← 返回 Skills 市场
mathiasthu

Use Browser (Scrape leads, like, post on socials or perform actions on the web)

作者 mathiasthu · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
583
总下载
1
收藏
3
当前安装
1
版本数
在 OpenClaw 中安装
/install use-browser
功能描述
Automates browser interactions for social media management across Instagram, LinkedIn, and X. Handles posting, DMs, connection requests, lead scraping, and m...
安全使用建议
Before installing, verify the source and installation method for the required 'browser-use' binary (the SKILL.md expects it but the registry metadata doesn't declare it). Inspect the GitHub repo and ensure you trust the binary provider and release artifacts. Confirm how and where session cookies/login state are stored on the VM, who can access them, and how long they persist — if possible, require ephemeral sessions or explicit user confirmation for sensitive actions. Consider restricting autonomous actions (require confirmation for sending messages/connection requests by default) and double-check the domain allowlist. If you plan to use production accounts, run this on a tightly isolated VM and avoid using high-value credentials until you understand the binary and storage behavior.
功能分析
Type: OpenClaw Skill Name: use-browser Version: 1.0.0 The skill bundle is classified as suspicious due to the inclusion of powerful and high-risk commands like `browser-use:eval` and `browser-use:cookies` in SKILL.md. While the documentation provides extensive and explicit instructions for the AI agent to prevent misuse (e.g., strict domain allowlist, 'NEVER' rules for `eval` regarding network calls or cookie access, and robust prompt injection defenses), these are textual instructions. The inherent power of these commands, particularly `eval` which can execute arbitrary JavaScript within the browser context, presents a significant vulnerability if the agent's adherence to these instructions is compromised by a sophisticated prompt injection attack, potentially leading to data exfiltration or unauthorized actions despite the stated intent to prevent them.
能力评估
Purpose & Capability
SKILL.md describes a browser-automation CLI ('browser-use') for Instagram/LinkedIn/X which is coherent with the declared purpose. However, the skill frontmatter (metadata.openclaw) requires the 'browser-use' binary while the registry metadata shows 'Required binaries: none' — a clear inconsistency. If the binary is genuinely required, it should be declared and an install mechanism provided or documented.
Instruction Scope
Instructions allow scraping profiles/leads and sending DMs/connection requests without confirmation and assume pre-authenticated, persistent sessions on an 'isolated VM'. The doc enforces a domain allowlist and blocks local/cloud-metadata ranges (good), but it does not state where scraped data, cookies, or session state are stored/transmitted, nor how long persistence lasts. Lack of guidance on data retention/exfiltration and the permission to act autonomously on messaging/connection requests are scope concerns.
Install Mechanism
There is no install spec (instruction-only), but the CLI 'browser-use' is required by the SKILL.md. The README links to a GitHub repo, but the skill provides no explicit install steps or vetted source for the binary. This gap makes it unclear who provides/maintains the executable and increases risk if the binary must be fetched manually.
Credentials
The skill declares no required environment variables or credentials, which aligns with the claim that sessions are pre-authenticated manually. However, persistent cookies/session storage are implied but not described (location, encryption, access controls), so sensitive authentication material may persist outside the user's control. No unrelated credentials are requested.
Persistence & Privilege
always is false and the skill is user-invocable, which is appropriate. However, because the agent is allowed to reuse persistent authenticated sessions and perform high-impact actions (send DMs, connection requests, posting, scraping) without confirmation, autonomous invocation could have a large blast radius. The skill lacks safer defaults (e.g., require confirmation for messaging by default), increasing risk.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install use-browser
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /use-browser 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
browser-use 1.0.0 – Initial Release - Automates browser-based social media management for Instagram, LinkedIn, and X, including posting, DMs, connection requests, lead scraping, and monitoring. - Operates on an isolated VM with user-pre-authenticated sessions for persistent login and session continuity. - Enforces domain allowlist; agent will only navigate to officially approved social platform domains. - Provides high autonomy for typical tasks (posting, messaging, engagement), but pauses for user confirmation before any destructive or irreversible actions. - Supports parallel sessions, browser switching (Safari default, Chrome fallback), and a versatile command set for navigation, interaction, and data extraction. - Designed to be safe, configurable, and streamlined for social media workflows. (effecitly scrape leads, like, post, etc on socials or perform actions on the web)
元数据
Slug use-browser
版本 1.0.0
许可证
累计安装 3
当前安装数 3
历史版本数 1
常见问题

Use Browser (Scrape leads, like, post on socials or perform actions on the web) 是什么?

Automates browser interactions for social media management across Instagram, LinkedIn, and X. Handles posting, DMs, connection requests, lead scraping, and m... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 583 次。

如何安装 Use Browser (Scrape leads, like, post on socials or perform actions on the web)?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install use-browser」即可一键安装,无需额外配置。

Use Browser (Scrape leads, like, post on socials or perform actions on the web) 是免费的吗?

是的,Use Browser (Scrape leads, like, post on socials or perform actions on the web) 完全免费(开源免费),可自由下载、安装和使用。

Use Browser (Scrape leads, like, post on socials or perform actions on the web) 支持哪些平台?

Use Browser (Scrape leads, like, post on socials or perform actions on the web) 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Use Browser (Scrape leads, like, post on socials or perform actions on the web)?

由 mathiasthu(@mathiasthu)开发并维护,当前版本 v1.0.0。

💬 留言讨论