feat(skills): add hardened HAR-derived API client - #121
Conversation
|
Warning Review limit reached
Next review available in: 13 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (5)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Record a site's XHR into a HAR with Playwright, derive its private JSON API, and call it directly over plain HTTP instead of browser-controlling the page every time. Credit: trick by Jared Longster, popularized by Dax (thdxr). - scripts/har_capture.py: Playwright HAR recorder with scripted --action steps and embedded response bodies - scripts/har_to_client.py: distills the HAR to endpoints (method/path template /params/body/response) plus User-Agent+cookie+auth replay hints - Validated live: derived + replayed the Algolia HN-search POST API and the Wikipedia rest.php search-title GET, both browserless - tests exercise the real derivation logic on a synthetic HAR fixture optional-skills placement: heavy Playwright dependency, niche use case.
…ient Adds scripts/har_capture_cdp.py for browsers reached over CDP -- cloud backends (Browserbase, Browser-Use, Firecrawl), Camofox-with-CDP, and any /browser connect endpoint. record_har_path only works on a locally-owned Playwright context, so the CDP capturer attaches via connect_over_cdp() and assembles the HAR from page request/response events instead, leaving the attached browser open (it doesn't own it). - SKILL.md: pathway->capturer routing table, CDP prerequisites, pitfalls for wrong-capturer/empty-HAR, headless-UA weakness, and no-close-on-attach - Validated live: attached to an external CDP Chrome, drove DuckDuckGo autocomplete, derived the /ac/ endpoint, replayed it browserless - tests: assert CDP capturer attaches (not launches) and that the skill documents every browser backend
97f5ecb to
5199950
Compare
Summary
Promote upstream NousResearch/hermes-agent PR NousResearch#70823's optional
har-derived-api-clientskill into the fork live branch, with an additional reviewed hardening commit.The skill captures browser traffic to HAR, derives API endpoints, and supports both local Playwright and remote/CDP browser pathways.
Security and correctness hardening
0600.Verification
Candidate:
f56385601c7206925c1fb68ba747ccad1f254081scripts/run_tests.sh tests/skills/test_har_derived_api_client_skill.py -q— 12 passedscripts/run_tests.sh tests/skills -q— 338 passed--helpsmokes — passedScope
Five files only under the optional skill and its focused test. This PR does not deploy or restart the gateway by itself.