larik v0.3.0

Guide

Web

web_fetch downloads a page and returns its main content as Markdown:

  • Scripts, navigation, headers and footers, and decorative images are stripped, and links are resolved against the page URL.
  • Text and JSON responses are returned as-is.
  • Long pages come back in chunks (start / max_length).
  • It asks per domain. "Always allow" saves a rule such as web_fetch(domain:go.dev), which also covers subdomains.
  • A redirect to a different host is reported rather than followed, so it can't sidestep a domain rule.
  • Link-local and cloud-metadata addresses (169.254.169.254 and similar) are blocked.
  • Responses are capped at 5 MB and 30 s, and cached for 15 minutes.

web_search appears when a search backend is configured. Larik detects one from the environment:

Backend Setting
Brave Search BRAVE_API_KEY
Tavily TAVILY_API_KEY
SearXNG (self-hosted; enable the JSON format) SEARXNG_URL

You can also set it explicitly:

json
{ "web": { "search": { "provider": "brave", "api_key_env": "MY_BRAVE_KEY" } } }

Trust and permissions:

  • Search settings are honored only from personal files, since a shared .larik/settings.json could otherwise send your queries to its own server. Shared files can only disable web tools ("web": {"fetch_disabled": true} or {"search": {"disabled": true}}).
  • Both tools ask before running (web_search can be always-allowed).
  • Plan mode asks for them rather than blocking them, because research is part of planning.
  • Web content is marked as untrusted data for the model.

Browser

For pages that need JavaScript, a sign-in or clicking through, Larik can drive a real Chrome window. It's off by default; turn it on in your personal config:

json
{ "browser": { "enabled": true } }

Chrome (or Chromium) must be installed; set "chrome_path" if Larik can't find it, and "headless": true to hide the window. Chrome starts on the first browser call and keeps its own profile under ~/.local/share/larik/browser-profile, so sign-ins you make in that window last between sessions.

The model gets these tools:

Tool Does
browser_navigate Opens a URL and returns a snapshot of the page
browser_snapshot The page's text, plus its links, buttons and fields, each with a ref such as e12
browser_screenshot An image of the viewport, the full page or one element; labels draws each ref on it
browser_click Clicks (or hovers) an element by ref with a real mouse event
browser_type Types into a field by ref, key by key; optionally presses Enter
browser_select Picks options in a <select>
browser_press_key Presses Enter, Escape, Tab, arrow keys, PageDown…
browser_history Back and forward
browser_tabs Lists, opens, selects and closes tabs; tabs a page opens become active
browser_eval Runs a JavaScript expression in the page
browser_console Console messages, exceptions and dialogs since the last call
  • browser_navigate asks per domain like web_fetch ("always allow" saves browser_navigate(domain:github.com)), only opens http(s), and refuses link-local and cloud-metadata addresses. Clicks and typing ask per call unless you allow the tool.
  • Plan mode asks before opening a page and blocks everything that could change something on a site. browser_snapshot, browser_screenshot and browser_console only read, so they never ask.
  • Screenshots need a model that can see images. They're JPEGs at one pixel per CSS pixel (a 1280×900 viewport is about 1,500 tokens on Claude) and stay in the conversation until it's compacted.
  • Only personal files can enable the browser or choose its binary; a shared .larik/settings.json can only switch it off.
  • Alerts are accepted and confirm or prompt dialogs dismissed automatically, and noted in browser_console.

Generated from README.md · section “Web”. Edit that file to change this page.