
Research
/Security News
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.
@zenalexa/unicli
Advanced tools
Give agents every interface—install once to search, run, inspect, and repair real software across APIs, browsers, desktops, local tools, and MCP.
Give agents every interface
Install once. Search, run, inspect, repair.
Uni-CLI turns intent into a selected operation and a structured receipt across web, browser, desktop, local, and MCP surfaces.
npm install -g @zenalexa/unicli
unicli search "list the top Hacker News stories"
unicli hackernews top --limit 3 -f json
The catalog handles discovery and operation contracts. Execution then selects the strongest operator with the smallest effective scope. One provider runs; a failed path keeps its original cause and repair command.
| Task boundary | Execution operator | Why |
|---|---|---|
| Public data or stable service contract | Structured API | Typed fields, explicit auth, stable provenance |
| Files, system state, local tools | Local runtime | Direct process and OS boundaries without browser state |
| Authenticated or private web contract | Browser protocol | Explicit profile, cookie session, or network contract |
| Page-only web flow | Semantic browser | DOM and CDP semantics with an explicit target and session |
| Native desktop application | Accessibility | Structured AX, UIA, or AT-SPI control trees |
| Pixel-only or unstructured interface | Visual computer use | Coordinate and visual observation when no stronger interface exists |
unicli search "export my saved posts" # discover and rank
unicli list --site reddit # inspect one surface
unicli browser doctor --json # inspect browser delivery state
unicli repair reddit saved # verify a supported drift path
The public model stays compact:
intent → candidate operations → explicit selection → policy → substrate → receipt
| Stage | Runtime behavior |
|---|---|
| Discover | BM25 bilingual search returns a small ranked candidate set |
| Select | The caller chooses one operation with a declared strategy and substrate |
| Govern | open, confirm, and locked profiles evaluate effect and capability scope |
| Act | The selected adapter, core command, browser, desktop, or protocol path executes |
| Observe | Every normal command returns a stable success or error envelope |
| Repair | Owned drift paths expose their source, failed boundary, and bounded verification command |
Uni-CLI supplies the interface runtime. The model, planner, agent loop, and sandbox remain independent choices.
| Surface | Current runtime |
|---|---|
| Web | Public data, cookies, headers, downloads, uploads, publishing, search, and Chinese platforms |
| Browser | CDP navigation, semantic action, network, snapshots, screenshots, and post-action evidence |
| Desktop | Native controls, macOS services, design tools, Office, and media applications |
| Local | Subprocess bridges, files, PDF and paper workflows, media transforms, and developer CLIs |
| Protocols | Native CLI, MCP stdio, MCP Streamable HTTP, ACP, generated configs, and agent skills |
| Policy | Permission profiles, deny rules, scoped approvals, recordings, replay, and evidence |
Static catalog:
Fixed core and host-discovered commands join at runtime.
| Surface | Sites | Operations | Examples |
|---|---|---|---|
| social | 33 | 395 | twitter, zhihu, instagram, reddit |
| video | 8 | 75 | tiktok, youtube, bilibili, douyin |
| news | 11 | 45 | hackernews, bloomberg, bbc, 36kr |
| finance | 10 | 67 | eastmoney, xueqiu, binance, coingecko |
| shopping | 13 | 47 | amazon, jd, taobao, 1688 |
| dev | 37 | 180 | codex, cursor, gh, stackoverflow |
| ai | 25 | 215 | chatgpt, antigravity, chatwise, notebooklm |
| scholarly | 22 | 81 | openreview, zotero, pubmed, arxiv |
| patent | 17 | 42 | epo, espacenet, cipo, cnipa |
| reference | 12 | 48 | marxists-cn, imdb, anilist, bangumi |
| audio | 4 | 46 | spotify, netease-music, xiaoyuzhou, apple-podcasts |
| content | 16 | 93 | lesswrong, danbooru, dlsite, weread |
| productivity | 10 | 78 | notion-app, ones, obsidian, quark |
| jobs | 6 | 42 | nowcoder, boss, 51job, linkedin |
| desktop | 25 | 201 | macos, freecad, blender, gimp |
| games | 1 | 7 | steam |
| utility | 7 | 29 | linear, bitwarden, todoist, qweather |
| other | 68 | 116 | slay-the-spire-ii, xiaoe, archive, ke |
| travel | 1 | 4 | ctrip |
The generated operation catalog is the authoritative inventory.
unicli search "download the latest arXiv paper on computer use" -f json
unicli arxiv search "computer use agents" --limit 5 -f json
unicli --auth-retry openreview conference "ICML.cc/2026/Conference" --rpm 20 -f json
unicli extract https://example.com --max-chars 1200
Piped output defaults to Markdown. Use -f json, yaml, csv, or compact when the next step needs a stable machine format.
The OpenReview archive guide
covers authenticated, resumable conference and multi-year research archives.
{
"mcpServers": {
"unicli": {
"command": "npx",
"args": ["-y", "@zenalexa/unicli-mcp"]
}
}
}
Equivalent command:
npx -y @zenalexa/unicli mcp serve
The default profile exposes four meta-tools. Deferred and expanded profiles project adapter operations when the host needs tool-level discovery. Inspect the live projection with unicli mcp health -f json.
unicli compute apps --format compact
unicli compute snapshot --app Calculator --format compact
unicli compute find --app Calculator --role AXButton --title "7"
unicli compute click --ref <ref-from-find>
Desktop actions prefer accessibility references. Visual routes require an explicitly selected backend and never appear as a hidden fallback.
Success:
ok: true
schema_version: "2"
command: "hackernews.top"
meta:
duration_ms: 412
count: 3
surface: web
data:
- { rank: "1", title: "...", url: "...", author: "..." }
error: null
Failure:
ok: false
schema_version: "2"
command: "reddit.saved"
data: null
error:
code: auth_required
adapter_path: "src/adapters/reddit/saved.yaml"
step: 1
suggestion: "Run: unicli auth setup reddit"
retryable: false
Exit codes distinguish success, empty results, unavailable dependencies, temporary failures, auth, and configuration. See the output and exit-code reference.
Adapters stay agent-readable and locally replaceable:
run → read error.adapter_path → patch the owned step → save override → verify once
unicli repair <site> <command>
repair does not edit source or Git state. It reruns the original command as a bounded subprocess and succeeds only when the target returns ok: true with exit code 0. Local overrides under ~/.unicli/adapters/ survive npm updates.
A minimal YAML adapter:
site: example
name: search
description: Search example.com
transport: http
strategy: public
pipeline:
- fetch: { url: "https://api.example.com/search?q=${{ args.query }}" }
- select: data.results
- map: { title: "${{ item.title }}", url: "${{ item.url }}" }
- limit: "${{ args.limit }}"
args:
- { name: query, type: string, required: true, positional: true }
- { name: limit, type: int, default: 20 }
columns: [title, url]
Read the adapter format, pipeline reference, and self-repair guide.
auth import or browser cookies.~/.unicli/. Chrome 136+ does not support remote debugging on its default user-data directory.unicli browser doctor --json reports the available delivery path and exact repair command without starting a browser provider.UNICLI_NO_LOG=1.The detailed behavior and storage paths live in Trust, Auth, and Limits.
npm install
npm run typecheck
npm run lint
npm test
npm run verify # full E2E and adapter coverage; required before release
Requires Node.js 22.19 or newer. See CONTRIBUTING.md for adapter and engine conventions.
v1.0.3 — Artemis · Glover
Apache-2.0
FAQs
Give agents every interface—install once to search, run, inspect, and repair real software across APIs, browsers, desktops, local tools, and MCP.
The npm package @zenalexa/unicli receives a total of 156 weekly downloads. As such, @zenalexa/unicli popularity was classified as not popular.
We found that @zenalexa/unicli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.