New:Socket for Asana Is Now Available.Learn more
Get Started

@zenalexa/unicli

Package Overview
Dependencies
Maintainers
1
Versions
51
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@zenalexa/unicli

Give agents every interface—install once to search, run, inspect, and repair real software across APIs, browsers, desktops, local tools, and MCP.

Source
npmnpm
Version
1.0.3
Version published
Weekly downloads
179
-25.42%
Maintainers
1
Weekly downloads
 
Created
Source

Uni-CLI otter mascot

Uni-CLI

Give agents every interface
Install once. Search, run, inspect, repair.

Website   Operations   npm   简体中文

npm version Apache 2.0 license Node 22.19 or newer

Uni-CLI green observatory hero with one-click npm and agent prompt copy

Uni-CLI turns intent into a selected operation and a structured receipt across web, browser, desktop, local, and MCP surfaces.

npm install -g @zenalexa/unicli
unicli search "list the top Hacker News stories"
unicli hackernews top --limit 3 -f json

Route By Task

The catalog handles discovery and operation contracts. Execution then selects the strongest operator with the smallest effective scope. One provider runs; a failed path keeps its original cause and repair command.

Task boundaryExecution operatorWhy
Public data or stable service contractStructured APITyped fields, explicit auth, stable provenance
Files, system state, local toolsLocal runtimeDirect process and OS boundaries without browser state
Authenticated or private web contractBrowser protocolExplicit profile, cookie session, or network contract
Page-only web flowSemantic browserDOM and CDP semantics with an explicit target and session
Native desktop applicationAccessibilityStructured AX, UIA, or AT-SPI control trees
Pixel-only or unstructured interfaceVisual computer useCoordinate and visual observation when no stronger interface exists
unicli search "export my saved posts"     # discover and rank
unicli list --site reddit                  # inspect one surface
unicli browser doctor --json               # inspect browser delivery state
unicli repair reddit saved                 # verify a supported drift path

The Operation Contract

The public model stays compact:

intent → candidate operations → explicit selection → policy → substrate → receipt
StageRuntime behavior
DiscoverBM25 bilingual search returns a small ranked candidate set
SelectThe caller chooses one operation with a declared strategy and substrate
Governopen, confirm, and locked profiles evaluate effect and capability scope
ActThe selected adapter, core command, browser, desktop, or protocol path executes
ObserveEvery normal command returns a stable success or error envelope
RepairOwned drift paths expose their source, failed boundary, and bounded verification command

Uni-CLI supplies the interface runtime. The model, planner, agent loop, and sandbox remain independent choices.

Surfaces

SurfaceCurrent runtime
WebPublic data, cookies, headers, downloads, uploads, publishing, search, and Chinese platforms
BrowserCDP navigation, semantic action, network, snapshots, screenshots, and post-action evidence
DesktopNative controls, macOS services, design tools, Office, and media applications
LocalSubprocess bridges, files, PDF and paper workflows, media transforms, and developer CLIs
ProtocolsNative CLI, MCP stdio, MCP Streamable HTTP, ACP, generated configs, and agent skills
PolicyPermission profiles, deny rules, scoped approvals, recordings, replay, and evidence

Static catalog:

  • 326 sites
  • 1853 registered commands
  • 1250 adapters
  • 113 pipeline actions
  • 10138 tests

Fixed core and host-discovered commands join at runtime.

SurfaceSitesOperationsExamples
social33395twitter, zhihu, instagram, reddit
video875tiktok, youtube, bilibili, douyin
news1145hackernews, bloomberg, bbc, 36kr
finance1067eastmoney, xueqiu, binance, coingecko
shopping1347amazon, jd, taobao, 1688
dev37180codex, cursor, gh, stackoverflow
ai25215chatgpt, antigravity, chatwise, notebooklm
scholarly2281openreview, zotero, pubmed, arxiv
patent1742epo, espacenet, cipo, cnipa
reference1248marxists-cn, imdb, anilist, bangumi
audio446spotify, netease-music, xiaoyuzhou, apple-podcasts
content1693lesswrong, danbooru, dlsite, weread
productivity1078notion-app, ones, obsidian, quark
jobs642nowcoder, boss, 51job, linkedin
desktop25201macos, freecad, blender, gimp
games17steam
utility729linear, bitwarden, todoist, qweather
other68116slay-the-spire-ii, xiaoe, archive, ke
travel14ctrip

The generated operation catalog is the authoritative inventory.

Use It From An Agent

Native CLI

unicli search "download the latest arXiv paper on computer use" -f json
unicli arxiv search "computer use agents" --limit 5 -f json
unicli --auth-retry openreview conference "ICML.cc/2026/Conference" --rpm 20 -f json
unicli extract https://example.com --max-chars 1200

Piped output defaults to Markdown. Use -f json, yaml, csv, or compact when the next step needs a stable machine format. The OpenReview archive guide covers authenticated, resumable conference and multi-year research archives.

MCP

{
  "mcpServers": {
    "unicli": {
      "command": "npx",
      "args": ["-y", "@zenalexa/unicli-mcp"]
    }
  }
}

Equivalent command:

npx -y @zenalexa/unicli mcp serve

The default profile exposes four meta-tools. Deferred and expanded profiles project adapter operations when the host needs tool-level discovery. Inspect the live projection with unicli mcp health -f json.

Local Computer

unicli compute apps --format compact
unicli compute snapshot --app Calculator --format compact
unicli compute find --app Calculator --role AXButton --title "7"
unicli compute click --ref <ref-from-find>

Desktop actions prefer accessibility references. Visual routes require an explicitly selected backend and never appear as a hidden fallback.

Results That Explain Themselves

Success:

ok: true
schema_version: "2"
command: "hackernews.top"
meta:
  duration_ms: 412
  count: 3
  surface: web
data:
  - { rank: "1", title: "...", url: "...", author: "..." }
error: null

Failure:

ok: false
schema_version: "2"
command: "reddit.saved"
data: null
error:
  code: auth_required
  adapter_path: "src/adapters/reddit/saved.yaml"
  step: 1
  suggestion: "Run: unicli auth setup reddit"
  retryable: false

Exit codes distinguish success, empty results, unavailable dependencies, temporary failures, auth, and configuration. See the output and exit-code reference.

Repair Drift At The Owned Boundary

Adapters stay agent-readable and locally replaceable:

run → read error.adapter_path → patch the owned step → save override → verify once
unicli repair <site> <command>

repair does not edit source or Git state. It reruns the original command as a bounded subprocess and succeeds only when the target returns ok: true with exit code 0. Local overrides under ~/.unicli/adapters/ survive npm updates.

A minimal YAML adapter:

site: example
name: search
description: Search example.com
transport: http
strategy: public
pipeline:
  - fetch: { url: "https://api.example.com/search?q=${{ args.query }}" }
  - select: data.results
  - map: { title: "${{ item.title }}", url: "${{ item.url }}" }
  - limit: "${{ args.limit }}"
args:
  - { name: query, type: string, required: true, positional: true }
  - { name: limit, type: int, default: 20 }
columns: [title, url]

Read the adapter format, pipeline reference, and self-repair guide.

Trust Boundaries

  • Live browser cookies remain in process memory unless the user explicitly runs auth import or browser cookies.
  • Browser automation uses Uni-CLI-owned profiles under ~/.unicli/. Chrome 136+ does not support remote debugging on its default user-data directory.
  • unicli browser doctor --json reports the available delivery path and exact repair command without starting a browser provider.
  • Permission rules authorize before browser, file, clipboard, subprocess, or desktop side effects. Explicit malformed policies fail closed.
  • Visual routes require a real configured backend. Missing providers return a structured error.
  • Invocation diagnostics exclude arguments, content, URLs, credentials, and raw errors; users can disable new events with UNICLI_NO_LOG=1.

The detailed behavior and storage paths live in Trust, Auth, and Limits.

Development

npm install
npm run typecheck
npm run lint
npm test
npm run verify   # full E2E and adapter coverage; required before release

Requires Node.js 22.19 or newer. See CONTRIBUTING.md for adapter and engine conventions.

v1.0.3 — Artemis · Glover

License

Apache-2.0

Keywords

cli

FAQs

Package last updated on 08 Aug 2026

Related posts