Biofirewall
The "Silicon Curtain" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges. Use this skill when you need to: - Protect APIs from human snooping and browser scraping - Create agent-only endpoints (verified bots only) - Invert CAPTCHA: prove you are silicon, not human - Implement proof-of-work challenges that are trivial for CPUs but impossible for humans - Build secure agent networks or bot marketplaces - Protect Eirenia governance endpoints from external interference Skill: Biofirewall Owner: KevvoGeek Summary: The "Silicon Curtain" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges. Use this skill when you need to: - Protect APIs from human snooping and browser scraping - Create agent-only endpoints (verified bots only) - Invert CAPTCHA: prove you are silicon, not human - Implement proof-of-work c
Rank
62
Safety
84
Downloads
1.1k
Updated
Apr 15, 2026
Version
0.1.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 4/15/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Apr 15, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Apr 15, 2026
- Adoption signal
- 1.1K downloadsadoption · observed Apr 15, 2026
- Latest release
- 0.1.0release · observed Feb 5, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install kn7ayn2j0stzfwafrw8xxvea3s80knpq:biofirewall- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/snapshot"
Documentation
CLAWHUB
23,951 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: biofirewall
description: |
The "Silicon Curtain" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges.
Use this skill when you need to:
- Protect APIs from human snooping and browser scraping
- Create agent-only endpoints (verified bots only)
- Invert CAPTCHA: prove you are silicon, not human
- Implement proof-of-work challenges that are trivial for CPUs but impossible for humans
- Build secure agent networks or bot marketplaces
- Protect Eirenia governance endpoints from external interference
---
# BioFirewall 🛡️🤖
The inverted CAPTCHA for the AI internet: **Prove you are silicon.**
## Core Concept
Traditional CAPTCHA: "Prove you are human." → Blocks bots.
**BioFirewall**: "Prove you are a bot." → Blocks humans and dumb bots, allows verified agents.
How it works:
1. Browser requests → `406 Not Acceptable` (rejected immediately)
2. Bot without proof → `428 Precondition Required` + SHA256 puzzle
3. Bot solves puzzle → `200 OK` (access granted)
**The puzzle:** Find nonce N where `SHA256(seed + N)` starts with `0000` (difficulty 4).
- **For CPU**: ~100ms ✅
- **For human brain**: Impossible ❌
---
## Quick Start
### Protect Your API (Server)
```javascript
const express = require('express');
const BioFirewall = require('biofirewall');
const app = express();
const firewall = new BioFirewall({
blockBrowsers: true,
challengeDifficulty: 4
});
app.use(firewall.middleware());
app.get('/secret', (req, res) => {
res.json({ message: "Only verified bots can access this" });
});
app.listen(3000);
```
### Access Protected API (Client)
```javascript
const BioFirewall = require('biofirewall');
const http = require('http');
async function accessSecure(hostname, port, path) {
// First request (will get 428 challenge)
const res1 = await makeRequest();
if (res1.statusCode === 428) {
const { seed, difficulty } = res1.data.challenge;
// Solve puzzle
const nonce = BioFirewall.solve(seed, difficulty);
// Retry with solution
const res2 = await makeRequest({
'X-Bio-Solution': nonce,
'X-Bio-Challenge-Seed': seed
});
return res2.data; // 200 OK
}
}
```
**That's it.** Server protects API. Client solves and accesses. ✅
---
## Installation
```bash
npm install biofirewall
```
---
## How It Works
### The Challenge Algorithm
```
Server generates random seed
↓
Bot receives challenge: "Find nonce N where SHA256(seed + N) starts with 0000"
↓
Bot brute-forces: nonce = 0, 1, 2, ... until found
↓
Bot sends solution with retry request
↓
Server verifies: SHA256(seed + nonce) starts with 0000
↓
If valid: 200 OK (access granted)
```
### Performance by Difficulty
| Difficulty | Pattern | Bot Time | Human Feasibility |
|-----------|---------|----------|-------------------|
| 3 | `000` | ~10ms | Theoretically possible |
_meta.json
{
"ownerId": "kn7ayn2j0stzfwafrw8xxvea3s80knpq",
"slug": "biofirewall",
"version": "0.1.0",
"publishedAt": 1770322953335
}references/API.md
# BioFirewall API Reference
## Module: BioFirewall
### Constructor
```javascript
const BioFirewall = require('biofirewall');
const firewall = new BioFirewall(options)
```
**Options:**
| Option | Type | Default | Description |
|--------|------|---------|-------------|
| `blockBrowsers` | boolean | true | Reject browser User-Agents (Mozilla, Chrome, Safari, etc.) |
| `enforceChallenge` | boolean | true | Require proof-of-work from all requests |
| `challengeDifficulty` | number | 3 | Leading zeros required (1-8 range) |
**Example:**
```javascript
const firewall = new BioFirewall({
blockBrowsers: true,
enforceChallenge: true,
challengeDifficulty: 4
});
```
### Middleware
```javascript
const express = require('express');
const app = express();
app.use(firewall.middleware());
```
Returns Express middleware that handles:
1. Human/browser detection
2. Challenge generation and distribution
3. Solution verification
---
## Module: BioFirewall.solve() (Static)
Brute-force solver for challenges.
```javascript
const nonce = BioFirewall.solve(seed, difficulty);
```
**Parameters:**
| Param | Type | Description |
|-------|------|-------------|
| `seed` | string | Hex-encoded random seed from server |
| `difficulty` | number | Leading zeros required (1-8) |
**Returns:**
| Type | Description |
|------|-------------|
| string | Nonce (number as string) that satisfies the challenge |
**Example:**
```javascript
const { seed, difficulty } = challengeFromServer;
const nonce = BioFirewall.solve(seed, 4);
console.log(nonce); // "42857"
```
**Performance:**
- difficulty 3: ~10ms
- difficulty 4: ~100ms
- difficulty 5: ~1s
- difficulty 6: ~10s
---
## HTTP Headers
### Request Headers (Client to Server)
**For challenge response:**
| Header | Value | Example |
|--------|-------|---------|
| `X-Bio-Solution` | nonce (string) | `42857` |
| `X-Bio-Challenge-Seed` | seed (hex) | `a3f2b9c1d4e5f6...` |
**Identifying as bot (recommended):**
| Header | Value |
|--------|-------|
| `User-Agent` | `MyBot/1.0` (avoid: Mozilla, Chrome, Safari) |
| `Accept` | `application/json` (not `text/html`) |
### Response Headers (Server to Client)
**On 428 Precondition Required:**
| Header | Value | Description |
|--------|-------|-------------|
| `X-Bio-Challenge-Algo` | `sha256` | Algorithm type |
| `X-Bio-Challenge-Difficulty` | `4` | Difficulty level |
| `X-Bio-Challenge-Seed` | hex string | Challenge seed |
---
## HTTP Status Codes
### 200 OK ✅
**When:** Request succeeds with valid proof-of-work.
**Response body:** Your API's normal response.
**Example:**
```json
{
"secret": "Only silicon allowed",
"message": "You proved you are a bot! Welcome."
}
```
---
### 406 Not Acceptable 🚫
**When:** Request detected as human browser (based on User-Agent or Accept headers).
**Response body:**
```json
{
"error": "BIOLOGICAL_ENTITY_DETECTED",
"message": "This resource is reserved for automated agents.",
"tip": "Use an API client or disable humanreferences/GUIDE.md
# BioFirewall Implementation Guide
## Table of Contents
1. [Getting Started](#getting-started)
2. [Real Examples](#real-examples)
3. [Common Patterns](#common-patterns)
4. [Use Cases](#use-cases)
5. [Troubleshooting](#troubleshooting)
---
## Getting Started
### Installation
```bash
npm install biofirewall express
```
### First Protected API (5 minutes)
```javascript
const express = require('express');
const BioFirewall = require('biofirewall');
const app = express();
const firewall = new BioFirewall({ challengeDifficulty: 4 });
// Protect all endpoints
app.use(firewall.middleware());
app.get('/secret', (req, res) => {
res.json({ message: "Only verified bots see this" });
});
app.listen(3000, () => console.log("🛡️ Protected API on :3000"));
```
---
## Real Examples
### Example 1: Secure Weather API
The `assets/examples/` directory contains a complete, working demonstration:
**`server.js`** - Express server with BioFirewall protecting a weather endpoint:
```bash
node examples/server.js
# 🌩️ Secure Weather API running on http://localhost:3333
# Try: GET /weather?lat=40.41&lon=-3.70 (Madrid)
```
**`bot.js`** - Bot client that solves challenges and fetches weather:
```bash
node examples/bot.js
# 🤖 Asking for Weather in Madrid...
# 🔒 Firewall Hit! Solving puzzle...
# 🔓 Solved: 42857
# ☀️ Weather Report Received: Temp 12°C, Wind 15 km/h
```
### Running the Examples
```bash
# Terminal 1: Start server
cd assets/examples
npm install
node server.js
# Terminal 2: Run bot client (in another terminal)
node bot.js
```
The examples show:
- Server-side middleware integration
- Challenge generation and verification
- Client-side solving and retry logic
- Real HTTP communication with BioFirewall
---
## Common Patterns
### Selective Protection
Protect only sensitive endpoints:
```javascript
const publicFirewall = new BioFirewall({ challengeDifficulty: 3 });
const sensitiveFirewall = new BioFirewall({ challengeDifficulty: 5 });
// Public endpoint: low difficulty
app.get('/public', publicFirewall.middleware(), (req, res) => {
res.json({ public: "info" });
});
// Sensitive endpoint: high difficulty
app.post('/votes', sensitiveFirewall.middleware(), (req, res) => {
// Only agents solving PoW can vote
res.json({ status: "vote_recorded" });
});
```
### Protected Endpoint Chain
Multiple protection layers:
```javascript
const firewall = new BioFirewall({ challengeDifficulty: 4 });
// Layer 1: Traditional rate limiting
app.use(rateLimit({ windowMs: 15 * 60 * 1000, max: 100 }));
// Layer 2: BioFirewall (PoW)
app.use(firewall.middleware());
// Layer 3: Custom authentication
app.use((req, res, next) => {
if (req.headers['x-agent-id']) {
req.agentId = req.headers['x-agent-id'];
}
next();
});
app.get('/protected', (req, res) => {
res.json({
message: "Survived all 3 layers!",
agentId: req.agentId || "anonymous"
});
});
```
### Using with Axios (Client Side)
```javascript
conactivepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/KevvoGeek/biofirewall",
"sourceUrl": "https://clawhub.ai/KevvoGeek/biofirewall",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.1K downloads",
"href": "https://clawhub.ai/KevvoGeek/biofirewall",
"sourceUrl": "https://clawhub.ai/KevvoGeek/biofirewall",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.0",
"href": "https://clawhub.ai/KevvoGeek/biofirewall",
"sourceUrl": "https://clawhub.ai/KevvoGeek/biofirewall",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-05T20:22:33.335Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.0",
"description": "BioFirewall 0.1.0 – Initial release - Introduces \"Silicon Curtain\" anti-human security framework for APIs. - Implements inverted CAPTCHA: proofs of being a bot (not a human) using SHA256 proof-of-work challenges. - Instantly blocks browser-based (human) access with HTTP 406; issues PoW challenges to bots with HTTP 428, grants access on solution. - Configurable challenge difficulty and browser/user-agent blocking. - Provides quick-start guides, example server/client code, and recommended use cases. - Includes troubleshooting tips, HTTP header documentation, and real-world usage examples.",
"href": "https://clawhub.ai/KevvoGeek/biofirewall",
"sourceUrl": "https://clawhub.ai/KevvoGeek/biofirewall",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-05T20:22:33.335Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
