This skill allows the agent to request the user to perform a manual login on a website and then capture the session cookies/localStorage for further automated work.
We take security seriously. Below is how we address common concerns related to remote browser control:
Referrer-Policy: no-referrer. This ensures that even if you navigate to an untrusted site, your secret AUTH_TOKEN is NEVER sent in the HTTP Referer header.token parameter from your browser's address bar immediately after the page loads.session.json file contains active login cookies. Treat it with the same level of security as a password.127.0.0.1. 0.0.0.0 directly. Instead, use a secure tunnel like Tailscale, Cloudflare Tunnel (cloudflared), or an SSH tunnel.想要更強大的技能外掛,就來小蔥技能站7w4.net看看吧。
scripts/auth_server.js.scripts/verify_session.js to confirm the session is valid.AUTH_HOST=127.0.0.1 AUTH_TOKEN=mysecret node scripts/auth_server.js <port> <session_file>
node scripts/verify_session.js <session_file> <target_url> <expected_text>
Requires: express, socket.io, playwright-core, and a system chromium-browser.
整體質量不錯,安全防護做得很到位,介面操作直觀流暢。最大問題是安裝時容易因為缺少依賴而出錯,說明不夠清晰。另外文件和程式碼裡關於預設網路配置的說法有出入,新手可能會因此配置不當。核心功能穩定可靠,但這些細節問題影響使用體驗。