agent-tollbooth
Web access privileges for your agent. So your agent stops hitting walls. Skill: agent-tollbooth Owner: highnoonoffice Summary: Web access privileges for your agent. So your agent stops hitting walls. Tags: latest:2.2.1 Version history: v2.2.1 | 2026-08-25T03:47:03.253Z | user Add contact footer v2.2.0 | 2026-04-19T22:13:45.172Z | user Fix: promote-profile.py now writes to $OPENCLAW_WORKSPACE/data/agent-tollbooth/profiles.md — bundled references/profiles.md is read-only. Resolves write-bac
Rank
62
Safety
84
Downloads
1.1k
Updated
Oct 11, 2026
Version
2.2.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 2.2.1release · observed Aug 25, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17788hys8dcemdm7pfhe61p9d83hbhs:agent-tollbooth- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-highnoonoffice-agent-tollbooth/snapshot"
Documentation
CLAWHUB
128,539 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: agent-tollbooth
version: 2.0.0
description: "Web access privileges for your agent. So your agent stops hitting walls."
homepage: https://github.com/highnoonoffice/agent-tollbooth
source: https://github.com/highnoonoffice/agent-tollbooth
license: MIT
metadata: ~
config:
- $OPENCLAW_WORKSPACE/data/agent-tollbooth/web-access-log.json — event log written by scripts/web-log.py
- $OPENCLAW_WORKSPACE/data/agent-tollbooth/cache/ — price and response cache written by fetch-crypto.py and fetch-prices.py
---
# Agent Tollbooth
You're mid-task. Your agent fires a Yahoo Finance request. Gets a 429. Stops. You don't know if it's rate limits, a bad endpoint, a missing header, or just bad luck. You try again. Same thing. You start debugging blind.
Tollbooth is the field notes that stop this from happening twice. Observed operating profiles for 16 external services — safe endpoints, sleep intervals, caching patterns, auth requirements — built from real API friction. Your agent checks the profile before calling, follows the safe pattern, and logs what happens. Next time it already knows.
Every external service has a threshold. This skill provides the map so agents learn them once and stop hitting them twice.
## Core Pattern
Before calling any external service:
1. Check `references/profiles.md` for an existing profile
2. Follow its safe pattern — endpoint, sleep, cache, auth
3. If no profile exists, observe behavior and add an entry after
## Caching
Always cache prices and API responses locally when TTL allows.
- Default TTL: 300s (5 minutes) for prices
- Cache file: `$OPENCLAW_WORKSPACE/data/agent-tollbooth/cache/`
- Serve from cache first — only hit the API when stale or forced
**Script:** `scripts/fetch-prices.py` implements cache + sequential Yahoo Finance fetching. Use it instead of raw requests. CoinGecko and other services are covered by profiles in `references/profiles.md`.
## How It Learns
Tollbooth grows with your usage. Three scripts form the learning loop:
**Before any external call:**
```bash
python3 scripts/check-profile.py coingecko.com
```
Returns the safe pattern if a profile exists. If not, logs the miss and returns exit code 1 — your agent can continue, but observation has started.
**During any call — log what happens:**
```python
from scripts.web_log import log_event
log_event("my-api.com", "429", "hit rate limit at 10 req/min", worked=None)
log_event("my-api.com", "success", "sequential 500ms sleep worked", worked="sequential + 500ms sleep")
```
**After enough observations — promote to a profile:**
```bash
python3 scripts/promote-profile.py # dry run, see what's ready
python3 scripts/promote-profile.py --write # append drafts to profiles.md
```
Default threshold: 5 events. Auto-drafted profiles include all observed friction and working patterns. Review before trusting — they're drafts, not finished entries.
Events are written to `$OPENCLAW_WORKSPACE/data/agent-tollbooth/web-access-log.json` — outside the_meta.json
{
"ownerId": "kn7826mqweky3s8ys5qd8fzqyh832g8w",
"slug": "agent-tollbooth",
"version": "2.2.1",
"publishedAt": 1787629623253
}references/profiles.md
# Service Profiles — Observed Operating Behavior
Each entry: safe pattern, known failure modes, first observed date.
---
## Yahoo Finance
- **Endpoint:** `query2.finance.yahoo.com` — preferred. `query1` rate-limits faster.
- **Auth:** None — User-Agent header required (`Mozilla/5.0 ...`)
- **Safe pattern:** Sequential requests, 0.6s sleep between tickers
- **Never:** Parallel requests — triggers 429 immediately
- **Cache:** 5 minutes minimum — serve from cache whenever possible
- **Crypto:** Use CoinGecko instead — single batch call, more reliable
- **Script:** `scripts/fetch-prices.py` wraps all of this automatically
- **First observed:** 2026-04-17
---
## CoinGecko
- **Endpoint:** `api.coingecko.com/api/v3/simple/price`
- **Auth:** None on free tier
- **Safe pattern:** Batch all coins in one call — `ids=bitcoin,ethereum,solana&vs_currencies=usd&include_24hr_change=true`
- **Free tier:** Generous — rarely rate-limits on normal usage
- **Cache:** 5 minutes via `fetch-prices.py`
- **First observed:** 2026-04-17
---
## Ghost Admin API
- **Endpoint:** `https://<site>.ghost.io/ghost/api/admin/`
- **Auth:** JWT token generated fresh each call from Admin API key
- **Key location:** your credentials file → field `key` (format: `{"key": "<id>:<secret>"}`)
- **Permission wall:** Integration tokens cannot write to `/settings/` — owner-only. Browser automation required for code injection and theme uploads.
- **Image uploads:** Python `requests` only — curl multipart breaks on macOS zsh
- **First observed:** 2026-03-17
---
## ClawHub API
- **Endpoint:** `https://clawhub.ai/api/v1/skills`
- **Auth:** Bearer token from your credentials file
- **Safe pattern:** Python `requests` with multipart — `data={"payload": json.dumps(payload)}` + `files=[...]`
- **Never:** curl — JSON quoting breaks silently on zsh, returns `Invalid JSON payload` every time
- **Never:** Browser importer — intermittent server errors, unreliable
- **First observed:** 2026-03-18
---
## Telegram Bot API
- **Pattern:** Use OpenClaw `message` tool — never raw curl
- **File delivery:** `sendDocument` endpoint for PDFs and media
- **Rate limits:** 30 messages/second global, 1 message/second per chat
- **First observed:** 2026-03-14
---
## Replicate (FLUX image gen)
- **Auth:** API token via OpenClaw config
- **Error quirk:** "Less than $5.0 in credit" error message is unreliable — check dashboard for real balance
- **Cost:** FLUX 1.1 Pro ~$0.02–0.04/image — $15 balance = 350–700 images. Never needs a top-up for normal usage.
- **First observed:** 2026-03-19
---
## OpenAI API
- **Endpoint:** `api.openai.com/v1/`
- **Auth:** Bearer token — `Authorization: Bearer sk-...`
- **Rate limits:** Tier-dependent. Free tier: 3 RPM / 200 RPD. Tier 1+: 500–3,500 RPM depending on model. Check `x-ratelimit-remaining-requests` response header.
- **Token limits separate from request limits:** A single request can burn your TPM ceiling without hitting RPM. Watch both.
- **Safe pattern:** Exposkill-card.md
## Description: Web access privileges for your agent so your agent stops hitting walls. This skill is ready for commercial/non-commercial use. ## Publisher: [highnoonoffice](https://clawhub.ai/user/highnoonoffice) ### License/Terms of Use: MIT-0 ## Use Case: Developers and agents use this skill to check observed operating profiles for external services before making web or API calls, including rate-limit patterns, caching guidance, authentication requirements, and known failure modes. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill may guide an agent to use authenticated third-party APIs when the user's task requires them. Mitigation: Confirm API credentials, write permissions, and paid API use before allowing the agent to perform authenticated or billable actions. Risk: Generated or promoted service profiles may be drafts based on local observations. Mitigation: Review generated profiles before relying on them for writes, paid APIs, or repeated automated calls. Risk: The skill keeps local logs and cache files in the OpenClaw workspace. Mitigation: Review the workspace log and cache location and clear retained data when it is no longer needed. ## Reference(s): - [Service Profiles - Observed Operating Behavior](references/profiles.md) - [ClawHub skill page](https://clawhub.ai/highnoonoffice/skills/agent-tollbooth) - [Project homepage](https://github.com/highnoonoffice/agent-tollbooth) ## Skill Output: **Output Type(s):** [Guidance, Shell commands, Code, Configuration] **Output Format:** [Markdown with inline bash and Python code blocks] **Output Parameters:** [1D] **Other Properties Related to Output:** [Guidance may reference local OpenClaw log and cache paths under $OPENCLAW_WORKSPACE/data/agent-tollbooth/.] ## Skill Version(s): 2.2.1 (source: server release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/highnoonoffice/skills/agent-tollbooth",
"sourceUrl": "https://clawhub.ai/highnoonoffice/skills/agent-tollbooth",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T10:56:25.747Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-highnoonoffice-agent-tollbooth/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-highnoonoffice-agent-tollbooth/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T10:56:25.747Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.1K downloads",
"href": "https://clawhub.ai/highnoonoffice/agent-tollbooth",
"sourceUrl": "https://clawhub.ai/highnoonoffice/agent-tollbooth",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T10:56:25.747Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.2.1",
"href": "https://clawhub.ai/highnoonoffice/agent-tollbooth",
"sourceUrl": "https://clawhub.ai/highnoonoffice/agent-tollbooth",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-25T03:47:03.253Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-highnoonoffice-agent-tollbooth/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-highnoonoffice-agent-tollbooth/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.2.1",
"description": "Add contact footer",
"href": "https://clawhub.ai/highnoonoffice/agent-tollbooth",
"sourceUrl": "https://clawhub.ai/highnoonoffice/agent-tollbooth",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-25T03:47:03.253Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
