Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add sloemo01/hermes-skills-bundle --skill deep-web-researchgit clone --depth 1 https://github.com/sloemo01/hermes-skills-bundleWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/sloemo01/hermes-skills-bundle/deep-web-research)<a href="https://agentmods.dev/skills/sloemo01/hermes-skills-bundle/deep-web-research"><img src="https://agentmods.dev/badge/skills/sloemo01/hermes-skills-bundle/deep-web-research/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/sloemo01/hermes-skills-bundle/deep-web-research"><img src="https://agentmods.dev/badge/skills/sloemo01/hermes-skills-bundle/deep-web-research.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00019 | $0.01846 |
| Opus 5 | $0.00010 | $0.00923 |
| Sonnet 5 | $0.00004 | $0.00369 |
| Haiku 4.5 | $0.00002 | $0.00185 |
Grade A, and why
deep-web-research scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s -X POST http://127.0.0.1:10086/command \ How it starts
The opening of the file, as written. The whole thing — 182 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Deep Web Research with Kimi WebBridge
When to Use
- User asks for "deep research", "comprehensive research", "investigate thoroughly"
- Multi-source investigation needed (GitHub, X/Twitter, Google, docs sites)
- Need 10+ tabs organized in named tab groups
- User says "retry" to re-do with same approach
Core Methodology
1. Session & Tab Group Setup
# First navigate: create session + tab group with human-readable label
curl -s -X POST http://127.0.0.1:10086/command \
-H 'Content-Type: application/json' \
-d '{"action":"navigate","args":{"url":"<first_url>","newTab":true,"group_title":"<descriptive label>"},"session":"<task-name>"}'
Rules:
- One task = one session = one tab group
- Session name = task identifier (e.g.,
vsouthvpawv-research,web-search) group_title= user-language label shown in browser tab group- Never switch session names mid-task
2. Opening Additional Sources
# Subsequent navigates: same session, newTab:true, no group_title needed
curl -s -X POST http://127.0.0.1:10086/command \
-H 'Content-Type: application/json' \
-d '{"action":"navigate","args":{"url":"<url>","newTab":true},"session":"<task-name>"}'
3. Reading Page Content
# Snapshot returns accessibility tree with @e refs
curl -s -X POST http://127.0.0.1:10086/command \
-H 'Content-Type: application/json' \
-d '{"action":"snapshot","args":{},"session":"<task-name>"}'
4. Following Links / Interacting
- Use
@erefs from snapshot for click/fill - Prefer snapshot over CSS selectors
- For navigation, use
navigatewith same session
Proper Use of @e References
Important: The @e references (e.g., @e58, @e100) returned by the snapshot tool are special identifiers that work ONLY as direct values for the selector parameter in tools like click, fill, etc.
Common Mistake
Attempting to use @e references in evaluate() with DOM query methods will FAIL:
// ❌ WRONG - This will throw "Failed to execute 'querySelector' on 'Document': '@e58' is not a valid selector"
document.querySelector("@e58").href
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 182 lines · 19 tokens per session scan A 89e45f95cc91
deep-web-research is a skill published in the GitHub repository sloemo01/hermes-skills-bundle (9 stars, last pushed 1mo ago), licensed MIT. It adds 19 tokens to every session and 1,846 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
wstg-web-pentest
Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.
hunt-cors
Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled origin can perform a CREDENTIALED cross-origin read of sensitive…
hunt-dom
Hunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via HTML injection), PostMessage hijacking (missing origin check), Service Worker abuse (intercept requests from same-origin script), CSS Injection/Exfiltration (attribute selectors → token char-by-char via OOB), client-side template…
web-enumeration
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect.
http2-header-impersonation
Spoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile.
humanize-automation
Human-like mouse, keyboard and scroll behavior for behavioral bot bypass.