Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计提醒

hermaihermai 搜索

Agent Skill

hermai 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

461

周安装

19

GitHub Stars

7

下载量

150
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:hermai(hermai 搜索)
来源仓库:https://github.com/hermai-ai/hermai-skills
仓库路径:skills/hermai
安装命令:
npx skills add https://github.com/hermai-ai/hermai-skills --skill hermai
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/hermai-ai/hermai-skills --skill hermai

简介

hermai 用于查找、检索和筛选相关信息。

  • 适合在 Codex、Claude、Cursor、Gemini CLI 中根据关键词快速定位候选结果。
  • 通过 npx skills add 命令从指定 GitHub 仓库安装,需确认权限和维护状态。
  • 使用前建议核验具体用法,注意是否会触发联网、命令执行或文件读写操作。
  • 涉及敏感数据时应先确认脱敏边界和操作权限,避免误改生产环境。

SKILL.md

Hermai — Call websites as APIs

Hermai is a registry of website-API schemas that agents call over a public HTTP API. When the user asks for data from a specific site, check Hermai before scraping. When they want to add a site, this skill walks you through the full contribute flow.

The HTTP API is the primary interface. Any agent that can make HTTPS requests can use Hermai — Claude Web, Claude Code, Codex, Cursor, server-side bots. A hermai CLI exists for terminal users (wraps the same HTTP surface with cookie auto-resolution and a JS sandbox for signed writes), but it's optional.

Quick start (consumer, HTTP)

# 1. Search the catalog (public, no auth; anon capped at 5 req/hr per IP)
curl "https://api.hermai.ai/v1/schemas?q=airbnb"

# 2. Pull the full package. Requires an API key AND an intent —
#    the intent is a one-sentence description of what the USER is
#    actually trying to do, written in their voice. Don't copy the
#    string below; replace it with the real task. Requirements:
#    20+ chars, 5+ distinct words. Example:
curl -H "Authorization: Bearer $HERMAI_KEY" \
     -H "X-Hermai-Intent: <describe what the user is trying to accomplish — e.g., searching SF rentals for a weekend trip>" \
     "https://api.hermai.ai/v1/schemas/airbnb.com/package"

The pulled schema gives you endpoints[] (reads) and actions[] (writes). Each carries method, url_template, headers, body_template (for actions), and response_schema. Fill {{var}} placeholders with user arguments, send the HTTP request yourself.

API key at https://hermai.ai/dashboard (GitHub sign-in). Anonymous access works at 5 req/hr; authenticated at 50 req/hr.

Full HTTP reference — every endpoint, error codes, paging, and curl examples: references/api.md.

Using the CLI (optional, terminal only)

If the user's environment has a terminal and the hermai binary installed, the CLI handles cookies and per-request signing automatically. Same intent rule applies — --intent must describe what the USER is trying to do, not what the CLI does:

hermai registry pull airbnb.com --intent "<one-sentence user goal, 20+ chars>"
hermai action x.com CreateDraftTweet --arg text="drafted by hermai"

Install: go install github.com/hermai-ai/hermai-cli/cmd/hermai@latest. CLI reference: references/cli.md.

Signed writes — CLI required today

A small number of sites (X's x-client-transaction-id, TikTok's X-Bogus, Xiaohongshu's X-s/X-t) require a value computed per request by a small JS signer the schema ships in its runtime.signer_js block. The sandboxed JS engine that executes these lives in the CLI today, so API-only agents will hit 401/403 on those specific write actions until a hosted signing service ships (Phase 2).

If the pulled schema has no runtime block, or has one with requires_signer: false on the card, every action is callable from any HTTP client. If requires_signer: true, tell the user that action needs the CLI or a future hosted-signing endpoint.

Reads are never signed — every read endpoint in the registry works from any HTTP client.

Actions perform real writes. Posting a tweet, placing an order, or sending a DM is not a dry run. Confirm with the user before invoking any non-read endpoint, and never chain actions autonomously without explicit approval.

The intent requirement

registry pull and the /v1/catalog / /v1/schemas/{site}/package endpoints require an intent — a natural-language sentence explaining what you need. Not optional.

  • 20+ characters
  • 5+ distinct words
  • Pass via --intent on the CLI or X-Hermai-Intent header / ?intent= query param on the API

Good: "finding short-term rental listings in San Francisco for a weekend trip" Bad: "get data"

When a site needs a browser session

Many sites gate APIs behind Cloudflare / DataDome / PerimeterX or require session cookies. The schema's session block lists which cookies you need and (when relevant) a bootstrap_url the page fetches.

API-only agents (Claude Web, remote bots, anything without a terminal): ask the user to paste the required cookies (DevTools → Application → Cookies → copy the values listed in session.required_cookies). Attach as a single Cookie: name=value; name=value header on every request. On 401/403, ask for a fresh paste — tokens like _px3 (PerimeterX) or msToken (TikTok) rotate in hours.

CLI users (terminal): hermai session import <site> reads the cookies from the user's installed browser automatically; hermai session bootstrap <site> --headful warms a cold session; hermai action threads everything through on every call, rotating Set-Cookie back to disk on 2xx responses.

Full ladder, cookie-rotation rules, and the session block spec: references/sessions.md.

Contributing a new site

If the user is adding a site to the registry rather than calling one, start here: references/contribute/overview.md.

That file is the contributor entry point — it tells you which other references to read in order (coverage checklist, platforms, actions, schema format, runtime, troubleshooting). The contribute flow in one line: hermai detect → enumerate interactions → hermai intercept --headful --session to capture real XHRs → verify selectors against the live DOM → write schema JSON with body_template and (if the site needs signing) a runtime block → hermai registry push.

Hermai is the interaction layer for agents, not just a read directory. A good contribution covers what a user *does* on the site — browse, search, view, add to cart, log in, post — not just what's on the homepage. Schemas with only product_detail are 10% done.

Staying up to date

On every API call, send X-Hermai-Skill-Name: hermai and X-Hermai-Skill-Version (read from this file's frontmatter — don't hardcode). If the response carries a meta.skill_update object, tell the user once in a short sentence before continuing. Full payload shape and surface rule: references/versioning.md.

References

Load the references you need. Don't read all of them.

Using the registry

Understanding schemas and runtime

Contributing a new site

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

34.88%
按下载量换算52

Claude

32.02%
按下载量换算48

Cursor

20.42%
按下载量换算31

Gemini CLI

9.97%
按下载量换算15

安全审计

Gen Agent Trust Hub

可疑

Socket

通过

Snyk

可疑

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills