pair-agent — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited pair-agent (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use when asked to "pair agent", "connect agent", "share browser", "remote browser", "let another agent use my browser", or "give browser access".
eval "$(~/.vibestack/bin/vibe-slug 2>/dev/null)" 2>/dev/null || SLUG="unknown"
_LEARN_FILE="${VIBESTACK_HOME:-$HOME/.vibestack}/projects/${SLUG:-unknown}/learnings.jsonl"
if [ -f "$_LEARN_FILE" ]; then
_LEARN_COUNT=$(wc -l < "$_LEARN_FILE" 2>/dev/null | tr -d ' ')
echo "LEARNINGS: $_LEARN_COUNT entries loaded"
if [ "$_LEARN_COUNT" -gt 5 ] 2>/dev/null; then
~/.vibestack/bin/vibe-learnings-search --limit 5 2>/dev/null || true
fi
else
echo "LEARNINGS: none yet"
fi{{include lib/snippets/session-host.md}}
{{include lib/snippets/decision-brief.md}}
{{include lib/snippets/working-protocols.md}}
{{include lib/snippets/state-protocols.md}}
You're sitting in Claude Code with a browser running. You also have another AI agent open (OpenClaw, Hermes, Codex, Cursor, whatever). You want that other agent to be able to browse the web using YOUR browser. This skill makes that happen.
Your vibestack browser runs a local HTTP server. This skill creates a one-time setup key, prints a block of instructions, and you paste those instructions into the other agent. The other agent exchanges the key for a session token, creates its own tab, and starts browsing. Each agent gets its own tab. They can't mess with each other's tabs.
The setup key expires in 5 minutes and can only be used once. If it leaks, it's dead before anyone can abuse it. The session token lasts 24 hours.
Same machine: If the other agent is on the same machine (like OpenClaw running locally), you can skip the copy-paste ceremony and write the credentials directly to the agent's config directory.
Remote: If the other agent is on a different machine, you need an ngrok tunnel. The skill will tell you if one is needed and how to set it up.
_ROOT=$(git rev-parse --show-toplevel 2>/dev/null)
B=""
[ -n "$_ROOT" ] && [ -x "$_ROOT/.claude/skills/vibestack/browse/dist/browse" ] && B="$_ROOT/.claude/skills/vibestack/browse/dist/browse"
[ -z "$B" ] && B="$HOME/.claude/skills/vibestack/browse/dist/browse"
if [ -x "$B" ]; then echo "READY: $B"; else echo "NEEDS_SETUP"; fiIf NEEDS_SETUP, stop and tell the user: "The browse daemon is required for this skill but is not installed. vibestack does not bundle the browse daemon — it's a separate dependency. See docs/external-tools.md for current options."
$B status 2>/dev/nullIf the browse server is not running, start it:
$B goto about:blankThis ensures the server is up and healthy before pairing.
Use AskUserQuestion:
Which agent do you want to pair with your browser? This determines the instructions format and where credentials get written.
Options:
Based on the answer, set TARGET_HOST:
openclawcodexcursorclaudeUse AskUserQuestion:
Is the other agent running on this same machine, or on a different machine/server?
>
Same machine skips the copy-paste ceremony. Credentials are written directly to the agent's config directory. No tunnel needed.
>
Different machine generates a setup key and instruction block. If ngrok is installed, the tunnel starts automatically. If not, I'll walk you through setup.
>
RECOMMENDATION: Choose A if the agent is local. It's instant, no copy-paste needed.
Options:
Run pair-agent with --local flag:
$B pair-agent --local TARGET_HOSTReplace TARGET_HOST with the value from Step 2 (openclaw, codex, cursor, etc.).
If it succeeds, tell the user: "Done. TARGET_HOST can now use your browser. It will read credentials from the config file that was written. Try asking it to navigate to a URL."
If it fails (host not found, write permission error), show the error and suggest using the generic remote flow instead.
First, detect ngrok status:
which ngrok 2>/dev/null && echo "NGROK_INSTALLED" || echo "NGROK_NOT_INSTALLED"
ngrok config check 2>/dev/null && echo "NGROK_AUTHED" || echo "NGROK_NOT_AUTHED"If ngrok is installed and authed: Just run the command. The CLI will auto-detect ngrok, start the tunnel, and print the instruction block with the tunnel URL:
$B pair-agent --client TARGET_HOSTIf the user also needs admin access (JS execution, cookies, storage):
$B pair-agent --admin --client TARGET_HOSTCRITICAL: You MUST output the full instruction block to the user. The command prints everything between ═══ lines. Copy the ENTIRE block verbatim into your response so the user can copy-paste it into their other agent. Do NOT summarize it, do NOT skip it, do NOT just say "here's the output." The user needs to SEE the block to copy it. Output it inside a markdown code block so it's easy to select and copy.
Then tell the user: "Copy the block above and paste it into your other agent's chat. The setup key expires in 5 minutes."
If ngrok is installed but NOT authed: Walk the user through authentication:
Tell the user: "ngrok is installed but not logged in. Let's fix that:
STOP here and wait for the user to provide their auth token.
When they provide it, run:
ngrok config add-authtoken THEIR_TOKENThen retry $B pair-agent --client TARGET_HOST.
If ngrok is NOT installed: Walk the user through installation:
Tell the user: "To connect a remote agent, we need ngrok (a tunnel that exposes your local browser to the internet securely).
brew install ngroksnap install ngrok or download from ngrok.com/downloadngrok config add-authtoken YOUR_TOKEN(get your token from https://dashboard.ngrok.com/get-started/your-authtoken)
/pair-agent again."STOP here. Wait for the user to install ngrok and re-invoke.
After the user pastes the instructions into the other agent, wait a moment then check:
$B statusLook for the connected agent in the status output. If it appears, tell the user: "The remote agent is connected and has its own tab. You'll see its activity in the side panel if you have vibestack Browser open."
With default (read+write) access:
With admin access (--admin flag):
"Tab not owned by your agent" — The remote agent tried to interact with a tab it didn't create. Tell it to run newtab first to get its own tab.
"Domain not allowed" — The token has domain restrictions. Re-pair with broader domain access or no domain restrictions.
"Rate limit exceeded" — The agent is sending > 10 requests/second. It should wait for the Retry-After header and slow down.
"Token expired" — The 24-hour session expired. Run /pair-agent again to generate a new setup key.
Agent can't reach the server — If remote, check the ngrok tunnel is running ($B status). If local, check the browse server is running.
OpenClaw agents use the exec tool instead of Bash. The instruction block uses exec curl syntax which OpenClaw understands natively. When using --local openclaw, credentials are written to ~/.openclaw/skills/vibestack/browse-remote.json.
Codex agents can execute shell commands via codex exec. The instruction block's curl commands work directly. When using --local codex, credentials are written to ~/.codex/skills/vibestack/browse-remote.json.
Cursor's AI can run terminal commands. The instruction block works as-is. When using --local cursor, credentials are written to ~/.cursor/skills/vibestack/browse-remote.json.
To disconnect a specific agent:
$B tunnel revoke AGENT_NAMETo disconnect all agents and rotate the root token:
# This invalidates ALL scoped tokens immediately
$B tunnel rotate~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.