Agent skill

Web Autopilot

by LeoYeAI in LeoYeAI/openclaw-master-skills

Record any web app operation once, AI turns it into a reusable automation tool.

MITAuto-check passedBackend & APIs

Install Web Autopilot

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill web-autopilot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills web-autopilot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/web-autopilot .claude/skills/web-autopilot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
web-autopilot
GitHub stars
2.2k
Token cost
~4.5k tokens
SKILL.md length
1,328 words
Files
10 (incl. scripts)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

Record any web app operation once, AI turns it into a reusable automation tool.

  • Works in 6 steps: record — Record a workflow → analyze — Analyze the recording (AI does… → generate — Generate the task script → …
  • Automating repetitive tasks on any web application (reports
  • SKILL.md covers Overview, Task Types, Skill Directory and Commands, plus 3 more sections
  • Runs TypeScript scripts from its folder; calls npx; needs RPA_CREDENTIAL_KEY

What it does

Web Autopilot is an agent skill from LeoYeAI/openclaw-master-skills. Record any web app operation once, AI turns it into a reusable automation tool. Use when: (1) automating repetitive tasks on any web application (reports, submissions, data extraction), (2) creating no-code automation for any logged-in web app, (3) building callable tools from recorded browser sessions. Supports REST, GraphQL, form submissions, file uploads, any login method. Task types: query/export (data extraction) and submit (form submissions like expense reports, travel requests, payment requests).

Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts (for example `README.md`, `_meta.json` and `package.json`).

It sits in Backend & APIs, covering Accounting and bookkeeping, Workflow automation and GraphQL. It works with GraphQL. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • Automating repetitive tasks on any web application (reports
  • Data extraction)
  • Creating no-code automation for any logged-in web app
  • Building callable tools from recorded browser sessions

Example prompts

  • “/web-autopilot”

Requirements

  • Node.js
  • A credential in RPA_CREDENTIAL_KEY

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. record — Record a workflow
  2. analyze — Analyze the recording (AI does this)
  3. generate — Generate the task script
  4. test — Iterative test loop (max 5 rounds)
  5. run — Execute a registered task
  6. list — List all tasks

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (TypeScript), which the agent can run.

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • RPA_CREDENTIAL_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Web Autopilot loads about 4.5k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 1,328 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,328 words, ~4,474 tokens.

Download SKILL.mdSave it as .claude/skills/web-autopilot/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
web-autopilot
description
Record any web app operation once, AI turns it into a reusable automation tool. Use when: (1) automating repetitive tasks on any web application (reports, submissions, data extraction), (2) creating no-code automation for any logged-in web app, (3) building callable tools from recorded browser sessions. Supports REST, GraphQL, form submissions, file uploads, any login method. Task types: query/export (data extraction) and submit (form submissions like expense reports, travel requests, payment requests).

Web Autopilot

Record once in any web app, let AI handle it from now on.

Overview

Record → Analyze → Confirm Fields → Generate → Test → Register as Tool

🎬 Record         User performs the workflow once in a real browser (after login)
🔍 Analyze        AI analyzes network traffic, classifies fixed/dynamic/session fields
✅ Confirm Fields  [Required for submit tasks] User confirms field classifications
📝 Generate       Generates reusable TS script + field mapping
🧪 Test           Iterative test loop, up to 5 rounds of auto-fix
🔧 Register       Register as an OpenClaw tool for direct invocation

Task Types

📊 Query / Export

Data extraction and report generation. Scripts run and output results automatically — no manual intervention needed. Examples: pull sales reports, extract project data, export revenue details

📝 Submit

Submit forms such as expense reports, travel requests, payment requests, etc. Each run requires dynamic parameters. Examples: submit travel request, submit expense report, submit payment request

The key challenge for submit tasks: correctly distinguishing which fields are fixed vs. which change every time, and confirming with the user before generating the script.

Skill Directory

~/.openclaw/rpa/
├── recordings/<task-name>/recording.json
├── tasks/<task-name>/
│   ├── task-meta.json
│   ├── run.ts
│   └── field-mapping.json
└── sessions/<domain>.session.json

Skill scripts: /opt/homebrew/lib/node_modules/openclaw/skills/web-autopilot/scripts/


Commands

1. record — Record a workflow

Ask user: task name, login URL or app URL.

bash
cd /opt/homebrew/lib/node_modules/openclaw/skills/web-autopilot

# Option A: Start from login page (SSO, OAuth, username/password, etc.)
npx ts-node scripts/record.ts --name "my-task" --sso-url "https://login.example.com"

# Option B: Start directly from app (if already logged in or no login needed)
npx ts-node scripts/record.ts --name "my-task" --app-url "https://app.example.com"

Run in PTY mode (pty: true, background: true). User operates browser, types "done" when finished.

Note: --sso-url is a legacy parameter name; it works for any login URL (SSO, OAuth, plain login page, etc.).

2. analyze — Analyze the recording (AI does this)

Read recording.json, separate login traffic from business traffic, identify core APIs.

Key steps:

  1. Read ~/.openclaw/rpa/recordings/<task>/summary.txt for overview
  2. Parse recording.json to extract all API calls to app domain
  3. For each POST/PUT/PATCH with meaningful body:
    • Classify fields: FIXED / DYNAMIC / SESSION / RELATIONAL
    • Detect protocol: rest-json / graphql / form-urlencoded / multipart
  4. Map the complete API sequence (prerequisites → main operation → follow-ups)
  5. Analyze ALL response fields and create field-mapping.json with human-readable labels
  6. Create task-meta.json
  7. [Submit tasks] After analysis, present the field classification confirmation table to the user (see below)
Field Classification
TypeMeaningHandling
FIXEDSame value every submission (approval flow ID, company entity, currency, expense type enums…)Hardcoded in script
DYNAMICDifferent each submission (amount, date, reason, attachment path…)Becomes CLI --parameter
SESSIONAuth tokens/cookies, auto-managedInjected by session.ts
RELATIONALRequires a lookup from another API to get the ID (e.g., project ID, person ID…)Auto-queried in script, or exposed as DYNAMIC parameter
Field Analysis Rules (MANDATORY)

Every field must have a human-readable label. Including system-generated field names.

Inference priority:

  1. Data value type: timestamp (10^12-13) / monetary amount (contextual) / enum (fixed values) / URL / JSON object
  2. Field name pattern: *time/date/_at → datetime | *amount/*price/*cost → monetary | id/_key → ID | *status/*state → status
  3. Business context: infer from related fields, API endpoint names
  4. If uncertain → annotate as (unknown meaning: sample value)
Field Confirmation Step (MANDATORY for Submit tasks)

After analysis, you must present the following confirmation table to the user and wait for confirmation before generating the script:

📋 Field Classification Confirmation — <task name>

✅ FIXED (hardcoded):
  - approvalFlowId: "xxx"  → Approval Flow ID
  - companyId: "yyy"       → Company Entity
  - currency: "CNY"        → Currency

🔄 DYNAMIC (passed as parameters each run):
  - amount          → Amount (example: --amount 1500)
  - startDate       → Start Date (example: --startDate 2026-03-10)
  - endDate         → End Date (example: --endDate 2026-03-12)
  - destination     → Destination (example: --destination "New York")
  - reason          → Reason (example: --reason "Client visit")
  - attachments     → Attachment path (example: --attachments ~/Desktop/receipt.jpg)

🔗 RELATIONAL (auto-queried):
  - projectId       → Project ID (auto-looked up by project name, --projectName "Project X")

❓ Needs confirmation (AI uncertain):
  - field_abc123    → Unknown meaning (recorded value: "0"), suggest: FIXED("0") or DYNAMIC?

Please confirm the above classification or indicate any fields that need adjustment.

Only proceed to the Generate step after user confirmation.

CSV Export Rules (MANDATORY)
  • Keep ALL fields, including hidden fields, dynamic fields, system fields — never crop
  • Field order: preserve original order from data, never sort (sorting causes column misalignment)
  • JSON/object fields → convert to JSON string for storage
  • Use csv.writer + proper quoting to handle JSON fields containing commas
3. generate — Generate the task script

Pre-generation checklist (Query/Export tasks):

  • ✅ All fields are in field-mapping.json
  • ✅ All fields have human-readable labels
  • ✅ CSV export uses field-mapping.json for column headers
  • ✅ Field order preserves original order

Pre-generation checklist (Submit tasks):

  • ✅ User has confirmed field classification (FIXED / DYNAMIC / RELATIONAL)
  • ✅ All DYNAMIC fields converted to CLI parameters (with type, example value, required/optional)
  • ✅ RELATIONAL fields have auto-query logic or corresponding parameters
  • ✅ Script has --dry-run mode (prints request body without submitting, for testing)
  • ✅ Script outputs submission result (success/failure + document number/link)

Submit task invocation example (written to task-meta.json usage field after generation):

bash
# Preview (no actual submission)
npx ts-node run.ts --dry-run --amount 1500 --startDate 2026-03-10 ...

# Submit for real
npx ts-node run.ts --amount 1500 --startDate 2026-03-10 --destination "New York" --reason "Client visit"
4. test — Iterative test loop (max 5 rounds)

Run script → check output → if error: diagnose → fix → repeat.

ErrorCauseFix
401/403Session expired / wrong authRe-check auth headers, re-login
400Wrong field name/typeCompare with recording
404Wrong URLCheck URL exactly
JSON parse errorResponse is HTMLLog resp.raw
5. run — Execute a registered task
bash
npx ts-node ~/.openclaw/rpa/tasks/<task>/run.ts --param1 value1
6. list — List all tasks
bash
npx ts-node /opt/homebrew/lib/node_modules/openclaw/skills/web-autopilot/scripts/run-task.ts --list

Session & Credential Management

Sessions are cookie-based and work with any login method:

  • SSO (OIDC, SAML, CAS, etc.)
  • OAuth / OAuth2
  • Username + password forms
  • Any browser-based authentication

Session files: ~/.openclaw/rpa/sessions/<domain>.session.json

Credentials (Encrypted Storage)

Login credentials are stored encrypted (AES-256-GCM) in a separate file — never stored in plaintext.

File: ~/.openclaw/rpa/credentials.enc

  • Encryption key = machine identity (hostname+username) + optional RPA_CREDENTIAL_KEY env var
  • File permissions: 0600 (owner only)
  • Supports automatic extraction and encrypted storage from recording.json
bash
# Manage credentials
npx ts-node scripts/utils/credentials.ts list                    # List saved domains + usernames
npx ts-node scripts/utils/credentials.ts save <domain> <user> <pass>  # Save manually
npx ts-node scripts/utils/credentials.ts delete <domain>         # Delete
npx ts-node scripts/utils/credentials.ts extract <recording.json> # Extract from recording
Auto-Login Flow

When a session expires, the auto-login flow kicks in:

1. Read encrypted credentials for the target domain from credentials.enc
2. Select login strategy based on loginFlow.type
3. Launch browser (headless if credentials exist, headed if not)
4. Execute login steps → follow redirects → reach target app
5. Capture cookies/tokens → save new session
6. If all else fails → open headed browser for manual login (fallback)
Login Flow Types

When generating scripts, you must identify the login type from the recording and write it to the loginFlow field in task-meta.json:

typeScenarioAuto-login methodExample
apiSSO/app provides a REST login endpoint, single POST completes authCall API directly → follow redirectsEnterprise SSO (POST /api/sso/login)
formSingle-page login form (username + password on same page)Fill form fields → click submitCommon admin dashboards
multi-stepMulti-step login (email → next page → password → next page → possible 2FA)Execute step sequenceGoogle, Microsoft, Okta
manual-onlyHas CAPTCHA/2FA/risk control, cannot be fully automatedOpen headed browser directlyBanking systems, strong CAPTCHA sites
Show full SKILL.md (523 more words)Show less
loginFlow Schema (task-meta.json)
jsonc
{
  "loginFlow": {
    "type": "api",              // api | form | multi-step | manual-only
    "loginUrl": "https://sso.example.com",
    "loginDomain": "sso.example.com",
    "appDomain": "app.example.com",

    // ── type=api specific fields ──
    "loginApiPath": "/api/sso/login",
    "authType": "passwordAuth",       // Optional, auth type field in API body
    "appId": "1234567890",            // Optional, SSO portal app ID (for forward redirect)
    "appForwardUrl": "...",           // Optional, direct redirect URL (alternative to appId)

    // ── type=form specific fields ──
    "usernameSelector": "input[name='email']",    // Optional, custom selectors
    "passwordSelector": "input[type='password']",
    "submitSelector": "button[type='submit']",

    // ── type=multi-step specific fields ──
    "steps": [
      { "action": "fill", "selector": "input[type=email]", "field": "username" },
      { "action": "click", "selector": "#identifierNext" },
      { "action": "wait", "selector": "input[type=password]", "timeoutMs": 5000 },
      { "action": "fill", "selector": "input[type=password]", "field": "password" },
      { "action": "click", "selector": "#passwordNext" }
    ],

    // ── Common fields ──
    "successIndicator": "url_contains:app.example.com",  // Condition to detect successful login
    "postLoginWaitMs": 3000          // Wait time after login success (for cookies to settle)
  }
}
Login Identification Guide for Analyze Step (MANDATORY)

During the analyze step, you must complete the following login analysis:

  1. Extract credentials → credentials.ts extract <recording.json> (auto-detects username/password in POST body)
  2. Identify login type → Inspect the login flow in the recording:
    • Has a clear POST login/auth API → type = api
    • Has form fill actions (password type input) on the same page → type = form
    • Has multiple form fill actions with page navigations in between → type = multi-step
    • Has CAPTCHA image requests or reCAPTCHA scripts → type = manual-only
  3. Document the SSO → app redirect path:
    • Does it use an appId forward?
    • Does it use a redirect_uri callback?
    • Where is the token — in URL query / response body / cookie?
  4. Write loginFlow → Write all fields to task-meta.json
  5. Sanitize → Replace passwords in recording.json with [REDACTED]

⚠️ If credentials.ts extract cannot extract credentials (e.g., Google multi-step login), prompt the user to save credentials manually:

bash
npx ts-node scripts/utils/credentials.ts save accounts.google.com user@gmail.com 'password'
Login Code Templates for Script Generation

Choose the auto-login implementation based on loginFlow.type:

type=api (REST API login):

typescript
// API login → follow redirects → navigate to app
const resp = await page.evaluate(async (p) => {
  const r = await fetch(p.url, { method: 'POST', headers: {'Content-Type':'application/json'},
    body: JSON.stringify(p.body), credentials: 'include' });
  return { status: r.status, ok: r.ok };
}, { url: loginApiUrl, body: { authType, credential: { username, password } } });

type=form:

typescript
await page.fill(loginFlow.usernameSelector || 'input[name="username"]', cred.username);
await page.fill(loginFlow.passwordSelector || 'input[type="password"]', cred.password);
await page.click(loginFlow.submitSelector || 'button[type="submit"]');

type=multi-step:

typescript
for (const step of loginFlow.steps) {
  if (step.action === 'fill') {
    const value = step.field === 'username' ? cred.username : cred.password;
    await page.fill(step.selector, value);
  } else if (step.action === 'click') {
    await page.click(step.selector);
  } else if (step.action === 'wait') {
    await page.waitForSelector(step.selector, { timeout: step.timeoutMs || 10000 });
  }
}

type=manual-only:

typescript
// Open headed browser, wait for user to complete login manually
const browser = await pw.chromium.launch({ headless: false });
// ... wait for successIndicator

task-meta.json loginFlow example (SSO → enterprise app):

json
{
  "loginFlow": {
    "type": "api",
    "loginUrl": "https://sso.example.com",
    "loginDomain": "sso.example.com",
    "loginApiPath": "/api/sso/login",
    "authType": "passwordAuth",
    "appId": "1234567890",
    "appDomain": "app.example.com",
    "successIndicator": "url_contains:app.example.com"
  }
}
⚠️ Security Rules (MANDATORY)
  1. Passwords in recording.json must be sanitized immediately after analysis (replace with [REDACTED])
  2. credentials.enc is an encrypted binary file — do not attempt to read or edit directly
  3. credentials.enc and sessions/ directory must never be committed to version control or shared
  4. Skill packages (.skill) must not contain any credentials, sessions, or recording data
  5. Generated task scripts (run.ts) must never hardcode any passwords

Known Issues & Lessons Learned

🔐 Login flow must match app — don't assume one-size-fits-all
  • Current implemented scripts use type=api mode (enterprise SSO → business app)
  • Each new app recording must re-identify the login type — do not reuse login logic from old scripts
  • Google/Microsoft multi-step logins require type=multi-step + steps sequence
  • Sites with CAPTCHA/2FA can only use type=manual-only
  • Inlining login logic into run.ts (rather than importing external login.ts) is more stable due to Node ESM/CJS compatibility issues
⚠️ Node v25 ESM compatibility
  • Node v25 defaults to ESM, require() is unavailable
  • Solution: place tsconfig.json in the task directory to force "module": "commonjs"
  • Dependencies like Playwright need full-path require: require('/opt/.../node_modules/playwright')
  • Cross-directory .ts imports under ts-node are unstable — recommend inlining critical logic into run.ts
⚠️ Multi-tab traffic capture (fixed)

Some login flows or apps open new tabs. Recorder uses context.on('request/response') to capture ALL tabs.

📋 CSV must include ALL fields with human-readable labels
  • Never crop fields — include everything from the API response
  • System-generated field names (e.g. field_*, attr_*, custom_*) must be analyzed from sample data
  • Create field-mapping.json for every task
  • Field order: preserve original order from data, never sort
  • Use proper CSV quoting to handle JSON fields with commas
📝 Submit tasks: always confirm field classification before generating
  • Never skip the field confirmation step — wrong FIXED/DYNAMIC split breaks every future submission
  • Fields that look fixed (e.g. a hardcoded project ID) might actually need to be dynamic in real use
  • Always include --dry-run in generated scripts so users can verify the request body before committing
  • RELATIONAL fields (e.g. approver ID looked up by name) should be auto-resolved in script, exposed as human-readable params

File Locations

ItemPath
Recorderscripts/record.ts
Task runnerscripts/run-task.ts
Session utilityscripts/utils/session.ts
Login helperscripts/utils/login.ts
Recordings~/.openclaw/rpa/recordings/<task>/
Generated tasks~/.openclaw/rpa/tasks/<task>/
Sessions~/.openclaw/rpa/sessions/<domain>.session.json

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts) in skills/web-autopilot of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • README.md
  • _meta.json
  • package.json
  • scripts/record.ts
  • scripts/run-task.ts
  • scripts/utils/credentials.ts
  • scripts/utils/login.ts
  • scripts/utils/session.ts
  • tsconfig.json

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Web Autopilot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Web Autopilot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Web Autopilot this skillLeoYeAI/openclaw-master-skills2.2k—~4.5kAutomated safety check: PassMIT
Gh QueueLanternOps/breeze132—~5kAutomated safety check: PassAGPL-3.0
Experience UI Bundle Deployforcedotcom/sf-skills1.1k—~4.4kAutomated safety check: NotesApache-2.0
Linear Reference Architecturejeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works16218 repos~4kAutomated safety check: PassAGPL-3.0
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT

Similar skills

  • Gh Queue

    LanternOps/breeze

    A skill your agent uses when reviewing, triaging, or managing the incoming GitHub backlog on the Breeze repo — PRs, Discussions, AND Issues.

    132 GitHub stars~5k tokensUpdated today
    DevelopmentAuto-check passed
  • Experience UI Bundle Deploy

    forcedotcom/sf-skills

    MUST activate when the project has a uiBundles//src/ directory and the task involves deploying to an org or post-deploy org setup.

    1.1k GitHub stars~4.4k tokensUpdated 2 days ago
    Backend & APIsAuto-check: notes
  • Linear Reference Architecture

    jeremylongshore/tons-of-skills-marketplace

    Design a Linear integration with separated auth, GraphQL, webhook, queue, policy, and reconciliation boundaries.

    2.8k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    162 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • GraphQL Operations with Codegen

    ChrisWiles/claude-code-showcase

    Sets the rules for writing GraphQL queries and mutations in .gql files, running codegen, and using generated Apollo hooks with proper error and loading handling.

    6.1k GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Web Autopilot

What does Web Autopilot do?

Record any web app operation once, AI turns it into a reusable automation tool. Web Autopilot is an agent skill from LeoYeAI/openclaw-master-skills. Record any web app operation once, AI turns it into a reusable automation tool.

When should I use Web Autopilot?

Web Autopilot fits situations like: automating repetitive tasks on any web application (reports; data extraction); creating no-code automation for any logged-in web app; building callable tools from recorded browser sessions.

How do I install Web Autopilot in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill web-autopilot -a claude-code`. Or copy the skill folder (skills/web-autopilot in LeoYeAI/openclaw-master-skills) into .claude/skills/web-autopilot in your project. Claude Code loads it when a task matches its description.

How do I install Web Autopilot in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill web-autopilot -a codex`. Or copy the skill folder (skills/web-autopilot in LeoYeAI/openclaw-master-skills) into .agents/skills/web-autopilot in your project. Codex loads it when a task matches its description.

Can I use Web Autopilot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill web-autopilot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web-autopilot, .gemini/skills/web-autopilot, .github/skills/web-autopilot and .opencode/skills/web-autopilot in your project.

What does Web Autopilot need to run?

Going by SKILL.md and its folder, Web Autopilot needs TypeScript for the scripts in its folder, the command-line tools its instructions call (npx) and credentials named RPA_CREDENTIAL_KEY. Our summary lists: Node.js; A credential in RPA_CREDENTIAL_KEY.

Does Web Autopilot access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Web Autopilot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Web Autopilot use?

Web Autopilot is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Web Autopilot use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Web Autopilot?

Skills that share tags, products or a category with Web Autopilot: Gh Queue (LanternOps/breeze, 132 stars), Experience UI Bundle Deploy (forcedotcom/sf-skills, 1.1k stars), Linear Reference Architecture (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Nodejs Backend Patterns (ever-works/ever-works, 162 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Web Autopilot?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.