Repository research · research next

Wigolo: research next

Research status: source-checked. Not installed, executed, benchmarked, adopted, security-reviewed, or recommended here. This card tracks KnockOutEZ/wigolo for a possible future evaluation; it summarizes source research, not hands-on results.

The canonical repository describes Wigolo as a local-first web-intelligence server for AI agents, with acquisition and research functions exposed through MCP, REST, a CLI, and SDK integrations. That makes it a relevant candidate for the acquisition interface discussed in Reproducible web acquisition, but documented capability is not evidence from a local evaluation.

What “local-first” means here

The project's privacy and security documentation describes local processing and a default data directory under ~/.wigolo. That directory can contain fetched pages, search results, indexes, jobs, models, configuration, plugins, skill receipts, shell history, and optional encrypted credential files.

It is not an offline tool. Queries make requests to search engines and target websites. Initial setup or first use can download browser and model components. A configured remote language-model provider receives synthesis requests, and a user-configured telemetry endpoint can receive events when both telemetry and that endpoint are enabled. The project says there is no default vendor telemetry endpoint.

Current source snapshot

At the September 20 source check, package metadata identified version 0.2.1, Node.js 20 or newer, and the GNU AGPL-3.0-only license; the repository labeled the project public beta. The repository documentation described a roughly 1.5 GB disk footprint for browser and on-device model components. These are observed source facts, not a promise that the version or requirements remain current.

The license and separate trademark policy may affect modified network-service deployments and redistribution. Review those source terms for the intended use; this card is not legal advice.

Open issue reports are useful evaluation inputs, not confirmed findings. As of the source-check date, reports included bot-challenge timeout behavior, proxy configuration, authenticated browser-state handling, MCP conformance, and search-engine selection. A trial should attempt to reproduce relevant reports rather than treating issue titles as product behavior.

A bounded evaluation plan

Use a disposable environment and synthetic, non-authenticated targets. Before installation, record an exact release and artifact digest, inspect dependency and installation behavior, and decide whether the AGPL and trademark terms fit the intended deployment.

Run the same fixed acquisition cases in three configurations: no language model, a local model, and—only if separately authorized—a remote provider. Capture DNS and network egress, files written, resource use, source URLs, provenance spans, failure labels, cache behavior, and repeat-run differences. Do not put credentials or private pages in the fixture set.

Exercise robots and rate-limit handling, stale-cache behavior, prompt-injection containment, malformed content, and partial backend failure. Separately test remote REST authentication and origin handling, plugin and executable supply-chain boundaries, supported platforms, uninstall behavior, and complete data deletion.

The decision record should say which exact cases passed, failed, or were not run. An install is not adoption, and a successful happy path is not a recommendation.

Primary sources

Continue

Keep reading

Repository research records →

All library entries →