browser start\n```\n仅 restart gateway 或仅重启浏览器均不够。\n\nArchive v1.0.5: 6 files, 8796 bytes\n\nFiles: scripts/setup-optional.sh (831b), scripts/setup.sh (5697b), skill-card.md (2633b), SKILL.md (3769b), TOOLS.md (3849b), _meta.json (142b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 2.1.0\ndescription: 在新的 openclaw 环境中安装并初始化 Playwright MCP 和中文字体，无需 root 权限。当用户说「初始化测试环境」「安装浏览器工具」「setup browser」或在新机器首次部署测试 agent 时触发。\n---\n\n# Browser Setup\n\n一次性环境初始化，在新 openclaw 容器上执行。不需要 root 权限。\n\n## 重要前提\n\n**`mcp doctor --probe` 是假阳性，不能用来判断 Playwright 是否真正可用。**\n它只检查 MCP server 进程能否启动，不验证 Chromium 是否能实际运行。\n真正的可用标准：`playwright__browser_navigate` 返回页面内容（而不是报错）。\n\n**无 root 环境下 Playwright MCP 可能因缺系统 `.so` 而无法运行。**\n此时不要尝试 `sudo`/`apt`/`npx playwright install-deps`，直接走内置浏览器 + CDP 截图的 fallback 路径（见 testagent-browser-testing REFERENCE.md）。\n\n**`noSandbox` 只针对内置浏览器，与 Playwright MCP 无关。**\nPlaywright MCP 有自己的 Chromium 进程，不受 `openclaw.json` 的 `browser.noSandbox` 控制。\n\n## 执行顺序\n\n### 第一步：运行核心安装脚本\n\n```bash\nbash scripts/setup.sh\n```\n\n脚本完成三件事：\n1. Playwright Chromium 下载（幂等，`~/.cache/ms-playwright/` 存在则跳过）\n2. 注册到 openclaw MCP（使用 `openclaw mcp set`）\n3. 中文字体从 GitHub 下载到 `~/.local/share/fonts/`（无需 root，幂等）\n\n### 第二步：配置内置浏览器\n\n**重要**：browser 配置必须直接编辑 `~/.openclaw/openclaw.json`，`config.patch` 无法修改（受保护路径）。\n\n编辑 `~/.openclaw/openclaw.json`，加入以下配置：\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"你的目标产品域名（如 app.example.com）\",\n        \"对应的登录域名（如 xxx.us.auth0.com）\"\n      ]\n    }\n  }\n}\n```\n\n- `noSandbox: true`：容器 seccomp 限制，内置浏览器必须设置，否则报 `Timeout waiting for browser`\n- `allowedHostnames`：内置浏览器 SSRF 防护，未列入的域名报 `blocked by policy`；Auth0 等登录域名也需加入\n\n### 第三步：重启 Gateway（让内置浏览器配置生效）\n\n**按顺序执行（顺序不能错）**：\n\n```\nbrowser stop\ngateway restart\n# 等待约 15 秒\nbrowser start\n```\n\n仅 `gateway restart` 或仅 `browser stop/start` 都不够，三步必须完整执行。\n\n### 第四步：初始化 TOOLS.md\n\n将工具使用指南复制到项目根目录（与 SOUL.md、IDENTITY.md 同级）：\n\n```bash\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n若已存在则覆盖，确保版本与 skill 一致。\n\n### 第五步（可选）：安装 browser-use\n\n有网络时运行，失败不影响主测试流程（Playwright MCP 已足够）：\n\n```bash\nbash scripts/setup-optional.sh\n```\n\n安装成功后注册 API Key：\n1. 检查是否有内置命令：`browser-use register`\n2. 若无，参考 https://docs.browser-use.com 的 Self-Registration API：\n   - 请求 challenge → 计算答案 → 提交验证 → 拿到 `bu_` 开头的 API Key\n3. 写入环境变量：\n   ```bash\n   echo 'export BROWSER_USE_API_KEY=bu_xxx' >> ~/.bashrc\n   export BROWSER_USE_API_KEY=bu_xxx\n   ```\n\n### 第六步：Smoke Test（自动验收）\n\n**验证 Playwright MCP**：\n```\n调用 playwright__browser_navigate → https://example.com\n调用 playwright__browser_take_screenshot → filename=\"~/.openclaw/workspace/smoke_test.png\"\n确认文件存在且大小 > 0，且截图中文字清晰无乱码\n```\n\n**验证 browser-use**（若已安装）：\n```bash\nbrowser-use --version\n```\n\n任一验收失败时，输出具体错误信息，提示修复方向，不要静默跳过。\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1782133826080\n}\n\nFile v1.0.5:skill-card.md\n\n## Description: <br>\nInstalls and initializes Playwright MCP, local Chromium support, Chinese fonts, and browser testing guidance for new OpenClaw environments without requiring root access. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[wangyin717](https://clawhub.ai/user/wangyin717) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and testing agents use this skill to prepare a new OpenClaw container for browser automation, screenshot capture, Chinese text rendering, and optional browser-use workflows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill makes persistent browser automation configuration changes and can overwrite local tool guidance files. <br>\nMitigation: Review each command and configuration edit before execution, and preserve any existing local files that should not be overwritten. <br>\nRisk: Optional browser-use setup introduces third-party tooling, API-key handling, profile reuse, and tunneling guidance. <br>\nMitigation: Install optional browser-use components only when needed, avoid plaintext API-key persistence unless accepted, and use profile reuse or tunnels only for authorized services. <br>\nRisk: Browser automation setup can expand access to local sessions or network targets. <br>\nMitigation: Limit browser SSRF allowlists to required hostnames and validate the environment with smoke tests before relying on automated browsing. <br>\n\n\n## Reference(s): <br>\n- [ClawHub package page](https://clawhub.ai/wangyin717/testagent-browser-setup) <br>\n- [browser-use documentation](https://docs.browser-use.com) <br>\n- [browser-use GitHub repository](https://github.com/browser-use/browser-use) <br>\n- [WenQuanYi Micro Hei font source](https://github.com/anthonyfok/fonts-wqy-microhei/raw/master/wqy-microhei.ttc) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown instructions with shell commands and JSON configuration snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Includes setup, restart, smoke-test, fallback, and optional browser-use registration guidance.] <br>\n\n## Skill Version(s): <br>\n1.0.5 (source: server release metadata; artifact frontmatter lists 2.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.5:TOOLS.md\n\n# TOOLS.md — 浏览器工具使用指南\n\n## 三个浏览器工具对比\n\n| | OpenClaw 内置浏览器 | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **调用方式** | `browser` 工具（snapshot/act/screenshot） | `playwright__browser_*` 系列工具 | `exec` 调用 `browser-use` 命令 |\n| **浏览器引擎** | 本地 Chromium | 本地 Chromium | 本地 Chromium / 云端浏览器 |\n| **状态获取** | accessibility snapshot（文本树） | snapshot（文本树） | `state`（元素索引列表） |\n| **元素定位** | ref（如 e36） | ref + selector | 数字索引（如 click 5） |\n| **截图返回** | AI 分析文本（❌ 不可分享） | PNG 文件（✅ 可分享） | 保存路径（✅ 可分享） |\n| **JS 执行** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **键盘事件** | ⚠️ React 受控组件不生效 | ✅ 支持良好 | ✅ `keys \"Enter\"` |\n| **云浏览器** | ❌ | ❌ | ✅ `cloud connect` |\n| **复用登录态** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **反爬/CAPTCHA** | ❌ | ❌ | ✅ 云浏览器内置 |\n| **住宅代理** | ❌ | ❌ | ✅ 195+ 国家 |\n| **内网隧道** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **多会话并行** | 有限（tabs） | 有限（tabs） | ✅ `--session NAME` |\n| **命令链** | 不支持 | 不支持 | ✅ `&&` 链式执行 |\n| **登录态保持** | ✅ 同一 tab 内保持 | ✅ 同一 page 内保持 | ✅ daemon 保活，跨命令保持 |\n\n## 使用场景选择\n\n### → 用 OpenClaw 内置浏览器（默认首选）\n- 常规功能测试和页面交互\n- 已登录的会话内操作\n- 不需要截图分享给用户时\n- **优势**：工具集成度高，一步到位\n\n### → 用 Playwright MCP\n- 需要截图分享给用户（bug 截图、状态确认）\n- React/Vue 受控组件的精确交互（键盘事件支持好）\n- 需要精确 selector 定位元素\n- **优势**：元素定位最精确，截图可用\n\n### → 用 browser-use CLI\n- 需要云浏览器（反爬、CAPTCHA、住宅代理）\n- 需要复用用户本地 Chrome 登录态\n- 内网服务需通过隧道访问（`tunnel <port>`）\n- 新产品快速探索（命令链 `&&` 高效）\n- 多产品并行测试（`--session` 多会话）\n- **优势**：浏览器能力最强，云+本地+隧道全覆盖\n\n## 典型测试流程\n\n1. **新产品首次探索** → browser-use CLI（云浏览器 + 命令链快速摸底）\n2. **已熟悉产品回归测试** → OpenClaw 内置（快）或 Playwright MCP（精）\n3. **需要截图记录 Bug** → Playwright MCP 或 browser-use CLI\n4. **登录态受限的网站** → browser-use CLI（`--profile` 复用登录）\n5. **反爬严格的网站** → browser-use CLI（`cloud connect`）\n\n## 截图正确流程\n\n```\n1. playwright__browser_take_screenshot → filename=\"/tmp/screenshot.png\"\n2. cp /tmp/screenshot.png /root/.openclaw/workspace/<描述>.png\n3. 回复中附加: MEDIA:/root/.openclaw/workspace/<描述>.png\n```\n\n- 内置浏览器的 `browser screenshot` 只返回 AI 分析文本，**无法**用 `MEDIA:` 分享\n- `MEDIA:` 只在聊天回复中渲染，写进 `.md` 文件里不会显示图片\n\n## 常见踩坑\n\n### React/Vue 受控组件键盘事件不生效\n`keyboard.press('Control+Enter')` 等快捷键在受控组件中可能无法触发。\n\n解决：找页面上的实际提交按钮，用 JS 点击：\n```javascript\ndocument.querySelector('[aria-label=\"发送\"]').click()\n// 或用 evaluate / dispatchEvent\n```\n\n### 截图中文乱码（□□□）\n运行 `testagent-browser-setup` skill 中的 `setup.sh`，会自动安装 `fonts-noto-cjk` + `fonts-wqy-zenhei` 并配置 fontconfig。\n\n### 配置修改后不生效\n改 `~/.openclaw/openclaw.json` 后必须完整执行：\n```\nbrowser stop → openclaw gateway restart → 等 15 秒 → browser start\n```\n仅 restart gateway 或仅重启浏览器均不够。\n\nArchive v1.0.4: 6 files, 7709 bytes\n\nFiles: scripts/setup-optional.sh (831b), scripts/setup.sh (3192b), skill-card.md (2861b), SKILL.md (3513b), TOOLS.md (3849b), _meta.json (142b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 2.1.0\ndescription: 在新的 openclaw 环境中安装并初始化 Playwright MCP 和中文字体，无需 root 权限。当用户说「初始化测试环境」「安装浏览器工具」「setup browser」或在新机器首次部署测试 agent 时触发。\n---\n\n# Browser Setup\n\n一次性环境初始化，在新 openclaw 容器上执行。不需要 root 权限。\n\n## 重要前提\n\n**Playwright MCP 无需 root，系统依赖已由容器环境提供。**\n`ldd ~/.cache/ms-playwright/chromium-*/chrome-linux/chrome` 不会报 missing，LD_LIBRARY_PATH 不需要设置。\n`openclaw mcp doctor playwright --probe` 返回 `ok` 即可直接使用，不要绕道。\n\n**`noSandbox` 只针对内置浏览器，与 Playwright MCP 无关。**\nPlaywright MCP 有自己的 Chromium 进程，不受 `openclaw.json` 的 `browser.noSandbox` 控制。\n\n## 执行顺序\n\n### 第一步：运行核心安装脚本\n\n```bash\nbash scripts/setup.sh\n```\n\n脚本完成三件事：\n1. Playwright Chromium 下载（幂等，`~/.cache/ms-playwright/` 存在则跳过）\n2. 注册到 openclaw MCP（使用 `openclaw mcp set`）\n3. 中文字体从 GitHub 下载到 `~/.local/share/fonts/`（无需 root，幂等）\n\n### 第二步：配置内置浏览器\n\n**重要**：browser 配置必须直接编辑 `~/.openclaw/openclaw.json`，`config.patch` 无法修改（受保护路径）。\n\n编辑 `~/.openclaw/openclaw.json`，加入以下配置：\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"你的目标产品域名（如 app.example.com）\",\n        \"对应的登录域名（如 xxx.us.auth0.com）\"\n      ]\n    }\n  }\n}\n```\n\n- `noSandbox: true`：容器 seccomp 限制，内置浏览器必须设置，否则报 `Timeout waiting for browser`\n- `allowedHostnames`：内置浏览器 SSRF 防护，未列入的域名报 `blocked by policy`；Auth0 等登录域名也需加入\n\n### 第三步：重启 Gateway（让内置浏览器配置生效）\n\n**按顺序执行（顺序不能错）**：\n\n```\nbrowser stop\ngateway restart\n# 等待约 15 秒\nbrowser start\n```\n\n仅 `gateway restart` 或仅 `browser stop/start` 都不够，三步必须完整执行。\n\n### 第四步：初始化 TOOLS.md\n\n将工具使用指南复制到项目根目录（与 SOUL.md、IDENTITY.md 同级）：\n\n```bash\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n若已存在则覆盖，确保版本与 skill 一致。\n\n### 第五步（可选）：安装 browser-use\n\n有网络时运行，失败不影响主测试流程（Playwright MCP 已足够）：\n\n```bash\nbash scripts/setup-optional.sh\n```\n\n安装成功后注册 API Key：\n1. 检查是否有内置命令：`browser-use register`\n2. 若无，参考 https://docs.browser-use.com 的 Self-Registration API：\n   - 请求 challenge → 计算答案 → 提交验证 → 拿到 `bu_` 开头的 API Key\n3. 写入环境变量：\n   ```bash\n   echo 'export BROWSER_USE_API_KEY=bu_xxx' >> ~/.bashrc\n   export BROWSER_USE_API_KEY=bu_xxx\n   ```\n\n### 第六步：Smoke Test（自动验收）\n\n**验证 Playwright MCP**：\n```\n调用 playwright__browser_navigate → https://example.com\n调用 playwright__browser_take_screenshot → filename=\"~/.openclaw/workspace/smoke_test.png\"\n确认文件存在且大小 > 0，且截图中文字清晰无乱码\n```\n\n**验证 browser-use**（若已安装）：\n```bash\nbrowser-use --version\n```\n\n任一验收失败时，输出具体错误信息，提示修复方向，不要静默跳过。\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1782128482734\n}\n\nFile v1.0.4:skill-card.md\n\n## Description: <br>\nInstalls and initializes Playwright MCP, Chromium, and Chinese font support for a new OpenClaw browser-testing environment without requiring root access. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[wangyin717](https://clawhub.ai/user/wangyin717) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and testing agents use this skill to prepare a fresh OpenClaw container for browser-based product testing, Playwright MCP screenshots, Chinese text rendering, and optional browser-use workflows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The optional browser-use installer runs a remote shell script and adds broader browser automation capabilities. <br>\nMitigation: Review scripts/setup-optional.sh and the referenced installer before running it; skip the optional path unless those capabilities are needed. <br>\nRisk: The browser-use API key guidance stores credentials in ~/.bashrc. <br>\nMitigation: Prefer a safer secret store or session-scoped environment variable, and avoid committing or sharing shell configuration containing API keys. <br>\nRisk: Reusable browser profiles and shareable screenshots can expose cookies, account data, secrets, or personal data. <br>\nMitigation: Use a dedicated test browser profile and inspect or redact screenshots before sharing them. <br>\nRisk: Browser configuration changes include noSandbox and hostname allowlists for the built-in browser. <br>\nMitigation: Keep ssrfPolicy.allowedHostnames limited to the tested application and required login domains, then run the documented smoke test after restarting the browser gateway. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/wangyin717/testagent-browser-setup) <br>\n- [browser-use documentation](https://docs.browser-use.com) <br>\n- [browser-use GitHub repository](https://github.com/browser-use/browser-use) <br>\n- [WenQuanYi Micro Hei font source](https://github.com/anthonyfok/fonts-wqy-microhei/raw/master/wqy-microhei.ttc) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown instructions with Bash and JSON snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Includes setup scripts, OpenClaw browser configuration guidance, a TOOLS.md usage guide, and smoke-test instructions.] <br>\n\n## Skill Version(s): <br>\n1.0.4 (source: server release metadata; artifact frontmatter states 2.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.4:TOOLS.md\n\n# TOOLS.md — 浏览器工具使用指南\n\n## 三个浏览器工具对比\n\n| | OpenClaw 内置浏览器 | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **调用方式** | `browser` 工具（snapshot/act/screenshot） | `playwright__browser_*` 系列工具 | `exec` 调用 `browser-use` 命令 |\n| **浏览器引擎** | 本地 Chromium | 本地 Chromium | 本地 Chromium / 云端浏览器 |\n| **状态获取** | accessibility snapshot（文本树） | snapshot（文本树） | `state`（元素索引列表） |\n| **元素定位** | ref（如 e36） | ref + selector | 数字索引（如 click 5） |\n| **截图返回** | AI 分析文本（❌ 不可分享） | PNG 文件（✅ 可分享） | 保存路径（✅ 可分享） |\n| **JS 执行** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **键盘事件** | ⚠️ React 受控组件不生效 | ✅ 支持良好 | ✅ `keys \"Enter\"` |\n| **云浏览器** | ❌ | ❌ | ✅ `cloud connect` |\n| **复用登录态** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **反爬/CAPTCHA** | ❌ | ❌ | ✅ 云浏览器内置 |\n| **住宅代理** | ❌ | ❌ | ✅ 195+ 国家 |\n| **内网隧道** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **多会话并行** | 有限（tabs） | 有限（tabs） | ✅ `--session NAME` |\n| **命令链** | 不支持 | 不支持 | ✅ `&&` 链式执行 |\n| **登录态保持** | ✅ 同一 tab 内保持 | ✅ 同一 page 内保持 | ✅ daemon 保活，跨命令保持 |\n\n## 使用场景选择\n\n### → 用 OpenClaw 内置浏览器（默认首选）\n- 常规功能测试和页面交互\n- 已登录的会话内操作\n- 不需要截图分享给用户时\n- **优势**：工具集成度高，一步到位\n\n### → 用 Playwright MCP\n- 需要截图分享给用户（bug 截图、状态确认）\n- React/Vue 受控组件的精确交互（键盘事件支持好）\n- 需要精确 selector 定位元素\n- **优势**：元素定位最精确，截图可用\n\n### → 用 browser-use CLI\n- 需要云浏览器（反爬、CAPTCHA、住宅代理）\n- 需要复用用户本地 Chrome 登录态\n- 内网服务需通过隧道访问（`tunnel <port>`）\n- 新产品快速探索（命令链 `&&` 高效）\n- 多产品并行测试（`--session` 多会话）\n- **优势**：浏览器能力最强，云+本地+隧道全覆盖\n\n## 典型测试流程\n\n1. **新产品首次探索** → browser-use CLI（云浏览器 + 命令链快速摸底）\n2. **已熟悉产品回归测试** → OpenClaw 内置（快）或 Playwright MCP（精）\n3. **需要截图记录 Bug** → Playwright MCP 或 browser-use CLI\n4. **登录态受限的网站** → browser-use CLI（`--profile` 复用登录）\n5. **反爬严格的网站** → browser-use CLI（`cloud connect`）\n\n## 截图正确流程\n\n```\n1. playwright__browser_take_screenshot → filename=\"/tmp/screenshot.png\"\n2. cp /tmp/screenshot.png /root/.openclaw/workspace/<描述>.png\n3. 回复中附加: MEDIA:/root/.openclaw/workspace/<描述>.png\n```\n\n- 内置浏览器的 `browser screenshot` 只返回 AI 分析文本，**无法**用 `MEDIA:` 分享\n- `MEDIA:` 只在聊天回复中渲染，写进 `.md` 文件里不会显示图片\n\n## 常见踩坑\n\n### React/Vue 受控组件键盘事件不生效\n`keyboard.press('Control+Enter')` 等快捷键在受控组件中可能无法触发。\n\n解决：找页面上的实际提交按钮，用 JS 点击：\n```javascript\ndocument.querySelector('[aria-label=\"发送\"]').click()\n// 或用 evaluate / dispatchEvent\n```\n\n### 截图中文乱码（□□□）\n运行 `testagent-browser-setup` skill 中的 `setup.sh`，会自动安装 `fonts-noto-cjk` + `fonts-wqy-zenhei` 并配置 fontconfig。\n\n### 配置修改后不生效\n改 `~/.openclaw/openclaw.json` 后必须完整执行：\n```\nbrowser stop → openclaw gateway restart → 等 15 秒 → browser start\n```\n仅 restart gateway 或仅重启浏览器均不够。\n\nArchive v1.0.3: 6 files, 7319 bytes\n\nFiles: scripts/setup-optional.sh (831b), scripts/setup.sh (3188b), skill-card.md (2495b), SKILL.md (3024b), TOOLS.md (3849b), _meta.json (142b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 2.0.0\ndescription: 在新的 openclaw 环境中安装并初始化 Playwright MCP 和中文字体，无需 root 权限。当用户说「初始化测试环境」「安装浏览器工具」「setup browser」或在新机器首次部署测试 agent 时触发。\n---\n\n# Browser Setup\n\n一次性环境初始化，在新 openclaw 容器上执行。不需要 root 权限。\n\n## 执行顺序\n\n### 第一步：运行核心安装脚本\n\n```bash\nbash scripts/setup.sh\n```\n\n脚本完成两件事：\n1. Playwright Chromium 下载（幂等，`~/.cache/ms-playwright/` 存在则跳过）并注册到 openclaw MCP\n2. 中文字体从 `fonts/wqy-microhei.ttc` 复制到 `~/.local/share/fonts/`（无需 root）\n\n### 第二步：配置内置浏览器\n\n**重要**：browser 配置必须直接编辑 `~/.openclaw/openclaw.json`，`config.patch` 无法修改（受保护路径）。\n\n编辑 `~/.openclaw/openclaw.json`，加入以下配置：\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"你的目标产品域名（如 app.example.com）\",\n        \"对应的登录域名（如 xxx.us.auth0.com）\"\n      ]\n    }\n  }\n}\n```\n\n- `noSandbox: true`：容器 seccomp 限制导致 Chromium sandbox 无法启动，必须设置，否则报 `Timeout waiting for browser`\n- `allowedHostnames`：内置浏览器默认启用 SSRF 防护，未列入的域名报 `blocked by policy`；登录页（Auth0 等 SSO 域名）也需单独加入\n\n### 第三步：重启 Gateway（让配置生效）\n\n**按顺序执行（顺序不能错）**：\n\n```\nbrowser stop\ngateway restart\n# 等待约 15 秒\nbrowser start\n```\n\n仅 `gateway restart` 或仅 `browser stop/start` 都不够，三步必须完整执行。\n\n### 第四步：初始化 TOOLS.md\n\n将工具使用指南复制到项目根目录（与 SOUL.md、IDENTITY.md 同级）：\n\n```bash\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n若已存在则覆盖，确保版本与 skill 一致。\n\n### 第五步（可选）：安装 browser-use\n\n有网络时运行，失败不影响主测试流程（Playwright MCP 已足够）：\n\n```bash\nbash scripts/setup-optional.sh\n```\n\n安装成功后注册 API Key：\n1. 检查是否有内置命令：`browser-use register`\n2. 若无，参考 https://docs.browser-use.com 的 Self-Registration API：\n   - 请求 challenge → 计算答案 → 提交验证 → 拿到 `bu_` 开头的 API Key\n3. 写入环境变量：\n   ```bash\n   echo 'export BROWSER_USE_API_KEY=bu_xxx' >> ~/.bashrc\n   export BROWSER_USE_API_KEY=bu_xxx\n   ```\n\n### 第六步：Smoke Test（自动验收）\n\n**验证 Playwright MCP**：\n```\n调用 playwright__browser_navigate → https://example.com\n调用 playwright__browser_take_screenshot → filename=\"/root/.openclaw/workspace/smoke_test.png\"\n确认文件存在且大小 > 0\n```\n\n**验证 browser-use**（若已安装）：\n```bash\nbrowser-use --version\n```\n\n任一验收失败时，输出具体错误信息，提示修复方向，不要静默跳过。\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1782117769581\n}\n\nFile v1.0.3:skill-card.md\n\n## Description: <br>\nInstalls and initializes Playwright MCP and Chinese fonts in a new OpenClaw environment without requiring root access. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[wangyin717](https://clawhub.ai/user/wangyin717) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and test agents use this skill to initialize browser automation in a new OpenClaw container, configure Playwright MCP and browser settings, copy browser tool guidance, and optionally install browser-use. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Optional setup installs broader third-party browser-use tooling, including a remote install script. <br>\nMitigation: Review or skip setup-optional.sh; if used, trust and pin the source before running the installer. <br>\nRisk: Setup guidance can overwrite local agent guidance and requires editing OpenClaw browser configuration. <br>\nMitigation: Back up TOOLS.md and ~/.openclaw/openclaw.json before copying or editing configuration. <br>\nRisk: The browser configuration disables Chromium sandboxing and depends on SSRF allowlists. <br>\nMitigation: Use the no-sandbox setting only in the intended container environment and keep allowedHostnames narrow. <br>\nRisk: The optional browser-use flow stores an API key in the shell profile. <br>\nMitigation: Prefer a secret manager or session-scoped environment variable instead of persisting the key in ~/.bashrc. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/wangyin717/testagent-browser-setup) <br>\n- [browser-use documentation](https://docs.browser-use.com) <br>\n- [browser-use GitHub repository](https://github.com/browser-use/browser-use) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Configuration instructions, Markdown, Guidance] <br>\n**Output Format:** [Markdown guidance with bash, JSON, and command snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Includes optional browser-use setup and smoke-test guidance.] <br>\n\n## Skill Version(s): <br>\n1.0.3 (source: server release metadata; artifact frontmatter says 2.0.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.3:TOOLS.md\n\n# TOOLS.md — 浏览器工具使用指南\n\n## 三个浏览器工具对比\n\n| | OpenClaw 内置浏览器 | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **调用方式** | `browser` 工具（snapshot/act/screenshot） | `playwright__browser_*` 系列工具 | `exec` 调用 `browser-use` 命令 |\n| **浏览器引擎** | 本地 Chromium | 本地 Chromium | 本地 Chromium / 云端浏览器 |\n| **状态获取** | accessibility snapshot（文本树） | snapshot（文本树） | `state`（元素索引列表） |\n| **元素定位** | ref（如 e36） | ref + selector | 数字索引（如 click 5） |\n| **截图返回** | AI 分析文本（❌ 不可分享） | PNG 文件（✅ 可分享） | 保存路径（✅ 可分享） |\n| **JS 执行** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **键盘事件** | ⚠️ React 受控组件不生效 | ✅ 支持良好 | ✅ `keys \"Enter\"` |\n| **云浏览器** | ❌ | ❌ | ✅ `cloud connect` |\n| **复用登录态** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **反爬/CAPTCHA** | ❌ | ❌ | ✅ 云浏览器内置 |\n| **住宅代理** | ❌ | ❌ | ✅ 195+ 国家 |\n| **内网隧道** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **多会话并行** | 有限（tabs） | 有限（tabs） | ✅ `--session NAME` |\n| **命令链** | 不支持 | 不支持 | ✅ `&&` 链式执行 |\n| **登录态保持** | ✅ 同一 tab 内保持 | ✅ 同一 page 内保持 | ✅ daemon 保活，跨命令保持 |\n\n## 使用场景选择\n\n### → 用 OpenClaw 内置浏览器（默认首选）\n- 常规功能测试和页面交互\n- 已登录的会话内操作\n- 不需要截图分享给用户时\n- **优势**：工具集成度高，一步到位\n\n### → 用 Playwright MCP\n- 需要截图分享给用户（bug 截图、状态确认）\n- React/Vue 受控组件的精确交互（键盘事件支持好）\n- 需要精确 selector 定位元素\n- **优势**：元素定位最精确，截图可用\n\n### → 用 browser-use CLI\n- 需要云浏览器（反爬、CAPTCHA、住宅代理）\n- 需要复用用户本地 Chrome 登录态\n- 内网服务需通过隧道访问（`tunnel <port>`）\n- 新产品快速探索（命令链 `&&` 高效）\n- 多产品并行测试（`--session` 多会话）\n- **优势**：浏览器能力最强，云+本地+隧道全覆盖\n\n## 典型测试流程\n\n1. **新产品首次探索** → browser-use CLI（云浏览器 + 命令链快速摸底）\n2. **已熟悉产品回归测试** → OpenClaw 内置（快）或 Playwright MCP（精）\n3. **需要截图记录 Bug** → Playwright MCP 或 browser-use CLI\n4. **登录态受限的网站** → browser-use CLI（`--profile` 复用登录）\n5. **反爬严格的网站** → browser-use CLI（`cloud connect`）\n\n## 截图正确流程\n\n```\n1. playwright__browser_take_screenshot → filename=\"/tmp/screenshot.png\"\n2. cp /tmp/screenshot.png /root/.openclaw/workspace/<描述>.png\n3. 回复中附加: MEDIA:/root/.openclaw/workspace/<描述>.png\n```\n\n- 内置浏览器的 `browser screenshot` 只返回 AI 分析文本，**无法**用 `MEDIA:` 分享\n- `MEDIA:` 只在聊天回复中渲染，写进 `.md` 文件里不会显示图片\n\n## 常见踩坑\n\n### React/Vue 受控组件键盘事件不生效\n`keyboard.press('Control+Enter')` 等快捷键在受控组件中可能无法触发。\n\n解决：找页面上的实际提交按钮，用 JS 点击：\n```javascript\ndocument.querySelector('[aria-label=\"发送\"]').click()\n// 或用 evaluate / dispatchEvent\n```\n\n### 截图中文乱码（□□□）\n运行 `testagent-browser-setup` skill 中的 `setup.sh`，会自动安装 `fonts-noto-cjk` + `fonts-wqy-zenhei` 并配置 fontconfig。\n\n### 配置修改后不生效\n改 `~/.openclaw/openclaw.json` 后必须完整执行：\n```\nbrowser stop → openclaw gateway restart → 等 15 秒 → browser start\n```\n仅 restart gateway 或仅重启浏览器均不够。\n\nArchive v1.0.2: 5 files, 6865 bytes\n\nFiles: scripts/setup.sh (2812b), skill-card.md (2523b), SKILL.md (3279b), TOOLS.md (3849b), _meta.json (142b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 1.2.0\ndescription: 在新的 openclaw 环境中安装并初始化 Playwright MCP 和 browser-use CLI，含中文字体修复和自动验收。当用户说「初始化测试环境」「安装浏览器工具」「setup browser」或在新机器首次部署测试 agent 时触发。\n---\n\n# Browser Setup\n\n一次性环境初始化，在新 openclaw 容器/机器上执行。需要 root 权限。\n\n## 执行顺序\n\n### 第一步：运行安装脚本\n\n```bash\nbash scripts/setup.sh\n```\n\n脚本按顺序完成：\n1. Playwright Chromium 安装 + 注册到 openclaw MCP（统一 `--browser chromium`，ARM64/x86 通用）\n2. 中文字体安装 + fontconfig 配置（截图无乱码）\n3. `openclaw gateway restart`（让字体生效，Chromium 重载 fontconfig 缓存）\n4. browser-use CLI 安装\n5. browser-use skill 安装\n\n### 第二步：配置内置浏览器（容器必须）\n\n**重要**：browser 相关配置必须直接编辑 `~/.openclaw/openclaw.json`，`config.patch` 无法修改 browser 配置（受保护路径）。\n\n编辑 `~/.openclaw/openclaw.json`，加入以下配置：\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"你的目标产品域名（如 app.example.com）\",\n        \"对应的 Auth0 / 登录域名（如 xxx.us.auth0.com）\"\n      ]\n    }\n  }\n}\n```\n\n- `noSandbox: true`：容器内 root 运行 Chromium 必须，否则报 `Timeout waiting for browser`\n- `allowedHostnames`：内置浏览器默认启用 SSRF 防护，未列入白名单的域名会报 `blocked by policy`；登录页（Auth0 等 SSO 域名）也需要单独加入，否则登录跳转被拦截\n\n**配置生效的完整重启序列**（顺序不能错）：\n\n```bash\nbrowser stop\nopenclaw gateway restart\n# 等待约 15 秒\nbrowser start\n```\n\n仅 `gateway restart` 或仅 `browser stop/start` 都不够，必须三步完整执行。\n\n### 第三步：初始化 TOOLS.md\n\n将工具使用指南复制到项目根目录（与 SOUL.md、IDENTITY.md 同级），供 agent 在任意会话中随时查阅：\n\n```bash\n# 在 openclaw 项目根目录执行\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n若已存在则覆盖，确保版本与 skill 一致。\n\n### 第四步：自动注册 browser-use API Key\n\n脚本跑完后，agent 执行注册流程（无需人工介入）：\n\n1. 检查 CLI 是否有内置注册命令：`browser-use register`\n2. 若无，参考 https://docs.browser-use.com 的 Self-Registration API，流程为：\n   - 请求 challenge（返回一道数学题）\n   - 计算答案并提交验证\n   - 拿到 `bu_` 开头的 API Key\n3. 写入环境变量：\n   ```bash\n   echo 'export BROWSER_USE_API_KEY=bu_xxx' >> ~/.bashrc\n   export BROWSER_USE_API_KEY=bu_xxx\n   ```\n\n### 第五步：Smoke Test（自动验收）\n\n**验证 Playwright MCP**：\n```\n调用 playwright__browser_navigate → https://example.com\n调用 playwright__browser_take_screenshot → filename=\"/root/.openclaw/workspace/smoke_test.png\"\n确认文件存在且大小 > 0\n```\n\n**验证 browser-use**：\n```bash\nbrowser-use --version\n# 用 BROWSER_USE_API_KEY 执行一条简单命令，确认鉴权通过\n```\n\n任一验收失败时，输出具体错误信息，提示修复方向，不要静默跳过。\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1781699150925\n}\n\nFile v1.0.2:skill-card.md\n\n## Description: <br>\nInitializes Playwright MCP and browser-use CLI in a new OpenClaw environment, including Chinese font setup and smoke-test guidance. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[wangyin717](https://clawhub.ai/user/wangyin717) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and test agents use this skill to prepare a fresh OpenClaw container or machine for browser-based testing with Playwright MCP, browser-use CLI, screenshots, browser configuration, and automated smoke checks. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The setup flow performs privileged and persistent browser tooling changes in the OpenClaw environment. <br>\nMitigation: Install only in a disposable or trusted OpenClaw/container environment where root-level browser tooling changes are acceptable. <br>\nRisk: The setup script uses a curl-to-bash installer for browser-use CLI. <br>\nMitigation: Review the browser-use installer before running it, or replace it with a pinned and verified installation path. <br>\nRisk: The documented API key flow may persist BROWSER_USE_API_KEY in ~/.bashrc. <br>\nMitigation: Avoid storing the API key in ~/.bashrc unless the exposure is acceptable and rotation or removal steps are understood. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/wangyin717/testagent-browser-setup) <br>\n- [browser-use documentation](https://docs.browser-use.com) <br>\n- [browser-use GitHub repository referenced by the skill](https://github.com/browser-use/browser-use) <br>\n- [browser-use CLI installer referenced by the setup script](https://browser-use.com/cli/install.sh) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with bash, JSON, and shell command snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May guide privileged local setup, browser configuration changes, tool installation, and API key environment variable setup.] <br>\n\n## Skill Version(s): <br>\n1.0.2 (source: server release metadata; artifact frontmatter says 1.2.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.2:TOOLS.md\n\n# TOOLS.md — 浏览器工具使用指南\n\n## 三个浏览器工具对比\n\n| | OpenClaw 内置浏览器 | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **调用方式** | `browser` 工具（snapshot/act/screenshot） | `playwright__browser_*` 系列工具 | `exec` 调用 `browser-use` 命令 |\n| **浏览器引擎** | 本地 Chromium | 本地 Chromium | 本地 Chromium / 云端浏览器 |\n| **状态获取** | accessibility snapshot（文本树） | snapshot（文本树） | `state`（元素索引列表） |\n| **元素定位** | ref（如 e36） | ref + selector | 数字索引（如 click 5） |\n| **截图返回** | AI 分析文本（❌ 不可分享） | PNG 文件（✅ 可分享） | 保存路径（✅ 可分享） |\n| **JS 执行** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **键盘事件** | ⚠️ React 受控组件不生效 | ✅ 支持良好 | ✅ `keys \"Enter\"` |\n| **云浏览器** | ❌ | ❌ | ✅ `cloud connect` |\n| **复用登录态** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **反爬/CAPTCHA** | ❌ | ❌ | ✅ 云浏览器内置 |\n| **住宅代理** | ❌ | ❌ | ✅ 195+ 国家 |\n| **内网隧道** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **多会话并行** | 有限（tabs） | 有限（tabs） | ✅ `--session NAME` |\n| **命令链** | 不支持 | 不支持 | ✅ `&&` 链式执行 |\n| **登录态保持** | ✅ 同一 tab 内保持 | ✅ 同一 page 内保持 | ✅ daemon 保活，跨命令保持 |\n\n## 使用场景选择\n\n### → 用 OpenClaw 内置浏览器（默认首选）\n- 常规功能测试和页面交互\n- 已登录的会话内操作\n- 不需要截图分享给用户时\n- **优势**：工具集成度高，一步到位\n\n### → 用 Playwright MCP\n- 需要截图分享给用户（bug 截图、状态确认）\n- React/Vue 受控组件的精确交互（键盘事件支持好）\n- 需要精确 selector 定位元素\n- **优势**：元素定位最精确，截图可用\n\n### → 用 browser-use CLI\n- 需要云浏览器（反爬、CAPTCHA、住宅代理）\n- 需要复用用户本地 Chrome 登录态\n- 内网服务需通过隧道访问（`tunnel <port>`）\n- 新产品快速探索（命令链 `&&` 高效）\n- 多产品并行测试（`--session` 多会话）\n- **优势**：浏览器能力最强，云+本地+隧道全覆盖\n\n## 典型测试流程\n\n1. **新产品首次探索** → browser-use CLI（云浏览器 + 命令链快速摸底）\n2. **已熟悉产品回归测试** → OpenClaw 内置（快）或 Playwright MCP（精）\n3. **需要截图记录 Bug** → Playwright MCP 或 browser-use CLI\n4. **登录态受限的网站** → browser-use CLI（`--profile` 复用登录）\n5. **反爬严格的网站** → browser-use CLI（`cloud connect`）\n\n## 截图正确流程\n\n```\n1. playwright__browser_take_screenshot → filename=\"/tmp/screenshot.png\"\n2. cp /tmp/screenshot.png /root/.openclaw/workspace/<描述>.png\n3. 回复中附加: MEDIA:/root/.openclaw/workspace/<描述>.png\n```\n\n- 内置浏览器的 `browser screenshot` 只返回 AI 分析文本，**无法**用 `MEDIA:` 分享\n- `MEDIA:` 只在聊天回复中渲染，写进 `.md` 文件里不会显示图片\n\n## 常见踩坑\n\n### React/Vue 受控组件键盘事件不生效\n`keyboard.press('Control+Enter')` 等快捷键在受控组件中可能无法触发。\n\n解决：找页面上的实际提交按钮，用 JS 点击：\n```javascript\ndocument.querySelector('[aria-label=\"发送\"]').click()\n// 或用 evaluate / dispatchEvent\n```\n\n### 截图中文乱码（□□□）\n运行 `testagent-browser-setup` skill 中的 `setup.sh`，会自动安装 `fonts-noto-cjk` + `fonts-wqy-zenhei` 并配置 fontconfig。\n\n### 配置修改后不生效\n改 `~/.openclaw/openclaw.json` 后必须完整执行：\n```\nbrowser stop → openclaw gateway restart → 等 15 秒 → browser start\n```\n仅 restart gateway 或仅重启浏览器均不够。\n\nArchive v1.0.1: 4 files, 4133 bytes\n\nFiles: scripts/setup.sh (1418b), skill-card.md (2539b), SKILL.md (2961b), _meta.json (142b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: testagent-browser-setup\nversion: 1.1.0\ndescription: 在新的 openclaw 环境中安装并初始化 Playwright MCP 和 browser-use CLI，含中文字体修复和自动验收。当用户说「初始化测试环境」「安装浏览器工具」「setup browser」或在新机器首次部署测试 agent 时触发。\n---\n\n# Browser Setup\n\n一次性环境初始化，在新 openclaw 容器/机器上执行。需要 root 权限。\n\n## 执行顺序\n\n### 第一步：运行安装脚本\n\n```bash\nbash scripts/setup.sh\n```\n\n脚本按顺序完成：\n1. Playwright Chromium 安装 + 注册到 openclaw MCP（统一 `--browser chromium`，ARM64/x86 通用）\n2. 中文字体安装 + fontconfig 配置（截图无乱码）\n3. `openclaw gateway restart`（让字体生效，Chromium 重载 fontconfig 缓存）\n4. browser-use CLI 安装\n5. browser-use skill 安装\n\n### 第二步：配置内置浏览器（容器必须）\n\n**重要**：browser 相关配置必须直接编辑 `~/.openclaw/openclaw.json`，`config.patch` 无法修改 browser 配置（受保护路径）。\n\n编辑 `~/.openclaw/openclaw.json`，加入以下配置：\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"你的目标产品域名（如 app.example.com）\",\n        \"对应的 Auth0 / 登录域名（如 xxx.us.auth0.com）\"\n      ]\n    }\n  }\n}\n```\n\n- `noSandbox: true`：容器内 root 运行 Chromium 必须，否则报 `Timeout waiting for browser`\n- `allowedHostnames`：内置浏览器默认启用 SSRF 防护，未列入白名单的域名会报 `blocked by policy`；登录页（Auth0 等 SSO 域名）也需要单独加入，否则登录跳转被拦截\n\n**配置生效的完整重启序列**（顺序不能错）：\n\n```bash\nbrowser stop\nopenclaw gateway restart\n# 等待约 15 秒\nbrowser start\n```\n\n仅 `gateway restart` 或仅 `browser stop/start` 都不够，必须三步完整执行。\n\n### 第三步：自动注册 browser-use API Key\n\n脚本跑完后，agent 执行注册流程（无需人工介入）：\n\n1. 检查 CLI 是否有内置注册命令：`browser-use register`\n2. 若无，参考 https://docs.browser-use.com 的 Self-Registration API，流程为：\n   - 请求 challenge（返回一道数学题）\n   - 计算答案并提交验证\n   - 拿到 `bu_` 开头的 API Key\n3. 写入环境变量：\n   ```bash\n   echo 'export BROWSER_USE_API_KEY=bu_xxx' >> ~/.bashrc\n   export BROWSER_USE_API_KEY=bu_xxx\n   ```\n\n### 第四步：Smoke Test（自动验收）\n\n**验证 Playwright MCP**：\n```\n调用 playwright__browser_navigate → https://example.com\n调用 playwright__browser_take_screenshot → filename=\"/root/.openclaw/workspace/smoke_test.png\"\n确认文件存在且大小 > 0\n```\n\n**验证 browser-use**：\n```bash\nbrowser-use --version\n# 用 BROWSER_USE_API_KEY 执行一条简单命令，确认鉴权通过\n```\n\n任一验收失败时，输出具体错误信息，提示修复方向，不要静默跳过。\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1781694509763\n}\n\nFile v1.0.1:skill-card.md\n\n## Description: <br>\nInstalls and configures Playwright MCP, browser-use CLI, Chinese font support, browser allowlists, API-key setup, and smoke tests for a new OpenClaw environment. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[wangyin717](https://clawhub.ai/user/wangyin717) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and test-agent operators use this skill to bootstrap browser automation in a new OpenClaw container or machine, then configure allowlisted browser access and run smoke tests. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The setup path can run remote code and install additional agent behavior. <br>\nMitigation: Review the setup script before installation, pin and verify remote installers where possible, and run first in a disposable or test environment. <br>\nRisk: The setup can change system-wide font configuration and requires elevated environment changes. <br>\nMitigation: Run it only in environments intended for browser automation, and back up or avoid global font configuration changes when they are not required. <br>\nRisk: The registration flow can persist BROWSER_USE_API_KEY in a shell profile. <br>\nMitigation: Store the API key in a dedicated secret store or scoped runtime environment instead of a broadly loaded shell profile. <br>\nRisk: Browser configuration can broaden web access through sandbox and hostname allowlist settings. <br>\nMitigation: Limit allowedHostnames to the exact target and authentication domains, and review the noSandbox requirement before using it outside a container. <br>\n\n\n## Reference(s): <br>\n- [Browser-use documentation](https://docs.browser-use.com) <br>\n- [browser-use repository](https://github.com/browser-use/browser-use) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, shell commands, configuration] <br>\n**Output Format:** [Markdown instructions with shell and JSON snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Includes browser allowlist, API-key registration, and smoke-test guidance.] <br>\n\n## Skill Version(s): <br>\n1.0.1 (source: server release evidence; artifact frontmatter lists 1.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: Testagent Browser Setup Owner: wangyin717 Summary: One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no ro... Tags: latest:1.0.10 Version history: v1.0.10 | 2026-07-23T09:56:19.919Z | auto - Version bump to 1.0.10 with no file changes detected. - No updates or modifications to the skill code or documentation i","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"bash scripts/setup.sh"},{"language":"json","snippet":"{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"your target product domain (e.g. app.example.com)\",\n        \"the corresponding login domain (e.g. xxx.us.auth0.com)\"\n      ]\n    }\n  }\n}"},{"language":"bash","snippet":"cp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md"},{"language":"bash","snippet":"bash scripts/setup-optional.sh"},{"language":"bash","snippet":"curl -s http://localhost:9223/json | python3 -m json.tool | head -20"},{"language":"bash","snippet":"# Start Chrome CDP\nchrome-cdp &\nsleep 2\n\n# Verify CDP is reachable\ncurl -s http://localhost:9223/json | python3 -m json.tool | head -20\n\n# Verify with a screenshot (see the CDP screenshot flow in REFERENCE.md)"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: testagent-browser-setup\nversion: 2.2.0\ndescription: One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no root required. Triggered when the user says \"initialize test environment\", \"install browser tools\", \"setup browser\", or when deploying a test agent to a new machine for the first time.\n---\n\n# Browser Setup\n\nOne-time environment initialization, run on a fresh openclaw container. No root required.\n\n## Notes\n\nThe openclaw environment ships with Chromium pre-installed by default; `setup.sh` prefers it and only falls back to downloading via Playwright if it's not found.\n\n**The primary path for screenshots and browser actions is: Chrome + direct CDP.**\nsetup.sh creates a `~/.local/bin/chrome-cdp` launcher script.\n\n**`mcp doctor --probe` gives false positives.**\nIt returning ok only means the MCP server process started — not that Chromium can actually run. The only reliable check is: `playwright__browser_navigate` actually returning page content.\n\n## Execution order\n\n### Step 1: Run the core setup script\n\n```bash\nbash scripts/setup.sh\n```\n\nThe script does three things:\n1. **Chromium detection**: prefers the system-preinstalled Chromium, falling back to a Playwright download if not found\n2. **`chrome-cdp` launcher script**: `~/.local/bin/chrome-cdp`, wrapping the `--headless=new --no-sandbox --remote-allow-origins=*` flags\n3. **Chinese fonts**: downloads WenQuanYi Micro Hei from GitHub into `~/.local/share/fonts/`\n\n### Step 2: Try configuring the built-in browser (optional, often ineffective)\n\nEdit `~/.openclaw/openclaw.json` (`config.patch` refuses to modify protected paths, so the file must be written by hand):\n\n```json\n{\n  \"browser\": {\n    \"noSandbox\": true,\n    \"ssrfPolicy\": {\n      \"allowedHostnames\": [\n        \"your target product domain (e.g. app.example.com)\",\n        \"the corresponding login domain (e.g. xxx.us.auth0.com)\"\n      ]\n    }\n  }\n}\n```\n\nAfter editing: `browser stop → gateway restart → wait 15s → browser start`\n\n> ⚠️ **The SSRF allowlist often doesn't take effect** (the gateway has a runtime cache and doesn't always pick up the file).\n> If `browser navigate` still reports `blocked by policy`, **immediately abandon the built-in browser and switch to direct CDP (see TOOLS.md)** rather than continuing to restart-and-retry.\n\n### Step 4: Initialize TOOLS.md\n\n```bash\ncp \"$(dirname \"$0\")/../TOOLS.md\" ./TOOLS.md\n```\n\n### Step 6 (optional): Install browser-use\n\n```bash\nbash scripts/setup-optional.sh\n```\n\n### Step 7: Smoke test\n\n```bash\n# Start Chrome CDP\nchrome-cdp &\nsleep 2\n\n# Verify CDP is reachable\ncurl -s http://localhost:9223/json | python3 -m json.tool | head -20\n\n# Verify with a screenshot (see the CDP screenshot flow in REFERENCE.md)\n```\n\nAcceptance criteria: CDP `/json` returns a target list, and Chinese text in screenshots renders cleanly with no mojibake."},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn727a13c3vqvhag3n56qpqva588v5sx\",\n  \"slug\": \"testagent-browser-setup\",\n  \"version\": \"1.0.10\",\n  \"publishedAt\": 1784800579919\n}"},{"path":"skill-card.md","content":"## Description:\n\nOne-time installation and initialization of Chromium, browser dependencies, Chinese fonts, and a Chrome CDP launcher in a fresh OpenClaw environment without root access.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[wangyin717](https://clawhub.ai/user/wangyin717)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and test engineers use this skill to initialize browser automation support in a fresh OpenClaw environment, including Chromium/CDP setup, Chinese font support, Playwright MCP registration, and optional browser-use tooling.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill weakens browser and network safeguards through no-sandbox CDP launch options and SSRF allowlist guidance.\n\nMitigation: Use only in an isolated test container and require explicit authorization before direct CDP is used to work around network policy.\n\nRisk: The setup scripts install mutable third-party tooling and assets from external URLs.\n\nMitigation: Review, pin, and verify third-party installers and downloads before deployment.\n\nRisk: The optional browser-use workflow can reuse local Chrome profiles or real credentials.\n\nMitigation: Do not reuse personal browser profiles or production credentials; use disposable test accounts and isolated browser state.\n\nRisk: Security evidence marks the release suspicious and recommends review before use.\n\nMitigation: Perform security review and scanner review before installing or running the skill.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/wangyin717/skills/testagent-browser-setup)\n- [browser-use repository](https://github.com/browser-use/browser-use)\n- [WenQuanYi Micro Hei font source](https://github.com/anthonyfok/fonts-wqy-microhei/raw/master/wqy-microhei.ttc)\n- [browser-use CLI installer](https://browser-use.com/cli/install.sh)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration, Guidance, Code]\n\n**Output Format:** [Markdown guidance with shell commands, JSON configuration snippets, and JavaScript CDP examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces setup and testing guidance for an agent; setup scripts may install browser tooling and create local configuration files.]\n\n## Skill Version(s):\n\n1.0.10 (source: server release metadata; artifact frontmatter reports 2.2.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"TOOLS.md","content":"# TOOLS.md — Browser Tools Guide\n\n## Comparison of the three browser tools\n\n| | OpenClaw built-in browser | Playwright MCP | browser-use CLI |\n|---|---|---|---|\n| **Invocation** | `browser` tool (snapshot/act/screenshot) | `playwright__browser_*` tool family | `exec` calling the `browser-use` command |\n| **Browser engine** | Local Chromium | Local Chromium | Local Chromium / cloud browser |\n| **State retrieval** | accessibility snapshot (text tree) | snapshot (text tree) | `state` (indexed element list) |\n| **Element targeting** | ref (e.g. e36) | ref + selector | numeric index (e.g. click 5) |\n| **Screenshot output** | AI analysis text (❌ not shareable) | PNG file (✅ shareable) | saved path (✅ shareable) |\n| **JS execution** | ✅ evaluate | ✅ evaluate | ✅ eval |\n| **Keyboard events** | ⚠️ doesn't work on React controlled components | ✅ works well | ✅ `keys \"Enter\"` |\n| **Cloud browser** | ❌ | ❌ | ✅ `cloud connect` |\n| **Reuse login session** | ❌ | ❌ | ✅ `--profile \"Default\"` |\n| **Anti-bot/CAPTCHA** | ❌ | ❌ | ✅ built into the cloud browser |\n| **Residential proxy** | ❌ | ❌ | ✅ 195+ countries |\n| **Internal network tunnel** | ❌ | ❌ | ✅ `tunnel <port>` |\n| **Parallel multi-session** | limited (tabs) | limited (tabs) | ✅ `--session NAME` |\n| **Command chaining** | not supported | not supported | ✅ chainable with `&&` |\n| **Persisted login state** | ✅ persists within the same tab | ✅ persists within the same page | ✅ kept alive by a daemon, persists across commands |\n\n## Choosing a tool for the task\n\n### → Use the OpenClaw built-in browser (default choice)\n- Routine functional testing and page interaction\n- Actions within an already-logged-in session\n- When screenshots don't need to be shared with the user\n- **Advantage**: tightly integrated tooling, gets things done in one step\n\n### → Use Playwright MCP\n- Need to share a screenshot with the user (bug screenshots, state confirmation)\n- Precise interaction with React/Vue controlled components (good keyboard event support)\n- Need precise selector-based element targeting\n- **Advantage**: most precise element targeting, screenshots are usable\n\n### → Use browser-use CLI\n- Need a cloud browser (anti-bot, CAPTCHA, residential proxy)\n- Need to reuse the user's local Chrome login session\n- Internal services need to be reached via a tunnel (`tunnel <port>`)\n- Fast exploration of a new product (efficient with `&&` command chains)\n- Parallel testing across multiple products (`--session` multi-session)\n- **Advantage**: strongest browser capabilities, full coverage across cloud + local + tunnel\n\n## Typical testing workflow\n\n1. **First-time exploration of a new product** → browser-use CLI (cloud browser + command chains for a quick survey)\n2. **Regression testing on a familiar product** → OpenClaw built-in (fast) or Playwright MCP (precise)\n3. **Need a screenshot to document a bug** → Playwright MCP or browser-use CLI\n4. **Sites with restricted login sessions** → browser-use CLI (`--profile` to reuse login)\n5. **Si"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no ro... Skill: Testagent Browser Setup Owner: wangyin717 Summary: One-time installation and initialization of Chromium, system dependencies, Chinese fonts, and the CDP launcher script in a fresh openclaw environment — no ro... Tags: latest:1.0.10 Version history: v1.0.10 | 2026-07-23T09:56:19.919Z | auto - Version bump to 1.0.10 with no file changes detected. - No updates or modifications to the skill code or documentation i","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1709,"uniquenessScore":45,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T10:45:28.101Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T10:45:28.101Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:13:18.779Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}