Agent skill

Unbrowse

by unbrowse-ai in unbrowse-ai/unbrowse

Search and call websites through Unbrowse's hosted API or remote MCP, reuse indexed site tools, read pages, and learn missing routes in its cloud browser.

MITAuto-check passedAgent Workflows

Install Unbrowse

skills CLI
$ npx skills add unbrowse-ai/unbrowse --skill unbrowse -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install unbrowse-ai/unbrowse unbrowse --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/unbrowse-ai/unbrowse.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill .claude/skills/unbrowse && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
unbrowse
GitHub stars
783
Token cost
~3.7k tokens
SKILL.md length
2,056 words
Files
2 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Search and call websites through Unbrowse's hosted API or remote MCP, reuse indexed site tools, read pages, and learn missing routes in its cloud browser.

  • Works in 2 steps: MCP: if unbrowse_discover is in this… → CLI: npx unbrowse whoami. Exit 0 means…
  • Structured website tasks
  • SKILL.md covers Onboarding: sign in with OAuth, Host plugins, Choose the interface and Execute a task, plus 6 more sections
  • Calls npx, claude and codex; reaches unbrowse.ai; needs UNBROWSE_API_KEY

What it does

Unbrowse is an agent skill from unbrowse-ai/unbrowse. Search and call websites through Unbrowse's hosted API or remote MCP, reuse indexed site tools, read pages, and learn missing routes in its cloud browser. Use for structured website tasks, and authenticated site access with Unbrowse.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/tools.json`).

It sits in Agent Workflows, covering Browser automation and MCP servers. It works with Model Context Protocol. The repository describes itself as: Unbrowse - Reverse engineer any website so that your agents can access its APIs directly. The licence is MIT.

When your agent uses it

  • Structured website tasks
  • Authenticated site access with Unbrowse

Example prompts

  • “/unbrowse”

Requirements

  • Node.js
  • A credential in UNBROWSE_API_KEY

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. MCP: if unbrowse_discover is in this session's tool list, the MCP is signed in.
  2. CLI: npx unbrowse whoami. Exit 0 means signed in. Exit 3 means not signed in.

What it can do on your machine

Read from SKILL.md and the folder at commit b335b96. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • claude
    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • unbrowse.ai

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • UNBROWSE_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Unbrowse loads about 3.7k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 2,056 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from unbrowse-ai/unbrowse at commit b335b96, republished under its MIT licence (© unbrowse-ai). 2,056 words, ~3,703 tokens.

Download SKILL.mdSave it as .claude/skills/unbrowse/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
unbrowse
description
Search and call websites through Unbrowse's hosted API or remote MCP, reuse indexed site tools, read pages, and learn missing routes in its cloud browser. Use for structured website tasks, and authenticated site access with Unbrowse.

Unbrowse

Use the hosted service at https://unbrowse.ai. Execution, indexed routes and website sessions stay server-side. This skill supplies operating guidance; signing in is OAuth, below.

Onboarding: sign in with OAuth

Sign-in is OAuth in the person's browser: an emailed sign-in link, then Allow. No password, and nothing to paste. Never ask the person for a token or key in chat.

Check first, then sign in only what is missing:

  1. MCP: if unbrowse_discover is in this session's tool list, the MCP is signed in.
  2. CLI: npx unbrowse whoami. Exit 0 means signed in. Exit 3 means not signed in.

Sign in the MCP (agent hosts):

sh
claude mcp add --transport http unbrowse https://unbrowse.ai/mcp
json
{"mcpServers":{"unbrowse":{"url":"https://unbrowse.ai/mcp"}}}

The host runs the OAuth sign-in itself (in Claude Code: /mcp, pick unbrowse, Authenticate). Do not put a bearer header in the config; with one set, hosts skip OAuth. A URL in a config is not a signed-in session: until the host finishes OAuth, the Unbrowse tools are not listed.

Sign in the CLI:

sh
npx skills add unbrowse-ai/unbrowse && npx unbrowse login

unbrowse login opens the sign-in page in the browser on this machine. The person enters their email, opens the link, presses Allow; the CLI prints Signed in to https://unbrowse.ai (workspace ws_…) and stores the token at ~/.config/unbrowse/cli.json (mode 0600, refreshed automatically).

From an agent's shell (no terminal for the person): run npx unbrowse login --no-open in the background, give the person the https://unbrowse.ai/authorize?… link it prints, and wait for the Signed in line. The link returns to 127.0.0.1 on this machine, so the person must open it in a browser on the same machine. On a remote or headless box, use an API key instead (below). Any other command run with no sign-in starts the same browser sign-in when it has a terminal; without one it exits 3 and asks for unbrowse login.

Then the first call: npx unbrowse run 'top stories on hacker news'. The site requests go from the person's own IP by default; --from-unbrowse sends them from Unbrowse instead.

npx unbrowse mcp (a stdio MCP for hosts that need one) uses the CLI sign-in. A remote MCP in a host config uses only that host's own OAuth: one sign-in does not cover the other, and the CLI token does not go into an MCP config.

For automation and CI without a browser, set UNBROWSE_API_KEY from the caller's secret manager (create a key in the signed-in console at https://unbrowse.ai/app). Never put keys into committed config, prompts, command arguments or logs.

CLI and SDK: https://github.com/unbrowse-ai/unbrowse

Host plugins

Packaged installs that bundle this skill, connect Unbrowse and redirect the host's own browser to it (https://github.com/unbrowse-ai/unbrowse/tree/main/plugins):

  • Claude Code: claude plugin marketplace add unbrowse-ai/unbrowse, then claude plugin install unbrowse@unbrowse.
  • Codex: codex plugin marketplace add unbrowse-ai/unbrowse, then codex plugin add unbrowse@unbrowse; set web_search = "disabled" to drop built-in search.
  • Grok Build: grok plugin install unbrowse-ai/unbrowse#plugins/grok-build --trust.
  • OpenClaw (@unbrowse/openclaw), Hermes (plugins/hermes), elizaOS (@unbrowse/plugin-unbrowse): native tools or actions over the same MCP.

Hosts that need a stdio server or reject dotted tool names can run npx unbrowse mcp: tool names there use _ (unbrowse_scrape). With a plugin installed, built-in web fetch, web search and browser navigation to non-local URLs are refused with a pointer to the matching Unbrowse tool; UNBROWSE_ALLOW_BUILTIN_BROWSER=1 lifts that for a session.

Choose the interface

  • MCP: discovery, runs, page reading, cloud browsing, indexing and saved-login requests. These names are MCP tools. They are not CLI commands.
  • CLI: unbrowse discover, run, inspect, resume, scrape <url> (one page as markdown), index <url> (teach a site; index status), registry, site, whoami. scrape and index need CLI 12.2.0 or later. unbrowse run never drives a website in a browser (the only browser it opens is the first-use sign-in). There is no unbrowse browse and no unbrowse install. unbrowse help describes the installed version.
  • SDK: REST integration and scripting. Consult the public SDK docs for its supported methods; MCP tools and REST methods are not interchangeable names.

Core MCP tools: unbrowse_discover, unbrowse_run, unbrowse_inspect, unbrowse_resume, unbrowse_cancel, unbrowse_scrape, unbrowse_map, unbrowse_sites, unbrowse_usage, unbrowse_credits, unbrowse_forget, unbrowse_learn, unbrowse_index, unbrowse_index_status, unbrowse_credentials_list, unbrowse_credentials_request, unbrowse_credentials_status, unbrowse_connect (connect an app's own MCP server, such as Linear, Notion or GitHub, so its tools run as the person: an app with sign-in returns a link the person opens), and the cloud browser unbrowse_browse_open, unbrowse_browse_snapshot, unbrowse_browse_act, unbrowse_browse_finish, unbrowse_browse_close.

references/tools.json contains the exported core MCP input schemas. The connected server's tools/list is authoritative: it also includes dynamic tools available to this user's workspace. Never invent a capability ID or input schema.

Execute a task

  1. Discover with unbrowse_discover {query}. Inspect returned inputs, choices and hints. Prefer a healthy matching capability; warm means HTTP replay, rendered needs rendering. Check unbrowse_sites for saved session and login state when relevant. Public tools carry version, the Unbrowse version that generated them (YYYY.MM.DD); among equal matches the newest comes first, and minVersion leaves older ones out.
  2. Call the selected tool with its listed schema, or unbrowse_run {capability, input}. A natural-language task can route when no ID was selected. Use a stable idempotencyKey for the same intended mutation. For a large answer pass select (MCP run tools, unbrowse_resume, unbrowse_inspect, POST /api/v1/runs): paths like ["results[].{id,title,price}", "total"]. It narrows only what comes back, after verification; billing is unchanged. Results over 40,000 characters are shortened (truncated: true); selectMissing lists paths that matched nothing.
  3. Inspect the returned status and actual result. input_required means answer the open requirements on the same run: unbrowse_resume {runId, answers:{field:value}}. For a choice, pass the listed option's value. Preserve revision checks when supplied.
  4. no_capability means no reusable route matched. Follow result.next: tool is unbrowse_index (POST /api/v1/index, then GET /api/v1/index/{jobId}; CLI unbrowse index <url>). To answer now, read the page instead: unbrowse_scrape (CLI unbrowse scrape <url>). Call unbrowse_browse_open only when that name is in this session's tool list. Do not POST /api/v1/browse/open. It is not a route. Report unsupported or blocked sites honestly.
  5. Only report completion from a verified result. outcome_unknown means a change may have occurred: inspect the effect receipt and destination before retrying. Cancellation stops future dispatches; it does not undo completed effects.

Do not infer business success from HTTP 200, tool transport success, a screenshot, or a generated plan. Do not promise universal coverage or browserless execution on every first request. Obtain the user's authorization for posting, sending, purchasing or other external writes.

Unbrowse a URL

When the person names a site:

  1. If unbrowse_discover is not in this session's tool list, the MCP is not signed in. Stop. Name the configured MCP URL and say the CLI login does not cover it.
  2. Look the host up (unbrowse_sites, or CLI unbrowse site <host>). Tools already compiled: use one. Stop.
  3. No tools: unbrowse_index {url, focus} or POST /api/v1/index. Poll unbrowse_index_status or GET /api/v1/index/{jobId}.
  4. status: failed and error.code: model_unavailable: the indexing model is out of credit. Report the job id and the message. Do not browse instead, and do not start the same job again in a loop.
  5. status: done with indexed: 0 means nothing was learned. Say so. indexed > 0 means call one tool and check the result.

A 202 from /api/v1/index is a job id, not a compiled tool.

A site's tools over plain HTTP

Each compiled site is also a REST API, for code rather than an agent session:

  • GET https://unbrowse.ai/api/v1/sites/<host>/openapi.json: OpenAPI 3.1, one operation per tool, typed inputs, an example input it was verified with, every status and header. No key needed to read.
  • POST https://unbrowse.ai/api/v1/sites/<host>/call/<tool> with the tool's inputs as the JSON body and Authorization: Bearer <key>. Options: x-unbrowse-deadline-ms, Idempotency-Key, select. 202 means input_required; 504 run_timeout gives a runId to poll; 409 tool_quarantined means use another tool.
  • SDK: new Unbrowse().callTool(host, tool, input).

Contract and examples: https://unbrowse.ai/docs/site-apis.md

Show full SKILL.md (795 more words)Show less

Read or learn a site

Prefer unbrowse_discover and a matching tool or unbrowse_run for structured data and site tasks. unbrowse_scrape {url} is a last resort for static pages and documents, only when no suitable API or learned tool is available. A PDF, .docx, .xls or .xlsx URL comes back as extracted markdown text (metadata.pages for PDFs; spreadsheets preserve sheet names, rows and formatted values). metadata.truncated marks bounded extraction; formats: ["raw"] returns the exact document bytes as base64; unbrowse_map {url} finds same-site URLs. A known URL or scrape's rendering support does not make it the default. For dynamic content, search, pagination or interaction with no matching route, use unbrowse_index or the available cloud browser tools to learn and replay the site's API:

  1. unbrowse_browse_open {url,task} returns the page and element refs.
  2. Use browse.act with the latest refs. For ordinary inputs, include a meaningful name such as date or query; exercise every filter the task needs. Refresh the snapshot after page changes.
  3. Use browse.finish {sessionId} to return the final page and compile observed routes. Two sessions with different inputs help identify reusable parameters. Check learnError and newTool; browsing success alone does not prove a reusable route exists.
  4. Close sessions when finished. browse.close still indexes unless discard:true.

To cover a whole site ahead of need, unbrowse_index {url, focus?, maxCapabilities?} starts a background job: Unbrowse's own agent performs the site's core read-only capabilities, proves each with a browserless replay and adds them to your tools. Follow it with unbrowse_index_status {jobId}. maxCapabilities caps every tool the job indexes (declared, sitemap page types and recorded flows together). A focus keeps only sitemap page types that match it, and none when it names flows such as paging, page size, filters or search. Query keys in the start URL (?page=0&pageSize=100) become the tool's inputs. stoppedReason says why a job ended. The time budget is extended once, by half, while tools are still being proven.

An existing HAR pair can be sent through unbrowse_learn. Only submit recordings the user authorized; HARs can contain private data. Private and loopback destinations are refused by the hosted service.

Website sign-in

Unbrowse account sign-in and a website's saved login are separate. Never ask for passwords in chat or type credentials via ordinary tool arguments.

  • On a login page, use browse.act {sessionId,action:"autofill"}, or vault:"username"|"email"|"password"|"totp" on a fill action. Values go directly from the vault to the site.
  • Missing login: present the returned signIn.url or details.url save-login link. unbrowse_credentials_request can create one; credentials.status checks whether it was fulfilled. Resume only after it is ready.
  • Do not bypass CAPTCHA, MFA or human verification. Present the supported handoff or report the blocker.
  • Saved sessions are reused automatically (the person can turn that off per site or for the whole workspace); do not sign in again merely because another task started.

Read-only secretless learned routes may be scrubbed and shared to the public registry. The owner can opt out in the console. Logins, private session values and writes are not public tool definitions.

Serving many users (orgs)

When the caller is an agent a builder runs for its own users, it uses an org key and names the user on every call: X-Unbrowse-End-User: <that user's id> (REST and MCP headers). Each user has their own logins and sessions.

  • Always send the id of the user the task is for. Never reuse one user's id for another user's task, and never omit it: without it the call acts as the org itself, not any user.
  • A signIn.url (a /connect/… link) is for that same user: deliver it to them, not to the builder or another user. They save the login there without an Unbrowse account; wait for unbrowse_credentials_status to be fulfilled, then call again.
  • org__… tools are shared by the org's users (read-only, no logins); my__… tools are the current user's own.
  • Quota errors are the org's balance, not the user's. Report them to the builder.

Guide: https://github.com/lekt9/unbrowse6/blob/master/docs/orgs.md

Limits and recovery

  • 401: sign that door in again with OAuth. CLI 401: npx unbrowse login. Remote MCP 401: the host's own OAuth for that server (Claude Code: /mcp). One sign-in does not fix the other.
  • model_unavailable on an index job: the indexing model is out of credit. Report the job id. No tools were compiled. This is not unbrowse_usage and not the site.
  • Quota/payment error: show the returned limit and console link; do not retry payments blindly. When listed, unbrowse_credits shows free/paid balances and can return a checkout link for the user. Opening a billing link does not authorize payment.
  • Verification or login block: use the returned handoff; don't present a challenge page as source content.
  • Timeout on a write: inspect the existing run before retrying.
  • Pricing and quotas: consult the account's current plan and unbrowse_usage; this skill does not fix prices.

© unbrowse-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skill of unbrowse-ai/unbrowse.

  • SKILL.md
  • references/tools.json

Open the folder on GitHubat commit b335b96

Compare with similar skills

Unbrowse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Unbrowse compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Unbrowse this skillunbrowse-ai/unbrowse783—~3.7kAutomated safety check: PassMIT
Cross Origin Iframe Probejumodada/Drissionpage-MCP-Server487—~1.2kAutomated safety check: PassCustom licence
Turnstile Testingjumodada/Drissionpage-MCP-Server487—~1.7kAutomated safety check: PassCustom licence
Xiaohongshu Content Researchjumodada/Drissionpage-MCP-Server487—~768Automated safety check: PassCustom licence
Lightpandalightpanda-io/agent-skill101—~6kAutomated safety check: PassApache-2.0
Claude in Chrome MCP Troubleshootingtrailofbits/skills7.5k3 repos~2.6kAutomated safety check: PassCC-BY-SA-4.0

Similar skills

  • Cross Origin Iframe Probe

    jumodada/Drissionpage-MCP-Server

    A skill your agent uses when a drissionpage-mcp task targets an iframe such as a payment widget, challenge, SSO flow, or embedded checkout.

    487 GitHub stars~1.2k tokensUpdated 27 days ago
    Agent WorkflowsAuto-check passed
  • Turnstile Testing

    jumodada/Drissionpage-MCP-Server

    A skill your agent uses when testing an authorized Cloudflare Turnstile integration or operating an authorized production challenge with drissionpage-mcp.

    487 GitHub stars~1.7k tokensUpdated 27 days ago
    Agent WorkflowsAuto-check passed
  • Xiaohongshu Content Research

    jumodada/Drissionpage-MCP-Server

    A skill your agent uses for authorized, read-only research on public Xiaohongshu content or the local Xiaohongshu-like playground fixture.

    487 GitHub stars~768 tokensUpdated 27 days ago
    Productivity & AutomationAuto-check passed
  • Lightpanda

    lightpanda-io/agent-skill

    Lightpanda browser, drop-in replacement for Chrome-based browsing in any AI agent - faster and lighter for tasks without graphical rendering like data retrieval.

    101 GitHub stars~6k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check passed
  • Official

    Diagnoses why the Claude in Chrome MCP tools report the browser extension as not connected, with macOS-specific checks and a fix for the Claude.app native host conflict.

    7.5k GitHub starsUsed in 3 repos~2.6k tokens
    Agent WorkflowsAuto-check passed
  • Agents SDK

    hodgef/apiker

    Build AI agents on Cloudflare Workers using the Agents SDK. An agent skill from hodgef/apiker.

    127 GitHub starsUsed in 3 repos~3k tokens
    Backend & APIsAuto-check passed

Questions about Unbrowse

What does Unbrowse do?

Search and call websites through Unbrowse's hosted API or remote MCP, reuse indexed site tools, read pages, and learn missing routes in its cloud browser. Unbrowse is an agent skill from unbrowse-ai/unbrowse. Search and call websites through Unbrowse's hosted API or remote MCP, reuse indexed site tools, read pages, and learn missing routes in its cloud browser.

When should I use Unbrowse?

Unbrowse fits situations like: structured website tasks; authenticated site access with Unbrowse.

How do I install Unbrowse in Claude Code?

Run `npx skills add unbrowse-ai/unbrowse --skill unbrowse -a claude-code`. Or copy the skill folder (skill in unbrowse-ai/unbrowse) into .claude/skills/unbrowse in your project. Claude Code loads it when a task matches its description.

How do I install Unbrowse in Codex?

Run `npx skills add unbrowse-ai/unbrowse --skill unbrowse -a codex`. Or copy the skill folder (skill in unbrowse-ai/unbrowse) into .agents/skills/unbrowse in your project. Codex loads it when a task matches its description.

Can I use Unbrowse in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add unbrowse-ai/unbrowse --skill unbrowse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unbrowse, .gemini/skills/unbrowse, .github/skills/unbrowse and .opencode/skills/unbrowse in your project.

What does Unbrowse need to run?

Going by SKILL.md and its folder, Unbrowse needs the command-line tools its instructions call (npx, claude and codex) and credentials named UNBROWSE_API_KEY. Our summary lists: Node.js; A credential in UNBROWSE_API_KEY.

Does Unbrowse access the network?

SKILL.md names 2 domains. In commands or code: unbrowse.ai; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Unbrowse safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Unbrowse use?

Unbrowse is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Unbrowse use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.4k tokens, read only when the agent opens those files.

What are the alternatives to Unbrowse?

Skills that share tags, products or a category with Unbrowse: Cross Origin Iframe Probe (jumodada/Drissionpage-MCP-Server, 487 stars), Turnstile Testing (jumodada/Drissionpage-MCP-Server, 487 stars), Xiaohongshu Content Research (jumodada/Drissionpage-MCP-Server, 487 stars) and Lightpanda (lightpanda-io/agent-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Unbrowse?

unbrowse-ai (a GitHub organization) maintains it in unbrowse-ai/unbrowse, which has 783 GitHub stars. The repository was last updated on October 10, 2026.

Source: unbrowse-ai/unbrowse on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.