{"id":"04513a19-4b43-4454-939b-93869c82582a","entityType":"agent","slug":"clawhub-ziniao-open-ziniao-assistant","name":"ziniao-assistant","canonicalUrl":"https://www.xpersona.co/agent/clawhub-ziniao-open-ziniao-assistant","canonicalPath":"/agent/clawhub-ziniao-open-ziniao-assistant","generatedAt":"2026-10-09T17:45:38.228Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T05:58:06.415Z","emptyReason":null},"description":"Control Ziniao Browser via the local Ziniao bridge. On skill load or before first invoke, GET /zclaw/tools and treat returned name list as the only allowed t... Skill: ziniao-assistant Owner: ziniao-open Summary: Control Ziniao Browser via the local Ziniao bridge. On skill load or before first invoke, GET /zclaw/tools and treat returned name list as the only allowed t... Tags: latest:1.0.1 Version history: v1.0.1 | 2026-03-26T13:00:40.032Z | user **Ziniao Assistant 1.0.1 introduces dynamic tool discovery for safer, more reliable browser control.** - On skill load or before f","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 4.1K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17daw69gp84x2gww3hnm0tsqh83nv19:ziniao-assistant","sourceUrl":"https://clawhub.ai/ziniao-open/ziniao-assistant","homepage":"https://clawhub.ai/ziniao-open/skills/ziniao-assistant","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/ziniao-open/ziniao-assistant","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/ziniao-open/skills/ziniao-assistant","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Control Ziniao Browser via the local Ziniao bridge. On skill load or before first invoke, GET /zclaw/tools and treat returned name list as the only allowed t..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:58:06.415Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:58:06.415Z","emptyReason":null},"stars":null,"forks":null,"downloads":4135,"packageName":null,"latestVersion":"1.0.1","tractionLabel":"4.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:58:06.414Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T05:58:06.415Z","lastCrawledAt":"2026-10-09T05:58:06.414Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T05:58:06.414Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.1","createdAt":"2026-03-26T13:00:40.032Z","changelog":"**Ziniao Assistant 1.0.1 introduces dynamic tool discovery for safer, more reliable browser control.** - On skill load or before first tool use, fetch available tools from the bridge via GET /zclaw/tools and only allow invoking tool names from this live list. - Prevents using hallucinated or invalid tool names by always mapping user actions to names in the session's allowedTools. - Retains static fallback allowlist for tool names only if the bridge registry cannot be reached. - No changes to browser control capabilities or stop-on-blocker logic. - Updated documentation for dynamic discovery, static fallback, and stricter tool invocation flow.","fileCount":3,"zipByteSize":9909},{"version":"1.0.0","createdAt":"2026-03-16T09:28:51.763Z","changelog":"Ziniao Assistant v1.0.0 - Initial release: allows control of Ziniao Browser via the local ZClaw bridge using a unified set of Core Tools. - Supports listing/opening stores, navigation, page reading, clicking, input, screenshots, automation, and file/download management exclusively via `POST /zclaw/tools/invoke`. - Enforces hard constraints: stop immediately on bridge/tool failure, no retries or follow-up actions, and no custom scripting or templates. - Provides user-configurable API key management via conversation, environment variable, or config file for seamless authentication. - Clear separation of valid/invalid tool names and strict usage of Core Tools only.","fileCount":2,"zipByteSize":6809}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17daw69gp84x2gww3hnm0tsqh83nv19:ziniao-assistant","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T17:45:38.226Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ziniao-open-ziniao-assistant/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T05:58:06.415Z","emptyReason":null},"readme":"Skill: ziniao-assistant\n\nOwner: ziniao-open\n\nSummary: Control Ziniao Browser via the local Ziniao bridge. On skill load or before first invoke, GET /zclaw/tools and treat returned name list as the only allowed t...\n\nTags: latest:1.0.1\n\nVersion history:\n\nv1.0.1 | 2026-03-26T13:00:40.032Z | user\n\n**Ziniao Assistant 1.0.1 introduces dynamic tool discovery for safer, more reliable browser control.**\n\n- On skill load or before first tool use, fetch available tools from the bridge via GET /zclaw/tools and only allow invoking tool names from this live list.\n- Prevents using hallucinated or invalid tool names by always mapping user actions to names in the session's allowedTools.\n- Retains static fallback allowlist for tool names only if the bridge registry cannot be reached.\n- No changes to browser control capabilities or stop-on-blocker logic.\n- Updated documentation for dynamic discovery, static fallback, and stricter tool invocation flow.\n\nv1.0.0 | 2026-03-16T09:28:51.763Z | user\n\nZiniao Assistant v1.0.0\n\n- Initial release: allows control of Ziniao Browser via the local ZClaw bridge using a unified set of Core Tools.\n- Supports listing/opening stores, navigation, page reading, clicking, input, screenshots, automation, and file/download management exclusively via `POST /zclaw/tools/invoke`.\n- Enforces hard constraints: stop immediately on bridge/tool failure, no retries or follow-up actions, and no custom scripting or templates.\n- Provides user-configurable API key management via conversation, environment variable, or config file for seamless authentication.\n- Clear separation of valid/invalid tool names and strict usage of Core Tools only.\n\nArchive index:\n\nArchive v1.0.1: 3 files, 9909 bytes\n\nFiles: skill-card.md (2257b), SKILL.md (22625b), _meta.json (135b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: ziniao-assistant\ndescription: Control Ziniao Browser via the local Ziniao bridge. On skill load or before first invoke, GET /zclaw/tools and treat returned name list as the only allowed tool strings; then POST /zclaw/tools/invoke. API key for invoke via ~/.zclaw/config.json or ZCLAW_API_KEY. On bridge failure stop the turn per skill.\n---\n# Ziniao Assistant\n\n## Session tool allowlist (Mandatory — fetch first)\n\n**Goal:** Put the **authoritative** tool names into context before any `invoke`, so every `tool` field is chosen from that set only (reduces hallucinated names).\n\n1. **First HTTP call** when handling a ZClaw task (or immediately after this skill is loaded):  \n   **`GET {baseUrl}/zclaw/tools`**  \n   Same `baseUrl` as invoke (`ZCLAW_BASE_URL` / `ZINIAO_ZCLAW_BASE_URL`, default `http://127.0.0.1:9481`).  \n   **No `X-ZClaw-Api-Key` and no Ziniao login are required** for this GET (public registry on the bridge).\n\n2. **Parse the response:** JSON shape `{ ret, data }` where `data` is an array of `{ name, description, inputSchema }`. Build  \n   **`allowedTools = data.map((t) => t.name)`**  \n   and **retain it in working memory** for the session. Optionally keep `description` / `inputSchema` next to each name when choosing args.\n\n3. **Before every `POST {baseUrl}/zclaw/tools/invoke`:** ensure **`allowedTools.includes(tool)`**. If the name you intend is not in `allowedTools`, **do not send the request**—map the user’s intent to a real name from `allowedTools` (e.g. open URL → `visit_page` or `open_store` + `launchUrl`).\n\n4. **If `invoke` returns an error** like unsupported / unknown tool: re-run **`GET /zclaw/tools`**, refresh `allowedTools`, and retry with a valid `name`.\n\n5. **If `GET /zclaw/tools` fails** (connection refused, timeout): follow **Stop on Blocker** for unreachable bridge; if you must proceed with static knowledge only, use the **Static fallback allowlist** below—still **no** invented names.\n\n### Static fallback allowlist (when GET is impossible)\n\nComma-separated `tool` names that match a healthy bridge (re-sync when GET works):\n\n`list_stores`, `resolve_store`, `open_store`, `close_store`, `visit_page`, `get_page_content`, `query_elements`, `click_element`, `input_text`, `scroll_page`, `take_screenshot`, `wait_for_element`, `wait_for_navigation`, `execute_script`, `run_automation`, `extract_data`, `prepare_agent`, `get_logs`, `download_file`, `debug_compare_lists`\n\n---\n\n## Available Capabilities\n\nAll **`invoke`** operations use `POST {baseUrl}/zclaw/tools/invoke` with `tool` + `args`. **Authoritative names** come from **`GET /zclaw/tools`** (see above); the table below is documentation aligned with that registry.\n\n| Category | Tool | Description |\n|----------|------|-------------|\n| **Store** | `list_stores` | List stores (storeId, storeName, platformName, ip). Call once; no loop. |\n| | `resolve_store` | Resolve store by storeId or storeName. |\n| | `open_store` | Open store (by storeId/storeName from list or resolve). Call once. |\n| | `close_store` | Close store by storeId. |\n| **Page** | `visit_page` | Navigate to URL, optional waitUntil/timeout. |\n| | `get_page_content` | Read page content (text/html/structured). |\n| **Interaction** | `query_elements` | Query DOM by selector. |\n| | `click_element` | Click element by selector, optional waitForNavigation. |\n| | `input_text` | Type into element; optional clear, submit. |\n| | `scroll_page` | Scroll page or element. |\n| | `take_screenshot` | Screenshot (full page or viewport). |\n| **Waiting** | `wait_for_element` | Wait for selector. |\n| | `wait_for_navigation` | Wait for navigation. |\n| **Automation** | `execute_script` | Run JavaScript in page. |\n| | `run_automation` | Multi-step automation (steps array). |\n| | `extract_data` | Extract metadata / page state; mode=running lists launched stores. |\n| **Utilities** | `prepare_agent` | Prepare agent resources. |\n| | `download_file` | Write content to Downloads (content, filename). |\n| | `get_logs` | Get bridge logs. |\n| **Debug** | `debug_compare_lists` | Debug: compare account/list vs store/list (optional; in GET /zclaw/tools registry). |\n\n**Do not use:** `run_script` → use `execute_script`; `screenshot` / `get_screenshot` → use `take_screenshot`; `execute_automation` → use `run_automation`.\n\n---\n\n## Tool names: no hallucination (Mandatory)\n\nThe bridge **only** accepts the `tool` strings listed in **Core Tools** below. There is no separate “navigate API”, “browser API”, or “store tool” namespace—everything is one `POST .../zclaw/tools/invoke` body field `tool`.\n\n**You MUST NOT** invent or guess tool names from general automation habits (Playwright, Selenium, browser-use, etc.). If a name is not in Core Tools, it **does not exist**.\n\n**These and similar names are INVALID** (will fail or be rejected): `navigate`, `navigation`, `go_to`, `goto`, `open_url`, `openUrl`, `goto_url`, `load_url`, `browse`, `open_page`, `openPage`, `call_store_tool`, `store_tool`, `browser_navigate`, `visit`, `goto_tab`, `switch_tab` (as a tool name—use `visit_page` / `open_store` instead).\n\n**Opening a URL in a store—only two supported ways:**\n\n1. **`visit_page`** — args: `storeId`, `url` (and optional `waitUntil`, `timeoutMs`, `targetId`). Use after the store is already open.\n2. **`open_store`** — args: `storeId` or `storeName`, and optional **`launchUrl`** so the first tab opens that URL when the store starts.\n\nDo not chain imaginary tools before trying `visit_page` or `open_store` + `launchUrl`.\n\n---\n\n## API: How to Invoke Tools (Required)\n\n**All tools are invoked through one endpoint only.** Do not call other paths.\n\n- **Discover tools (no auth):** `GET {baseUrl}/zclaw/tools` — use first; see **Session tool allowlist**.\n- **Method and path:** `POST {baseUrl}/zclaw/tools/invoke` (e.g. `POST http://127.0.0.1:9481/zclaw/tools/invoke`). Base URL from `ZCLAW_BASE_URL` or `ZINIAO_ZCLAW_BASE_URL` (default `http://127.0.0.1:9481`).\n- **Auth is mandatory for invoke:** Every `POST {baseUrl}/zclaw/tools/invoke` **must carry API key credentials**. Preferred header: `X-ZClaw-Api-Key: <key>`. Also accepted: body `apiKey`, or `Authorization: Bearer <key>` (compatibility only). **Never send invoke without key.**\n- **Request body (JSON):** `{ \"tool\": \"<name>\", \"args\": { ... } }`. Optional: `\"action\": \"json\"`.\n- **`tool`** must be exactly one of the tool names in the **Core Tools** list below (e.g. `list_stores`, `visit_page`, `get_page_content`, `click_element`, `take_screenshot`, `execute_script`, `run_automation`). Wrong names (e.g. `run_script`, `screenshot`) or custom paths will fail.\n- **Do not** call paths like `/zclaw/page/execute`, `/zclaw/page/visit`, `/zclaw/page/click`, etc. Every tool call must be `POST /zclaw/tools/invoke` with the correct `tool` name in the body.\n\n### Invoke Auth Examples (Mandatory)\n\n**Correct (preferred):**\n\n```bash\ncurl -X POST http://127.0.0.1:9481/zclaw/tools/invoke \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-ZClaw-Api-Key: <ZCLAW_API_KEY>\" \\\n  -d '{\"tool\":\"open_store\",\"args\":{\"storeName\":\"Rosehut\"}}'\n```\n\n**Also accepted (compatibility):**\n\n```bash\ncurl -X POST http://127.0.0.1:9481/zclaw/tools/invoke \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Authorization: Bearer <ZCLAW_API_KEY>\" \\\n  -d '{\"tool\":\"open_store\",\"args\":{\"storeName\":\"Rosehut\"}}'\n```\n\n**Invalid (must not generate):** no API key in header/body.\n\n## When To Use\n\nUse when the user wants to operate Ziniao Browser or configure the Ziniao bridge (list stores, open store, visit pages, read content, click, input, screenshot, export, automation). When a task has multiple similar sub-items (e.g. several order types or reports), visit or check each one separately before concluding; do not infer from a subset.\n\n## Stop on Blocker (Mandatory — Enforced First)\n\n**Trigger:** Any of: (a) `POST {baseUrl}/zclaw/tools/invoke` fails with connection refused, timeout, or no response; (b) a required tool call returns an error that makes the task impossible; (c) a required resource (e.g. store not found, API key missing) is missing.\n\n**You MUST:**\n\n1. **Stop immediately.** Do not retry the same request. Do not read more code, grep, or open other files to \"diagnose\" or \"work around\". Do not design or write \"run these steps when the bridge is up\" or any follow-up plan.\n2. **End the turn.** Do not speculate on other causes, suggest code changes, or continue the task. Connection or tool failure means the task is not executable—stop only. (User-facing messages for unreachable bridge are handled by the software.)\n\n## Hard Constraints\n\n- **Stop on blocker:** If the bridge is unreachable or a required tool call fails, stop and end the turn; do not retry, read code, or create templates or follow-up plans. See \"Stop on Blocker\" above.\n- **Invoke must include API key:** Every `POST /zclaw/tools/invoke` request must include API key credentials (`X-ZClaw-Api-Key` preferred; or body `apiKey`; or `Authorization: Bearer <key>`). Do not generate keyless invoke commands.\n- **No script files:** Do not create or run any scripts (`.sh`/`.js`/`.py` or other code files) to execute tasks; use only the tools in **Core Tools** via `POST /zclaw/tools/invoke`. **Temporary files are allowed** (e.g. intermediate data, content for `download_file`); **script/executable files are not.**\n- All browser actions must stay inside **Ziniao Browser** or a Ziniao store exposed by the bridge. Do not open system browser, Chrome, Safari, Edge, Firefox, or use Playwright/Puppeteer/browser-use when the bridge fails.\n- Use only the tools in **Core Tools**. Do NOT use: `run_script` (use `execute_script`), `screenshot` or `get_screenshot` (use `take_screenshot`), `execute_automation` (use `run_automation`), or any tool not listed there. Do NOT invent `navigate`, `open_url`, `call_store_tool`, or any name not in Core Tools.\n- Prefer tool-based flow: open store (optionally with `launchUrl`) → **`visit_page`** for further URLs → get_page_content / query_elements / click_element / input_text / take_screenshot / download_file / run_automation. Use `execute_script` only for in-page JavaScript (e.g. DOM extraction), not for orchestration.\n\n## API Key: Configure via Conversation (Preferred)\n\n**The user can configure the API key by sending it in the conversation.** When the user provides an API key (e.g. pastes it, or says “设置 API key 为 xxx”, “my API key is znoc_xxx”, “configure ZCLAW_API_KEY: xxx”), you MUST:\n\n1. **Write the key to the config file** the skill reads from:\n   - **macOS / Linux:** `~/.zclaw/config.json`\n   - **Windows:** `%USERPROFILE%\\.zclaw\\config.json` (e.g. `C:\\Users\\<YourName>\\.zclaw\\config.json`)\n   Create the `.zclaw` directory if it does not exist. File content: JSON with at least `\"ZCLAW_API_KEY\": \"<the key the user provided>\"`. If the file already exists, **merge**: update `ZCLAW_API_KEY` and keep other keys (e.g. `ZCLAW_BASE_URL`) unchanged.\n2. **Immediately use this new API key** for all subsequent `POST /zclaw/tools/invoke` requests in this conversation. Do not wait for a reload; treat the key you just wrote as the current key. If the user provides a new key again later, write again and switch to the new key for the rest of the conversation.\n\nWriting the config file is allowed for API key setup only (creating/updating `~/.zclaw/config.json`). Do not create or run scripts; use normal file write to that path.\n\n## API Key: Read into Context (Required)\n\nWhen this skill is used, **load the API key into the conversation context** so every request (including the first) can authenticate. Use this order (Ziniao and ZClaw both use **ZCLAW_API_KEY**):\n\n1. **User just provided in this conversation** — if you have just written the key to the config per “API Key: Configure via Conversation”, use that key for all requests.\n2. **Environment variable** `ZCLAW_API_KEY` — use if set.\n3. **Config file** `~/.zclaw/config.json` — if the key is not in env and not set in conversation, read `ZCLAW_API_KEY` from this JSON file (e.g. `{ \"ZCLAW_API_KEY\": \"your-key\" }`).\n\nUse the resolved key for all `POST /zclaw/tools/invoke` requests (e.g. header `X-ZClaw-Api-Key` or body `apiKey`). Optionally `ZCLAW_BASE_URL` or `ZINIAO_ZCLAW_BASE_URL` (default `http://127.0.0.1:9481`).\n\nDo this at skill load or at the start of the conversation so the key is available and the first tool call does not fail with \"Missing bearer token\". **After the user configures a new key via conversation, update to the new key immediately** for the rest of the turn.\n\n## Environment & Setup\n\n- **API key**: Env `ZCLAW_API_KEY`, or `ZCLAW_API_KEY` in `~/.zclaw/config.json` (see path note below). The bridge also accepts the key via header `X-ZClaw-Api-Key` or body `apiKey`.\n- **Base URL**: `ZCLAW_BASE_URL` or `ZINIAO_ZCLAW_BASE_URL` (default `http://127.0.0.1:9481`).\n- **First time / Rotate key**: Obtain a ZClaw API key from your **server or [Ziniao Ecosystem Center](https://open.ziniao.com/contactUs)** (there is no API key generation in the app settings). You can **(1) configure via conversation** — tell the assistant your API key and it will write it to `~/.zclaw/config.json` and use it immediately; or **(2)** set `ZCLAW_API_KEY` in your environment or in `~/.zclaw/config.json`; or **(3)** run `bash ziniao-skills/install-ziniao-openclaw-skill.sh \"YOUR_API_KEY\"` (Windows: use `install-ziniao-openclaw-skill.ps1` with `-ApiKey`). After configuring via conversation, the assistant uses the new key for all subsequent requests in that conversation.\n\n**Reading the key:** The bridge uses `process.env.ZCLAW_API_KEY`, which works on **Windows, macOS, and Linux**. The variable must be present in the environment of the process that runs the app (Ziniao/Electron). If the app is started from the GUI (e.g. Dock, Start menu), only **system/user environment variables** are visible; shell-only exports (e.g. in a terminal) are not. To ensure the key is always available on all platforms, you can use the config file instead of env.\n\n**Setting `ZCLAW_API_KEY` by OS:**\n\n- **macOS / Linux**: (1) **Config file (recommended):** `~/.zclaw/config.json` with `{ \"ZCLAW_API_KEY\": \"your-key\" }` (same path on both). (2) **Env:** In the same shell that starts the app: `export ZCLAW_API_KEY=your-key`. For GUI launches, add `export ZCLAW_API_KEY=...` to `~/.bashrc`, `~/.zshrc`, or `~/.profile`, or set it system-wide (e.g. `/etc/environment` on Linux).\n- **Windows**: (1) **Config file (recommended):** `%USERPROFILE%\\.zclaw\\config.json` (e.g. `C:\\Users\\YourName\\.zclaw\\config.json`) with `{ \"ZCLAW_API_KEY\": \"your-key\" }`. (2) **Env:** System Properties → Environment Variables → add User or System variable `ZCLAW_API_KEY`; or in PowerShell (current user): `[Environment]::SetUserVariable(\"ZCLAW_API_KEY\",\"your-key\")`. Restart the app after changing system env.\n\n**Invocation:** This skill is designed for use with the ZClaw framework (recommended). The Ziniao bridge is an HTTP API; any client that can send requests with a valid API key can call the same tools.\n\n## Store Resolution and Opening: Validation and Response Contract\n\n**Getting and opening stores** follows Ziniao’s existing validation and launch flow: store detail (e.g. `default_browser`, `platform`) is fetched via **store/detail** when launching; the browser is then started using the same logic as the client.\n\n**ZClaw responses** are filtered by convention and do not expose full Ziniao store details: **open_store** returns only **storeId**, **name**, **debugPort**, **reused**, etc.; **list_stores** returns only **storeId**, **storeName**, **platformName**, **ip**. **ZClaw does not expose full store detail**; it only exposes status for stores launched via ZClaw. The running-stores list (e.g. **extract_data** with `mode=running` or the running-stores API) contains only **storeId**, **storeName**, **debugPort**, **wsUrl**.\n\nIf **open_store** or **visit_page** returns 400 \"Store detail not found\", the backend **store/detail** API or its response shape may be failing; the bridge tries several response paths and, when present, includes the server’s `msg` in the error.\n\n\n## No Extra Scripts (Mandatory)\n\n**You must not create or use any scripts to execute tasks.** All actions must be performed only through the tools listed in **Core Tools**. Do not:\n\n- Create or run Node.js, shell, Python, or other script files (e.g. `.sh`, `.js`, `.py`) to accomplish the task.\n- Invoke external commands or scripts for steps that the tools can do (list stores, open store, visit page, click, input, screenshot, download_file, run_automation, etc.).\n\n**Temporary files are allowed** during the run (e.g. temporary data files, intermediate content to pass to `download_file`, or scratch files). **Script files are not allowed** — do not create or execute any file intended to be run as code. Use only `POST /zclaw/tools/invoke` with the tool names and args from Core Tools. If something cannot be done with the existing tools, report the limitation instead of scripting around it.\n\n## Store List and Opening (Mandatory)\n\n- **No looping:** Call `list_stores` at most once to get data; then call `open_store` once. Do not repeatedly call list in a cycle.\n- **To open a store:** (1) Get **storeId** — either from one `list_stores` (use the item whose `storeName` matches the user’s store) or from one `resolve_store(storeName)`; (2) Call `open_store` once with that `storeId` or with `storeName` (exact string from the list).\n- **list_stores response:** Each item has exactly: `storeId`, `storeName`, `platformName`, `ip`. Use **`storeName`** when calling `resolve_store` or `open_store` (exact match). Do not use other fields as the store name.\n\n## Recommended Workflow\n\n0. **Allowlist:** `GET /zclaw/tools` → keep `allowedTools` (and schemas) in context; every `invoke` uses `tool` ∈ `allowedTools`.\n0.5. **Auth:** Resolve API key first (`conversation-provided` > env `ZCLAW_API_KEY` > `~/.zclaw/config.json`) and include it in **every** invoke request.\n1. **Store:** One `list_stores` or one `resolve_store` → get `storeId` / `storeName` → one `open_store` (pass **`launchUrl`** if the user gave a target URL up front—avoids a second navigation step). Match by `storeName` from list; if ambiguous, ask user or use exact `storeId`. No fuzzy/substring matching.\n2. **Page:** If the store is open and you need a URL: **`visit_page`** only (`storeId` + `url`). Never use `navigate`, `open_url`, or other non-listed tool names. Then use `get_page_content`, `query_elements`, `click_element`, `input_text`, `take_screenshot`, `download_file` as needed; prefer `run_automation` for multi-step flows.\n3. **Errors:** Use `get_logs` on failure; after API key rotation, update config and refresh skills.\n4. **Multiple similar items:** When a task involves multiple similar sub-items (e.g. several order types, several reports), visit or check **each item separately** before drawing a conclusion; do not infer \"all have no data\" or \"all behave the same\" from only a subset.\n\n## Core Tools\n\n**Only these tools exist.** Use exactly these names as the `tool` field in `POST /zclaw/tools/invoke`; put parameters in `args`. Do not use or invent other tool names or other URLs.\n\nPass one arguments object per call (as `args`); required keys must be present. When running ZClaw tasks, the bridge operates on the correct tab but **does not bring the browser window to the front**, so your other windows and work are not interrupted.\n\n### Store Management\n- **list_stores** — List stores (call once; no loop). **Response:** `{ page, limit, total, items }` where each item has `storeId`, `storeName`, `platformName`, `ip`. Use `storeName` for resolve/open. Args: `page?`, `limit?`, `all?`, `filterKeyword?`, `storeListType?`.\n- **resolve_store** — Resolve by exact storeId or storeName. Args: `storeId?`, `storeName?`, `expectedName?`. Returns `storeId` and `name` for `open_store`.\n- **open_store** — Open store (need storeId from list_stores or resolve_store). Uses store/detail + launch. Returns (filtered): storeId, name, debugPort, reused, and optionally status, windowHandler, launchUrl. Call once. Args: `storeId?`, `storeName?` (use list item `storeName`), `expectedName?`, `launchUrl?`, `isHeadless?`, `privacyMode?`, `windowRatio?`.\n- **close_store** — Close store. Args: `storeId` (required).\n\n### Page Navigation & Content\n- **visit_page** — Navigate and wait. Args: `storeId`, `url`; optional `waitUntil` (domcontentloaded|load|networkidle), `timeoutMs`, `targetId`.\n- **get_page_content** — Read page content. Args: `storeId`; optional `format` (text|html|structured), `timeoutMs`, `targetId`.\n\n### Page Interaction\n- **query_elements** — DOM by selector. Args: `storeId`, `selector`; optional `timeoutMs`, `targetId`.\n- **click_element** — Click. Args: `storeId`, `selector`; optional `waitForNavigation`, `timeoutMs`, `targetId`.\n- **input_text** — Type into element. Args: `storeId`, `selector`, `text`; optional `clear`, `submit`, `timeoutMs`, `targetId`.\n- **scroll_page** — Scroll. Args: `storeId`; optional `x`, `y`, `selector`, `behavior` (auto|smooth), `timeoutMs`, `targetId`.\n- **take_screenshot** — Screenshot (not `screenshot`). Args: `storeId`; optional `fullPage`, `path`, `timeoutMs`, `targetId`.\n\n### Page Waiting\n- **wait_for_element** — Wait for selector. Args: `storeId`, `selector`; optional `timeoutMs`, `targetId`.\n- **wait_for_navigation** — Wait for navigation. Args: `storeId`; optional `timeoutMs`, `targetId`.\n\n### Automation & Scripting\n- **execute_script** — Run JS in page (not `run_script`). Args: `storeId`, `script`; optional `timeoutMs`, `targetId`.\n- **run_automation** — Multi-step flow. Args: `steps` (array of `{ type, ... }`).\n- **extract_data** — Extract metadata or page state. Use `mode=running` to list launched stores (returns only `storeId`, `storeName`, `debugPort`, `wsUrl`); `mode=store` returns that store’s launch status only (no store detail). Args: `mode?` (store|running|plugin|page), `storeId?`, `payload?`.\n\n### Utilities\n- **prepare_agent** — Prepare agent resources.\n- **download_file** — Write to Downloads. Args: `content`, `filename`.\n- **get_logs** — Bridge logs.\n\n### Debug\n- **debug_compare_lists** — Compare account/list vs store/list (debug). Args: `limit?`.\n\nInvalid tool names (will fail): `run_script`, `screenshot`, `get_screenshot`, `execute_automation` — use `execute_script` and `take_screenshot`, `run_automation` instead. Also invalid: any name in **Tool names: no hallucination** (e.g. `navigate`, `open_url`, `call_store_tool`).\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn71w0k7nr8gzjyvhtsqcy1dcd82t8pv\",\n  \"slug\": \"ziniao-assistant\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1774530040032\n}\n\nFile v1.0.1:skill-card.md\n\n## Description:\n\nControls Ziniao Browser through the local Ziniao bridge, discovers available ZClaw tools before invoking them, and requires an API key for browser actions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[ziniao-open](https://clawhub.ai/user/ziniao-open)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to control Ziniao Browser stores, navigate pages, read content, interact with page elements, take screenshots, export files, and run supported browser automation through the ZClaw bridge.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can operate authenticated browser sessions through the Ziniao/ZClaw bridge.\n\nMitigation: Install only when the bridge is trusted and limit use to intended browser stores and sessions.\n\nRisk: The skill relies on a ZClaw API key for invoke requests.\n\nMitigation: Store the key in a protected secret manager or tightly permissioned environment/config file, avoid exposing it in chat or shell history, and rotate it if exposure is possible.\n\nRisk: Changing the bridge base URL can route browser automation to an unintended or untrusted endpoint.\n\nMitigation: Keep the base URL on the intended local bridge unless a remote endpoint is explicitly trusted.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/ziniao-open/skills/ziniao-assistant)\n- [Ziniao Ecosystem Center](https://open.ziniao.com/contactUs)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, JSON request bodies, and browser automation instructions.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce page-content summaries, browser action guidance, screenshots, downloaded files, and configuration updates when supported by the bridge.]\n\n## Skill Version(s):\n\n1.0.1 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.0: 2 files, 6809 bytes\n\nFiles: SKILL.md (17183b), _meta.json (135b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: ziniao-assistant\ndescription: Control Ziniao Browser via the local ZClaw bridge—list/open stores, navigate, read content, click, input, screenshot, run automation. Use only tools in Core Tools; API key can be set by user in conversation (written to ~/.zclaw/config.json) or read from env ZCLAW_API_KEY / ~/.zclaw/config.json. On bridge/tool failure you MUST stop and end the turn—no retries, no templates, no follow-up plans.\n---\n# Ziniao Assistant\n\n## Available Capabilities\n\nAll operations go through `POST {baseUrl}/zclaw/tools/invoke` with `tool` + `args`. Only the following tools are valid.\n\n| Category | Tool | Description |\n|----------|------|-------------|\n| **Store** | `list_stores` | List stores (storeId, storeName, platformName, ip). Call once; no loop. |\n| | `resolve_store` | Resolve store by storeId or storeName. |\n| | `open_store` | Open store (by storeId/storeName from list or resolve). Call once. |\n| | `close_store` | Close store by storeId. |\n| **Page** | `visit_page` | Navigate to URL, optional waitUntil/timeout. |\n| | `get_page_content` | Read page content (text/html/structured). |\n| **Interaction** | `query_elements` | Query DOM by selector. |\n| | `click_element` | Click element by selector, optional waitForNavigation. |\n| | `input_text` | Type into element; optional clear, submit. |\n| | `scroll_page` | Scroll page or element. |\n| | `take_screenshot` | Screenshot (full page or viewport). |\n| **Waiting** | `wait_for_element` | Wait for selector. |\n| | `wait_for_navigation` | Wait for navigation. |\n| **Automation** | `execute_script` | Run JavaScript in page. |\n| | `run_automation` | Multi-step automation (steps array). |\n| | `extract_data` | Extract metadata / page state; mode=running lists launched stores. |\n| **Utilities** | `prepare_agent` | Prepare agent resources. |\n| | `download_file` | Write content to Downloads (content, filename). |\n| | `get_logs` | Get bridge logs. |\n\n**Do not use:** `run_script` → use `execute_script`; `screenshot` / `get_screenshot` → use `take_screenshot`; `execute_automation` → use `run_automation`.\n\n---\n\n## API: How to Invoke Tools (Required)\n\n**All tools are invoked through one endpoint only.** Do not call other paths.\n\n- **Method and path:** `POST {baseUrl}/zclaw/tools/invoke` (e.g. `POST http://127.0.0.1:9481/zclaw/tools/invoke`). Base URL from `ZCLAW_BASE_URL` or `ZINIAO_ZCLAW_BASE_URL` (default `http://127.0.0.1:9481`).\n- **Request body (JSON):** `{ \"tool\": \"<name>\", \"args\": { ... } }`. Optional: `\"action\": \"json\"`.\n- **`tool`** must be exactly one of the tool names in the **Core Tools** list below (e.g. `list_stores`, `visit_page`, `get_page_content`, `click_element`, `take_screenshot`, `execute_script`, `run_automation`). Wrong names (e.g. `run_script`, `screenshot`) or custom paths will fail.\n- **Do not** call paths like `/zclaw/page/execute`, `/zclaw/page/visit`, `/zclaw/page/click`, etc. Every tool call must be `POST /zclaw/tools/invoke` with the correct `tool` name in the body.\n\n## When To Use\n\nUse when the user wants to operate Ziniao Browser or configure the Ziniao–ZClaw bridge (list stores, open store, visit pages, read content, click, input, screenshot, export, automation). When a task has multiple similar sub-items (e.g. several order types or reports), visit or check each one separately before concluding; do not infer from a subset.\n\n## Stop on Blocker (Mandatory — Enforced First)\n\n**Trigger:** Any of: (a) `POST {baseUrl}/zclaw/tools/invoke` fails with connection refused, timeout, or no response; (b) a required tool call returns an error that makes the task impossible; (c) a required resource (e.g. store not found, API key missing) is missing.\n\n**You MUST:**\n\n1. **Stop immediately.** Do not retry the same request. Do not read more code, grep, or open other files to \"diagnose\" or \"work around\". Do not design or write \"run these steps when the bridge is up\" or any follow-up plan.\n2. **End the turn.** Do not speculate on other causes, suggest code changes, or continue the task. Connection or tool failure means the task is not executable—stop only. (User-facing messages for unreachable bridge are handled by the software.)\n\n## Hard Constraints\n\n- **Stop on blocker:** If the bridge is unreachable or a required tool call fails, stop and end the turn; do not retry, read code, or create templates or follow-up plans. See \"Stop on Blocker\" above.\n- **No script files:** Do not create or run any scripts (`.sh`/`.js`/`.py` or other code files) to execute tasks; use only the tools in **Core Tools** via `POST /zclaw/tools/invoke`. **Temporary files are allowed** (e.g. intermediate data, content for `download_file`); **script/executable files are not.**\n- All browser actions must stay inside **Ziniao Browser** or a Ziniao store exposed by the bridge. Do not open system browser, Chrome, Safari, Edge, Firefox, or use Playwright/Puppeteer/browser-use when the bridge fails.\n- Use only the tools in **Core Tools**. Do NOT use: `run_script` (use `execute_script`), `screenshot` or `get_screenshot` (use `take_screenshot`), `execute_automation` (use `run_automation`), or any tool not listed there.\n- Prefer tool-based flow: open store → visit_page → get_page_content / query_elements / click_element / input_text / take_screenshot / download_file / run_automation. Use `execute_script` only for in-page JavaScript (e.g. DOM extraction), not for orchestration.\n\n## API Key: Configure via Conversation (Preferred)\n\n**The user can configure the API key by sending it in the conversation.** When the user provides an API key (e.g. pastes it, or says “设置 API key 为 xxx”, “my API key is znoc_xxx”, “configure ZCLAW_API_KEY: xxx”), you MUST:\n\n1. **Write the key to the config file** the skill reads from:\n   - **macOS / Linux:** `~/.zclaw/config.json`\n   - **Windows:** `%USERPROFILE%\\.zclaw\\config.json` (e.g. `C:\\Users\\<YourName>\\.zclaw\\config.json`)\n   Create the `.zclaw` directory if it does not exist. File content: JSON with at least `\"ZCLAW_API_KEY\": \"<the key the user provided>\"`. If the file already exists, **merge**: update `ZCLAW_API_KEY` and keep other keys (e.g. `ZCLAW_BASE_URL`) unchanged.\n2. **Immediately use this new API key** for all subsequent `POST /zclaw/tools/invoke` requests in this conversation. Do not wait for a reload; treat the key you just wrote as the current key. If the user provides a new key again later, write again and switch to the new key for the rest of the conversation.\n\nWriting the config file is allowed for API key setup only (creating/updating `~/.zclaw/config.json`). Do not create or run scripts; use normal file write to that path.\n\n## API Key: Read into Context (Required)\n\nWhen this skill is used, **load the API key into the conversation context** so every request (including the first) can authenticate. Use this order (Ziniao and ZClaw both use **ZCLAW_API_KEY**):\n\n1. **User just provided in this conversation** — if you have just written the key to the config per “API Key: Configure via Conversation”, use that key for all requests.\n2. **Environment variable** `ZCLAW_API_KEY` — use if set.\n3. **Config file** `~/.zclaw/config.json` — if the key is not in env and not set in conversation, read `ZCLAW_API_KEY` from this JSON file (e.g. `{ \"ZCLAW_API_KEY\": \"your-key\" }`).\n\nUse the resolved key for all `POST /zclaw/tools/invoke` requests (e.g. header `X-ZClaw-Api-Key` or body `apiKey`). Optionally `ZCLAW_BASE_URL` or `ZINIAO_ZCLAW_BASE_URL` (default `http://127.0.0.1:9481`).\n\nDo this at skill load or at the start of the conversation so the key is available and the first tool call does not fail with \"Missing bearer token\". **After the user configures a new key via conversation, update to the new key immediately** for the rest of the turn.\n\n## Environment & Setup\n\n- **API key**: Env `ZCLAW_API_KEY`, or `ZCLAW_API_KEY` in `~/.zclaw/config.json` (see path note below). The bridge also accepts the key via header `X-ZClaw-Api-Key` or body `apiKey`.\n- **Base URL**: `ZCLAW_BASE_URL` or `ZINIAO_ZCLAW_BASE_URL` (default `http://127.0.0.1:9481`).\n- **First time / Rotate key**: Obtain a ZClaw API key from your **server or [Ziniao Ecosystem Center](https://open.ziniao.com/contactUs)** (there is no API key generation in the app settings). You can **(1) configure via conversation** — tell the assistant your API key and it will write it to `~/.zclaw/config.json` and use it immediately; or **(2)** set `ZCLAW_API_KEY` in your environment or in `~/.zclaw/config.json`; or **(3)** run `bash ziniao-skills/install-ziniao-openclaw-skill.sh \"YOUR_API_KEY\"` (Windows: use `install-ziniao-openclaw-skill.ps1` with `-ApiKey`). After configuring via conversation, the assistant uses the new key for all subsequent requests in that conversation.\n\n**Reading the key:** The bridge uses `process.env.ZCLAW_API_KEY`, which works on **Windows, macOS, and Linux**. The variable must be present in the environment of the process that runs the app (Ziniao/Electron). If the app is started from the GUI (e.g. Dock, Start menu), only **system/user environment variables** are visible; shell-only exports (e.g. in a terminal) are not. To ensure the key is always available on all platforms, you can use the config file instead of env.\n\n**Setting `ZCLAW_API_KEY` by OS:**\n\n- **macOS / Linux**: (1) **Config file (recommended):** `~/.zclaw/config.json` with `{ \"ZCLAW_API_KEY\": \"your-key\" }` (same path on both). (2) **Env:** In the same shell that starts the app: `export ZCLAW_API_KEY=your-key`. For GUI launches, add `export ZCLAW_API_KEY=...` to `~/.bashrc`, `~/.zshrc`, or `~/.profile`, or set it system-wide (e.g. `/etc/environment` on Linux).\n- **Windows**: (1) **Config file (recommended):** `%USERPROFILE%\\.zclaw\\config.json` (e.g. `C:\\Users\\YourName\\.zclaw\\config.json`) with `{ \"ZCLAW_API_KEY\": \"your-key\" }`. (2) **Env:** System Properties → Environment Variables → add User or System variable `ZCLAW_API_KEY`; or in PowerShell (current user): `[Environment]::SetUserVariable(\"ZCLAW_API_KEY\",\"your-key\")`. Restart the app after changing system env.\n\n**Invocation:** This skill is designed for use with the ZClaw framework (recommended). The Ziniao bridge is an HTTP API; any client that can send requests with a valid API key can call the same tools.\n\n## Store Resolution and Opening: Validation and Response Contract\n\n**Getting and opening stores** follows Ziniao’s existing validation and launch flow: store detail (e.g. `default_browser`, `platform`) is fetched via **store/detail** when launching; the browser is then started using the same logic as the client.\n\n**ZClaw responses** are filtered by convention and do not expose full Ziniao store details: **open_store** returns only **storeId**, **name**, **debugPort**, **reused**, etc.; **list_stores** returns only **storeId**, **storeName**, **platformName**, **ip**. **ZClaw does not expose full store detail**; it only exposes status for stores launched via ZClaw. The running-stores list (e.g. **extract_data** with `mode=running` or the running-stores API) contains only **storeId**, **storeName**, **debugPort**, **wsUrl**.\n\nIf **open_store** or **visit_page** returns 400 \"Store detail not found\", the backend **store/detail** API or its response shape may be failing; the bridge tries several response paths and, when present, includes the server’s `msg` in the error.\n\n\n## No Extra Scripts (Mandatory)\n\n**You must not create or use any scripts to execute tasks.** All actions must be performed only through the tools listed in **Core Tools**. Do not:\n\n- Create or run Node.js, shell, Python, or other script files (e.g. `.sh`, `.js`, `.py`) to accomplish the task.\n- Invoke external commands or scripts for steps that the tools can do (list stores, open store, visit page, click, input, screenshot, download_file, run_automation, etc.).\n\n**Temporary files are allowed** during the run (e.g. temporary data files, intermediate content to pass to `download_file`, or scratch files). **Script files are not allowed** — do not create or execute any file intended to be run as code. Use only `POST /zclaw/tools/invoke` with the tool names and args from Core Tools. If something cannot be done with the existing tools, report the limitation instead of scripting around it.\n\n## Store List and Opening (Mandatory)\n\n- **No looping:** Call `list_stores` at most once to get data; then call `open_store` once. Do not repeatedly call list in a cycle.\n- **To open a store:** (1) Get **storeId** — either from one `list_stores` (use the item whose `storeName` matches the user’s store) or from one `resolve_store(storeName)`; (2) Call `open_store` once with that `storeId` or with `storeName` (exact string from the list).\n- **list_stores response:** Each item has exactly: `storeId`, `storeName`, `platformName`, `ip`. Use **`storeName`** when calling `resolve_store` or `open_store` (exact match). Do not use other fields as the store name.\n\n## Recommended Workflow\n\n1. **Store:** One `list_stores` or one `resolve_store` → get `storeId` / `storeName` → one `open_store`. Match by `storeName` from list; if ambiguous, ask user or use exact `storeId`. No fuzzy/substring matching.\n2. **Page:** Before page operations, ensure store is open and call `visit_page` if needed. Use `get_page_content`, `query_elements`, `click_element`, `input_text`, `take_screenshot`, `download_file` as needed; prefer `run_automation` for multi-step flows.\n3. **Errors:** Use `get_logs` on failure; after API key rotation, update config and refresh skills.\n4. **Multiple similar items:** When a task involves multiple similar sub-items (e.g. several order types, several reports), visit or check **each item separately** before drawing a conclusion; do not infer \"all have no data\" or \"all behave the same\" from only a subset.\n\n## Core Tools\n\n**Only these tools exist.** Use exactly these names as the `tool` field in `POST /zclaw/tools/invoke`; put parameters in `args`. Do not use or invent other tool names or other URLs.\n\nPass one arguments object per call (as `args`); required keys must be present. When running ZClaw tasks, the bridge operates on the correct tab but **does not bring the browser window to the front**, so your other windows and work are not interrupted.\n\n### Store Management\n- **list_stores** — List stores (call once; no loop). **Response:** `{ page, limit, total, items }` where each item has `storeId`, `storeName`, `platformName`, `ip`. Use `storeName` for resolve/open. Args: `page?`, `limit?`, `all?`, `filterKeyword?`, `storeListType?`.\n- **resolve_store** — Resolve by exact storeId or storeName. Args: `storeId?`, `storeName?`, `expectedName?`. Returns `storeId` and `name` for `open_store`.\n- **open_store** — Open store (need storeId from list_stores or resolve_store). Uses store/detail + launch. Returns (filtered): storeId, name, debugPort, reused, and optionally status, windowHandler, launchUrl. Call once. Args: `storeId?`, `storeName?` (use list item `storeName`), `expectedName?`, `launchUrl?`, `isHeadless?`, `privacyMode?`, `windowRatio?`.\n- **close_store** — Close store. Args: `storeId` (required).\n\n### Page Navigation & Content\n- **visit_page** — Navigate and wait. Args: `storeId`, `url`; optional `waitUntil` (domcontentloaded|load|networkidle), `timeoutMs`, `targetId`.\n- **get_page_content** — Read page content. Args: `storeId`; optional `format` (text|html|structured), `timeoutMs`, `targetId`.\n\n### Page Interaction\n- **query_elements** — DOM by selector. Args: `storeId`, `selector`; optional `timeoutMs`, `targetId`.\n- **click_element** — Click. Args: `storeId`, `selector`; optional `waitForNavigation`, `timeoutMs`, `targetId`.\n- **input_text** — Type into element. Args: `storeId`, `selector`, `text`; optional `clear`, `submit`, `timeoutMs`, `targetId`.\n- **scroll_page** — Scroll. Args: `storeId`; optional `x`, `y`, `selector`, `behavior` (auto|smooth), `timeoutMs`, `targetId`.\n- **take_screenshot** — Screenshot (not `screenshot`). Args: `storeId`; optional `fullPage`, `path`, `timeoutMs`, `targetId`.\n\n### Page Waiting\n- **wait_for_element** — Wait for selector. Args: `storeId`, `selector`; optional `timeoutMs`, `targetId`.\n- **wait_for_navigation** — Wait for navigation. Args: `storeId`; optional `timeoutMs`, `targetId`.\n\n### Automation & Scripting\n- **execute_script** — Run JS in page (not `run_script`). Args: `storeId`, `script`; optional `timeoutMs`, `targetId`.\n- **run_automation** — Multi-step flow. Args: `steps` (array of `{ type, ... }`).\n- **extract_data** — Extract metadata or page state. Use `mode=running` to list launched stores (returns only `storeId`, `storeName`, `debugPort`, `wsUrl`); `mode=store` returns that store’s launch status only (no store detail). Args: `mode?` (store|running|plugin|page), `storeId?`, `payload?`.\n\n### Utilities\n- **prepare_agent** — Prepare agent resources.\n- **download_file** — Write to Downloads. Args: `content`, `filename`.\n- **get_logs** — Bridge logs.\n\nInvalid tool names (will fail): `run_script`, `screenshot`, `get_screenshot`, `execute_automation` — use `execute_script` and `take_screenshot`, `run_automation` instead.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn71w0k7nr8gzjyvhtsqcy1dcd82t8pv\",\n  \"slug\": \"ziniao-assistant\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1773653331763\n}","readmeExcerpt":"Skill: ziniao-assistant Owner: ziniao-open Summary: Control Ziniao Browser via the local Ziniao bridge. On skill load or before first invoke, GET /zclaw/tools and treat returned name list as the only allowed t... Tags: latest:1.0.1 Version history: v1.0.1 | 2026-03-26T13:00:40.032Z | user **Ziniao Assistant 1.0.1 introduces dynamic tool discovery for safer, more reliable browser control.** - On skill load or before f","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"curl -X POST http://127.0.0.1:9481/zclaw/tools/invoke \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-ZClaw-Api-Key: <ZCLAW_API_KEY>\" \\\n  -d '{\"tool\":\"open_store\",\"args\":{\"storeName\":\"Rosehut\"}}'"},{"language":"bash","snippet":"curl -X POST http://127.0.0.1:9481/zclaw/tools/invoke \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-ZClaw-Api-Key: <ZCLAW_API_KEY>\" \\\n  -d '{\"tool\":\"open_store\",\"args\":{\"storeName\":\"Rosehut\"}}'"},{"language":"bash","snippet":"curl -X POST http://127.0.0.1:9481/zclaw/tools/invoke \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Authorization: Bearer <ZCLAW_API_KEY>\" \\\n  -d '{\"tool\":\"open_store\",\"args\":{\"storeName\":\"Rosehut\"}}'"},{"language":"bash","snippet":"curl -X POST http://127.0.0.1:9481/zclaw/tools/invoke \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Authorization: Bearer <ZCLAW_API_KEY>\" \\\n  -d '{\"tool\":\"open_store\",\"args\":{\"storeName\":\"Rosehut\"}}'"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: ziniao-assistant\ndescription: Control Ziniao Browser via the local Ziniao bridge. On skill load or before first invoke, GET /zclaw/tools and treat returned name list as the only allowed tool strings; then POST /zclaw/tools/invoke. API key for invoke via ~/.zclaw/config.json or ZCLAW_API_KEY. On bridge failure stop the turn per skill.\n---\n# Ziniao Assistant\n\n## Session tool allowlist (Mandatory — fetch first)\n\n**Goal:** Put the **authoritative** tool names into context before any `invoke`, so every `tool` field is chosen from that set only (reduces hallucinated names).\n\n1. **First HTTP call** when handling a ZClaw task (or immediately after this skill is loaded):  \n   **`GET {baseUrl}/zclaw/tools`**  \n   Same `baseUrl` as invoke (`ZCLAW_BASE_URL` / `ZINIAO_ZCLAW_BASE_URL`, default `http://127.0.0.1:9481`).  \n   **No `X-ZClaw-Api-Key` and no Ziniao login are required** for this GET (public registry on the bridge).\n\n2. **Parse the response:** JSON shape `{ ret, data }` where `data` is an array of `{ name, description, inputSchema }`. Build  \n   **`allowedTools = data.map((t) => t.name)`**  \n   and **retain it in working memory** for the session. Optionally keep `description` / `inputSchema` next to each name when choosing args.\n\n3. **Before every `POST {baseUrl}/zclaw/tools/invoke`:** ensure **`allowedTools.includes(tool)`**. If the name you intend is not in `allowedTools`, **do not send the request**—map the user’s intent to a real name from `allowedTools` (e.g. open URL → `visit_page` or `open_store` + `launchUrl`).\n\n4. **If `invoke` returns an error** like unsupported / unknown tool: re-run **`GET /zclaw/tools`**, refresh `allowedTools`, and retry with a valid `name`.\n\n5. **If `GET /zclaw/tools` fails** (connection refused, timeout): follow **Stop on Blocker** for unreachable bridge; if you must proceed with static knowledge only, use the **Static fallback allowlist** below—still **no** invented names.\n\n### Static fallback allowlist (when GET is impossible)\n\nComma-separated `tool` names that match a healthy bridge (re-sync when GET works):\n\n`list_stores`, `resolve_store`, `open_store`, `close_store`, `visit_page`, `get_page_content`, `query_elements`, `click_element`, `input_text`, `scroll_page`, `take_screenshot`, `wait_for_element`, `wait_for_navigation`, `execute_script`, `run_automation`, `extract_data`, `prepare_agent`, `get_logs`, `download_file`, `debug_compare_lists`\n\n---\n\n## Available Capabilities\n\nAll **`invoke`** operations use `POST {baseUrl}/zclaw/tools/invoke` with `tool` + `args`. **Authoritative names** come from **`GET /zclaw/tools`** (see above); the table below is documentation aligned with that registry.\n\n| Category | Tool | Description |\n|----------|------|-------------|\n| **Store** | `list_stores` | List stores (storeId, storeName, platformName, ip). Call once; no loop. |\n| | `resolve_store` | Resolve store by storeId or storeName. |\n| | `open_store` | Open store (by storeId/storeName from list or resolve). Call on"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71w0k7nr8gzjyvhtsqcy1dcd82t8pv\",\n  \"slug\": \"ziniao-assistant\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1774530040032\n}"},{"path":"skill-card.md","content":"## Description:\n\nControls Ziniao Browser through the local Ziniao bridge, discovers available ZClaw tools before invoking them, and requires an API key for browser actions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[ziniao-open](https://clawhub.ai/user/ziniao-open)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to control Ziniao Browser stores, navigate pages, read content, interact with page elements, take screenshots, export files, and run supported browser automation through the ZClaw bridge.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can operate authenticated browser sessions through the Ziniao/ZClaw bridge.\n\nMitigation: Install only when the bridge is trusted and limit use to intended browser stores and sessions.\n\nRisk: The skill relies on a ZClaw API key for invoke requests.\n\nMitigation: Store the key in a protected secret manager or tightly permissioned environment/config file, avoid exposing it in chat or shell history, and rotate it if exposure is possible.\n\nRisk: Changing the bridge base URL can route browser automation to an unintended or untrusted endpoint.\n\nMitigation: Keep the base URL on the intended local bridge unless a remote endpoint is explicitly trusted.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/ziniao-open/skills/ziniao-assistant)\n- [Ziniao Ecosystem Center](https://open.ziniao.com/contactUs)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, JSON request bodies, and browser automation instructions.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce page-content summaries, browser action guidance, screenshots, downloaded files, and configuration updates when supported by the bridge.]\n\n## Skill Version(s):\n\n1.0.1 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Control Ziniao Browser via the local Ziniao bridge. On skill load or before first invoke, GET /zclaw/tools and treat returned name list as the only allowed t... Skill: ziniao-assistant Owner: ziniao-open Summary: Control Ziniao Browser via the local Ziniao bridge. On skill load or before first invoke, GET /zclaw/tools and treat returned name list as the only allowed t... Tags: latest:1.0.1 Version history: v1.0.1 | 2026-03-26T13:00:40.032Z | user **Ziniao Assistant 1.0.1 introduces dynamic tool discovery for safer, more reliable browser control.** - On skill load or before f","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1288,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:58:06.415Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:58:06.415Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T17:45:38.228Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}