本文へ移動
cccskills
無料GitHub で公開

ultimate-browsing

Renders, drives, and screenshots web pages: JS-rendered sources, clicks and forms, persistent logins, WAF-blocked hosts (platform-native readers, stealth Chrome), and the browsing lane of a research run, with screenshots as provenance. Not for plain search or unblocked static fetch.

インストール方法を見る

含まれるファイル(56)

  • SKILL.md10.7 KB
  • agents/openai.yaml52 B
  • ATTRIBUTION.md2.5 KB
  • engine/__init__.py668 B
  • engine/__main__.py4.8 KB
  • engine/AGENTS.md10.4 KB
  • engine/bias_check.py7.1 KB
  • engine/curl_probe.py2.4 KB
  • engine/executor.py6.3 KB
  • engine/fetch_chain.py13.0 KB
  • engine/referers.py327 B
  • engine/result_schema.py1.5 KB
  • engine/summary.py1.2 KB
  • engine/surrogate.py7.9 KB
  • engine/surrogates.yaml2.3 KB
  • engine/templates/package.json349 B
  • engine/templates/playwright_mobile_chrome.js3.6 KB
  • engine/templates/playwright_real_chrome.js5.6 KB
  • engine/tests/fixtures/amp_redirect_stub.html323 B
  • engine/tests/fixtures/search_interstitial.html90.4 KB
  • engine/tests/fixtures/wayback_available.json246 B
  • engine/tests/fixtures/wayback_snapshot.html181.4 KB
  • engine/tests/test_fetch_chain.py2.7 KB
  • engine/tests/test_playwright_stealth.py3.9 KB
  • engine/tests/test_playwright_templates.py10.7 KB
  • engine/tests/test_surrogate_validators.py3.5 KB
  • engine/tests/test_surrogate.py11.3 KB
  • engine/url_transforms.py3.2 KB
  • engine/validators.py9.1 KB
  • engine/waf_detector.py6.9 KB
  • engine/waf_profiles.yaml6.2 KB
  • references/agent-reach/career.md712 B
  • references/agent-reach/dev.md1.3 KB
  • references/agent-reach/README.md2.2 KB
  • references/agent-reach/search.md821 B
  • references/agent-reach/social.md5.6 KB
  • references/agent-reach/video.md2.7 KB
  • references/agent-reach/web.md1.9 KB
  • references/chrome-stealth.md2.2 KB
  • references/insane-search/cache-archive.md4.1 KB
  • references/insane-search/fallback.md6.0 KB
  • references/insane-search/jina.md3.8 KB
  • references/insane-search/json-api.md3.5 KB
  • references/insane-search/media.md3.5 KB
  • references/insane-search/metadata.md2.9 KB
  • references/insane-search/naver.md3.3 KB
  • references/insane-search/playwright.md6.7 KB
  • references/insane-search/public-api.md3.4 KB
  • references/insane-search/README.md19.5 KB
  • references/insane-search/rss.md2.9 KB
  • references/insane-search/tls-impersonate.md6.3 KB
  • references/insane-search/twitter.md3.5 KB
  • scripts/cookie_crypto.py2.9 KB
  • scripts/cookie_domains.py1.1 KB
  • scripts/cookie_paths.py3.8 KB
  • scripts/extract_cookies.py9.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Ultimate Browsing

Web access for everything a plain fetch cannot finish: a page that renders in JS, a click or a form, a screenshot, a login that must persist across pages, or a host that blocks generic fetchers (WAF / 403 / Cloudflare). Start at the cheapest tier that can do the job and climb only when it cannot:

Tier 1 — insane-search (headless extraction + WAF bypass) -> Tier 1.5 — agent-reach (platform-native APIs, esp. Chinese platforms) -> Tier 2 — a real browser through omowright from js eval: 2a the owned engine (a browser your code launches, CloakBrowser for stealth), 2b the attached engine (the user's own signed-in browser).

PHASE 0 — ROUTE FIRST (MANDATORY)

User request
  |
  +- extract text/data from a URL --------------------- TIER 1  insane-search
  +- URL blocked / 403 / Cloudflare / WAF ------------- TIER 1  insane-search
  +- YouTube/Vimeo/TikTok subtitles or metadata ------- TIER 1  insane-search (yt-dlp)
  +- read an article / blog / Reddit / HN / arXiv ----- TIER 1  insane-search
  |
  +- Chinese platform (xhs/douyin/weibo/bilibili/v2ex/wechat)  TIER 1.5 agent-reach
  +- podcast transcript / stock forum ----------------- TIER 1.5 agent-reach
  +- Twitter feed / LinkedIn profile / GitHub via CLI - TIER 1.5 agent-reach
  |
  +- Tier 1/1.5 returned empty or partial ------------- TIER 2  2a owned engine -> 2b attached engine
  +- click / fill form / scroll / interact ------------ TIER 2  2a owned engine -> 2b attached engine
  +- screenshot / render / play video ----------------- TIER 2  2a owned engine -> 2b attached engine
  +- login session across pages / the user's account --- TIER 2  2b attached engine (their browser)
  +- test web app / QA / dogfood ---------------------- TIER 2  2a owned engine -> 2b attached engine
  |
  +- simple search query ------------------------------ NOT this skill (use web-search)

Read the matching reference before acting: references/insane-search/README.md, references/agent-reach/README.md, or references/chrome-stealth.md.

Tier 1 — insane-search (headless extraction)

When: content extraction, blocked-URL bypass, media metadata — no browser UI needed. Why first: ~10x faster than a browser, no process spin-up; handles most "fetch this blocked page" requests via curl_cffi TLS impersonation, yt-dlp (1858 sites), official public APIs, mobile URL transforms, Phase-2.5 surrogate archives (Wayback / archive.today snapshots, provenance-tagged — see references/insane-search/cache-archive.md), a key-gated Jina Reader (JINA_API_KEY), and a Playwright real-Chrome fallback. The engine lives inside this skill at engine/ and is invoked as a module. Surrogate results are dated COPIES: a result whose provenance is snapshot must be reported with its snapshot_timestamp, never presented as the live page.

# Core command — auto-detects WAF, runs the full fetch grid (run from the skill dir):
python3 -m engine "https://example.com/blocked-page"
#   add --selector "<CSS>" for positive-proof validation, --device auto|desktop|mobile,
#   --trace to inspect every attempt, --json for machine-readable output.

# YouTube subtitles / metadata (no browser):
yt-dlp --write-sub --write-auto-sub --sub-lang "en,ko" --skip-download -o "/tmp/%(id)s" "<URL>"

# Reddit / HN / Bluesky / arXiv etc. use official public endpoints — see the Phase 0 index in
# references/insane-search/README.md (Twitter syndication, Reddit .json, HN Firebase, ...).

The full engine harness (rules R1-R7, the Phase 0 official-API index, the no-site-name rule, and the references/insane-search/*.md deep-dives for TLS, Playwright routing, Naver, media, etc.) is in references/insane-search/README.md. Read it before tuning the engine or adding a WAF profile.

Escalate to Tier 1.5 or Tier 2 when

  • The target is a Chinese / social platform with a native reader -> Tier 1.5.
  • insane-search returns empty/partial, or the page needs JS interaction, a screenshot, a persistent login, or media playback -> Tier 2.

Tier 1.5 — agent-reach (platform-native readers)

When: the target is a platform with a first-class API/CLI that beats generic fetching — especially Chinese platforms that stealth browsers still cannot reach cleanly. Several channels are zero-config (Douyin, V2EX, Reddit, RSS, YouTube); others need a one-time auth you supply via environment variables if you have access (JINA_API_KEY for Jina Reader — anonymous access is dead, see references/insane-search/jina.md; TWITTER_* for X; a transcription key for podcasts).

CategoryPlatformsEntry
socialxhs (Xiaohongshu), douyin, weibo, bilibili, V2EX, Reddit, Twitter/Xreferences/agent-reach/social.md
webJina Reader, WeChat articles, RSSreferences/agent-reach/web.md
videoYouTube, Bilibili, podcast transcripts, Douyin videoreferences/agent-reach/video.md
careerLinkedInreferences/agent-reach/career.md
devGitHub (gh CLI)references/agent-reach/dev.md
searchExa AIreferences/agent-reach/search.md
mcporter call 'douyin.parse_douyin_video_info(url: "<URL>")'   # douyin, zero-config
curl -s "https://r.jina.ai/https://weibo.com/<uid>/<pid>"      # weibo via Jina
yt-dlp --dump-json "<bilibili-url>"                            # Bilibili (overseas: add --cookies-from-browser)
curl -s "https://www.v2ex.com/api/topics/hot.json"            # V2EX public API

Routing table, per-platform auth (set TWITTER_* env vars, gh auth login, a transcription key — only if you have access), rate-limit notes, and known version quirks are in references/agent-reach/README.md.

Tier 2 — a real browser (real interaction)

When: real interaction is needed (clicks, forms, screenshots, video, persistent login), or Tier 1/1.5 failed.

Both tiers are omowright, staged inside the browser skill and loaded from js eval:

const { loadOmowright } = await import("<browser-skill-root>/scripts/omowright.mjs")
const { omowright } = await loadOmowright()

Tier 2a — owned engine (default)

A browser your code launches with a task-owned profile. connectPipe opens no listening port; connectCloakProfile launches CloakBrowser with a pinned fingerprint seed and is the path for WAF, Cloudflare and bot-scored pages.

const browser = await omowright.connectPipe({ browserPath, browserArgs: ["--headless", `--user-data-dir=${profile}`], storageRoot: profile })
try {
  const page = await browser.newTab(url)
  const tree = omowright.compactSnapshot(await page.snapshot())   // the read; refs come from it
  const snoop = omowright.createNetworkSnoop(page)                  // read the API JSON instead of the DOM when there is one
  await page.locator("e3").click()
  await Bun.write(pngPath, await page.screenshot())
} finally {
  await browser.close()                                            // then rm -rf the profile
}

The rest of the surface (CUA coordinates, captcha solving, routes, traces, frames, human handoff) is in the browser skill's references/owned-engine/. A stealth binary is not proof of access: inspect the rendered result and report challenges that remain.

Tier 2b — attached engine (logged-in pages)

When the page needs the user's account, drive the browser they are already signed into instead of cloning their profile: connectBrowserSkill() → session.navigate → bskSnapshot(session) / session.observe() → session.click → session.stop(). NEVER launch against or clear cookies/cache/site data from the user's live profile, and never fall back to the owned engine for an authenticated criterion: if no extension is connected, run the browser skill's onboarding script and relay its one human step. The full loop is the browser skill.

Cookie login (cross-platform)

scripts/extract_cookies.py reads cookies from a local Chromium-family or Firefox-family browser and optionally injects them into the running CDP session. It resolves browser profile paths and decrypts cookie values per-OS (macOS Keychain, Linux libsecret, Windows DPAPI):

# Extract cookies to a file:
mkdir -p ~/.local/state/omo-cookies
python3 scripts/extract_cookies.py --browser chrome --domain youtube.com --output ~/.local/state/omo-cookies/youtube.cookies.json
# Extract and inject into the running CDP session:
python3 scripts/extract_cookies.py --browser chrome --domain youtube.com --inject --cdp 9242

Cookie export files are written with owner-only 0600 permissions. Do not place live auth cookies in shared temp directories or commit them to a repo. Cookie injection sends values to CDP over stdin rather than argv. Cookies apply on next navigation — reload after injecting. Google services use fingerprint-bound tokens that may not transfer across browser profiles. Limits in references/chrome-stealth.md.

Reference docs

FileWhen to read
references/insane-search/README.mdTier-1 engine harness (R1-R7, Phase 0 API index, no-site-name rule) + its *.md deep-dives
references/agent-reach/README.mdTier-1.5 routing table, platform auth, per-category *.md
references/chrome-stealth.mdTier-2 stealth through omowright + CloakBrowser, cookie login limits

Environment variables

# agent-reach auth: set the channel-specific env vars from each tool's docs only if you have access
# insane-search needs no env vars — it auto-installs deps on first run

Anti-patterns

  • Do NOT launch Chrome stealth for plain text extraction — use Tier 1.
  • Use stealth plugins only in an explicitly installed script environment, not injected into WebView.
  • Close every WebView/browser context when done and remove only task-owned profile clones.
  • Do NOT inject cookies without reloading the page.
  • Do NOT hardcode site domains/selectors into engine/** or waf_profiles.yaml — runtime hints only (see the no-site-name rule in the insane-search reference).

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

ast-grep

無料

Searches and rewrites code by AST shape across 25 languages. Use when the target is a syntax pattern (every call/class/import shaped like X, a codemod, a YAML rule) rather than literal text; for plain strings, comments, or filenames, use rg.

日本語の概要は準備中です。原文の説明を表示しています。

code-yeongyu/lazycodex3,7582026年10月10日 更新

browser

無料

Drives a real browser through the omowright library from the js eval kernel: sites the user is already signed into, forms and clicks, JS-rendered pages, screenshots, web QA, extension popups, a human handoff for login, CAPTCHA or OTP, and a browser you own for scraping, bot-scored targets, network capture and QA traces. Use for any interactive browser task; not for a plain search or an unblocked static fetch.

日本語の概要は準備中です。原文の説明を表示しています。

code-yeongyu/lazycodex3,7582026年10月10日 更新

Finds, reads, and reconstructs coding-agent sessions across Codex, Claude, OpenCode, OMO/Senpi, and other local agent logs. Use when asked to find or search past sessions, transcripts, or subagent runs, or to recover what an earlier session did.

日本語の概要は準備中です。原文の説明を表示しています。

code-yeongyu/lazycodex3,7582026年10月10日 更新

Use when Codex needs to understand or respond to automatic comment-checker feedback emitted after an edit-like PostToolUse hook.

日本語の概要は準備中です。原文の説明を表示しています。

code-yeongyu/lazycodex3,7582026年10月10日 更新

Processes and analyzes data with resident-kernel engines (DuckDB, Polars) and one-shot tools. Use for CSV/parquet/JSON analysis, group-by/join/aggregation, time series, distributions, cleaning, or plotting a dataset.

日本語の概要は準備中です。原文の説明を表示しています。

code-yeongyu/lazycodex3,7582026年10月10日 更新

debugging

無料

Runs a hypothesis-driven debugging loop across any language or binary, escalating to orthogonal oracle angles and locking the fix with a failing test. Use for crashes, silent failures, hangs, wrong responses, memory leaks, async misbehavior, or reverse engineering.

日本語の概要は準備中です。原文の説明を表示しています。

code-yeongyu/lazycodex3,7582026年10月10日 更新

code-yeongyu のスキルをすべて見る

このスキルの問題を報告する