headful-browser-vncHeadful Chromium with VNC/noVNC operator UI and Chrome CDP exports (cookies, screenshots, outerHTML).
Install via ClawdBot CLI:
clawdbot install waylonsong/headful-browser-vncGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/proc/Calls external URL not in known-safe list
https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.debAI Analysis
The skill's core functionality is legitimate and aligns with its stated purpose of providing a controlled, auditable browser environment for human-in-the-loop automation. The identified signals (UNSAFE_SHELL, SUSPICIOUS_PERMISSIONS, UNDOCUMENTED_EXTERNAL) are typical for system-level automation tools and do not indicate malicious intent, but they do introduce potential risks if the skill is misconfigured or compromised. No evidence of credential harvesting, data exfiltration, or hidden malicious instructions was found in the provided definition.
Usage Guide
Loading usage data… refresh in a few seconds.
Scored May 17, 2026
Audited Apr 17, 2026 · audit v1.0
A fast Rust-based headless browser automation CLI with Node.js fallback that enables AI agents to navigate, click, type, and snapshot pages via structured commands.
Uses a headless browser to navigate web pages, interact with elements, and extract clean, readable text content from URLs.
Headless browser automation CLI optimized for AI agents with accessibility tree snapshots and ref-based element selection
通过已登录的Edge或Chrome浏览器,利用Chrome DevTools Protocol执行JS渲染页面的导航、点击、截图及数据提取等自动化操作。
High-performance browser automation for heavy scraping, multi-tab management, and precise DOM extraction. Use this when you need speed, reliability, or advanced state management (cookies/local storage) beyond standard web fetching.
Ultimate stealth browser automation with anti-detection, Cloudflare bypass, CAPTCHA solving, persistent sessions, and silent operation. Use for any web automation requiring bot detection evasion, login persistence, headless browsing, or bypassing security measures. Triggers on "bypass cloudflare", "solve captcha", "stealth browse", "silent automation", "persistent login", "anti-detection", or any task needing undetectable browser automation. When user asks to "login to X website", automatically use headed mode for login, then save session for future headless reuse.