Web
web_fetch downloads a page and returns its main content as Markdown:
- Scripts, navigation, headers and footers, and decorative images are stripped, and links are resolved against the page URL.
- Text and JSON responses are returned as-is.
- Long pages come back in chunks (
start/max_length). - It asks per domain. "Always allow" saves a rule such as
web_fetch(domain:go.dev), which also covers subdomains. - A redirect to a different host is reported rather than followed, so it can't sidestep a domain rule.
- Link-local and cloud-metadata addresses (
169.254.169.254and similar) are blocked. - Responses are capped at 5 MB and 30 s, and cached for 15 minutes.
web_search appears when a search backend is configured. Larik detects one from the environment:
| Backend | Setting |
|---|---|
| Brave Search | BRAVE_API_KEY |
| Tavily | TAVILY_API_KEY |
| SearXNG (self-hosted; enable the JSON format) | SEARXNG_URL |
You can also set it explicitly:
{ "web": { "search": { "provider": "brave", "api_key_env": "MY_BRAVE_KEY" } } }
Trust and permissions:
- Search settings are honored only from personal files, since a shared
.larik/settings.jsoncould otherwise send your queries to its own server. Shared files can only disable web tools ("web": {"fetch_disabled": true}or{"search": {"disabled": true}}). - Both tools ask before running (
web_searchcan be always-allowed). - Plan mode asks for them rather than blocking them, because research is part of planning.
- Web content is marked as untrusted data for the model.
Browser
For pages that need JavaScript, a sign-in or clicking through, Larik can drive a real Chrome window. It's off by default; turn it on in your personal config:
{ "browser": { "enabled": true } }
Chrome (or Chromium) must be installed; set "chrome_path" if Larik can't find it, and "headless": true to hide the window. Chrome starts on the first browser call and keeps its own profile under ~/.local/share/larik/browser-profile, so sign-ins you make in that window last between sessions.
The model gets these tools:
| Tool | Does |
|---|---|
browser_navigate |
Opens a URL and returns a snapshot of the page |
browser_snapshot |
The page's text, plus its links, buttons and fields, each with a ref such as e12 |
browser_screenshot |
An image of the viewport, the full page or one element; labels draws each ref on it |
browser_click |
Clicks (or hovers) an element by ref with a real mouse event |
browser_type |
Types into a field by ref, key by key; optionally presses Enter |
browser_select |
Picks options in a <select> |
browser_press_key |
Presses Enter, Escape, Tab, arrow keys, PageDown… |
browser_history |
Back and forward |
browser_tabs |
Lists, opens, selects and closes tabs; tabs a page opens become active |
browser_eval |
Runs a JavaScript expression in the page |
browser_console |
Console messages, exceptions and dialogs since the last call |
browser_navigateasks per domain likeweb_fetch("always allow" savesbrowser_navigate(domain:github.com)), only opens http(s), and refuses link-local and cloud-metadata addresses. Clicks and typing ask per call unless you allow the tool.- Plan mode asks before opening a page and blocks everything that could change something on a site.
browser_snapshot,browser_screenshotandbrowser_consoleonly read, so they never ask. - Screenshots need a model that can see images. They're JPEGs at one pixel per CSS pixel (a 1280×900 viewport is about 1,500 tokens on Claude) and stay in the conversation until it's compacted.
- Only personal files can enable the browser or choose its binary; a shared
.larik/settings.jsoncan only switch it off. - Alerts are accepted and confirm or prompt dialogs dismissed automatically, and noted in
browser_console.