Open Websearch

v0.1.2

Single entry skill for open-websearch setup and focused live retrieval, preferring local CLI/daemon paths while remaining compatible with workspace-exposed M...

1· 60·0 current·0 all-time
byAasee@aas-ee·duplicate of @aas-ee/openwebsearch
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Pending
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description (open-websearch setup and focused retrieval) align with the content: SKILL.md details local CLI/daemon, MCP/tool, HTTP endpoint, and source/build workflows that are expected for such a skill. Nothing requested (no env-vars, no binaries, no config paths) is disproportionate to this purpose.
Instruction Scope
The runtime instructions are detailed and remain within the stated purpose (detect capability, prefer smallest path, ask before installing, validate with 'open-websearch status', use 'search'/'fetchWebContent'/'fetchGithubReadme'). The docs mention optional runtime/config env vars and Playwright/browser-related variables (e.g., PLAYWRIGHT_EXECUTABLE_PATH, PLAYWRIGHT_MODULE_PATH, PLAYWRIGHT_WS_ENDPOINT, PLAYWRIGHT_CDP_ENDPOINT, FETCH_WEB_INSECURE_TLS, SEARCH_MODE) and npm proxy/registry guidance. These references are reasonable as optional configuration or fallbacks, but they do mean the skill may ask to read or set such variables or to install Playwright/browser artifacts if the user consents — the instructions explicitly require confirmation before such actions.
Install Mechanism
Instruction-only skill with no install spec and no code files; lowest-risk install posture. The only potential installs discussed are user-confirmed npm/Playwright/browser installs, which the SKILL.md explicitly says to ask about before proceeding.
Credentials
The skill declares no required env vars or credentials. It sensibly documents optional environment variables and proxy settings that may be relevant for specific setup paths. No unrelated credentials or broad access is requested.
Persistence & Privilege
always is false and the skill does not request persistent or system-wide privileges. It does not modify other skills or global agent configs by default. It can be invoked autonomously (default behavior), but that is normal and not combined with other red flags here.
Assessment
This skill appears coherent and low-risk: it is purely instruction-driven and asks for no secrets. Before proceeding, be prepared to: (1) confirm any installs (npm, Playwright, browser binaries) — the skill says it will ask first; (2) approve writing or changing any MCP/client or endpoint configuration; and (3) provide proxy/registry details if you are in a restricted network. If you do not want the agent to attempt installs or change local configs, tell it not to perform those steps when it offers them.

Like a lobster shell, security has layers — review code before you run it.

latestvk974mam9d9b2sdt8md3fzc70xn849j99

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments