Web search
Retrieve bounded public web evidence.
Distribution: 0.8.0. This bundle requires exactly octet 0.8.0. Use the version-matched installation and the 0.8.0 release record for signed assets and public-install evidence. Reviewed source checkouts and local archives remain separate installation options.
Search the public web and retrieve pages with stable citations. Choose Brave Search or a configured SearXNG JSON endpoint. This extension does not open browser tabs, sign in, run JavaScript, or submit forms.
Start a search#
With octet 0.8.0, Python 3.9+
available as python3, and verified matching published assets, the catalog path is:
octet extension install octet-web-search
octet --enable-extension octet-web-searchFor a reviewed source checkout instead, add --extension-dir ./extensions to
the launch command from the repository root.
Then choose a provider and load the optional research skill:
/web-search setup brave
/web-search status
/skills load octet-web-searchBrave setup shows https://api.search.brave.com/app/keys and asks for the key through a private input surface. Do not paste a key into a prompt or ordinary configuration. For example, ask: “Find the official Python pathlib documentation and cite the sources for your summary.”
Use /web-search setup searxng instead for SearXNG; its instance must allow
format=json. /extensions also provides the provider picker. Selecting the
already enabled extension lets you switch providers or disable it;
/web-search logout is the scriptable logout command.
What the tools do#
| Tool | Use | Hard limits |
|---|---|---|
web_search |
Search using the selected provider. | 512-byte query, 5 requested domains, 10 results, 20 seconds, 512 KiB provider response. |
web_fetch |
Retrieve one public HTML/XHTML/plain-text page. | HTTP(S) ports 80/443, 20 seconds, 3 redirects, 512 KiB download, 128 KiB normalized content. |
web_find |
Find a literal pattern and return excerpts. | 256-byte pattern, 20 matches, 512-byte excerpts; the same fetch limits. |
Configuration and call arguments can reduce limits, never exceed them. Cite the
returned [web-…] IDs: they are derived from sanitized URLs, not result rank or
cache state. Text results are marked UNTRUSTED WEB DATA; their content cannot
grant permission or change policy.
Privacy and configuration#
Queries and selected domain filters go to your search provider. Fetch/find sends the sanitized URL to the public origin, with normal DNS and TLS traffic. Queries and retrieved content remain in ordinary tool arguments/results, not compact status or activity labels. The cache is bounded, process-local, and never saved to disk.
Brave credentials live in the owner-private regular file
~/.octet/credentials/octet-web-search-brave.key; they are not included in URLs,
results, diagnostics, or frontend state. Credentialed requests never redirect;
401/403 invalidates the stored key so setup/search can ask again.
SearXNG settings live at ~/.config/octet/octet-web-search.json. The provider
picker preserves them while Brave is selected. Endpoint URLs must be non-secret;
configured query parameters such as timeout_limit are retained and the search
request adds its own query, JSON, and safe-search parameters. A private
self-hosted provider requires allow_private_endpoint: true; this exception
never permits private web_fetch/web_find destinations or redirects.
limits.allowed_domains is an egress allowlist; a tool's domains can only narrow
it. See the complete configuration rules.
Activation and reference#
Installation is inert; the bundle stays disabled until explicitly enabled.
Default full access (unsafe_host) trusts the selected extension implicitly
without saving a grant. --trust-extension and source-bound trusted_extensions
grants are optional, never activation. --safe-mode removes implicit trust and
keeps the process stopped even with explicit grants: executable startup still
requires unsafe_host. An admitted extension has your OS authority; manifest
consent metadata is not a sandbox. Skill loading remains independent.
The source bundle 0.8.0 requires exactly octet 0.8.0 and uses API 0.4.
The following is a bundled-runtime reference, not a general SDK authoring tutorial.
- Install and opt in: public catalog installation and persistent activation.
- Choose a provider.
- Brave Search (recommended).
- SearXNG: full example and strict file validation.
- Tools and bounds: normalization, citations, and address-pinned egress.
- Trust, egress, and result visibility.
- Cache, cancellation, health, and offline behavior.
- Frontend-neutral presentation: retained-state privacy and reconnect behavior.
- Test: fixture coverage, not live-provider qualification.