Skip to content

feat(skills): add hardened HAR-derived API client - #121

Merged
batumilove merged 4 commits into
batumi/livefrom
promote/har-derived-api-client-20260725
Jul 25, 2026
Merged

batumilove merged 4 commits into
batumi/livefrom
promote/har-derived-api-client-20260725

Conversation

@batumilove

Copy link
Copy Markdown
Owner

Summary

Promote upstream NousResearch/hermes-agent PR NousResearch#70823's optional har-derived-api-client skill into the fork live branch, with an additional reviewed hardening commit.

The skill captures browser traffic to HAR, derives API endpoints, and supports both local Playwright and remote/CDP browser pathways.

Security and correctness hardening

  • Redact sensitive header, query, and JSON-body values from derivation output.
  • Preserve query parameters in CDP HARs and fall back to parsing the request URL.
  • Fail cleanly for malformed HAR input.
  • Cap CDP response-body capture at 1 MB.
  • Write HAR files with mode 0600.
  • Remove dead request-tracking code.
  • Add behavioral and adversarial regression tests.

Verification

Candidate: f56385601c7206925c1fb68ba747ccad1f254081

  • scripts/run_tests.sh tests/skills/test_har_derived_api_client_skill.py -q — 12 passed
  • scripts/run_tests.sh tests/skills -q — 338 passed
  • Ruff, Python compile, and all three CLI --help smokes — passed
  • Independent exact-SHA review — PASS; no security concerns or logic errors

Scope

Five files only under the optional skill and its focused test. This PR does not deploy or restart the gateway by itself.

@coderabbitai

coderabbitai Bot commented Jul 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@batumilove, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 13 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 002919bf-49dd-4066-b9fd-e3c9770fad31

📥 Commits

Reviewing files that changed from the base of the PR and between 3dd0115 and 5199950.

📒 Files selected for processing (5)
  • optional-skills/web-development/har-derived-api-client/SKILL.md
  • optional-skills/web-development/har-derived-api-client/scripts/har_capture.py
  • optional-skills/web-development/har-derived-api-client/scripts/har_capture_cdp.py
  • optional-skills/web-development/har-derived-api-client/scripts/har_to_client.py
  • tests/skills/test_har_derived_api_client_skill.py
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch promote/har-derived-api-client-20260725

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

teknium1 and others added 4 commits July 25, 2026 13:28
Record a site's XHR into a HAR with Playwright, derive its private JSON API,
and call it directly over plain HTTP instead of browser-controlling the page
every time. Credit: trick by Jared Longster, popularized by Dax (thdxr).

- scripts/har_capture.py: Playwright HAR recorder with scripted --action steps
  and embedded response bodies
- scripts/har_to_client.py: distills the HAR to endpoints (method/path template
  /params/body/response) plus User-Agent+cookie+auth replay hints
- Validated live: derived + replayed the Algolia HN-search POST API and the
  Wikipedia rest.php search-title GET, both browserless
- tests exercise the real derivation logic on a synthetic HAR fixture

optional-skills placement: heavy Playwright dependency, niche use case.
…ient

Adds scripts/har_capture_cdp.py for browsers reached over CDP -- cloud
backends (Browserbase, Browser-Use, Firecrawl), Camofox-with-CDP, and any
/browser connect endpoint. record_har_path only works on a locally-owned
Playwright context, so the CDP capturer attaches via connect_over_cdp() and
assembles the HAR from page request/response events instead, leaving the
attached browser open (it doesn't own it).

- SKILL.md: pathway->capturer routing table, CDP prerequisites, pitfalls for
  wrong-capturer/empty-HAR, headless-UA weakness, and no-close-on-attach
- Validated live: attached to an external CDP Chrome, drove DuckDuckGo
  autocomplete, derived the /ac/ endpoint, replayed it browserless
- tests: assert CDP capturer attaches (not launches) and that the skill
  documents every browser backend
@batumilove
batumilove force-pushed the promote/har-derived-api-client-20260725 branch from 97f5ecb to 5199950 Compare July 25, 2026 13:33
@batumilove
batumilove merged commit eb4e875 into batumi/live Jul 25, 2026
56 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants