Agent skill

CLI Anything Safari

by HKUDS in HKUDS/CLI-Anything

Safari browser automation CLI on macOS via safari-mcp. An agent skill from HKUDS/CLI-Anything.

Apache-2.0Auto-check passedProductivity & Automation

Install CLI Anything Safari

skills CLI
$ npx skills add HKUDS/CLI-Anything --skill cli-anything-safari -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HKUDS/CLI-Anything cli-anything-safari --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HKUDS/CLI-Anything.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cli-anything-safari .claude/skills/cli-anything-safari && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cli-anything-safari
GitHub stars
52k
Token cost
~3.4k tokens
SKILL.md length
1,207 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Safari browser automation CLI on macOS via safari-mcp. An agent skill from HKUDS/CLI-Anything.

  • Works in 5 steps: macOS — Safari MCP is macOS-only. → Safari — already installed on macOS. → Node.js 18+ — brew install node or from… → …
  • Tasks that involve MCP servers
  • SKILL.md covers When to use this CLI, Installation, Command Structure and Usage Examples, plus 7 more sections
  • Calls npx, pip and python3

What it does

CLI Anything Safari is an agent skill from HKUDS/CLI-Anything. Safari browser automation CLI on macOS via safari-mcp. Controls real Safari (native, keeps logins) by wrapping the safari-mcp MCP server. Every one of the 84 MCP tools is exposed 1:1 with schema-accurate arguments — guaranteed parity, no manual drift.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering MCP servers and Browser automation. It works with Model Context Protocol and macOS. The repository describes itself as: "CLI-Anything: Making ALL Software Agent-Native" -- CLI-Hub: https://clianything.cc/. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve MCP servers
  • Tasks that involve Browser automation

Example prompts

  • “/cli-anything-safari”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. macOS — Safari MCP is macOS-only.
  2. Safari — already installed on macOS.
  3. Node.js 18+ — brew install node or from https://nodejs.org/
  4. Python 3.10+
  5. Enable Apple Events for Safari: Safari → Develop → Allow JavaScript from Apple Events

What it can do on your machine

Read from SKILL.md and the folder at commit 34f5195. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • pip
    • python3
    • python
    • npm
    • jq
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • nodejs.org
    • npmjs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CLI Anything Safari loads about 3.4k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 1,207 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HKUDS/CLI-Anything at commit 34f5195, republished under its Apache-2.0 licence (© HKUDS). 1,207 words, ~3,393 tokens.

Download SKILL.mdSave it as .claude/skills/cli-anything-safari/SKILL.md (or your agent's skills folder).
name
cli-anything-safari
description
Safari browser automation CLI on macOS via safari-mcp. Controls real Safari (native, keeps logins) by wrapping the safari-mcp MCP server. Every one of the 84 MCP tools is exposed 1:1 with schema-accurate arguments — guaranteed parity, no manual drift.

cli-anything-safari

A command-line interface for Safari browser automation on macOS. Wraps the safari-mcp Node.js MCP server in a Python Click CLI.

Feature parity is guaranteed. Every Click command is generated automatically from safari-mcp's tool schema (bundled as resources/tools.json). All 84 tools are reachable with the exact argument names and types the MCP server expects.

When to use this CLI

Each CLI invocation spawns a fresh subprocess, so there is per-call overhead. If your agent speaks MCP natively (Claude Code, Cursor, Cline, etc.), using safari-mcp directly over MCP stdio will be faster.

Use this CLI when:

  • Your agent framework does not speak MCP (Codex CLI, GitHub Copilot CLI, custom scripts, older agent frameworks).
  • You need to script browser automation from bash — cli-anything-safari --json tool snapshot | jq '...'.
  • You run in CI/CD and want cron-able, subprocess-friendly output.
  • You're debugging interactively from Terminal.

Installation

Prerequisites
  1. macOS — Safari MCP is macOS-only.
  2. Safari — already installed on macOS.
  3. Node.js 18+ — brew install node or from https://nodejs.org/
  4. Python 3.10+
  5. Enable Apple Events for Safari: Safari → Develop → Allow JavaScript from Apple Events
Install the CLI
bash
cd safari/agent-harness
pip install -e .

The first tool call will download the safari-mcp npm package (one-time, a few MB).

Command Structure

The CLI has 5 top-level commands:

CommandPurpose
toolCall any of safari-mcp's 84 tools (dynamic, schema-driven)
toolsInspect the bundled tool registry (list, describe, count)
rawEscape hatch — call a tool by full name with raw JSON args
sessionIn-memory session state (last URL, current tab)
replInteractive REPL (default when no subcommand given)

Usage Examples

Discover the tool surface
bash
# Count of tools (sanity check — must match safari-mcp's registered tools)
cli-anything-safari tools count
# → 84

# List every tool
cli-anything-safari tools list
cli-anything-safari tools list --filter click   # filter by substring

# Full schema for one tool (JSON or human format)
cli-anything-safari tools describe safari_scroll
cli-anything-safari --json tools describe safari_click
Call a tool (schema-driven)
bash
# Navigate
cli-anything-safari tool navigate --url https://example.com

# Take a snapshot (preferred over screenshot — structured text with ref IDs)
cli-anything-safari --json tool snapshot

# Click by ref (refs come from snapshot; they expire on the next snapshot!)
cli-anything-safari tool click --ref 0_5

# Click by selector or visible text
cli-anything-safari tool click --selector "#submit"
cli-anything-safari tool click --text "Log in"

# Fill a field
cli-anything-safari tool fill --selector "#email" --value "user@example.com"

# Scroll by direction/amount (NOT x/y — note the schema!)
cli-anything-safari tool scroll --direction down --amount 500

# Drag one element onto another
cli-anything-safari tool drag \
    --source-selector ".card" \
    --target-selector ".trash"

# Screenshot — returns base64 JPEG in stdout. Decode with:
cli-anything-safari --json tool screenshot --full-page \
    | python3 -c "import sys,json,base64; \
        d=json.load(sys.stdin); \
        open('/tmp/shot.jpg','wb').write(base64.b64decode(d['data']))"

# Save as PDF (this one writes to disk directly)
cli-anything-safari tool save-pdf --path /tmp/page.pdf

# Evaluate JavaScript (note: parameter is --script, not --code)
cli-anything-safari tool evaluate --script "document.title"
Navigate and read in one round-trip
bash
cli-anything-safari --json tool navigate-and-read --url https://example.com
Form fill (bulk)

safari_fill_form takes an array of {selector, value} objects. Pass it as a JSON string:

bash
cli-anything-safari tool fill-form --fields '[
  {"selector": "#email",    "value": "user@example.com"},
  {"selector": "#password", "value": "hunter2"}
]'

Run cli-anything-safari tools describe safari_fill_form to see the exact schema, including any new fields safari-mcp adds upstream.

Network monitoring
bash
cli-anything-safari tool start-network-capture
cli-anything-safari tool navigate --url https://example.com
cli-anything-safari --json tool network
cli-anything-safari tool performance-metrics
Storage
bash
cli-anything-safari tool get-cookies
cli-anything-safari tool set-cookie --name session --value abc123 --domain example.com
cli-anything-safari tool local-storage --key theme
# export-storage returns JSON to stdout — no --path arg. Pipe to a file:
cli-anything-safari --json tool export-storage > /tmp/storage.json
Raw JSON escape hatch

When you need to pass a complex nested object or want to drive the CLI from a pre-built JSON blob:

bash
cli-anything-safari raw safari_evaluate \
    --json-args '{"code":"[...document.querySelectorAll(\"a\")].map(a => a.href)"}'
Interactive REPL
bash
cli-anything-safari

The REPL banner prints the absolute path to this SKILL.md so agents can self-discover capabilities.

JSON Output

All commands support --json as a global flag:

bash
cli-anything-safari --json tool snapshot
cli-anything-safari --json tool list-tabs
cli-anything-safari --json tools list

State Management

The CLI maintains a small amount of in-memory state for REPL display only:

  • last_url — last URL the CLI navigated to (updated after every successful tool navigate, tool navigate-and-read, or tool new-tab)
  • current_tab_index — last known active tab index

There is no persistent session, no undo/redo, no document model. Every CLI invocation starts with fresh state. Safari MCP itself is stateless per-call: each tool command spawns a fresh npx safari-mcp subprocess, performs the action, and exits. This is a deliberate design choice; see HARNESS.md and TEST.md for the reasoning behind the deviation from the standard undo/redo pattern.

Output Formats

All commands support dual output modes:

  • Human-readable (default): indented key-value text for dict results, bullet lists for arrays, plain text otherwise
  • Machine-readable (--json flag): structured JSON for agent consumption
bash
# Human output
cli-anything-safari tool snapshot

# JSON output for agents
cli-anything-safari --json tool snapshot
cli-anything-safari --json tools list
cli-anything-safari --json tools describe safari_click

For AI Agents

When using this CLI programmatically:

  1. Always use --json flag for parseable output.
  2. Check return codes — 0 for success, non-zero for errors (URL validation failures, MCP call failures, invalid JSON args).
  3. Parse stderr for error messages; use stdout for data.
  4. File-handling tools have inconsistent path arg names — always check tools describe <name> first:
    • tool save-pdf --path /tmp/x.pdf
    • tool upload-file --selector ... --file-path /tmp/x.txt (note: --file-path, not --path)
    • tool export-storage — no path arg; pipe JSON output to a file
    • tool import-storage --path /tmp/x.json
    • tool screenshot / screenshot-element — return base64 in the JSON response, no path arg (decode it yourself)
  5. Snapshot before click — refs from tool snapshot expire on the next snapshot. Always snapshot → find ref → click in close succession.
  6. Discover tools via tools list — the bundled registry is the source of truth for what's available. Do not hard-code tool names that may change upstream.
  7. Use tools describe <name> to learn the exact schema (required args, enum choices, JSON-typed args) before constructing a call. Never assume parameter names from the description — for example, safari_evaluate takes --script (not --code) even though the description says "JavaScript code to execute".

Agent-Specific Guidance

Finding the right tool

Use the introspection commands. The CLI is guaranteed to reflect the MCP server 1:1:

bash
# Find all click-related tools
cli-anything-safari tools list --filter click

# Get the full schema (including every argument with type, description,
# required/optional, enum choices, defaults)
cli-anything-safari --json tools describe safari_click
Show full SKILL.md (511 more words)Show less
Tool selection strategy
  1. tool snapshot over tool screenshot — structured text with ref IDs is orders of magnitude cheaper and carries the refs needed for clicks.
  2. tool click --ref over tool click --selector — refs are stable within a single snapshot, selectors may be brittle.
  3. tool navigate-and-read over navigate + read-page — saves one round-trip.
  4. tool click-and-read over click + read-page — saves one round-trip.
  5. tool native-click only when regular click fails with 405/403 (WAF blocks, G2, Cloudflare) — it physically moves the cursor.
Refs Expire

Refs from tool snapshot expire when you take a new snapshot:

  • First snapshot: refs 0_1, 0_2, 0_3...
  • Second snapshot: refs 1_1, 1_2, 1_3...

Always snapshot → click in close succession. If in doubt, snapshot again.

Tab Ownership Safety

Safari MCP tracks tab ownership per session. Tools that modify a tab (navigate, click, fill) are blocked on tabs the session did not open. To operate on a specific page, always start with tool new-tab --url ....

Error Handling

Common errors:

  • npx not found → install Node.js 18+
  • safari-mcp package not found on npm registry → check network
  • Not macOS → harness is macOS-only
  • AppleScript denied → enable "Allow JavaScript from Apple Events" in Safari → Develop
  • Blocked URL scheme: file → URL validation rejected the input (by design)
URL Validation

The CLI validates URLs before passing them to safari_navigate, safari_navigate_and_read, and safari_new_tab. Blocked schemes: file, javascript, data, vbscript, about, chrome, safari, webkit, x-apple, and other browser-internal schemes. The raw command also enforces this for navigation tools.

Multi-Session Warning

Safari MCP enforces a single active session by killing stale Node.js processes older than 10 seconds. If you run two CLI instances at once, one will kill the other's backend. There is currently no daemon mode — for latency-sensitive workflows, drive the CLI from a long-lived Python script that imports cli_anything.safari.utils.safari_backend.call() directly to avoid re-spawning the subprocess on every invocation.

Security Considerations

URL Validation

All navigation tools (tool navigate, tool navigate-and-read, tool new-tab, and raw safari_navigate*) pass the url argument through utils/security.py which blocks dangerous schemes and optionally blocks private networks (set CLI_ANYTHING_SAFARI_BLOCK_PRIVATE=1).

Tab Isolation

Safari MCP enforces per-session tab ownership upstream — tools cannot operate on tabs the session did not open.

Profile Isolation

Set SAFARI_PROFILE env var to use a separate Safari profile for automation:

bash
export SAFARI_PROFILE="Automation"
cli-anything-safari tool navigate --url https://example.com

This keeps cookies/logins/history separate from the user's main browsing.

JavaScript Execution

tool evaluate and tool run-script run arbitrary JavaScript in the page context. Treat untrusted input with the same care as any dynamic code execution path.

Clipboard

tool clipboard-read and tool clipboard-write touch the system clipboard. Be careful when running inside a user's active session — overwriting the clipboard mid-task is disruptive.

Regenerating the tool registry

If you upgrade safari-mcp, regenerate the bundled schema:

bash
python scripts/extract_tools.py \
    "$(npm root -g)/safari-mcp/index.js" \
    cli_anything/safari/resources/tools.json

The parity test (test_parity.py) pins the expected tool count; update it when the upstream tool list changes.

More Information

  • Full documentation: cli_anything/safari/README.md in the package
  • Test coverage: cli_anything/safari/tests/TEST.md in the package
  • Architecture analysis: safari/agent-harness/SAFARI.md
  • Methodology: cli-anything-plugin/HARNESS.md
  • MCP backend pattern: cli-anything-plugin/guides/mcp-backend.md

Version

1.0.0 — targets safari-mcp 2.7.8 (84 tools). Bundled tool registry is regenerated via scripts/extract_tools.py when safari-mcp upgrades.

© HKUDS, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cli-anything-safari of HKUDS/CLI-Anything.

Open the folder on GitHubat commit 34f5195

Compare with similar skills

CLI Anything Safari next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CLI Anything Safari compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CLI Anything Safari this skillHKUDS/CLI-Anything52k—~3.4kAutomated safety check: PassApache-2.0
Altic Studioaltic-dev/altic-mcp174—~3.3kAutomated safety check: PassApache-2.0
Claude in Chrome MCP Troubleshootingtrailofbits/skills7.5k3 repos~2.6kAutomated safety check: PassCC-BY-SA-4.0
Browser MCP Agentantibrow/anti-detect-browser-skills171 repos~4.2kAutomated safety check: WarnMIT
Isolated Linux Agent Workspaceagent-sh/agent-workspace-linux186—~2.1kAutomated safety check: PassMIT
Xiaohongshu Content Researchjumodada/Drissionpage-MCP-Server487—~768Automated safety check: PassCustom licence

Similar skills

  • Altic Studio

    altic-dev/altic-mcp

    macOS automation skill for AppleScript actions and Chrome browser control via MCP CDP tools.

    174 GitHub stars~3.3k tokensUpdated 2 mo ago
    Productivity & AutomationAuto-check passed
  • Official

    Diagnoses why the Claude in Chrome MCP tools report the browser extension as not connected, with macOS-specific checks and a fix for the Claude.app native host conflict.

    7.5k GitHub starsUsed in 3 repos~2.6k tokens
    Agent WorkflowsAuto-check passed
  • Browser MCP Agent

    antibrow/anti-detect-browser-skills

    Give an AI agent its own real browser over MCP tool calls - launch, navigate, click, fill, screenshot, extract text, run JS - with a kernel-level real-device fingerprint and a persistent profile, so…

    17 GitHub starsUsed in 1 repo~4.2k tokens
    Productivity & AutomationAuto-check: warnings
  • Isolated Linux Agent Workspace

    agent-sh/agent-workspace-linux

    Drives a hidden, agent-owned Linux desktop and browser over MCP for GUI testing and web automation without touching the user's real desktop.

    186 GitHub stars~2.1k tokensUpdated 7 days ago
    Productivity & AutomationAuto-check passed
  • Xiaohongshu Content Research

    jumodada/Drissionpage-MCP-Server

    A skill your agent uses for authorized, read-only research on public Xiaohongshu content or the local Xiaohongshu-like playground fixture.

    487 GitHub stars~768 tokensUpdated 26 days ago
    Productivity & AutomationAuto-check passed
  • Inspects, plans, changes and rolls back macOS default app handlers for file types, MIME types and URL schemes through Dutis, with approval before any write.

    250 GitHub stars~1.2k tokensUpdated 5 days ago
    Productivity & AutomationAuto-check passed

More from HKUDS/CLI-Anything

All 78 skills in this repo
  • CLI-Anything for Codex

    HKUDS/CLI-Anything

    Lets Codex build, refine, test, validate and list CLI-Anything harnesses for GUI applications or source repositories, following the project's full methodology.

    52k GitHub stars~1.5k tokensUpdated 18 days ago
    Auto-check passed
  • CLI-Anything for Reasonix

    HKUDS/CLI-Anything

    Adapts the CLI-Anything methodology so Reasonix can build, refine, test and validate a command-line harness for an existing GUI application or source repository.

    52k GitHub stars~1.8k tokensUpdated 18 days ago
    Auto-check passed
  • Guides Hermes Agent through building, refining and testing a CLI-Anything harness that wraps a GUI application or source repository in a scriptable command line.

    52k GitHub stars~1.1k tokensUpdated 18 days ago
    Auto-check passed
  • Builds, refines, tests or validates a CLI-Anything harness that wraps a GUI application or source repository as a stateful Click CLI with JSON output and a REPL mode.

    52k GitHub stars~839 tokensUpdated 18 days ago
    Auto-check passed
  • Krita CLI Harness

    HKUDS/CLI-Anything

    Drives Krita from the command line to create projects, add layers, apply filters, resize the canvas and export images, with JSON output for agents.

    52k GitHub stars~931 tokensUpdated 18 days ago
    Auto-check passed
  • MacroCLI GUI Macros

    HKUDS/CLI-Anything

    Defines, lists, inspects and runs parameterized GUI macros from the command line, with the runtime choosing the execution backend.

    52k GitHub stars~1.4k tokensUpdated 18 days ago
    Auto-check passed

Questions about CLI Anything Safari

What does CLI Anything Safari do?

Safari browser automation CLI on macOS via safari-mcp. An agent skill from HKUDS/CLI-Anything. CLI Anything Safari is an agent skill from HKUDS/CLI-Anything. Safari browser automation CLI on macOS via safari-mcp.

When should I use CLI Anything Safari?

CLI Anything Safari fits situations like: tasks that involve MCP servers; tasks that involve Browser automation.

How do I install CLI Anything Safari in Claude Code?

Run `npx skills add HKUDS/CLI-Anything --skill cli-anything-safari -a claude-code`. Or copy the skill folder (skills/cli-anything-safari in HKUDS/CLI-Anything) into .claude/skills/cli-anything-safari in your project. Claude Code loads it when a task matches its description.

How do I install CLI Anything Safari in Codex?

Run `npx skills add HKUDS/CLI-Anything --skill cli-anything-safari -a codex`. Or copy the skill folder (skills/cli-anything-safari in HKUDS/CLI-Anything) into .agents/skills/cli-anything-safari in your project. Codex loads it when a task matches its description.

Can I use CLI Anything Safari in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HKUDS/CLI-Anything --skill cli-anything-safari -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cli-anything-safari, .gemini/skills/cli-anything-safari, .github/skills/cli-anything-safari and .opencode/skills/cli-anything-safari in your project.

What does CLI Anything Safari need to run?

Going by SKILL.md and its folder, CLI Anything Safari needs the command-line tools its instructions call (npx, pip, python3, python, npm and jq). Our summary lists: Python 3; Node.js.

Does CLI Anything Safari access the network?

SKILL.md names 3 domains. As links in the text: github.com, nodejs.org and npmjs.com. This is read from the text; nothing was executed.

Is CLI Anything Safari safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CLI Anything Safari use?

CLI Anything Safari is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CLI Anything Safari use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to CLI Anything Safari?

Skills that share tags, products or a category with CLI Anything Safari: Altic Studio (altic-dev/altic-mcp, 174 stars), Claude in Chrome MCP Troubleshooting (trailofbits/skills, 7.5k stars), Browser MCP Agent (antibrow/anti-detect-browser-skills, 17 stars) and Isolated Linux Agent Workspace (agent-sh/agent-workspace-linux, 186 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CLI Anything Safari?

HKUDS (a GitHub organization) maintains it in HKUDS/CLI-Anything, which has 51,809 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on September 22, 2026.

Source: HKUDS/CLI-Anything on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.