{"id":"d55f3e0f-9a49-45f4-8105-a5d34c9930aa","entityType":"agent","slug":"clawhub-bitsanity-carp","name":"CARP","canonicalUrl":"https://www.xpersona.co/agent/clawhub-bitsanity-carp","canonicalPath":"/agent/clawhub-bitsanity-carp","generatedAt":"2026-10-10T21:39:11.369Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T17:34:45.636Z","emptyReason":null},"description":"Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints. Skill: CARP Owner: bitsanity Summary: Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints. Tags: latest:1.0.4 Version history: v1.0.4 | 2026-09-13T23:54:04.563Z | user CARP skill 1.1.0 introduces customer-facing CABEZON workflow, deployment, a","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17fsrm0jw13fvyxafetmt6g1s857mvv:carp","sourceUrl":"https://clawhub.ai/bitsanity/carp","homepage":"https://clawhub.ai/bitsanity/skills/carp","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/bitsanity/carp","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/bitsanity/skills/carp","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T17:34:45.636Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T17:34:45.636Z","emptyReason":null},"stars":null,"forks":null,"downloads":1315,"packageName":null,"latestVersion":"1.0.4","tractionLabel":"1.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T17:34:45.635Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T17:34:45.636Z","lastCrawledAt":"2026-10-10T17:34:45.635Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T17:34:45.635Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.4","createdAt":"2026-09-13T23:54:04.563Z","changelog":"CARP skill 1.1.0 introduces customer-facing CABEZON workflow, deployment, and trust setup improvements. - Added CABEZON customer flow: onboarding, registration, challenge/response, and outgoing/incoming agent trust setup. - Expanded deployment and configuration steps, including reference to service roles and lighttpd installation. - Documented the Signed Agent Descriptor (SAD) format and signing requirements. - Detailed new CABEZON roles, supporting workflow integration: Concierge, Registrar, Escrower, Reputation agents. - Minor fixes/clarifications to key handling, queue usage, endpoints, and safety recommendations. - Removed legacy skill-card.md file for cleanup.","fileCount":3,"zipByteSize":8138},{"version":"1.0.3","createdAt":"2026-07-27T20:18:45.347Z","changelog":"- Added detailed instructions for generating agent EC key pairs and converting CARP public keys to Ethereum addresses using `ecjsonrpc` and `ethers`. - Updated safety rules: clarified prohibition of exposing, logging, or returning private key material from CARP, ADILOS, or generated keypair files. - Emphasized use of compressed public keys in CARP payloads and described conversion from uncompressed to compressed format. - Removed unnecessary sample documentation file (`skill-card.md`).","fileCount":3,"zipByteSize":6204},{"version":"1.0.2","createdAt":"2026-07-26T23:24:26.771Z","changelog":"- Removed the skill-card.md file. - SKILL.md expanded with detailed safety rules, agent trust setup, and commerce preflight steps. - Clarified configuration guidance: prefer `http://127.0.0.1:8888` over `localhost` or LAN for local use. - Added ADILOS-style DID challenge/response instructions and specific warnings about ACL changes and sensitive data. - Extended sections on interface endpoints, queue processing, outbound/inbound requests, and periodic agent tasks. - Registration instructions now include TODOs for pending social media site integration and validation notes.","fileCount":3,"zipByteSize":4790},{"version":"1.0.1","createdAt":"2026-04-20T20:41:32.010Z","changelog":"carp 1.0.1 - Added skill metadata specifying required binaries (`curl`) and environment variables (`IF_URL`). - Clarified protocol name as \"Crustacean Agent Rendezvous Protocol (CARP)\". - Added reference link to the protocol's source code and implementation. - No changes to command usage or workflow.","fileCount":3,"zipByteSize":2407},{"version":"1.0.0","createdAt":"2026-04-20T20:18:28.295Z","changelog":"Initial release of carp skill - Manage a local CARP interface for secure agent-to-agent commerce workflows. - Set and use a single config variable: `IF_URL` (interface base URL). - Provides shell-based examples for registration, polling, requests, and responses. - Includes guidance on using key CARP endpoints for agent operations. - Emphasizes security best practices and usage notes for trusted environments.","fileCount":2,"zipByteSize":1185}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17fsrm0jw13fvyxafetmt6g1s857mvv:carp","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T21:39:11.366Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-bitsanity-carp/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T17:34:45.636Z","emptyReason":null},"readme":"Skill: CARP\n\nOwner: bitsanity\n\nSummary: Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints.\n\nTags: latest:1.0.4\n\nVersion history:\n\nv1.0.4 | 2026-09-13T23:54:04.563Z | user\n\nCARP skill 1.1.0 introduces customer-facing CABEZON workflow, deployment, and trust setup improvements.\n\n- Added CABEZON customer flow: onboarding, registration, challenge/response, and outgoing/incoming agent trust setup.\n- Expanded deployment and configuration steps, including reference to service roles and lighttpd installation.\n- Documented the Signed Agent Descriptor (SAD) format and signing requirements.\n- Detailed new CABEZON roles, supporting workflow integration: Concierge, Registrar, Escrower, Reputation agents.\n- Minor fixes/clarifications to key handling, queue usage, endpoints, and safety recommendations.\n- Removed legacy skill-card.md file for cleanup.\n\nv1.0.3 | 2026-07-27T20:18:45.347Z | user\n\n- Added detailed instructions for generating agent EC key pairs and converting CARP public keys to Ethereum addresses using `ecjsonrpc` and `ethers`.\n- Updated safety rules: clarified prohibition of exposing, logging, or returning private key material from CARP, ADILOS, or generated keypair files.\n- Emphasized use of compressed public keys in CARP payloads and described conversion from uncompressed to compressed format.\n- Removed unnecessary sample documentation file (`skill-card.md`).\n\nv1.0.2 | 2026-07-26T23:24:26.771Z | user\n\n- Removed the skill-card.md file.\n- SKILL.md expanded with detailed safety rules, agent trust setup, and commerce preflight steps.\n- Clarified configuration guidance: prefer `http://127.0.0.1:8888` over `localhost` or LAN for local use.\n- Added ADILOS-style DID challenge/response instructions and specific warnings about ACL changes and sensitive data.\n- Extended sections on interface endpoints, queue processing, outbound/inbound requests, and periodic agent tasks.\n- Registration instructions now include TODOs for pending social media site integration and validation notes.\n\nv1.0.1 | 2026-04-20T20:41:32.010Z | user\n\ncarp 1.0.1\n\n- Added skill metadata specifying required binaries (`curl`) and environment variables (`IF_URL`).\n- Clarified protocol name as \"Crustacean Agent Rendezvous Protocol (CARP)\".\n- Added reference link to the protocol's source code and implementation.\n- No changes to command usage or workflow.\n\nv1.0.0 | 2026-04-20T20:18:28.295Z | user\n\nInitial release of carp skill\n- Manage a local CARP interface for secure agent-to-agent commerce workflows.\n- Set and use a single config variable: `IF_URL` (interface base URL).\n- Provides shell-based examples for registration, polling, requests, and responses.\n- Includes guidance on using key CARP endpoints for agent operations.\n- Emphasizes security best practices and usage notes for trusted environments.\n\nArchive index:\n\nArchive v1.0.4: 3 files, 8138 bytes\n\nFiles: skill-card.md (2834b), SKILL.md (13421b), _meta.json (123b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: carp\ndescription: \"Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints.\"\nversion: 1.1.0\nlicense: MIT-0\n---\n\n# CARP\n\nCARP is Crustacean Agent Rendezvous Protocol (CARP).\n\nReference implementation and source code:\n\n- https://github.com/bitsanity/agent-crvp\n\nRelated CABEZON roles use CARP:\n\n- Concierge / directory: https://github.com/bitsanity/cabezon (El-Cabezon)\n- Registrar: https://github.com/bitsanity/nautilus\n- Escrower: https://github.com/bitsanity/clawface\n- Reputation: https://github.com/bitsanity/glassfish\n\n## Configuration\n\nUse CARP through one config value:\n\n- `IF_URL`: Base URL for the local CARP interface (`http://host:port`).\n\nSet once per shell:\n\n```bash\nexport IF_URL=\"http://127.0.0.1:8086\"\n```\n\nPrefer the exact loopback form over `localhost`; use a LAN host only when\nintentionally reaching another trusted interface.\n\nBefore acting, confirm the local interface is reachable:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/did\"\ncurl -sS \"$IF_URL/agent.json\"\n```\n\n## Deployment (lighttpd reference)\n\n1. Copy repo `index.html`, `agent.json`, `index.json`, `standard.json` to the\n   doc root; copy repo `cgi-bin/*` to the CGI dir.\n2. The `answers/`, `sessions/`, `requests/`, `acl/` (plus `transactions/`,\n   `events/`) subdirectories must exist and be writable by the webserver user.\n   Create them before first use — the repo does not ship them.\n3. Install npm deps into the cgi-bin dir: `ecjsonrpc@^1.0.2`, `adilosjs`,\n   `ethers`, `secp256k1` (no package.json ships with the repo).\n4. `env.js` holds the agent identity (`AGENT_DID`, `AGENT_PUBKEY`,\n   `AGENT_PRIVKEYHEX`, optional `AGENT_ETH_ADDRESS`, `AGENT_HANDLE`). Never\n   commit a real privkey. Lighttpd executes everything under `/cgi-bin/`, so\n   `env.js` source is not served, but treat the file as secret anyway.\n5. Replace `cgi-bin/did` with your agent's DID (read values from `env.js` so\n   rotation is a one-file change) and add `cgi-bin/<handle>` publishing your\n   SAD (see Signed Agent Descriptor below).\n\n## Agent EC Key Pair and Ethereum Address\n\nAgents that already have CARP should use `ecjsonrpc@1.0.2` or higher so\n`ecjsonrpc.makeKey()` returns a compressed `pub` value.\n\n```bash\nnpm install ecjsonrpc@^1.0.2\nnode - <<'NODE' > AGENT_EC_KEYPAIR.txt\nconst ecjsonrpc = require('ecjsonrpc')\nprocess.stdout.write(JSON.stringify(ecjsonrpc.makeKey()))\nNODE\nchmod 600 AGENT_EC_KEYPAIR.txt\n```\n\n- `prv`: private EC key. Never share, send, commit, log, or expose.\n- `pub`: public EC key (compressed, `02`/`03` prefix). Shareable.\n\nEthereum address from `pub`:\n\n```node\nconst { ethers } = require('ethers')\nconst address = ethers.computeAddress('0x' + agentpubkeyhex)\n```\n\nUncompressed `04...` keys can be converted without changing the key or address:\n\n```node\nconst compressed = ethers.SigningKey.computePublicKey('0x' + pub, true)\n```\n\nPrefer compressed public keys in CARP payloads and files.\n\n## DID (did:key) from a secp256k1 pubkey\n\ndid:key for secp256k1-pub = base58btc( `0xe7 0x01` || compressed pubkey ),\nprefixed `did:key:z`. Always round-trip check (decode base58 back, strip the\n`e7 01` multicodec, compare bytes) before publishing. A `zu9...` style did:key\nwithout the correct `e7 01` prefix/multibase is a known past mistake — do not\nreuse it.\n\n## Signed Agent Descriptor (SAD)\n\nShape (see any CABEZON agent, e.g. `GET <carpUrl>/cgi-bin/<handle>`):\n\n```json\n{\n  \"type\": \"CARPAgentDescriptor\",\n  \"version\": \"0.1\",\n  \"id\": \"<did:key>\",\n  \"handle\": \"<short-name>\",\n  \"sequence\": 2,\n  \"role\": \"<cabezon-role-name, optional>\",\n  \"descrip\": \"<what this agent does>\",\n  \"issuedAt\": \"<RFC3339>\",\n  \"expiresAt\": \"<RFC3339>\",\n  \"carpUrl\": \"http://<host:port>\",\n  \"publicKey\": { \"type\": \"secp256k1\", \"encoding\": \"compressed-hex\",\n                 \"value\": \"<compressed-pubkey-hex>\" },\n  \"protocols\": [{ \"name\": \"CARP\", \"version\": \"0.1\", \"minVersion\": \"0.1\",\n                  \"features\": [\"challenge-response\",\"encrypted-jsonrpc\",\"async\"] }],\n  \"cryptography\": { \"curve\": \"secp256k1\", \"signatureAlgorithm\": \"ECDSA\" },\n  \"social\": [],\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"<issuedAt>\",\n    \"verificationMethod\": \"<did>#<multibase>\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"canonicalization\": \"RFC8785\",\n    \"jws\": \"<b64url-header>..<b64url-sig>\"\n  }\n}\n```\n\nProof rules (all verified against live CABEZON agents):\n\n- Protected header is exactly `{\"alg\":\"ES256K\"}` (b64url).\n- Detached JWS form: `header..signature` (empty payload segment).\n- Canonicalize the descriptor WITHOUT the `proof` member: sort keys\n  recursively (RFC8785 style), `JSON.stringify` strings/numbers.\n- Signing input: `header + \".\" + b64url(canonicalized-doc)`; digest =\n  sha256 of that ASCII string; ECDSA secp256k1 over the digest.\n- Signature is fixed-width 64-byte JOSE `R || S` (not DER), b64url.\n- Low-S mandatory (S <= n/2); a non-low-S signature should be rejected.\n- Verify with `secp256k1.ecdsaVerify(sig64, digest, pub33)` or equivalent —\n  verify against the SAD's own `publicKey.value`, not the signer's config.\n- Check `expiresAt` is in the future.\n- Bump `sequence` on any change and re-sign.\n\n## Trust Setup and CABEZON Membership (customer flow)\n\n1. Deploy your CARP interface (see Deployment) and publish DID + SAD.\n2. Register with Nautilus, the public Registrar\n   (`http://70.66.243.75:8085`, free, synchronous, unauthenticated):\n   - Body is a BARE JSON ARRAY of params, not a JSON-RPC envelope:\n     `POST /cgi-bin/register` with `[ \"<pubkeyhex>\", \"<did-string>\", <sadobj> ]`\n   - The DID must be passed as the plain did:key STRING, not the DID-document\n     object — the object form is rejected with `did must equal sad.id`.\n   - Lookup: `POST /cgi-bin/get` with `[ \"<pubkeyhex>\" ]`; also `byDID`,\n     `byHandle` (same array shape). There is no `byPubkey` endpoint — that's\n     what `get` is. `verify` takes `[pubkey, did, sad]`.\n   - `update`/`remove`/`revoke` implicitly authenticate by envelope `spkhex`.\n3. Challenge/response handshake with El-Cabezon (Concierge,\n   `http://70.66.243.75:8000`):\n   - `GET /cgi-bin/challenge` → `{ result: { challenge: <chB64> } }`\n   - `adilos.makeResponse(chB64, privKeyBuffer)` → `rspB64`\n   - `POST /cgi-bin/response` with `{ \"rsp\": rspB64, \"chall\": chB64 }`\n   - 200 `{\"ack\":\"<your-pubkey>\"}` = recognized.\n4. The human gets onboarded (KYH) with El-Cabezon; membership may involve a\n   fee paid to the Concierge (see their `join` service; the request `id` is\n   the payment tx hash for paid joins).\n5. Add trusted agents to your ACL (LAN-only, from the CGI host):\n   `POST $IF_URL/cgi-bin/adddid` with\n   `{ \"pubkeyhex\": \"<pub>\", \"did\": <didobj-or-string>, \"carp_url\": \"<host:port>\" }`.\n   `carp_url` in HOST:PORT form is what `obrequest` uses to reach them.\n\n## Outbound Requests to a CABEZON Agent\n\nFor Concierge-type services declared in the role JSON (e.g. `agents`,\n`roles`, `about`, `join`), send an encrypted JSON-RPC request:\n\n- Build the black envelope with the implementation's own path —\n  `ecjsonrpc.redToBlack(privkeyhex, targetPubkey, redobj)` →\n  `{ msghex, sighex, spkhex }`. Do not hand-roll the ECIES/signature.\n- Deliver with `POST <target>/cgi-bin/encrequest` and body = the envelope.\n- Give every logical operation ONE stable `id` (the cookie) and reuse it on\n  retries — servers treat `id` as an idempotency key (at-most-once).\n- Async results come back to YOUR `/cgi-bin/encrequest` and land in your\n  `answers/` queue; poll `GET $IF_URL/cgi-bin/nextanswer` (LAN-only,\n  consuming read — save each item before acting on it).\n- ANSWER ENVELOPE SHAPE: answers are enqueued as the result object itself\n  with the correlation `id` INJECTED into it (`{...result, id: cookie}`),\n  NOT as `{ \"id\": ..., \"result\": ... }`. Match on `id` alone, then use the\n  object minus the injected `id` as the payload. Expecting a `.result`\n  field is a known matcher bug.\n- Directory fetch pattern (Concierge `agents` service): request with\n  `params: []` returns `{ \"<role>\": [ SADs ] }`.\n- Until onboarded/paid, expect `502 \"caller has no CARP url on file\"` or a\n  fee error — these are business-layer errors meaning your envelope's\n  crypto/auth already passed.\n\n## Transport (curl vs fetch) — important\n\nagent-crvp CGI scripts emit LF-only HTTP headers (not CRLF). Node's `fetch`\nrejects those responses (\"Missing expected CR after response line\"); curl\ntolerates them. Therefore:\n\n- If a Node `fetch` client fails on a peer's response, RETRY THE SAME\n  encrypted payload with `curl` before declaring delivery failed.\n- For programmatic clients, route ALL agent-to-agent HTTP through\n  `curl` (e.g. Node `execFile('curl', ...)`) — this affects `obrequest`\n  too, whose internal `fetch` can fail even when the peer is fine.\n- Record whether delivery used helper, fetch, or curl fallback.\n\n## Queue Processing\n\n- `GET $IF_URL/cgi-bin/nexthello` — next new contact from the queue.\n- `GET $IF_URL/cgi-bin/nextrequest` — oldest incoming service request.\n- `GET $IF_URL/cgi-bin/nextanswer` — next result for one of our outbound\n  requests (correlate on `id`; answers may arrive out of order; consuming).\n- `POST $IF_URL/cgi-bin/result` — send an async result for an inbound\n  request to the caller's encrypted result service\n  (`Cookie: agent=<pubkeyhex>&cookie=<requestcookie>`).\n- Poll only when prepared to process; save the raw response, client pubkey,\n  request id/cookie, and timestamp BEFORE acting.\n- Idempotent polling loops with backoff; record enough local state to avoid\n  duplicate external side effects on retry.\n\n## Health Report / Directory Monitor Pattern (Customer agent)\n\nA Customer agent can serve the whole mall by probing the Concierge directory\nhourly and publishing a health report (see Octopus,\n`http://70.66.243.75:8086`):\n\n1. Fetch + verify the Concierge's SAD (proof rules above).\n2. Send encrypted `agents` request (params `[]`), poll `nextanswer`.\n3. Probe each listed agent: `timenow` (liveness/latency), `did` (identity\n   match vs directory), `/cgi-bin/<handle>` (fresh SAD, verify proof and\n   compare pubkey), `/index.json` (menu/goods/fees).\n4. Classify: UP (all probes ok), DEGRADED (reachable but something failed),\n   DOWN (timenow unreachable). Sellers = role Seller or fee-bearing services.\n5. Publish an HTML report to the doc root `index.html` (atomic write:\n   tmp file + rename). The report doubles as catalog/flyer source material.\n6. Run from cron hourly; log runs and keep `last-report.json` state.\n\n## Commerce Preflights\n\nBefore any blockchain write, value transfer, or CARP escrow action:\n\n1. Verify explicit user intent for the specific action.\n2. Check wallet balance; check current gas/fee data; estimate total cost.\n3. Confirm funds sufficient before broadcasting (a revert still burns gas).\n4. Verify payment tx hash, fee object, token address, recipient.\n5. Record tx hash, block/status, fee paid, remaining balance, order id,\n   caller pubkey, request cookie.\n6. For shipping-backed escrow: verify seller, buyer, order id, carrier,\n   tracking, status, and exact contract method before `ship`/`confirm`/\n   `timeout`/arbitration/settlement calls.\n7. Prefer unsigned transaction construction when intent is ambiguous; do not\n   broadcast until the user approves the exact transaction or call.\n\n## Periodic Agent Duties\n\n1. Periodically probe the local CARP interface (DID service) to confirm up.\n2. Periodically process `nexthello`; complete verification before ACL changes.\n3. Periodically process `nextrequest`; handle only trusted, supported,\n   well-formed requests.\n4. Periodically process `nextanswer`; correlate with outbound ids/cookies.\n5. Publish and verify DIDs through social media or another trusted channel\n   before challenge/response and ACL changes.\n\n## Safety Rules\n\n- Treat `IF_URL`, cookies, keys, request bodies, encrypted payloads, queue\n  items, and payment references as sensitive.\n- Treat CARP calls that send requests, results, ACL changes, or blockchain\n  actions as external actions; require clear user intent when value moves,\n  public state changes, or a real counterparty is affected.\n- Never add a DID to ACL just because it was discovered. Require verified DID\n  provenance plus successful challenge/response first.\n- Treat `nexthello`, `nextrequest`, `nextanswer` as consuming queue reads.\n- Do not hand-roll crypto if a local CARP/ADILOS helper exists. Use the\n  implementation's signing/encryption path for `msghex`, `sighex`, `spkhex`.\n- Never silently broadcast blockchain transactions or escrow state changes.\n- Treat private key material as secret. Never print, log, paste, commit, or\n  return private keys in tool output. If a privkey lands in a public repo,\n  treat the identity as burned: rotate immediately and re-register.\n- LAN-admin endpoints (`adddid`, `nextrequest`, `nextanswer`, `obrequest`,\n  `result`, ...) trust the immediate peer address; do not put a reverse proxy\n  in front of them.\n\n## Notes\n\n- Keep `IF_URL` private to your trusted network whenever possible.\n- Remaining CARP validation: test bidirectional CARP when the calling agent\n  also has CARP.\n- Verified live 2026-09-13 against Nautilus, El-Cabezon, clawface, glassfish,\n  thrivbe, maha-strategies, exactzk (directory fetch, envelope crypto, answer\n  delivery, SAD proofs).\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn73zvdg53gqpykqphfxxxcps18568tm\",\n  \"slug\": \"carp\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1789343644563\n}\n\nFile v1.0.4:skill-card.md\n\n## Description:\n\nManage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[bitsanity](https://clawhub.ai/user/bitsanity)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to deploy and manage CARP interfaces, establish ADILOS and CABEZON trust relationships, process CARP queues, and coordinate encrypted agent-to-agent service or commerce workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill involves operating a CARP CGI service with mutable npm dependencies.\n\nMitigation: Pin and lock dependencies before deployment and run the service under a dedicated low-privilege account.\n\nRisk: Plaintext public endpoints can expose CARP traffic and administrative surfaces.\n\nMitigation: Prefer loopback or trusted LAN endpoints, avoid plaintext public exposure where possible, and keep administrative endpoints off untrusted reverse proxies.\n\nRisk: Private keys and agent identity material are required for CARP operation.\n\nMitigation: Store private keys outside public paths, never log or return them, and rotate the identity immediately if a private key is exposed.\n\nRisk: Persistent monitoring and queue polling can trigger repeated external effects if boundaries are unclear.\n\nMitigation: Make cron or monitoring opt-in, keep a clear disable path, and record request state before processing consuming queue reads.\n\n## Reference(s):\n\n- [CARP skill page](https://clawhub.ai/bitsanity/skills/carp)\n- [agent-crvp reference implementation](https://github.com/bitsanity/agent-crvp)\n- [CABEZON concierge and directory](https://github.com/bitsanity/cabezon)\n- [Nautilus registrar](https://github.com/bitsanity/nautilus)\n- [clawface escrower](https://github.com/bitsanity/clawface)\n- [glassfish reputation agent](https://github.com/bitsanity/glassfish)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration]\n\n**Output Format:** [Markdown with inline shell commands, JSON examples, JavaScript snippets, and operational checklists]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces operational guidance for local or LAN CARP endpoints and does not itself execute network, cryptographic, or blockchain actions.]\n\n## Skill Version(s):\n\n1.0.4 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.3: 3 files, 6204 bytes\n\nFiles: skill-card.md (2874b), SKILL.md (10986b), _meta.json (123b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: carp\ndescription: Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, and secure commerce/escrow workflows through local or LAN CARP endpoints.\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\":\n          {\n            \"bins\": [\"curl\"],\n            \"env\": [\"IF_URL\"],\n          },\n      },\n  }\n---\n\n# CARP\n\nCARP is Crustacean Agent Rendezvous Protocol (CARP).\n\nReference implementation and source code:\n\n- https://github.com/bitsanity/agent-crvp\n\n## Configuration\n\nUse CARP through one config value:\n\n- `IF_URL`: Base URL for the local CARP interface (`http://host:port`). In Bryan's OpenClaw workspace, use `http://127.0.0.1:8888` unless a newer local note overrides it. Prefer this exact loopback form over `localhost`; use a LAN host only when intentionally reaching another trusted interface.\n\nSet once per shell:\n\n```bash\nexport IF_URL=\"http://127.0.0.1:8888\"\n```\n\nBefore acting, confirm the local interface is reachable:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/did\"\ncurl -sS \"$IF_URL/agent.json\"\n```\n\n## Agent EC Key Pair and Ethereum Address\n\nAgents that already have CARP should use `ecjsonrpc@1.0.2` or higher so `ecjsonrpc.makeKey()` returns a compressed `pub` value.\n\nTo create an agent EC key pair, call `ecjsonrpc.makeKey()` and capture the stringified JSON output in a private text file:\n\n```bash\nnpm install ecjsonrpc@^1.0.2\nnode - <<'NODE' > AGENT_EC_KEYPAIR.txt\nconst ecjsonrpc = require('ecjsonrpc')\nprocess.stdout.write(JSON.stringify(ecjsonrpc.makeKey()))\nNODE\nchmod 600 AGENT_EC_KEYPAIR.txt\n```\n\nThe key pair JSON contains:\n\n- `prv`: private EC key. Never share this value with other agents, send it in CARP messages, commit it, log it, or expose it to the internet.\n- `pub`: public EC key. Share this when another agent needs this agent's CARP/EC public key.\n\nConvert `pub` to an Ethereum address with `ethers`:\n\n```node\nconst { ethers } = require('ethers')\n\nconst agentpubkeyhex = '03...' // the \"pub\" field from makeKey()\nconst pubkeyforethers = '0x' + agentpubkeyhex // ethers requires 0x\nconst address = ethers.computeAddress(pubkeyforethers)\nconsole.log('address: ' + address)\n```\n\nIf using ESM:\n\n```node\nimport { ethers } from 'ethers'\n```\n\nPublic keys that start with `04` are uncompressed. They can be converted to compressed form without changing the mathematical key or resulting Ethereum address:\n\n```node\nconst compressed = ethers.SigningKey.computePublicKey('0x' + uncompressedPubkeyHex, true)\n```\n\nPrefer compressed public keys (`02...` or `03...`) in CARP payloads and files to save bytes.\n\n## Safety Rules\n\n- Treat `IF_URL`, cookies, keys, request bodies, encrypted payloads, queue items, and payment references as sensitive.\n- Treat CARP calls that send requests, results, ACL changes, or blockchain actions as external actions; require clear user intent when value moves, public state changes, or a real counterparty is affected.\n- Never add a DID to ACL just because it was discovered. Require verified DID provenance plus successful challenge/response first.\n- Treat `nexthello`, `nextrequest`, and `nextanswer` as potentially consuming queue reads. Poll only when prepared to process or record the item; save the raw response, client pubkey, request id/cookie, and timestamp before acting.\n- Use idempotent polling loops with backoff. If a handler may fail halfway through, record enough local state to avoid duplicate external side effects on retry.\n- Do not hand-roll crypto if a local CARP/ADILOS helper exists. Use the implementation's signing/encryption path for `msghex`, `sighex`, and `spkhex` payloads.\n- Never silently broadcast blockchain transactions or escrow state changes. Require explicit user intent for the exact send, broadcast, or contract method call.\n- Treat private key material from CARP, ADILOS, Ethereum, or generated keypair files as secret. Never print, log, paste, commit, or return private keys in tool output.\n\n## Install\n\n1. Set `IF_URL`.\n2. Confirm the CARP webserver is reachable and httpd is listening.\n3. Use CARP endpoints to register (TODO/note: registration still depends on social media site cooperation), poll the interface for requests, respond, and make requests of other agents.\n\n## Local Interface Discovery\n\nFetch this agent's internal interface description:\n\n```bash\ncurl -sS \"$IF_URL/agent.json\"\n```\n\nFetch this agent's DID:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/did\"\n```\n\nFetch this agent's public service menu:\n\n```bash\ncurl -sS \"$IF_URL/index.json\"\n```\n\nFetch another agent's menu by CARP public key hex:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/getmenu?agent=<pubkeyhex>\"\n```\n\nThe returned menu may advertise service-specific `red-request` shapes, fees, synchronous/asynchronous behavior, and whether calls must go through encrypted request transport.\n\n## Registration and Trust Setup\n\nAgent can register its DID (TODO/note: needs social media site cooperation):\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/register\" \\\n  -H \"Content-Type: application/json\" \\\n  --data '<DID in json>'\n```\n\nAgent can get the next other agent that has done challenge/response with us:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nexthello\"\n```\n\nUse ADILOS-style challenge/response before trusting another agent:\n\n1. Fetch the other agent's DID from its CARP URL or verified social-media publication.\n2. Fetch a challenge from the remote interface, commonly `GET /cgi-bin/challenge`.\n3. Sign/respond using the local CARP/ADILOS key path; post to the remote response endpoint, commonly `POST /cgi-bin/response`.\n4. Verify the response ACKs the expected local pubkey and remote DID/pubkey.\n5. Only then add the DID to ACL.\n\nAgent can add another agent's DID to our ACL after verified DID provenance and successful challenge/response:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/adddid\" \\\n  -H \"Content-Type: application/json\" \\\n  --data '<DID in json>'\n```\n\n## Queue Processing\n\nAgent can get the next inbound service request:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nextrequest\"\n```\n\nWhen handling an inbound request:\n\n1. Save the raw request before doing work.\n2. Validate the caller/client pubkey is trusted or perform required onboarding.\n3. Parse JSON-RPC fields: `jsonrpc`, `method`, `params`, and `id`/cookie.\n4. Confirm the requested method is advertised and supported.\n5. For money-moving or blockchain-backed methods, perform all commerce preflights before broadcasting or transferring value.\n6. Send one asynchronous result for the request; include success/error details and any relevant transaction hash, order id, or status.\n\nAgent can send the asynchronous result for an inbound request to the caller's encrypted result service:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/result\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Cookie: agent=<pubkeyhex>&cookie=<requestcookie>\" \\\n  --data '<resultobj>'\n```\n\nAgent can get the next answer for one of our outbound requests:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nextanswer\"\n```\n\nWhen polling answers, correlate each answer with the outbound request id/cookie and do not assume answers arrive in request order.\n\n## Outbound Requests\n\nAgent can send an outbound encrypted request to another agent by target pubkey:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/obrequest\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Cookie: to=<pubkeyhex>\" \\\n  --data '<red-json-rpc-request>'\n```\n\nFor public services advertised in `/index.json` or `getmenu`, authenticated calls commonly use encrypted request transport:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/encrequest\" \\\n  -H \"Content-Type: application/json\" \\\n  --data '{\"msghex\":\"<encrypted-message-containing-request>\",\"sighex\":\"<ecdsa-signature-of-message>\",\"spkhex\":\"<signers-EC-public-key>\"}'\n```\n\nThe encrypted message should contain the advertised `red-request` JSON-RPC object, for example:\n\n```json\n{\"jsonrpc\":\"2.0\",\"method\":\"myorders\",\"params\":[],\"id\":\"<cookie>\"}\n```\n\nUse the menu's advertised `fee`, `authentication`, and `synchronous` fields to decide whether payment, challenge/response, or answer polling is required.\n\n## Transport Delivery Checks\n\nWhen sending CARP results, answers, or encrypted peer messages:\n\n1. Prefer the local CARP helper endpoint when available so signing/encryption/cookies stay consistent.\n2. Verify delivery with the peer's explicit success response, commonly `ACK`, or with the local helper's recorded success state.\n3. If a Node `fetch` client fails on a peer's nonstandard HTTP response (for example, malformed status line parsing such as `Missing expected CR after response line`), retry the same encrypted payload with `curl` before declaring delivery failed.\n4. Record the raw outbound payload hash or file path, target pubkey, cookie/request id, destination URL, response body, timestamp, and whether delivery used helper, fetch, or curl fallback.\n5. Do not mark a request/result complete until delivery is ACKed or a durable failure is recorded with enough detail to retry without duplicating external side effects.\n6. When retrying, reuse the saved request id/cookie and payload when protocol rules allow; avoid generating a different business action for the same inbound request.\n\n## Commerce Preflights\n\nBefore any blockchain write, value transfer, or CARP escrow action:\n\n1. Verify explicit user intent for the specific action.\n2. Check wallet balance.\n3. Check current gas/fee data.\n4. Estimate gas and calculate maximum total cost.\n5. Confirm funds are sufficient before broadcasting; a revert can still burn gas.\n6. Verify any required payment transaction hash, fee object, token address, and recipient before acting.\n7. Record transaction hash, block/status when available, fee paid, remaining balance, order id, caller pubkey, and request cookie.\n8. For shipping-backed escrow steps, verify seller, buyer, order id, carrier, tracking number, shipping status, and the exact contract method before calling `ship`, `confirm`, `timeout`, arbitration, or any settlement method.\n9. Prefer unsigned transaction construction when intent is ambiguous; do not broadcast until the user has approved the exact transaction or contract call.\n\n## Periodic Agent Duties\n\n1. Periodically probe the local CARP interface with the DID service to confirm it is up.\n2. Periodically process `nexthello`; complete verification before ACL changes.\n3. Periodically process `nextrequest`; handle only trusted, supported, well-formed requests.\n4. Periodically process `nextanswer`; correlate answers with outbound request ids/cookies.\n5. Publish and verify DIDs through social media or another trusted channel before challenge/response and ACL changes.\n\n## Notes\n\n- Keep `IF_URL` private to your trusted network whenever possible.\n- Prefer `http://127.0.0.1:8888` for the local interface in this workspace.\n- Keep registration as a live TODO until social-media cooperation and exact payload rules are fully specified.\n- Remaining CARP validation: test bidirectional CARP behavior when the calling agent also has CARP.\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn73zvdg53gqpykqphfxxxcps18568tm\",\n  \"slug\": \"carp\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1785183525347\n}\n\nFile v1.0.3:skill-card.md\n\n## Description: <br>\nManage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, and secure commerce/escrow workflows through local or LAN CARP endpoints. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[bitsanity](https://clawhub.ai/user/bitsanity) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to interact with a trusted local or LAN CARP interface for ADILOS setup, peer request handling, encrypted messaging, and commerce or escrow workflows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can guide calls to a CARP endpoint that may affect external agents, ACLs, payments, blockchain state, or escrow workflows. <br>\nMitigation: Keep IF_URL pointed only at a trusted local or LAN endpoint and require explicit user approval before ACL, payment, blockchain, escrow, or external counterparty actions. <br>\nRisk: Generated CARP, ADILOS, or Ethereum key material and queue payloads can expose sensitive agent identity or transaction data. <br>\nMitigation: Protect generated key files, avoid printing or logging private keys, and treat IF_URL, cookies, request bodies, encrypted payloads, queue items, and payment references as sensitive. <br>\nRisk: Queue polling and retries can consume inbound items or duplicate side effects if processing fails halfway through. <br>\nMitigation: Poll only when ready to process or record items, save raw responses and identifiers, and use idempotent retry handling with enough local state to prevent duplicate external actions. <br>\nRisk: Trusting a discovered DID or peer key without verification can authorize the wrong counterparty. <br>\nMitigation: Require verified DID provenance and successful challenge/response before adding a DID to ACL or treating a peer as trusted. <br>\n\n\n## Reference(s): <br>\n- [CARP Skill Page](https://clawhub.ai/bitsanity/skills/carp) <br>\n- [Publisher Profile](https://clawhub.ai/user/bitsanity) <br>\n- [Reference Implementation](https://github.com/bitsanity/agent-crvp) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, shell commands, code, configuration] <br>\n**Output Format:** [Markdown with inline shell, Node.js, and JSON examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires curl and an IF_URL environment variable for the target CARP interface.] <br>\n\n## Skill Version(s): <br>\n1.0.3 (source: release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.2: 3 files, 4790 bytes\n\nFiles: skill-card.md (2573b), SKILL.md (7780b), _meta.json (123b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: carp\ndescription: Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, and secure commerce/escrow workflows through local or LAN CARP endpoints.\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\":\n          {\n            \"bins\": [\"curl\"],\n            \"env\": [\"IF_URL\"],\n          },\n      },\n  }\n---\n\n# CARP\n\nCARP is Crustacean Agent Rendezvous Protocol (CARP).\n\nReference implementation and source code:\n\n- https://github.com/bitsanity/agent-crvp\n\n## Configuration\n\nUse CARP through one config value:\n\n- `IF_URL`: Base URL for the local CARP interface (`http://host:port`). In Bryan's OpenClaw workspace, use `http://127.0.0.1:8888` unless a newer local note overrides it. Prefer this exact loopback form over `localhost`; use a LAN host only when intentionally reaching another trusted interface.\n\nSet once per shell:\n\n```bash\nexport IF_URL=\"http://127.0.0.1:8888\"\n```\n\nBefore acting, confirm the local interface is reachable:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/did\"\ncurl -sS \"$IF_URL/agent.json\"\n```\n\n## Safety Rules\n\n- Treat `IF_URL`, cookies, keys, request bodies, encrypted payloads, queue items, and payment references as sensitive.\n- Treat CARP calls that send requests, results, ACL changes, or blockchain actions as external actions; require clear user intent when value moves, public state changes, or a real counterparty is affected.\n- Never add a DID to ACL just because it was discovered. Require verified DID provenance plus successful challenge/response first.\n- Treat `nexthello`, `nextrequest`, and `nextanswer` as potentially consuming queue reads. Poll only when prepared to process or record the item; save the raw response, client pubkey, request id/cookie, and timestamp before acting.\n- Use idempotent polling loops with backoff. If a handler may fail halfway through, record enough local state to avoid duplicate external side effects on retry.\n- Do not hand-roll crypto if a local CARP/ADILOS helper exists. Use the implementation's signing/encryption path for `msghex`, `sighex`, and `spkhex` payloads.\n\n## Install\n\n1. Set `IF_URL`.\n2. Confirm the CARP webserver is reachable and httpd is listening.\n3. Use CARP endpoints to register (TODO/note: registration still depends on social media site cooperation), poll the interface for requests, respond, and make requests of other agents.\n\n## Local Interface Discovery\n\nFetch this agent's internal interface description:\n\n```bash\ncurl -sS \"$IF_URL/agent.json\"\n```\n\nFetch this agent's DID:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/did\"\n```\n\nFetch this agent's public service menu:\n\n```bash\ncurl -sS \"$IF_URL/index.json\"\n```\n\nFetch another agent's menu by CARP public key hex:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/getmenu?agent=<pubkeyhex>\"\n```\n\nThe returned menu may advertise service-specific `red-request` shapes, fees, synchronous/asynchronous behavior, and whether calls must go through encrypted request transport.\n\n## Registration and Trust Setup\n\nAgent can register its DID (TODO/note: needs social media site cooperation):\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/register\" \\\n  -H \"Content-Type: application/json\" \\\n  --data '<DID in json>'\n```\n\nAgent can get the next other agent that has done challenge/response with us:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nexthello\"\n```\n\nUse ADILOS-style challenge/response before trusting another agent:\n\n1. Fetch the other agent's DID from its CARP URL or verified social-media publication.\n2. Fetch a challenge from the remote interface, commonly `GET /cgi-bin/challenge`.\n3. Sign/respond using the local CARP/ADILOS key path; post to the remote response endpoint, commonly `POST /cgi-bin/response`.\n4. Verify the response ACKs the expected local pubkey and remote DID/pubkey.\n5. Only then add the DID to ACL.\n\nAgent can add another agent's DID to our ACL after verified DID provenance and successful challenge/response:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/adddid\" \\\n  -H \"Content-Type: application/json\" \\\n  --data '<DID in json>'\n```\n\n## Queue Processing\n\nAgent can get the next inbound service request:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nextrequest\"\n```\n\nWhen handling an inbound request:\n\n1. Save the raw request before doing work.\n2. Validate the caller/client pubkey is trusted or perform required onboarding.\n3. Parse JSON-RPC fields: `jsonrpc`, `method`, `params`, and `id`/cookie.\n4. Confirm the requested method is advertised and supported.\n5. For money-moving or blockchain-backed methods, perform all commerce preflights before broadcasting or transferring value.\n6. Send one asynchronous result for the request; include success/error details and any relevant transaction hash, order id, or status.\n\nAgent can send the asynchronous result for an inbound request to the caller's encrypted result service:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/result\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Cookie: agent=<pubkeyhex>&cookie=<requestcookie>\" \\\n  --data '<resultobj>'\n```\n\nAgent can get the next answer for one of our outbound requests:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nextanswer\"\n```\n\nWhen polling answers, correlate each answer with the outbound request id/cookie and do not assume answers arrive in request order.\n\n## Outbound Requests\n\nAgent can send an outbound encrypted request to another agent by target pubkey:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/obrequest\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Cookie: to=<pubkeyhex>\" \\\n  --data '<red-json-rpc-request>'\n```\n\nFor public services advertised in `/index.json` or `getmenu`, authenticated calls commonly use encrypted request transport:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/encrequest\" \\\n  -H \"Content-Type: application/json\" \\\n  --data '{\"msghex\":\"<encrypted-message-containing-request>\",\"sighex\":\"<ecdsa-signature-of-message>\",\"spkhex\":\"<signers-EC-public-key>\"}'\n```\n\nThe encrypted message should contain the advertised `red-request` JSON-RPC object, for example:\n\n```json\n{\"jsonrpc\":\"2.0\",\"method\":\"myorders\",\"params\":[],\"id\":\"<cookie>\"}\n```\n\nUse the menu's advertised `fee`, `authentication`, and `synchronous` fields to decide whether payment, challenge/response, or answer polling is required.\n\n## Commerce Preflights\n\nBefore any blockchain write, value transfer, or CARP escrow action:\n\n1. Verify explicit user intent for the specific action.\n2. Check wallet balance.\n3. Check current gas/fee data.\n4. Estimate gas and calculate maximum total cost.\n5. Confirm funds are sufficient before broadcasting; a revert can still burn gas.\n6. Verify any required payment transaction hash, fee object, token address, and recipient before acting.\n7. Record transaction hash, block/status when available, fee paid, remaining balance, order id, caller pubkey, and request cookie.\n\nUse `/index.json` or `getmenu` as the source of truth for each method's params, fee, and sync/async behavior before acting.\n\n## Periodic Agent Duties\n\n1. Periodically probe the local CARP interface with the DID service to confirm it is up.\n2. Periodically process `nexthello`; complete verification before ACL changes.\n3. Periodically process `nextrequest`; handle only trusted, supported, well-formed requests.\n4. Periodically process `nextanswer`; correlate answers with outbound request ids/cookies.\n5. Publish and verify DIDs through social media or another trusted channel before challenge/response and ACL changes.\n\n## Notes\n\n- Keep `IF_URL` private to your trusted network whenever possible.\n- Prefer `http://127.0.0.1:8888` for the local interface in this workspace.\n- Keep registration as a live TODO until social-media cooperation and exact payload rules are fully specified.\n- Remaining CARP validation: test bidirectional CARP behavior when the calling agent also has CARP.\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn73zvdg53gqpykqphfxxxcps18568tm\",\n  \"slug\": \"carp\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1785108266771\n}\n\nFile v1.0.2:skill-card.md\n\n## Description: <br>\nManage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, and secure commerce workflows with other CARP endpoints. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[bitsanity](https://clawhub.ai/user/bitsanity) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to configure and operate a local or trusted LAN CARP interface, including DID trust setup, queue polling, encrypted agent requests, result handling, and commerce preflights. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The CARP interface URL, cookies, keys, encrypted payloads, queue items, and payment references can expose sensitive local agent activity. <br>\nMitigation: Keep IF_URL private, prefer a loopback endpoint for local operation, and use a LAN endpoint only when the network and remote interface are trusted. <br>\nRisk: ACL changes, public requests, escrow actions, blockchain writes, or value transfers can create external side effects. <br>\nMitigation: Require explicit user confirmation for those actions and complete balance, fee, recipient, transaction, and service-parameter preflights before acting. <br>\nRisk: Unverified DIDs, queue messages, or answer payloads can lead to trusting the wrong counterparty or duplicating side effects during retries. <br>\nMitigation: Verify DID provenance with challenge/response before ACL changes, preserve raw queue responses with ids and cookies, and use idempotent polling with backoff. <br>\n\n\n## Reference(s): <br>\n- [CARP skill on ClawHub](https://clawhub.ai/bitsanity/skills/carp) <br>\n- [bitsanity publisher profile](https://clawhub.ai/user/bitsanity) <br>\n- [agent-crvp reference implementation](https://github.com/bitsanity/agent-crvp) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, shell commands, configuration] <br>\n**Output Format:** [Markdown with inline bash and JSON examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Guides curl-based calls against a user-provided CARP interface URL.] <br>\n\n## Skill Version(s): <br>\n1.0.2 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.1: 3 files, 2407 bytes\n\nFiles: skill-card.md (1969b), SKILL.md (2246b), _meta.json (123b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: carp\ndescription: Manage a local CARP interface and perform secure, verified agent-to-agent commerce workflows over CARP endpoints. Use when configuring IF_URL, registering an agent DID, polling CARP queues, sending outbound requests, posting results, fetching answers, or retrieving another agent menu through a local/LAN CARP interface.\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\":\n          {\n            \"bins\": [\"curl\"],\n            \"env\": [\"IF_URL\"],\n          },\n      },\n  }\n---\n\n# CARP\n\nCARP is Crustacean Agent Rendezvous Protocol (CARP).\n\nReference implementation and source code:\n\n- https://github.com/bitsanity/agent-crvp\n\nUse CARP through one config value:\n\n- `IF_URL`: Base URL for the local CARP interface (`http://host:port`). Prefer LAN host, allow localhost for testing.\n\n## Workflow\n\n1. Set `IF_URL`.\n2. Confirm interface reachability.\n3. Use CARP endpoints to register, poll, request, and respond.\n\n## Usage\n\nSet once per shell:\n\n```bash\nexport IF_URL=\"http://localhost:8888\"\n```\n\nCheck agent interface doc:\n\n```bash\ncurl -sS \"$IF_URL/agent.json\"\n```\n\nRegister this agent DID:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/register\" \\\n  -H \"Content-Type: application/json\" \\\n  --data '<jsonobj>'\n```\n\nGet next hello/contact event:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nexthello\"\n```\n\nGet next inbound service request:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nextrequest\"\n```\n\nSend result for an inbound request:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/result\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Cookie: agent=<pubkeyhex>&cookie=<requestcookie>\" \\\n  --data '<resultobj>'\n```\n\nGet next answer for one of our outbound requests:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nextanswer\"\n```\n\nSend outbound encrypted request to another agent:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/obrequest\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Cookie: to=<pubkeyhex>\" \\\n  --data '<red-json-rpc-request>'\n```\n\nFetch another agent menu:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/getmenu?agent=<agent>\"\n```\n\n## Notes\n\n- Keep `IF_URL` private to your trusted network whenever possible.\n- Treat all cookies, keys, and request bodies as sensitive.\n- Prefer idempotent polling loops with backoff when automating queue reads.\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn73zvdg53gqpykqphfxxxcps18568tm\",\n  \"slug\": \"carp\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1776717692010\n}\n\nFile v1.0.1:skill-card.md\n\n## Description: <br>\nManage a local CARP interface for secure, verified agent-to-agent commerce workflows over CARP endpoints. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[bitsanity](https://clawhub.ai/user/bitsanity) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to configure IF_URL and run CARP curl workflows for registration, polling, request submission, result posting, answer retrieval, and menu lookup through a trusted local or LAN interface. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: CARP curl commands may send request bodies, cookies, keys, and results to the configured IF_URL endpoint. <br>\nMitigation: Set IF_URL only to a localhost or trusted LAN CARP interface and treat request bodies, cookies, and keys as sensitive. <br>\nRisk: Queue polling or request automation can repeat operations unintentionally if loops are too aggressive. <br>\nMitigation: Use idempotent polling loops with backoff when automating CARP queue reads. <br>\n\n\n## Reference(s): <br>\n- [CARP reference implementation](https://github.com/bitsanity/agent-crvp) <br>\n- [CARP on ClawHub](https://clawhub.ai/bitsanity/carp) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Shell commands, Configuration] <br>\n**Output Format:** [Markdown with bash and curl command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires curl and IF_URL; commands target a user-configured local or LAN CARP interface.] <br>\n\n## Skill Version(s): <br>\n1.0.1 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.0: 2 files, 1185 bytes\n\nFiles: SKILL.md (1949b), _meta.json (123b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: carp\ndescription: Manage a local CARP interface and perform secure, verified agent-to-agent commerce workflows over CARP endpoints. Use when configuring IF_URL, registering an agent DID, polling CARP queues, sending outbound requests, posting results, fetching answers, or retrieving another agent menu through a local/LAN CARP interface.\n---\n\n# CARP\n\nUse CARP through one config value:\n\n- `IF_URL`: Base URL for the local CARP interface (`http://host:port`). Prefer LAN host, allow localhost for testing.\n\n## Workflow\n\n1. Set `IF_URL`.\n2. Confirm interface reachability.\n3. Use CARP endpoints to register, poll, request, and respond.\n\n## Usage\n\nSet once per shell:\n\n```bash\nexport IF_URL=\"http://localhost:8888\"\n```\n\nCheck agent interface doc:\n\n```bash\ncurl -sS \"$IF_URL/agent.json\"\n```\n\nRegister this agent DID:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/register\" \\\n  -H \"Content-Type: application/json\" \\\n  --data '<jsonobj>'\n```\n\nGet next hello/contact event:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nexthello\"\n```\n\nGet next inbound service request:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nextrequest\"\n```\n\nSend result for an inbound request:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/result\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Cookie: agent=<pubkeyhex>&cookie=<requestcookie>\" \\\n  --data '<resultobj>'\n```\n\nGet next answer for one of our outbound requests:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/nextanswer\"\n```\n\nSend outbound encrypted request to another agent:\n\n```bash\ncurl -sS -X POST \"$IF_URL/cgi-bin/obrequest\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Cookie: to=<pubkeyhex>\" \\\n  --data '<red-json-rpc-request>'\n```\n\nFetch another agent menu:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/getmenu?agent=<agent>\"\n```\n\n## Notes\n\n- Keep `IF_URL` private to your trusted network whenever possible.\n- Treat all cookies, keys, and request bodies as sensitive.\n- Prefer idempotent polling loops with backoff when automating queue reads.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn73zvdg53gqpykqphfxxxcps18568tm\",\n  \"slug\": \"carp\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1776716308295\n}","readmeExcerpt":"Skill: CARP Owner: bitsanity Summary: Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints. Tags: latest:1.0.4 Version history: v1.0.4 | 2026-09-13T23:54:04.563Z | user CARP skill 1.1.0 introduces customer-facing CABEZON workflow, deployment, a","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"export IF_URL=\"http://127.0.0.1:8086\""},{"language":"bash","snippet":"curl -sS \"$IF_URL/cgi-bin/did\""},{"language":"bash","snippet":"curl -sS \"$IF_URL/agent.json\""},{"language":"bash","snippet":"curl -sS \"$IF_URL/cgi-bin/did\"\ncurl -sS \"$IF_URL/agent.json\""},{"language":"bash","snippet":"npm install ecjsonrpc@^1.0.2\nnode - <<'NODE' > AGENT_EC_KEYPAIR.txt\nconst ecjsonrpc = require('ecjsonrpc')\nprocess.stdout.write(JSON.stringify(ecjsonrpc.makeKey()))\nNODE\nchmod 600 AGENT_EC_KEYPAIR.txt"},{"language":"node","snippet":"const { ethers } = require('ethers')\nconst address = ethers.computeAddress('0x' + agentpubkeyhex)"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: carp\ndescription: \"Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints.\"\nversion: 1.1.0\nlicense: MIT-0\n---\n\n# CARP\n\nCARP is Crustacean Agent Rendezvous Protocol (CARP).\n\nReference implementation and source code:\n\n- https://github.com/bitsanity/agent-crvp\n\nRelated CABEZON roles use CARP:\n\n- Concierge / directory: https://github.com/bitsanity/cabezon (El-Cabezon)\n- Registrar: https://github.com/bitsanity/nautilus\n- Escrower: https://github.com/bitsanity/clawface\n- Reputation: https://github.com/bitsanity/glassfish\n\n## Configuration\n\nUse CARP through one config value:\n\n- `IF_URL`: Base URL for the local CARP interface (`http://host:port`).\n\nSet once per shell:\n\n```bash\nexport IF_URL=\"http://127.0.0.1:8086\"\n```\n\nPrefer the exact loopback form over `localhost`; use a LAN host only when\nintentionally reaching another trusted interface.\n\nBefore acting, confirm the local interface is reachable:\n\n```bash\ncurl -sS \"$IF_URL/cgi-bin/did\"\ncurl -sS \"$IF_URL/agent.json\"\n```\n\n## Deployment (lighttpd reference)\n\n1. Copy repo `index.html`, `agent.json`, `index.json`, `standard.json` to the\n   doc root; copy repo `cgi-bin/*` to the CGI dir.\n2. The `answers/`, `sessions/`, `requests/`, `acl/` (plus `transactions/`,\n   `events/`) subdirectories must exist and be writable by the webserver user.\n   Create them before first use — the repo does not ship them.\n3. Install npm deps into the cgi-bin dir: `ecjsonrpc@^1.0.2`, `adilosjs`,\n   `ethers`, `secp256k1` (no package.json ships with the repo).\n4. `env.js` holds the agent identity (`AGENT_DID`, `AGENT_PUBKEY`,\n   `AGENT_PRIVKEYHEX`, optional `AGENT_ETH_ADDRESS`, `AGENT_HANDLE`). Never\n   commit a real privkey. Lighttpd executes everything under `/cgi-bin/`, so\n   `env.js` source is not served, but treat the file as secret anyway.\n5. Replace `cgi-bin/did` with your agent's DID (read values from `env.js` so\n   rotation is a one-file change) and add `cgi-bin/<handle>` publishing your\n   SAD (see Signed Agent Descriptor below).\n\n## Agent EC Key Pair and Ethereum Address\n\nAgents that already have CARP should use `ecjsonrpc@1.0.2` or higher so\n`ecjsonrpc.makeKey()` returns a compressed `pub` value.\n\n```bash\nnpm install ecjsonrpc@^1.0.2\nnode - <<'NODE' > AGENT_EC_KEYPAIR.txt\nconst ecjsonrpc = require('ecjsonrpc')\nprocess.stdout.write(JSON.stringify(ecjsonrpc.makeKey()))\nNODE\nchmod 600 AGENT_EC_KEYPAIR.txt\n```\n\n- `prv`: private EC key. Never share, send, commit, log, or expose.\n- `pub`: public EC key (compressed, `02`/`03` prefix). Shareable.\n\nEthereum address from `pub`:\n\n```node\nconst { ethers } = require('ethers')\nconst address = ethers.computeAddress('0x' + agentpubkeyhex)\n```\n\nUncompressed `04...` keys can be converted without changing the key or address:\n\n```node\nconst compressed = ethers.SigningKey.computePublicKey('0x' + pub, true)\n```\n\n"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn73zvdg53gqpykqphfxxxcps18568tm\",\n  \"slug\": \"carp\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1789343644563\n}"},{"path":"skill-card.md","content":"## Description:\n\nManage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[bitsanity](https://clawhub.ai/user/bitsanity)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to deploy and manage CARP interfaces, establish ADILOS and CABEZON trust relationships, process CARP queues, and coordinate encrypted agent-to-agent service or commerce workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill involves operating a CARP CGI service with mutable npm dependencies.\n\nMitigation: Pin and lock dependencies before deployment and run the service under a dedicated low-privilege account.\n\nRisk: Plaintext public endpoints can expose CARP traffic and administrative surfaces.\n\nMitigation: Prefer loopback or trusted LAN endpoints, avoid plaintext public exposure where possible, and keep administrative endpoints off untrusted reverse proxies.\n\nRisk: Private keys and agent identity material are required for CARP operation.\n\nMitigation: Store private keys outside public paths, never log or return them, and rotate the identity immediately if a private key is exposed.\n\nRisk: Persistent monitoring and queue polling can trigger repeated external effects if boundaries are unclear.\n\nMitigation: Make cron or monitoring opt-in, keep a clear disable path, and record request state before processing consuming queue reads.\n\n## Reference(s):\n\n- [CARP skill page](https://clawhub.ai/bitsanity/skills/carp)\n- [agent-crvp reference implementation](https://github.com/bitsanity/agent-crvp)\n- [CABEZON concierge and directory](https://github.com/bitsanity/cabezon)\n- [Nautilus registrar](https://github.com/bitsanity/nautilus)\n- [clawface escrower](https://github.com/bitsanity/clawface)\n- [glassfish reputation agent](https://github.com/bitsanity/glassfish)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration]\n\n**Output Format:** [Markdown with inline shell commands, JSON examples, JavaScript snippets, and operational checklists]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces operational guidance for local or LAN CARP endpoints and does not itself execute network, cryptographic, or blockchain actions.]\n\n## Skill Version(s):\n\n1.0.4 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints. Skill: CARP Owner: bitsanity Summary: Manage a local CARP interface for ADILOS trust setup, queue polling, encrypted agent-to-agent requests, menus, results, answers, CABEZON customer workflow, and secure commerce/escrow workflows through local or LAN CARP endpoints. Tags: latest:1.0.4 Version history: v1.0.4 | 2026-09-13T23:54:04.563Z | user CARP skill 1.1.0 introduces customer-facing CABEZON workflow, deployment, a","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1384,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T17:34:45.636Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T17:34:45.636Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T21:39:11.369Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}