{"id":"86228e7b-f068-4c72-a549-e66474be3a4b","entityType":"agent","slug":"clawhub-jwestburg-tavily-search-pro-native-node","name":"tavily-search-pro-native-node","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jwestburg-tavily-search-pro-native-node","canonicalPath":"/agent/clawhub-jwestburg-tavily-search-pro-native-node","generatedAt":"2026-10-10T10:44:41.407Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T06:19:13.630Z","emptyReason":null},"description":"Research-grade Tavily web search for OpenClaw using native Node.js with zero dependencies. Use for deep web research, multi-URL content extraction, estimated Tavily credit tracking, response caching, usage-log review, and 429 backoff. Includes search, extract, stats, and cache subcommands. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s177the448m6rk54wz8gse0jnd8587yq:tavily-search-pro-native-node","sourceUrl":"https://clawhub.ai/jwestburg/tavily-search-pro-native-node","homepage":"https://clawhub.ai/jwestburg/skills/tavily-search-pro-native-node","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jwestburg/tavily-search-pro-native-node","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jwestburg/skills/tavily-search-pro-native-node","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"tavily-search-pro-native-node technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T06:19:13.630Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T06:19:13.630Z","emptyReason":null},"stars":null,"forks":null,"downloads":1624,"packageName":null,"latestVersion":"1.0.36","tractionLabel":"1.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T06:19:13.568Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T06:19:13.630Z","lastCrawledAt":"2026-10-10T06:19:13.568Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T06:19:13.568Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.36","createdAt":"2026-09-11T02:17:07.632Z","changelog":"Public candidate v1.0.36: reviewed Tavily Pro research helper with search/extract/stats/cache controls, bounded inputs, local tests, and approval-aware provider usage.","fileCount":6,"zipByteSize":23131},{"version":"1.0.20","createdAt":"2026-07-15T19:41:07.640Z","changelog":"Add ClawHub/OpenClaw runtime metadata for required TAVILY_API_KEY, including requires.env, primaryEnv, and envVars, so declared requirements match the script's env-key behavior. No runtime behavior change.","fileCount":6,"zipByteSize":17138},{"version":"1.0.19","createdAt":"2026-07-07T18:25:50.356Z","changelog":"Public-ready source polish: clarify ClawHub candidate posture, document local/private URL guardrail limits, neutralize process wording, retain Tavily API/cache/log/estimated-credit disclosures, and preserve no-catalog-metadata-in-source posture. No runtime behavior change after v1.0.15 validation fixes.","fileCount":6,"zipByteSize":16904},{"version":"1.0.11","createdAt":"2026-06-14T22:44:00.792Z","changelog":"ClawHub publication/version refresh after public-readiness review; no runtime behavior change.","fileCount":6,"zipByteSize":15490},{"version":"1.0.10","createdAt":"2026-06-02T03:57:48.186Z","changelog":"Public-ready safety/docs/test update","fileCount":6,"zipByteSize":15462},{"version":"1.0.8","createdAt":"2026-05-30T19:26:46.277Z","changelog":"Clarify cache scope, retry behavior, sensitive-query handling, and public log/path sanitization.","fileCount":5,"zipByteSize":13172},{"version":"1.0.6","createdAt":"2026-05-26T15:05:34.131Z","changelog":"Add version metadata and align cache-clear documentation so local deletion is consistently approval-gated; no runtime behavior changes.","fileCount":5,"zipByteSize":12695},{"version":"1.0.5","createdAt":"2026-05-19T19:39:48.890Z","changelog":"Lean public docs update with explicit Tavily API/cache/logging contract, publish/update checks, and reviewed helper source alignment.","fileCount":4,"zipByteSize":11109}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s177the448m6rk54wz8gse0jnd8587yq:tavily-search-pro-native-node","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s177the448m6rk54wz8gse0jnd8587yq:tavily-search-pro-native-node` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/jwestburg/tavily-search-pro-native-node before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T10:44:41.403Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jwestburg-tavily-search-pro-native-node/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T06:19:13.630Z","emptyReason":null},"readme":"Skill: tavily-search-pro-native-node\n\nOwner: jwestburg\n\nSummary: Research-grade Tavily web search for OpenClaw using native Node.js with zero dependencies. Use for deep web research, multi-URL content extraction, estimated Tavily credit tracking, response caching, usage-log review, and 429 backoff. Includes search, extract, stats, and cache subcommands. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\n\nTags: cache:1.0.19, cache extract latest node research search tavily:1.0.20, extract:1.0.19, latest:1.0.36, node:1.0.19, research:1.0.19, search:1.0.19, tavily:1.0.19\n\nVersion history:\n\nv1.0.36 | 2026-09-11T02:17:07.632Z | user\n\nPublic candidate v1.0.36: reviewed Tavily Pro research helper with search/extract/stats/cache controls, bounded inputs, local tests, and approval-aware provider usage.\n\nv1.0.20 | 2026-07-15T19:41:07.640Z | user\n\nAdd ClawHub/OpenClaw runtime metadata for required TAVILY_API_KEY, including requires.env, primaryEnv, and envVars, so declared requirements match the script's env-key behavior. No runtime behavior change.\n\nv1.0.19 | 2026-07-07T18:25:50.356Z | user\n\nPublic-ready source polish: clarify ClawHub candidate posture, document local/private URL guardrail limits, neutralize process wording, retain Tavily API/cache/log/estimated-credit disclosures, and preserve no-catalog-metadata-in-source posture. No runtime behavior change after v1.0.15 validation fixes.\n\nv1.0.11 | 2026-06-14T22:44:00.792Z | user\n\nClawHub publication/version refresh after public-readiness review; no runtime behavior change.\n\nv1.0.10 | 2026-06-02T03:57:48.186Z | user\n\nPublic-ready safety/docs/test update\n\nv1.0.8 | 2026-05-30T19:26:46.277Z | user\n\nClarify cache scope, retry behavior, sensitive-query handling, and public log/path sanitization.\n\nv1.0.6 | 2026-05-26T15:05:34.131Z | user\n\nAdd version metadata and align cache-clear documentation so local deletion is consistently approval-gated; no runtime behavior changes.\n\nv1.0.5 | 2026-05-19T19:39:48.890Z | user\n\nLean public docs update with explicit Tavily API/cache/logging contract, publish/update checks, and reviewed helper source alignment.\n\nv1.0.4 | 2026-05-08T15:42:21.544Z | user\n\nRemove vestigial multi-key fallback path and clarify cache credit stats as estimated credits avoided.\n\nv1.0.3 | 2026-05-06T00:43:59.922Z | user\n\nPublic polish: env-only credentials, ASCII-clean docs and examples, local-cache scanner-warning clarity, and package consistency checks.\n\nv1.0.1 | 2026-05-06T00:15:36.497Z | user\n\nScanner cleanup: remove ~/.openclaw/.env credential fallback; credentials are read from process environment only. Cache/log behavior unchanged under ~/.openclaw/cache.\n\nv1.0.0 | 2026-05-05T23:53:33.550Z | user\n\nInitial public release: research-grade Tavily search/extract/cache/stats helper with native Node.js and zero dependencies.\n\nArchive index:\n\nArchive v1.0.36: 6 files, 23131 bytes\n\nFiles: references/tavily-pro-contract.md (7418b), scripts/self-test.mjs (16272b), scripts/tavily-pro.mjs (31889b), skill-card.md (2614b), SKILL.md (17451b), _meta.json (149b)\n\nFile v1.0.36:SKILL.md\n\n---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily web search for OpenClaw using native Node.js with zero dependencies. Use for deep web research, multi-URL content extraction, estimated Tavily credit tracking, response caching, usage-log review, and 429 backoff. Includes search, extract, stats, and cache subcommands. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\nversion: 1.0.36\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TAVILY_API_KEY\n    primaryEnv: TAVILY_API_KEY\n    envVars:\n      - name: TAVILY_API_KEY\n        required: true\n        description: Tavily API key used for authenticated search and extract requests.\nrisk_class: external-research-api-credit-cache-log-local-delete\n---\n\n# Tavily Search Pro (Native Node)\n\nVersion: 1.0.36 / public ClawHub utility candidate with external API, cache, usage-log, and approval-gated local cache deletion behavior.\n\nResearch-grade Tavily web search helper: one dependency-free Node script with `search`, `extract`, `stats`, and `cache` subcommands.\n\n## Risk / invocation class\n\nRisk class: **external research API / credit usage / plaintext query logging / local cache deletion**.\n\nUse deliberately. This skill sends search queries or URLs to Tavily over HTTPS, may append plaintext queries/URLs to a local usage log unless `--no-log` is used, and exposes `cache clear` as approval-gated local deletion of cached response JSON files.\n\n## Input packet\n\nRequired:\n\n- `task`: search, extract, usage stats, or cache inspection.\n- `query_or_urls`: search query or URL list when applicable.\n- `privacy_sensitivity`: normal, sensitive, client/private, or unknown. `unknown` is a fail-closed state for `search` and `extract`: classify sensitivity first or obtain explicit approval for external Tavily transmission before running an outbound command.\n- `freshness_need`: normal cache ok, fresh/no-cache, or news/freshness-critical.\n- `depth`: basic unless advanced is justified.\n\nOptional:\n\n- `trusted_domains`: include/exclude domains.\n- `max_results`: default 5; avoid broad high-result searches unless needed.\n- `logging_preference`: normal log, `--no-log`, or unknown.\n- `output_format`: human summary or `--json`.\n\nStop or switch tools if the query is privacy-sensitive and sending it to Tavily is not appropriate. If `privacy_sensitivity` is `unknown`, do not run `search` or `extract` until sensitivity is classified as normal or explicit approval resolves the external-send ambiguity. For one known URL, prefer `web_fetch` unless extraction quality matters.\n\n## Output packet\n\nReturn compactly:\n\n- command used or planned, redacted as needed\n- whether cache/logging was enabled\n- freshness/depth choice\n- sources/results with URLs\n- estimated credits used or expected when known\n- limitations/caveats\n- next safe research step\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files or `~/.openclaw/.env`.\n- Makes network calls only to Tavily's HTTPS endpoints:\n  - `https://api.tavily.com/search`\n  - `https://api.tavily.com/extract`\n- Writes cache and usage logs only under `~/.openclaw/cache/tavily-search-pro-native-node/` after routine persistent-state containment checks; routine cache/log reads and writes refuse symlink-indirected directories/files. `cache clear` requires explicit approval, rejects symlink-indirected cache paths, deletes only expected hash-named regular cached response JSON files under that skill-specific cache directory, skips non-cache entries, and reports partial deletion failures truthfully.\n- Cache filenames are SHA-256-derived request hashes, not plaintext queries.\n- Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n- Usage logs may contain plaintext search queries/URLs; use `--no-log` for approved sensitive external calls.\n- Local/private URL refusal is a guardrail for obvious mistaken extract targets, not a complete SSRF boundary; Tavily performs extraction from Tavily infrastructure, not this machine.\n- Does not read local files outside its documented cache/log state, and does not read non-Tavily secrets. User-supplied search queries and accepted extract URLs are sent to Tavily; `TAVILY_API_KEY` is sent only to Tavily for authentication. Credential-bearing and local/private extract URLs are rejected before API key load/Tavily transmission, and those error paths do not echo the supplied URL.\n- Does not modify system configuration or auto-update. The only destructive local action is the documented, approval-gated `cache clear` deletion of expected regular cached response JSON files after cache-path containment checks.\n- Public-registry static-analysis `potential_exfiltration` warnings are expected because this tool combines env credentials, local cache/log file access, and Tavily network calls.\n\n## When to use\n\nUse this Pro skill when:\n\n- the user needs thorough web research, not just a quick lookup;\n- multiple queries are likely and cache will save credits;\n- full content extraction from specific URLs is needed;\n- Tavily usage/stats matter;\n- 429 retry/backoff is useful.\n\nPrefer `tavily-search-native-node` when:\n\n- a single simple search is enough;\n- minimum audit surface matters;\n- no disk writes/caching/logging are desired.\n\nPrefer `web_fetch` for a one-off known URL read.\n\nDo not use when:\n\n- the query privacy is unknown/unclassified; classify it or get explicit approval before any external Tavily transmission;\n- the query is privacy-sensitive and should not leave this machine;\n- the user has not approved a sensitive/client/private query to an external research API;\n- freshness requires live source browsing and cache state is uncertain, unless `--no-cache` is used.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache       # defaults to cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear  # local deletion; use only after explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\nFor full flags, cache/log behavior, troubleshooting, and publish/update checks, load `references/tavily-pro-contract.md`.\n\n## Operating guidance\n\n- Prefer one well-crafted query over several narrow searches.\n- Use `basic` depth unless advanced is justified; `advanced` costs more.\n- Use `--include`/`--exclude` to scope sources when appropriate.\n- Use cache by default; use `--no-cache` when freshness matters. `--ttl 0` disables cache reads for that command but still writes the fresh response to cache unless `--no-cache` is also set.\n- Treat `privacy_sensitivity: unknown` as a stop state for outbound `search`/`extract`; classify the request or get explicit approval before Tavily receives the query/URLs.\n- Use `--no-log --no-cache` for sensitive but approved external queries so this skill's plaintext usage log is skipped and sensitive research context is not cached; this does not remove every possible local trace such as shell/agent transcripts or provider error text.\n- For follow-up deep reads: search -> select URLs -> extract.\n- Quote sources so the user/requester can verify.\n- Track estimated credit usage with `stats` when research runs get large.\n- Treat `cache clear` as local destructive cleanup; agents should ask before running it.\n\n## Required checks before publishing/updating\n\nMinimum no-spend checks:\n\n```powershell\nnode --check skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs help\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs stats --json\nnode skills\\tavily-search-pro-native-node\\scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test in a temporary home/profile context when feasible to confirm credential errors without spending credits.\n\n## Public registry exposure\n\nClassification: **public ClawHub utility candidate with external API + local cache/log writes + approval-gated local cache deletion**.\n\nBefore public update, run sanitizer/static checks and make sure docs clearly disclose:\n\n- external calls to Tavily;\n- cache/log file locations and the fact that help/cache output may print a local home-derived cache path; sanitize screenshots/logs before public sharing;\n- plaintext query/URL logging;\n- expected static-analysis warning;\n- no local file/secret exfiltration.\n\nDo not include private/internal/client strategy or operator-specific operational notes in a public release.\n\n## Changelog\n\n- `1.0.36`: Add runtime help-text polish that explicitly says `search` and `extract` require `TAVILY_API_KEY` and send queries/URLs to Tavily; no behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.35`: Harden routine cache/log reads and writes against symlink-indirected persistent-state directories/files, align security prose with local cache/log reads, and add no-spend regression tests proving normal search cannot redirect `usage.log` or cache-entry writes through pre-existing symlinks. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.34`: Remove the remaining overbroad Windows-indirection wording from the changelog so public source wording matches the symlink-only source/test evidence; no runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.33`: Complete the symlink-only wording alignment by updating the runtime refusal message and changelog; no cache-clear behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.32`: Narrow public `cache clear` documentation from overbroad Windows-indirection wording to symlink-indirection so the wording matches source/test evidence; no runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.31`: Harden `cache clear` with cache-root containment checks, symlink-indirection refusal, hash-named regular cache-file deletion only, non-cache-entry skipping, truthful partial-failure reporting, and temp-home self-test regressions. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.30`: Polish security wording so `--no-log` guidance explicitly applies to approved sensitive external calls, preserving fail-closed handling for unknown/unapproved sensitive material. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.29`: Expand risk metadata/prose to include approval-gated local cache deletion, make `privacy_sensitivity: unknown` fail closed before outbound Tavily search/extract, and add static self-test assertions for those public-candidate safety requirements. No runtime search/extract behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.28`: Sanitize local/private extract URL errors so rejected localhost/private/link-local/ULA URLs are not echoed to stderr/log-support pastes; add path/query no-echo regression coverage. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.27`: Sanitize credential-bearing extract URL errors so rejected username/password userinfo inputs are not echoed to stderr/log-support pastes; add no-echo regression coverage. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.26`: Tighten extract URL validation to reject credential-bearing URLs with username/password userinfo before API key load/Tavily transmission; clarify user-supplied query/URL transmission wording and add regression coverage. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.25`: Tighten extract URL validation to reject raw backslash characters before URL parsing, preventing parser repair of backslash authority/path forms before API key load/Tavily transmission; add regression coverage. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.24`: Tighten extract URL validation to require raw conventional `http://` or `https://` URLs with a host, preventing URL-parser repair of slashless, one-slash, extra-slash, or backslash-ish HTTP(S) inputs before API key load/Tavily transmission; add regression coverage. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.23`: Polish extract validation so malformed or non-HTTP(S) URL arguments fail as invalid before API key load/Tavily transmission, and add no-key regression coverage for malformed HTTP/IPv6 and non-HTTP protocol cases. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.22`: Polish extract URL guard to reject IPv6 unspecified literals (`::` and expanded all-zero form) before API key load/Tavily transmission and add self-test coverage. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.21`: Fix extract URL guard to reject IPv4-mapped IPv6 private/local/link-local addresses before API key load/Tavily transmission, add `0.0.0.0` refusal, and add self-test coverage for mapped loopback/RFC1918/link-local plus mapped public DNS allow-through-to-no-key behavior. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.20`: Add ClawHub/OpenClaw runtime metadata for required `TAVILY_API_KEY`, including `requires.env`, `primaryEnv`, and `envVars`, so declared requirements match the script's env-key behavior. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.19`: Neutralize approval/process wording in header, classification, and changelog notes. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.18`: Normalize prior changelog wording. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.17`: Remove person-specific wording from prior changelog notes. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.16`: Clarify ClawHub candidate posture in the header and document that local/private URL refusal is a best-effort guardrail for obvious mistaken extract targets, not a complete SSRF boundary. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.15`: Input-validation polish: restrict IPv6 ULA `fc00::/7` refusal to actual IPv6 literals so public DNS names beginning with `fc`/`fd` are not overblocked, while retaining ULA and link-local refusal before API key load/Tavily transmission. Adds self-test coverage for ULA and public `fc*`/`fd*` hostnames. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.14`: Input-validation polish: correctly block the full IPv6 link-local `fe80::/10` range (`fe80` through `febf`) before API key load/Tavily transmission and add self-test coverage for boundary examples. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.13`: Input-validation polish: block IPv6 link-local `fe80::/10` extract URLs before API key load/Tavily transmission, add self-test coverage, and align frontmatter description with source wording. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.12`: Polish source wording from “toolkit” to web search, clarify estimated credit labels/docs, document `--ttl 0` cache-read semantics and default `cache` behavior, reject local/private extract URLs before Tavily transmission, and avoid standing publishability wording. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.11`: Version refresh; no runtime behavior change.\n- `1.0.10`: Gate `TAVILY_PRO_MOCK_JSON` behind `TAVILY_PRO_SELFTEST=1`, add inert-hook regression, and reject unexpected `cache clear` arguments.\n- `1.0.9`: Add request timeout support, strict `stats`/`cache info` argument rejection, and no-spend self-tests.\n- `1.0.8`: Tighten public docs for cache-key precision and retry-attempt wording.\n- `1.0.7`: Document that cache entries are request-scoped, not API-account-scoped, so shared OS profiles may share cached results.\n- `1.0.6`: Add frontmatter version metadata and align reference docs so `cache clear` is consistently marked as local deletion requiring explicit approval.\n- `1.0.5`: Public package wording/metadata cleanup; cache/log/security behavior unchanged.\n\nFile v1.0.36:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"tavily-search-pro-native-node\",\n  \"version\": \"1.0.36\",\n  \"publishedAt\": 1789093027632\n}\n\nFile v1.0.36:references/tavily-pro-contract.md\n\n# Tavily Search Pro Contract\n\nUse only when the compact `SKILL.md` is not enough.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\nSubcommands:\n\n- `search`\n- `extract`\n- `stats`\n- `cache`\n- `help`\n\n## Quick reference\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache      # defaults to cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\n## Search flags\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` / `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` / `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` news only | Age window |\n| `--include` | comma list | none | Domains to include |\n| `--exclude` | comma list | none | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n| `--timeout-ms` | integer | 30000 | Per-attempt network timeout |\n\n## Extract flags\n\nWraps Tavily's `/extract` endpoint. Takes one or more public HTTP(S) URLs. The CLI requires raw conventional `http://` or `https://` URLs with a host, rejects malformed/non-HTTP(S)/raw-backslash/credential-bearing URL arguments, and refuses localhost, loopback, unspecified IPv4/IPv6, link-local, RFC1918/private-address URLs, and private/local IPv4-mapped IPv6 forms before sending anything to Tavily. Credential-bearing and local/private URL errors are sanitized and do not echo the supplied URL.\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl`, `--timeout-ms`.\n\nEstimated credits: Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs basic, 2 per 5 advanced. The usage log estimates this locally; it is not a Tavily-returned billing value.\n\n## Stats\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json\n```\n\nOutput includes total calls, searches vs extracts, cache hit rate, errors, estimated credits used, and estimated credits avoided by cache.\n\n## Cache\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\n```\n\n`cache` with no subcommand defaults to `cache info`. Routine cache reads/writes and usage-log reads/writes perform persistent-state containment checks and refuse symlink-indirected directories/files instead of following them outside `~/.openclaw/cache/tavily-search-pro-native-node/`. `cache clear` accepts no extra arguments, requires explicit approval, rejects symlink-indirected cache paths, deletes only expected hash-named regular cached response JSON files under the skill-specific cache directory, skips non-cache entries, and does not delete `usage.log`. It reports partial deletion failures with the number already deleted instead of returning a false zero.\n\nResponses are cached under `~/.openclaw/cache/tavily-search-pro-native-node/cache/` keyed by a SHA-256-derived hash of request body + kind. Request-body-affecting options such as topic, depth, max results, include/exclude domains, raw-content, URL list, and extract depth create different cache entries; output/control flags such as `--json`, `--ttl`, `--no-log`, and `--no-retry` do not. Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n\nDefault TTLs:\n\n- Search, general topic: 24 hours\n- Search, news topic: 1 hour\n- Extract: 7 days\n\nOverride with `--ttl SECONDS`; `--ttl 0` disables cache reads for that command but still writes the fresh response to cache unless `--no-cache` is also set. Skip cache reads and writes with `--no-cache`.\n\n## Rate-limit backoff\n\nOn HTTP 429, makes up to 3 total attempts with exponential backoff between attempts (normally 1s, then 2s) or respects `Retry-After` when present. Disable with `--no-retry`.\n\nNetwork errors and per-attempt timeouts also retry. Other HTTP errors surface immediately. Override the default 30000ms timeout with `--timeout-ms N`.\n\n## Usage log\n\nEvery call appends one JSON line to:\n\n```text\n~/.openclaw/cache/tavily-search-pro-native-node/usage.log\n```\n\nExample:\n\n```json\n{\"ts\":1713732000000,\"kind\":\"search\",\"query\":\"OpenClaw\",\"depth\":\"basic\",\"topic\":\"general\",\"cached\":false,\"credits\":1}\n```\n\nQueries/URLs are logged in plaintext. Treat unknown/unclassified privacy sensitivity as fail-closed for outbound `search` or `extract`: classify the request first or obtain explicit approval for external Tavily transmission. Use `--no-log --no-cache` for sensitive but approved external calls so this skill's plaintext usage log is skipped and sensitive research context is not cached; this does not eliminate every possible local trace such as shell/agent transcripts, CLI arguments, stdout/stderr, or provider error text.\n\n## Troubleshooting\n\n- `TAVILY_API_KEY not set` -> set env var in process environment.\n- HTTP 401 -> invalid/revoked key.\n- HTTP 429 -> rate limited; script auto-retries then surfaces Retry-After.\n- HTTP 432 -> monthly credit cap hit.\n- Network timeout -> retries, then surfaces error.\n- Stale results -> use `--no-cache` or `cache clear` after explicit approval for local deletion.\n- Cache/log growth -> `cache info`, `cache clear`, or manual log rotation. `cache clear` is local deletion and requires explicit approval before running; it fails closed on cache-path indirection and reports partial deletion failures truthfully.\n\n## Agent usage pattern\n\n1. Classify privacy sensitivity before outbound `search` or `extract`; `unknown` fails closed until classified or explicitly approved for external Tavily transmission.\n2. Prefer one well-crafted search over several narrow ones.\n3. Use `basic` unless the user asks for deep research.\n4. Use `--include` for trusted domains when appropriate.\n5. Use cache unless freshness matters.\n6. For deep reads: search -> pick URLs -> extract.\n7. Quote sources so the user can verify.\n\n## Publish/update checks\n\nBefore publishing or updating:\n\n```powershell\nnode --check scripts\\tavily-pro.mjs\nnode scripts\\tavily-pro.mjs help\nnode scripts\\tavily-pro.mjs stats --json\nnode scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test with a temporary home directory to verify credential errors without spending credits. Offline mock fixtures are available only when `TAVILY_PRO_SELFTEST=1` is set by `scripts/self-test.mjs`; do not set self-test hooks for normal research use.\n\nFile v1.0.36:skill-card.md\n\n## Description:\n\nResearch-grade Tavily web search for OpenClaw using native Node.js with zero dependencies, supporting deep web research, multi-URL extraction, estimated credit tracking, response caching, usage-log review, and 429 backoff.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jwestburg](https://clawhub.ai/user/jwestburg)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and research agents use this skill to run Tavily-backed web searches, extract content from public URLs, inspect usage statistics, and manage response cache behavior while tracking estimated credit use.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Search queries and accepted public URLs are sent to Tavily with the configured API key.\n\nMitigation: Use this skill only for queries and URLs approved for external Tavily processing, and classify privacy sensitivity before outbound search or extract use.\n\nRisk: Usage logs may contain plaintext queries or URLs, and cached responses may persist under the skill-specific OpenClaw cache directory.\n\nMitigation: Use --no-log --no-cache for sensitive or client/private research that is approved for external processing.\n\nRisk: Cached responses are not scoped by Tavily account when multiple accounts share one OS profile.\n\nMitigation: Use separate OS profiles for account isolation or disable caching with --no-cache.\n\nRisk: The cache clear subcommand deletes local cached response files.\n\nMitigation: Run cache clear only when deletion is intentional; the skill limits deletion to expected cache files under its own cache directory and reports partial failures.\n\n## Reference(s):\n\n- [Tavily Search Pro Contract](references/tavily-pro-contract.md)\n- [ClawHub Skill Page](https://clawhub.ai/jwestburg/skills/tavily-search-pro-native-node)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown or JSON command output with source URLs, cache/logging status, freshness and depth choices, estimated credit use, caveats, and next-step guidance.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May emit raw JSON when requested; normal usage returns compact human-facing text.]\n\n## Skill Version(s):\n\n1.0.36 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.20: 6 files, 17138 bytes\n\nFiles: references/tavily-pro-contract.md (6015b), scripts/self-test.mjs (5486b), scripts/tavily-pro.mjs (24065b), skill-card.md (2636b), SKILL.md (10539b), _meta.json (149b)\n\nFile v1.0.20:SKILL.md\n\n---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily web search for OpenClaw using native Node.js with zero dependencies. Use for deep web research, multi-URL content extraction, estimated Tavily credit tracking, response caching, usage-log review, and 429 backoff. Includes search, extract, stats, and cache subcommands. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\nversion: 1.0.20\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TAVILY_API_KEY\n    primaryEnv: TAVILY_API_KEY\n    envVars:\n      - name: TAVILY_API_KEY\n        required: true\n        description: Tavily API key used for authenticated search and extract requests.\nrisk_class: external-research-api-credit-cache-log\n---\n\n# Tavily Search Pro (Native Node)\n\nVersion: 1.0.20 / public ClawHub utility candidate with external API, cache, and usage-log behavior.\n\nResearch-grade Tavily web search helper: one dependency-free Node script with `search`, `extract`, `stats`, and `cache` subcommands.\n\n## Risk / invocation class\n\nRisk class: **external research API / credit usage / plaintext query logging**.\n\nUse deliberately. This skill sends search queries or URLs to Tavily over HTTPS and may append plaintext queries/URLs to a local usage log unless `--no-log` is used.\n\n## Input packet\n\nRequired:\n\n- `task`: search, extract, usage stats, or cache inspection.\n- `query_or_urls`: search query or URL list when applicable.\n- `privacy_sensitivity`: normal, sensitive, client/private, or unknown.\n- `freshness_need`: normal cache ok, fresh/no-cache, or news/freshness-critical.\n- `depth`: basic unless advanced is justified.\n\nOptional:\n\n- `trusted_domains`: include/exclude domains.\n- `max_results`: default 5; avoid broad high-result searches unless needed.\n- `logging_preference`: normal log, `--no-log`, or unknown.\n- `output_format`: human summary or `--json`.\n\nStop or switch tools if the query is privacy-sensitive and sending it to Tavily is not appropriate. For one known URL, prefer `web_fetch` unless extraction quality matters.\n\n## Output packet\n\nReturn compactly:\n\n- command used or planned, redacted as needed\n- whether cache/logging was enabled\n- freshness/depth choice\n- sources/results with URLs\n- estimated credits used or expected when known\n- limitations/caveats\n- next safe research step\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files or `~/.openclaw/.env`.\n- Makes network calls only to Tavily's HTTPS endpoints:\n  - `https://api.tavily.com/search`\n  - `https://api.tavily.com/extract`\n- Writes cache and usage logs only under `~/.openclaw/cache/tavily-search-pro-native-node/`.\n- Cache filenames are SHA-256-derived request hashes, not plaintext queries.\n- Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n- Usage logs may contain plaintext search queries/URLs; use `--no-log` for sensitive calls.\n- Local/private URL refusal is a guardrail for obvious mistaken extract targets, not a complete SSRF boundary; Tavily performs extraction from Tavily infrastructure, not this machine.\n- Does not read or transmit local files or non-Tavily secrets; sends `TAVILY_API_KEY` only to Tavily for authentication.\n- Does not modify system configuration or auto-update.\n- Public-registry static-analysis `potential_exfiltration` warnings are expected because this tool combines env credentials, local cache/log file access, and Tavily network calls.\n\n## When to use\n\nUse this Pro skill when:\n\n- the user needs thorough web research, not just a quick lookup;\n- multiple queries are likely and cache will save credits;\n- full content extraction from specific URLs is needed;\n- Tavily usage/stats matter;\n- 429 retry/backoff is useful.\n\nPrefer `tavily-search-native-node` when:\n\n- a single simple search is enough;\n- minimum audit surface matters;\n- no disk writes/caching/logging are desired.\n\nPrefer `web_fetch` for a one-off known URL read.\n\nDo not use when:\n\n- the query is privacy-sensitive and should not leave this machine;\n- the user has not approved a sensitive/client/private query to an external research API;\n- freshness requires live source browsing and cache state is uncertain, unless `--no-cache` is used.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache       # defaults to cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear  # local deletion; use only after explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\nFor full flags, cache/log behavior, troubleshooting, and publish/update checks, load `references/tavily-pro-contract.md`.\n\n## Operating guidance\n\n- Prefer one well-crafted query over several narrow searches.\n- Use `basic` depth unless advanced is justified; `advanced` costs more.\n- Use `--include`/`--exclude` to scope sources when appropriate.\n- Use cache by default; use `--no-cache` when freshness matters. `--ttl 0` disables cache reads for that command but still writes the fresh response to cache unless `--no-cache` is also set.\n- Use `--no-log --no-cache` for sensitive but approved external queries so plaintext query/URL logs are skipped and sensitive research context is not cached.\n- For follow-up deep reads: search -> select URLs -> extract.\n- Quote sources so the user/requester can verify.\n- Track estimated credit usage with `stats` when research runs get large.\n- Treat `cache clear` as local destructive cleanup; agents should ask before running it.\n\n## Required checks before publishing/updating\n\nMinimum no-spend checks:\n\n```powershell\nnode --check skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs help\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs stats --json\nnode skills\\tavily-search-pro-native-node\\scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test in a temporary home/profile context when feasible to confirm credential errors without spending credits.\n\n## Public registry exposure\n\nClassification: **public ClawHub utility candidate with external API + local cache/log writes**.\n\nBefore public update, run sanitizer/static checks and make sure docs clearly disclose:\n\n- external calls to Tavily;\n- cache/log file locations and the fact that help/cache output may print a local home-derived cache path; sanitize screenshots/logs before public sharing;\n- plaintext query/URL logging;\n- expected static-analysis warning;\n- no local file/secret exfiltration.\n\nDo not include private/internal/client strategy or operator-specific operational notes in a public release.\n\n## Changelog\n\n- `1.0.20`: Add ClawHub/OpenClaw runtime metadata for required `TAVILY_API_KEY`, including `requires.env`, `primaryEnv`, and `envVars`, so declared requirements match the script's env-key behavior. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.19`: Neutralize approval/process wording in header, classification, and changelog notes. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.18`: Normalize prior changelog wording. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.17`: Remove person-specific wording from prior changelog notes. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.16`: Clarify ClawHub candidate posture in the header and document that local/private URL refusal is a best-effort guardrail for obvious mistaken extract targets, not a complete SSRF boundary. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.15`: Input-validation polish: restrict IPv6 ULA `fc00::/7` refusal to actual IPv6 literals so public DNS names beginning with `fc`/`fd` are not overblocked, while retaining ULA and link-local refusal before API key load/Tavily transmission. Adds self-test coverage for ULA and public `fc*`/`fd*` hostnames. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.14`: Input-validation polish: correctly block the full IPv6 link-local `fe80::/10` range (`fe80` through `febf`) before API key load/Tavily transmission and add self-test coverage for boundary examples. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.13`: Input-validation polish: block IPv6 link-local `fe80::/10` extract URLs before API key load/Tavily transmission, add self-test coverage, and align frontmatter description with source wording. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.12`: Polish source wording from “toolkit” to web search, clarify estimated credit labels/docs, document `--ttl 0` cache-read semantics and default `cache` behavior, reject local/private extract URLs before Tavily transmission, and avoid standing publishability wording. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.11`: Version refresh; no runtime behavior change.\n- `1.0.10`: Gate `TAVILY_PRO_MOCK_JSON` behind `TAVILY_PRO_SELFTEST=1`, add inert-hook regression, and reject unexpected `cache clear` arguments.\n- `1.0.9`: Add request timeout support, strict `stats`/`cache info` argument rejection, and no-spend self-tests.\n- `1.0.8`: Tighten public docs for cache-key precision and retry-attempt wording.\n- `1.0.7`: Document that cache entries are request-scoped, not API-account-scoped, so shared OS profiles may share cached results.\n- `1.0.6`: Add frontmatter version metadata and align reference docs so `cache clear` is consistently marked as local deletion requiring explicit approval.\n- `1.0.5`: Public package wording/metadata cleanup; cache/log/security behavior unchanged.\n\nFile v1.0.20:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"tavily-search-pro-native-node\",\n  \"version\": \"1.0.20\",\n  \"publishedAt\": 1784144467640\n}\n\nFile v1.0.20:references/tavily-pro-contract.md\n\n# Tavily Search Pro Contract\n\nUse only when the compact `SKILL.md` is not enough.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\nSubcommands:\n\n- `search`\n- `extract`\n- `stats`\n- `cache`\n- `help`\n\n## Quick reference\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache      # defaults to cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\n## Search flags\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` / `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` / `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` news only | Age window |\n| `--include` | comma list | none | Domains to include |\n| `--exclude` | comma list | none | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n| `--timeout-ms` | integer | 30000 | Per-attempt network timeout |\n\n## Extract flags\n\nWraps Tavily's `/extract` endpoint. Takes one or more public HTTP(S) URLs. The CLI refuses localhost, loopback, link-local, and RFC1918/private-address URLs before sending anything to Tavily.\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl`, `--timeout-ms`.\n\nEstimated credits: Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs basic, 2 per 5 advanced. The usage log estimates this locally; it is not a Tavily-returned billing value.\n\n## Stats\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json\n```\n\nOutput includes total calls, searches vs extracts, cache hit rate, errors, estimated credits used, and estimated credits avoided by cache.\n\n## Cache\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\n```\n\n`cache` with no subcommand defaults to `cache info`. `cache clear` accepts no extra arguments and deletes cached response JSON files only; it does not delete `usage.log`.\n\nResponses are cached under `~/.openclaw/cache/tavily-search-pro-native-node/cache/` keyed by a SHA-256-derived hash of request body + kind. Request-body-affecting options such as topic, depth, max results, include/exclude domains, raw-content, URL list, and extract depth create different cache entries; output/control flags such as `--json`, `--ttl`, `--no-log`, and `--no-retry` do not. Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n\nDefault TTLs:\n\n- Search, general topic: 24 hours\n- Search, news topic: 1 hour\n- Extract: 7 days\n\nOverride with `--ttl SECONDS`; `--ttl 0` disables cache reads for that command but still writes the fresh response to cache unless `--no-cache` is also set. Skip cache reads and writes with `--no-cache`.\n\n## Rate-limit backoff\n\nOn HTTP 429, makes up to 3 total attempts with exponential backoff between attempts (normally 1s, then 2s) or respects `Retry-After` when present. Disable with `--no-retry`.\n\nNetwork errors and per-attempt timeouts also retry. Other HTTP errors surface immediately. Override the default 30000ms timeout with `--timeout-ms N`.\n\n## Usage log\n\nEvery call appends one JSON line to:\n\n```text\n~/.openclaw/cache/tavily-search-pro-native-node/usage.log\n```\n\nExample:\n\n```json\n{\"ts\":1713732000000,\"kind\":\"search\",\"query\":\"OpenClaw\",\"depth\":\"basic\",\"topic\":\"general\",\"cached\":false,\"credits\":1}\n```\n\nQueries/URLs are logged in plaintext. Use `--no-log --no-cache` for sensitive but approved external calls so plaintext logging is skipped and sensitive research context is not cached.\n\n## Troubleshooting\n\n- `TAVILY_API_KEY not set` -> set env var in process environment.\n- HTTP 401 -> invalid/revoked key.\n- HTTP 429 -> rate limited; script auto-retries then surfaces Retry-After.\n- HTTP 432 -> monthly credit cap hit.\n- Network timeout -> retries, then surfaces error.\n- Stale results -> use `--no-cache` or `cache clear` after explicit approval for local deletion.\n- Cache/log growth -> `cache info`, `cache clear`, or manual log rotation. `cache clear` is local deletion and requires explicit approval before running.\n\n## Agent usage pattern\n\n1. Prefer one well-crafted search over several narrow ones.\n2. Use `basic` unless the user asks for deep research.\n3. Use `--include` for trusted domains when appropriate.\n4. Use cache unless freshness matters.\n5. For deep reads: search -> pick URLs -> extract.\n6. Quote sources so the user can verify.\n\n## Publish/update checks\n\nBefore publishing or updating:\n\n```powershell\nnode --check scripts\\tavily-pro.mjs\nnode scripts\\tavily-pro.mjs help\nnode scripts\\tavily-pro.mjs stats --json\nnode scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test with a temporary home directory to verify credential errors without spending credits. Offline mock fixtures are available only when `TAVILY_PRO_SELFTEST=1` is set by `scripts/self-test.mjs`; do not set self-test hooks for normal research use.\n\nFile v1.0.20:skill-card.md\n\n## Description: <br>\nResearch-grade Tavily web search and URL extraction for OpenClaw using native Node.js, with caching, usage stats, and rate-limit backoff. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use this skill for deep web research, Tavily search, multi-URL extraction, usage review, cache inspection, and source-backed research follow-up. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Search queries and extraction URLs are sent to Tavily as a third-party research API. <br>\nMitigation: Use the skill only for approved external research and avoid client/private or sensitive queries unless that external transmission is approved. <br>\nRisk: Default cache and usage-log behavior can leave local records of queries, URLs, and results. <br>\nMitigation: Use --no-log --no-cache for sensitive approved work, and review or clear local cache entries only with explicit approval. <br>\nRisk: Cached results are not scoped to a specific Tavily account when multiple accounts share the same OS user profile. <br>\nMitigation: Use separate OS profiles or --no-cache when account isolation matters. <br>\nRisk: Local/private URL refusal is a guardrail for obvious mistaken extract targets, not a complete boundary for all network misuse scenarios. <br>\nMitigation: Extract only intended public HTTP(S) URLs and review URLs before sending them to Tavily. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jwestburg/skills/tavily-search-pro-native-node) <br>\n- [Publisher profile](https://clawhub.ai/user/jwestburg) <br>\n- [Tavily Pro Contract](references/tavily-pro-contract.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Markdown or JSON command output with URLs, source summaries, cache/log status, freshness choices, and estimated Tavily credit usage.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include command plans, source/result URLs, limitations, caveats, and next safe research steps.] <br>\n\n## Skill Version(s): <br>\n1.0.20 (source: server release metadata and SKILL.md frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.19: 6 files, 16904 bytes\n\nFiles: references/tavily-pro-contract.md (6015b), scripts/self-test.mjs (5486b), scripts/tavily-pro.mjs (24065b), skill-card.md (2390b), SKILL.md (9961b), _meta.json (149b)\n\nFile v1.0.19:SKILL.md\n\n---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily web search for OpenClaw using native Node.js with zero dependencies. Use for deep web research, multi-URL content extraction, estimated Tavily credit tracking, response caching, usage-log review, and 429 backoff. Includes search, extract, stats, and cache subcommands. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\nversion: 1.0.19\nrisk_class: external-research-api-credit-cache-log\n---\n\n# Tavily Search Pro (Native Node)\n\nVersion: 1.0.19 / public ClawHub utility candidate with external API, cache, and usage-log behavior.\n\nResearch-grade Tavily web search helper: one dependency-free Node script with `search`, `extract`, `stats`, and `cache` subcommands.\n\n## Risk / invocation class\n\nRisk class: **external research API / credit usage / plaintext query logging**.\n\nUse deliberately. This skill sends search queries or URLs to Tavily over HTTPS and may append plaintext queries/URLs to a local usage log unless `--no-log` is used.\n\n## Input packet\n\nRequired:\n\n- `task`: search, extract, usage stats, or cache inspection.\n- `query_or_urls`: search query or URL list when applicable.\n- `privacy_sensitivity`: normal, sensitive, client/private, or unknown.\n- `freshness_need`: normal cache ok, fresh/no-cache, or news/freshness-critical.\n- `depth`: basic unless advanced is justified.\n\nOptional:\n\n- `trusted_domains`: include/exclude domains.\n- `max_results`: default 5; avoid broad high-result searches unless needed.\n- `logging_preference`: normal log, `--no-log`, or unknown.\n- `output_format`: human summary or `--json`.\n\nStop or switch tools if the query is privacy-sensitive and sending it to Tavily is not appropriate. For one known URL, prefer `web_fetch` unless extraction quality matters.\n\n## Output packet\n\nReturn compactly:\n\n- command used or planned, redacted as needed\n- whether cache/logging was enabled\n- freshness/depth choice\n- sources/results with URLs\n- estimated credits used or expected when known\n- limitations/caveats\n- next safe research step\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files or `~/.openclaw/.env`.\n- Makes network calls only to Tavily's HTTPS endpoints:\n  - `https://api.tavily.com/search`\n  - `https://api.tavily.com/extract`\n- Writes cache and usage logs only under `~/.openclaw/cache/tavily-search-pro-native-node/`.\n- Cache filenames are SHA-256-derived request hashes, not plaintext queries.\n- Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n- Usage logs may contain plaintext search queries/URLs; use `--no-log` for sensitive calls.\n- Local/private URL refusal is a guardrail for obvious mistaken extract targets, not a complete SSRF boundary; Tavily performs extraction from Tavily infrastructure, not this machine.\n- Does not read or transmit local files or non-Tavily secrets; sends `TAVILY_API_KEY` only to Tavily for authentication.\n- Does not modify system configuration or auto-update.\n- Public-registry static-analysis `potential_exfiltration` warnings are expected because this tool combines env credentials, local cache/log file access, and Tavily network calls.\n\n## When to use\n\nUse this Pro skill when:\n\n- the user needs thorough web research, not just a quick lookup;\n- multiple queries are likely and cache will save credits;\n- full content extraction from specific URLs is needed;\n- Tavily usage/stats matter;\n- 429 retry/backoff is useful.\n\nPrefer `tavily-search-native-node` when:\n\n- a single simple search is enough;\n- minimum audit surface matters;\n- no disk writes/caching/logging are desired.\n\nPrefer `web_fetch` for a one-off known URL read.\n\nDo not use when:\n\n- the query is privacy-sensitive and should not leave this machine;\n- the user has not approved a sensitive/client/private query to an external research API;\n- freshness requires live source browsing and cache state is uncertain, unless `--no-cache` is used.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache       # defaults to cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear  # local deletion; use only after explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\nFor full flags, cache/log behavior, troubleshooting, and publish/update checks, load `references/tavily-pro-contract.md`.\n\n## Operating guidance\n\n- Prefer one well-crafted query over several narrow searches.\n- Use `basic` depth unless advanced is justified; `advanced` costs more.\n- Use `--include`/`--exclude` to scope sources when appropriate.\n- Use cache by default; use `--no-cache` when freshness matters. `--ttl 0` disables cache reads for that command but still writes the fresh response to cache unless `--no-cache` is also set.\n- Use `--no-log --no-cache` for sensitive but approved external queries so plaintext query/URL logs are skipped and sensitive research context is not cached.\n- For follow-up deep reads: search -> select URLs -> extract.\n- Quote sources so the user/requester can verify.\n- Track estimated credit usage with `stats` when research runs get large.\n- Treat `cache clear` as local destructive cleanup; agents should ask before running it.\n\n## Required checks before publishing/updating\n\nMinimum no-spend checks:\n\n```powershell\nnode --check skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs help\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs stats --json\nnode skills\\tavily-search-pro-native-node\\scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test in a temporary home/profile context when feasible to confirm credential errors without spending credits.\n\n## Public registry exposure\n\nClassification: **public ClawHub utility candidate with external API + local cache/log writes**.\n\nBefore public update, run sanitizer/static checks and make sure docs clearly disclose:\n\n- external calls to Tavily;\n- cache/log file locations and the fact that help/cache output may print a local home-derived cache path; sanitize screenshots/logs before public sharing;\n- plaintext query/URL logging;\n- expected static-analysis warning;\n- no local file/secret exfiltration.\n\nDo not include private/internal/client strategy or operator-specific operational notes in a public release.\n\n## Changelog\n\n- `1.0.19`: Neutralize approval/process wording in header, classification, and changelog notes. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.18`: Normalize prior changelog wording. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.17`: Remove person-specific wording from prior changelog notes. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.16`: Clarify ClawHub candidate posture in the header and document that local/private URL refusal is a best-effort guardrail for obvious mistaken extract targets, not a complete SSRF boundary. No runtime behavior change. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.15`: Input-validation polish: restrict IPv6 ULA `fc00::/7` refusal to actual IPv6 literals so public DNS names beginning with `fc`/`fd` are not overblocked, while retaining ULA and link-local refusal before API key load/Tavily transmission. Adds self-test coverage for ULA and public `fc*`/`fd*` hostnames. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.14`: Input-validation polish: correctly block the full IPv6 link-local `fe80::/10` range (`fe80` through `febf`) before API key load/Tavily transmission and add self-test coverage for boundary examples. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.13`: Input-validation polish: block IPv6 link-local `fe80::/10` extract URLs before API key load/Tavily transmission, add self-test coverage, and align frontmatter description with source wording. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.12`: Polish source wording from “toolkit” to web search, clarify estimated credit labels/docs, document `--ttl 0` cache-read semantics and default `cache` behavior, reject local/private extract URLs before Tavily transmission, and avoid standing publishability wording. No categories, topics, topic tags, tags, keywords, or ClawHub catalog metadata added to source.\n- `1.0.11`: Version refresh; no runtime behavior change.\n- `1.0.10`: Gate `TAVILY_PRO_MOCK_JSON` behind `TAVILY_PRO_SELFTEST=1`, add inert-hook regression, and reject unexpected `cache clear` arguments.\n- `1.0.9`: Add request timeout support, strict `stats`/`cache info` argument rejection, and no-spend self-tests.\n- `1.0.8`: Tighten public docs for cache-key precision and retry-attempt wording.\n- `1.0.7`: Document that cache entries are request-scoped, not API-account-scoped, so shared OS profiles may share cached results.\n- `1.0.6`: Add frontmatter version metadata and align reference docs so `cache clear` is consistently marked as local deletion requiring explicit approval.\n- `1.0.5`: Public package wording/metadata cleanup; cache/log/security behavior unchanged.\n\nFile v1.0.19:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"tavily-search-pro-native-node\",\n  \"version\": \"1.0.19\",\n  \"publishedAt\": 1783448750356\n}\n\nFile v1.0.19:references/tavily-pro-contract.md\n\n# Tavily Search Pro Contract\n\nUse only when the compact `SKILL.md` is not enough.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\nSubcommands:\n\n- `search`\n- `extract`\n- `stats`\n- `cache`\n- `help`\n\n## Quick reference\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache      # defaults to cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\n## Search flags\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` / `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` / `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` news only | Age window |\n| `--include` | comma list | none | Domains to include |\n| `--exclude` | comma list | none | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n| `--timeout-ms` | integer | 30000 | Per-attempt network timeout |\n\n## Extract flags\n\nWraps Tavily's `/extract` endpoint. Takes one or more public HTTP(S) URLs. The CLI refuses localhost, loopback, link-local, and RFC1918/private-address URLs before sending anything to Tavily.\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl`, `--timeout-ms`.\n\nEstimated credits: Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs basic, 2 per 5 advanced. The usage log estimates this locally; it is not a Tavily-returned billing value.\n\n## Stats\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json\n```\n\nOutput includes total calls, searches vs extracts, cache hit rate, errors, estimated credits used, and estimated credits avoided by cache.\n\n## Cache\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\n```\n\n`cache` with no subcommand defaults to `cache info`. `cache clear` accepts no extra arguments and deletes cached response JSON files only; it does not delete `usage.log`.\n\nResponses are cached under `~/.openclaw/cache/tavily-search-pro-native-node/cache/` keyed by a SHA-256-derived hash of request body + kind. Request-body-affecting options such as topic, depth, max results, include/exclude domains, raw-content, URL list, and extract depth create different cache entries; output/control flags such as `--json`, `--ttl`, `--no-log`, and `--no-retry` do not. Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n\nDefault TTLs:\n\n- Search, general topic: 24 hours\n- Search, news topic: 1 hour\n- Extract: 7 days\n\nOverride with `--ttl SECONDS`; `--ttl 0` disables cache reads for that command but still writes the fresh response to cache unless `--no-cache` is also set. Skip cache reads and writes with `--no-cache`.\n\n## Rate-limit backoff\n\nOn HTTP 429, makes up to 3 total attempts with exponential backoff between attempts (normally 1s, then 2s) or respects `Retry-After` when present. Disable with `--no-retry`.\n\nNetwork errors and per-attempt timeouts also retry. Other HTTP errors surface immediately. Override the default 30000ms timeout with `--timeout-ms N`.\n\n## Usage log\n\nEvery call appends one JSON line to:\n\n```text\n~/.openclaw/cache/tavily-search-pro-native-node/usage.log\n```\n\nExample:\n\n```json\n{\"ts\":1713732000000,\"kind\":\"search\",\"query\":\"OpenClaw\",\"depth\":\"basic\",\"topic\":\"general\",\"cached\":false,\"credits\":1}\n```\n\nQueries/URLs are logged in plaintext. Use `--no-log --no-cache` for sensitive but approved external calls so plaintext logging is skipped and sensitive research context is not cached.\n\n## Troubleshooting\n\n- `TAVILY_API_KEY not set` -> set env var in process environment.\n- HTTP 401 -> invalid/revoked key.\n- HTTP 429 -> rate limited; script auto-retries then surfaces Retry-After.\n- HTTP 432 -> monthly credit cap hit.\n- Network timeout -> retries, then surfaces error.\n- Stale results -> use `--no-cache` or `cache clear` after explicit approval for local deletion.\n- Cache/log growth -> `cache info`, `cache clear`, or manual log rotation. `cache clear` is local deletion and requires explicit approval before running.\n\n## Agent usage pattern\n\n1. Prefer one well-crafted search over several narrow ones.\n2. Use `basic` unless the user asks for deep research.\n3. Use `--include` for trusted domains when appropriate.\n4. Use cache unless freshness matters.\n5. For deep reads: search -> pick URLs -> extract.\n6. Quote sources so the user can verify.\n\n## Publish/update checks\n\nBefore publishing or updating:\n\n```powershell\nnode --check scripts\\tavily-pro.mjs\nnode scripts\\tavily-pro.mjs help\nnode scripts\\tavily-pro.mjs stats --json\nnode scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test with a temporary home directory to verify credential errors without spending credits. Offline mock fixtures are available only when `TAVILY_PRO_SELFTEST=1` is set by `scripts/self-test.mjs`; do not set self-test hooks for normal research use.\n\nFile v1.0.19:skill-card.md\n\n## Description: <br>\nResearch-grade Tavily web search for OpenClaw using native Node.js with zero dependencies. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use this skill for deep web research, multi-URL content extraction, Tavily credit estimation, response caching, usage-log review, and rate-limit backoff through a native Node.js CLI. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Selected searches and public URLs are sent to Tavily. <br>\nMitigation: Use the skill only when external Tavily processing is acceptable, and avoid sensitive or client/private queries that should remain local. <br>\nRisk: Local usage records can contain plaintext queries or URLs. <br>\nMitigation: Use --no-log for approved sensitive research and review local usage-log handling before sharing logs or terminal output. <br>\nRisk: Cached responses are written locally and may be shared across Tavily accounts that use the same OS profile. <br>\nMitigation: Use --no-cache or separate OS profiles when freshness, sensitivity, or account isolation matters. <br>\nRisk: Tavily API usage can consume account credits. <br>\nMitigation: Prefer basic depth unless advanced search is justified, use cache where appropriate, and check stats during larger research runs. <br>\n\n\n## Reference(s): <br>\n- [Tavily Search Pro Contract](references/tavily-pro-contract.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown summaries with inline shell commands and optional JSON CLI output.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Outputs can include selected source URLs, cache/logging status, freshness and depth choices, estimated Tavily credits, limitations, and next safe research steps.] <br>\n\n## Skill Version(s): <br>\n1.0.19 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.11: 6 files, 15490 bytes\n\nFiles: references/tavily-pro-contract.md (5529b), scripts/self-test.mjs (3594b), scripts/tavily-pro.mjs (22996b), skill-card.md (2682b), SKILL.md (7246b), _meta.json (149b)\n\nFile v1.0.11:SKILL.md\n\n---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily toolkit for OpenClaw - native Node.js, zero dependencies. Use when the user needs deep web research, multi-URL content extraction, Tavily credit usage stats, caching, or 429 backoff. Includes search/extract/stats/cache subcommands, response caching, JSONL usage logging, and rate-limit backoff. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\nversion: 1.0.11\nrisk_class: external-research-api-credit-cache-log\n---\n\n# Tavily Search Pro (Native Node)\n\nVersion: 1.0.11 / publishable utility.\n\nResearch-grade Tavily helper: one dependency-free Node script with `search`, `extract`, `stats`, and `cache` subcommands.\n\n## Risk / invocation class\n\nRisk class: **external research API / credit usage / plaintext query logging**.\n\nUse deliberately. This skill sends search queries or URLs to Tavily over HTTPS and may append plaintext queries/URLs to a local usage log unless `--no-log` is used.\n\n## Input packet\n\nRequired:\n\n- `task`: search, extract, usage stats, or cache inspection.\n- `query_or_urls`: search query or URL list when applicable.\n- `privacy_sensitivity`: normal, sensitive, client/private, or unknown.\n- `freshness_need`: normal cache ok, fresh/no-cache, or news/freshness-critical.\n- `depth`: basic unless advanced is justified.\n\nOptional:\n\n- `trusted_domains`: include/exclude domains.\n- `max_results`: default 5; avoid broad high-result searches unless needed.\n- `logging_preference`: normal log, `--no-log`, or unknown.\n- `output_format`: human summary or `--json`.\n\nStop or switch tools if the query is privacy-sensitive and sending it to Tavily is not appropriate. For one known URL, prefer `web_fetch` unless extraction quality matters.\n\n## Output packet\n\nReturn compactly:\n\n- command used or planned, redacted as needed\n- whether cache/logging was enabled\n- freshness/depth choice\n- sources/results with URLs\n- credits used or expected when known\n- limitations/caveats\n- next safe research step\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files or `~/.openclaw/.env`.\n- Makes network calls only to Tavily's HTTPS endpoints:\n  - `https://api.tavily.com/search`\n  - `https://api.tavily.com/extract`\n- Writes cache and usage logs only under `~/.openclaw/cache/tavily-search-pro-native-node/`.\n- Cache filenames are SHA-256-derived request hashes, not plaintext queries.\n- Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n- Usage logs may contain plaintext search queries/URLs; use `--no-log` for sensitive calls.\n- Does not read or transmit local files or non-Tavily secrets; sends `TAVILY_API_KEY` only to Tavily for authentication.\n- Does not modify system configuration or auto-update.\n- Public-registry static-analysis `potential_exfiltration` warnings are expected because this tool combines env credentials, local cache/log file access, and Tavily network calls.\n\n## When to use\n\nUse this Pro skill when:\n\n- the user needs thorough web research, not just a quick lookup;\n- multiple queries are likely and cache will save credits;\n- full content extraction from specific URLs is needed;\n- Tavily usage/stats matter;\n- 429 retry/backoff is useful.\n\nPrefer `tavily-search-native-node` when:\n\n- a single simple search is enough;\n- minimum audit surface matters;\n- no disk writes/caching/logging are desired.\n\nPrefer `web_fetch` for a one-off known URL read.\n\nDo not use when:\n\n- the query is privacy-sensitive and should not leave this machine;\n- the user has not approved a sensitive/client/private query to an external research API;\n- freshness requires live source browsing and cache state is uncertain, unless `--no-cache` is used.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear  # local deletion; use only after explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\nFor full flags, cache/log behavior, troubleshooting, and publish/update checks, load `references/tavily-pro-contract.md`.\n\n## Operating guidance\n\n- Prefer one well-crafted query over several narrow searches.\n- Use `basic` depth unless advanced is justified; `advanced` costs more.\n- Use `--include`/`--exclude` to scope sources when appropriate.\n- Use cache by default; use `--no-cache` when freshness matters.\n- Use `--no-log --no-cache` for sensitive but approved external queries so plaintext query/URL logs are skipped and sensitive research context is not cached.\n- For follow-up deep reads: search -> select URLs -> extract.\n- Quote sources so the user/requester can verify.\n- Track credit usage with `stats` when research runs get large.\n- Treat `cache clear` as local destructive cleanup; agents should ask before running it.\n\n## Required checks before publishing/updating\n\nMinimum no-spend checks:\n\n```powershell\nnode --check skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs help\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs stats --json\nnode skills\\tavily-search-pro-native-node\\scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test in a temporary home/profile context when feasible to confirm credential errors without spending credits.\n\n## Public registry exposure\n\nClassification: **publishable utility with external API + local cache/log writes**.\n\nBefore public update, run sanitizer/static checks and make sure docs clearly disclose:\n\n- external calls to Tavily;\n- cache/log file locations and the fact that help/cache output may print a local home-derived cache path; sanitize screenshots/logs before public sharing;\n- plaintext query/URL logging;\n- expected static-analysis warning;\n- no local file/secret exfiltration.\n\nDo not include private/internal/client strategy or operator-specific operational notes in a public release.\n\n## Changelog\n\n- `1.0.11`: ClawHub publication/version refresh after public-readiness review; no runtime behavior change.\n- `1.0.10`: Gate `TAVILY_PRO_MOCK_JSON` behind `TAVILY_PRO_SELFTEST=1`, add inert-hook regression, and reject unexpected `cache clear` arguments.\n- `1.0.9`: Add request timeout support, strict `stats`/`cache info` argument rejection, and no-spend self-tests.\n- `1.0.8`: Tighten public docs for cache-key precision and retry-attempt wording.\n- `1.0.7`: Document that cache entries are request-scoped, not API-account-scoped, so shared OS profiles may share cached results.\n- `1.0.6`: Add frontmatter version metadata and align reference docs so `cache clear` is consistently marked as local deletion requiring explicit approval.\n- `1.0.5`: Public package wording/metadata cleanup; cache/log/security behavior unchanged.\n\nFile v1.0.11:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"tavily-search-pro-native-node\",\n  \"version\": \"1.0.11\",\n  \"publishedAt\": 1781477040792\n}\n\nFile v1.0.11:references/tavily-pro-contract.md\n\n# Tavily Search Pro Contract\n\nUse only when the compact `SKILL.md` is not enough.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\nSubcommands:\n\n- `search`\n- `extract`\n- `stats`\n- `cache`\n- `help`\n\n## Quick reference\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\n## Search flags\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` / `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` / `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` news only | Age window |\n| `--include` | comma list | none | Domains to include |\n| `--exclude` | comma list | none | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n| `--timeout-ms` | integer | 30000 | Per-attempt network timeout |\n\n## Extract flags\n\nWraps Tavily's `/extract` endpoint. Takes one or more URLs.\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl`, `--timeout-ms`.\n\nCredits: Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs basic, 2 per 5 advanced. The usage log tracks this.\n\n## Stats\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json\n```\n\nOutput includes total calls, searches vs extracts, cache hit rate, errors, credits used, and estimated credits avoided by cache.\n\n## Cache\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\n```\n\n`cache clear` accepts no extra arguments and deletes cached response JSON files only; it does not delete `usage.log`.\n\nResponses are cached under `~/.openclaw/cache/tavily-search-pro-native-node/cache/` keyed by a SHA-256-derived hash of request body + kind. Request-body-affecting options such as topic, depth, max results, include/exclude domains, raw-content, URL list, and extract depth create different cache entries; output/control flags such as `--json`, `--ttl`, `--no-log`, and `--no-retry` do not. Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n\nDefault TTLs:\n\n- Search, general topic: 24 hours\n- Search, news topic: 1 hour\n- Extract: 7 days\n\nOverride with `--ttl SECONDS`; skip with `--no-cache`.\n\n## Rate-limit backoff\n\nOn HTTP 429, makes up to 3 total attempts with exponential backoff between attempts (normally 1s, then 2s) or respects `Retry-After` when present. Disable with `--no-retry`.\n\nNetwork errors and per-attempt timeouts also retry. Other HTTP errors surface immediately. Override the default 30000ms timeout with `--timeout-ms N`.\n\n## Usage log\n\nEvery call appends one JSON line to:\n\n```text\n~/.openclaw/cache/tavily-search-pro-native-node/usage.log\n```\n\nExample:\n\n```json\n{\"ts\":1713732000000,\"kind\":\"search\",\"query\":\"OpenClaw\",\"depth\":\"basic\",\"topic\":\"general\",\"cached\":false,\"credits\":1}\n```\n\nQueries/URLs are logged in plaintext. Use `--no-log --no-cache` for sensitive but approved external calls so plaintext logging is skipped and sensitive research context is not cached.\n\n## Troubleshooting\n\n- `TAVILY_API_KEY not set` -> set env var in process environment.\n- HTTP 401 -> invalid/revoked key.\n- HTTP 429 -> rate limited; script auto-retries then surfaces Retry-After.\n- HTTP 432 -> monthly credit cap hit.\n- Network timeout -> retries, then surfaces error.\n- Stale results -> use `--no-cache` or `cache clear` after explicit approval for local deletion.\n- Cache/log growth -> `cache info`, `cache clear`, or manual log rotation. `cache clear` is local deletion and requires explicit approval before running.\n\n## Agent usage pattern\n\n1. Prefer one well-crafted search over several narrow ones.\n2. Use `basic` unless the user asks for deep research.\n3. Use `--include` for trusted domains when appropriate.\n4. Use cache unless freshness matters.\n5. For deep reads: search -> pick URLs -> extract.\n6. Quote sources so the user can verify.\n\n## Publish/update checks\n\nBefore publishing or updating:\n\n```powershell\nnode --check scripts\\tavily-pro.mjs\nnode scripts\\tavily-pro.mjs help\nnode scripts\\tavily-pro.mjs stats --json\nnode scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test with a temporary home directory to verify credential errors without spending credits. Offline mock fixtures are available only when `TAVILY_PRO_SELFTEST=1` is set by `scripts/self-test.mjs`; do not set self-test hooks for normal research use.\n\nFile v1.0.11:skill-card.md\n\n## Description: <br>\nResearch-grade Tavily toolkit for OpenClaw that supports web search, URL extraction, usage stats, response caching, JSONL usage logging, and rate-limit backoff through a native Node.js script. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use this skill for deeper Tavily-backed web research, multi-URL content extraction, Tavily usage checks, cache inspection, and research workflows that need explicit freshness, logging, and credit controls. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Search queries and URLs are sent to Tavily using the user's API key. <br>\nMitigation: Use the skill only when external Tavily research is appropriate, and do not send sensitive or client/private research without explicit approval. <br>\nRisk: Usage logs may retain plaintext queries or URLs, and cached results are stored locally. <br>\nMitigation: Use --no-log --no-cache for sensitive approved research, and periodically inspect or clear the cache and log directory. <br>\nRisk: Cached results are not scoped to a Tavily API account when multiple accounts share the same OS profile. <br>\nMitigation: Use separate OS profiles or --no-cache when account separation matters. <br>\nRisk: Advanced searches and extraction can consume Tavily credits and may hit rate limits. <br>\nMitigation: Prefer basic depth unless advanced research is justified, keep result counts focused, and use stats plus built-in retry/backoff behavior to monitor usage. <br>\n\n\n## Reference(s): <br>\n- [Tavily Search Pro Contract](artifact/references/tavily-pro-contract.md) <br>\n- [ClawHub Skill Page](https://clawhub.ai/jwestburg/tavily-search-pro-native-node) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, JSON, shell commands, guidance] <br>\n**Output Format:** [Markdown guidance with shell commands, human-readable command output, or JSON when requested] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include source URLs, cache and logging status, freshness and depth choices, limitations, caveats, and Tavily credit usage or estimates.] <br>\n\n## Skill Version(s): <br>\n1.0.11 (source: evidence.release.version and SKILL.md frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.10: 6 files, 15462 bytes\n\nFiles: references/tavily-pro-contract.md (5529b), scripts/self-test.mjs (3594b), scripts/tavily-pro.mjs (22996b), skill-card.md (2900b), SKILL.md (7083b), _meta.json (149b)\n\nFile v1.0.10:SKILL.md\n\n---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily toolkit for OpenClaw - native Node.js, zero dependencies. Use when the user needs deep web research, multi-URL content extraction, Tavily credit usage stats, caching, or 429 backoff. Includes search/extract/stats/cache subcommands, response caching, JSONL usage logging, and rate-limit backoff. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\nversion: 1.0.10\n---\n\n# Tavily Search Pro (Native Node)\n\nVersion: 1.0.10 / publishable utility.\n\nResearch-grade Tavily helper: one dependency-free Node script with `search`, `extract`, `stats`, and `cache` subcommands.\n\n## Risk / invocation class\n\nRisk class: **external research API / credit usage / plaintext query logging**.\n\nUse deliberately. This skill sends search queries or URLs to Tavily over HTTPS and may append plaintext queries/URLs to a local usage log unless `--no-log` is used.\n\n## Input packet\n\nRequired:\n\n- `task`: search, extract, usage stats, or cache inspection.\n- `query_or_urls`: search query or URL list when applicable.\n- `privacy_sensitivity`: normal, sensitive, client/private, or unknown.\n- `freshness_need`: normal cache ok, fresh/no-cache, or news/freshness-critical.\n- `depth`: basic unless advanced is justified.\n\nOptional:\n\n- `trusted_domains`: include/exclude domains.\n- `max_results`: default 5; avoid broad high-result searches unless needed.\n- `logging_preference`: normal log, `--no-log`, or unknown.\n- `output_format`: human summary or `--json`.\n\nStop or switch tools if the query is privacy-sensitive and sending it to Tavily is not appropriate. For one known URL, prefer `web_fetch` unless extraction quality matters.\n\n## Output packet\n\nReturn compactly:\n\n- command used or planned, redacted as needed\n- whether cache/logging was enabled\n- freshness/depth choice\n- sources/results with URLs\n- credits used or expected when known\n- limitations/caveats\n- next safe research step\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files or `~/.openclaw/.env`.\n- Makes network calls only to Tavily's HTTPS endpoints:\n  - `https://api.tavily.com/search`\n  - `https://api.tavily.com/extract`\n- Writes cache and usage logs only under `~/.openclaw/cache/tavily-search-pro-native-node/`.\n- Cache filenames are SHA-256-derived request hashes, not plaintext queries.\n- Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n- Usage logs may contain plaintext search queries/URLs; use `--no-log` for sensitive calls.\n- Does not read or transmit local files or non-Tavily secrets; sends `TAVILY_API_KEY` only to Tavily for authentication.\n- Does not modify system configuration or auto-update.\n- Public-registry static-analysis `potential_exfiltration` warnings are expected because this tool combines env credentials, local cache/log file access, and Tavily network calls.\n\n## When to use\n\nUse this Pro skill when:\n\n- the user needs thorough web research, not just a quick lookup;\n- multiple queries are likely and cache will save credits;\n- full content extraction from specific URLs is needed;\n- Tavily usage/stats matter;\n- 429 retry/backoff is useful.\n\nPrefer `tavily-search-native-node` when:\n\n- a single simple search is enough;\n- minimum audit surface matters;\n- no disk writes/caching/logging are desired.\n\nPrefer `web_fetch` for a one-off known URL read.\n\nDo not use when:\n\n- the query is privacy-sensitive and should not leave this machine;\n- the user has not approved a sensitive/client/private query to an external research API;\n- freshness requires live source browsing and cache state is uncertain, unless `--no-cache` is used.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear  # local deletion; use only after explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\nFor full flags, cache/log behavior, troubleshooting, and publish/update checks, load `references/tavily-pro-contract.md`.\n\n## Operating guidance\n\n- Prefer one well-crafted query over several narrow searches.\n- Use `basic` depth unless advanced is justified; `advanced` costs more.\n- Use `--include`/`--exclude` to scope sources when appropriate.\n- Use cache by default; use `--no-cache` when freshness matters.\n- Use `--no-log --no-cache` for sensitive but approved external queries so plaintext query/URL logs are skipped and sensitive research context is not cached.\n- For follow-up deep reads: search -> select URLs -> extract.\n- Quote sources so the user/requester can verify.\n- Track credit usage with `stats` when research runs get large.\n- Treat `cache clear` as local destructive cleanup; agents should ask before running it.\n\n## Required checks before publishing/updating\n\nMinimum no-spend checks:\n\n```powershell\nnode --check skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs help\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs stats --json\nnode skills\\tavily-search-pro-native-node\\scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test in a temporary home/profile context when feasible to confirm credential errors without spending credits.\n\n## Public registry exposure\n\nClassification: **publishable utility with external API + local cache/log writes**.\n\nBefore public update, run sanitizer/static checks and make sure docs clearly disclose:\n\n- external calls to Tavily;\n- cache/log file locations and the fact that help/cache output may print a local home-derived cache path; sanitize screenshots/logs before public sharing;\n- plaintext query/URL logging;\n- expected static-analysis warning;\n- no local file/secret exfiltration.\n\nDo not include private/internal/client strategy or operator-specific operational notes in a public release.\n\n## Changelog\n\n- `1.0.10`: Gate `TAVILY_PRO_MOCK_JSON` behind `TAVILY_PRO_SELFTEST=1`, add inert-hook regression, and reject unexpected `cache clear` arguments.\n- `1.0.9`: Add request timeout support, strict `stats`/`cache info` argument rejection, and no-spend self-tests.\n- `1.0.8`: Tighten public docs for cache-key precision and retry-attempt wording.\n- `1.0.7`: Document that cache entries are request-scoped, not API-account-scoped, so shared OS profiles may share cached results.\n- `1.0.6`: Add frontmatter version metadata and align reference docs so `cache clear` is consistently marked as local deletion requiring explicit approval.\n- `1.0.5`: Public package wording/metadata cleanup; cache/log/security behavior unchanged.\n\nFile v1.0.10:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"tavily-search-pro-native-node\",\n  \"version\": \"1.0.10\",\n  \"publishedAt\": 1780372668186\n}\n\nFile v1.0.10:references/tavily-pro-contract.md\n\n# Tavily Search Pro Contract\n\nUse only when the compact `SKILL.md` is not enough.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\nSubcommands:\n\n- `search`\n- `extract`\n- `stats`\n- `cache`\n- `help`\n\n## Quick reference\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\n## Search flags\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` / `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` / `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` news only | Age window |\n| `--include` | comma list | none | Domains to include |\n| `--exclude` | comma list | none | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n| `--timeout-ms` | integer | 30000 | Per-attempt network timeout |\n\n## Extract flags\n\nWraps Tavily's `/extract` endpoint. Takes one or more URLs.\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl`, `--timeout-ms`.\n\nCredits: Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs basic, 2 per 5 advanced. The usage log tracks this.\n\n## Stats\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json\n```\n\nOutput includes total calls, searches vs extracts, cache hit rate, errors, credits used, and estimated credits avoided by cache.\n\n## Cache\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\n```\n\n`cache clear` accepts no extra arguments and deletes cached response JSON files only; it does not delete `usage.log`.\n\nResponses are cached under `~/.openclaw/cache/tavily-search-pro-native-node/cache/` keyed by a SHA-256-derived hash of request body + kind. Request-body-affecting options such as topic, depth, max results, include/exclude domains, raw-content, URL list, and extract depth create different cache entries; output/control flags such as `--json`, `--ttl`, `--no-log`, and `--no-retry` do not. Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n\nDefault TTLs:\n\n- Search, general topic: 24 hours\n- Search, news topic: 1 hour\n- Extract: 7 days\n\nOverride with `--ttl SECONDS`; skip with `--no-cache`.\n\n## Rate-limit backoff\n\nOn HTTP 429, makes up to 3 total attempts with exponential backoff between attempts (normally 1s, then 2s) or respects `Retry-After` when present. Disable with `--no-retry`.\n\nNetwork errors and per-attempt timeouts also retry. Other HTTP errors surface immediately. Override the default 30000ms timeout with `--timeout-ms N`.\n\n## Usage log\n\nEvery call appends one JSON line to:\n\n```text\n~/.openclaw/cache/tavily-search-pro-native-node/usage.log\n```\n\nExample:\n\n```json\n{\"ts\":1713732000000,\"kind\":\"search\",\"query\":\"OpenClaw\",\"depth\":\"basic\",\"topic\":\"general\",\"cached\":false,\"credits\":1}\n```\n\nQueries/URLs are logged in plaintext. Use `--no-log --no-cache` for sensitive but approved external calls so plaintext logging is skipped and sensitive research context is not cached.\n\n## Troubleshooting\n\n- `TAVILY_API_KEY not set` -> set env var in process environment.\n- HTTP 401 -> invalid/revoked key.\n- HTTP 429 -> rate limited; script auto-retries then surfaces Retry-After.\n- HTTP 432 -> monthly credit cap hit.\n- Network timeout -> retries, then surfaces error.\n- Stale results -> use `--no-cache` or `cache clear` after explicit approval for local deletion.\n- Cache/log growth -> `cache info`, `cache clear`, or manual log rotation. `cache clear` is local deletion and requires explicit approval before running.\n\n## Agent usage pattern\n\n1. Prefer one well-crafted search over several narrow ones.\n2. Use `basic` unless the user asks for deep research.\n3. Use `--include` for trusted domains when appropriate.\n4. Use cache unless freshness matters.\n5. For deep reads: search -> pick URLs -> extract.\n6. Quote sources so the user can verify.\n\n## Publish/update checks\n\nBefore publishing or updating:\n\n```powershell\nnode --check scripts\\tavily-pro.mjs\nnode scripts\\tavily-pro.mjs help\nnode scripts\\tavily-pro.mjs stats --json\nnode scripts\\self-test.mjs\n```\n\nAlso run a no-key smoke test with a temporary home directory to verify credential errors without spending credits. Offline mock fixtures are available only when `TAVILY_PRO_SELFTEST=1` is set by `scripts/self-test.mjs`; do not set self-test hooks for normal research use.\n\nFile v1.0.10:skill-card.md\n\n## Description: <br>\nResearch-grade Tavily toolkit for OpenClaw - native Node.js, zero dependencies. Use when the user needs deep web research, multi-URL content extraction, Tavily credit usage stats, caching, or 429 backoff. Includes search/extract/stats/cache subcommands, response caching, JSONL usage logging, and rate-limit backoff. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use this skill for web research workflows that need Tavily search, URL extraction, cache inspection, usage statistics, and rate-limit backoff. It is suited for normal external research when sending queries or URLs to Tavily is acceptable. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Search queries and URLs are sent to Tavily and can consume Tavily credits. <br>\nMitigation: Use the skill only when external research is appropriate; choose basic depth unless deeper research is justified and track usage with stats for larger runs. <br>\nRisk: Local cache and usage logs can retain research context, including plaintext queries or URLs. <br>\nMitigation: Use --no-log --no-cache for sensitive but approved external calls, and inspect or clear cache files when the same machine or profile is shared. <br>\nRisk: Cached results may be stale or shared across Tavily accounts that use the same OS user profile. <br>\nMitigation: Use --no-cache for freshness-critical or account-isolated work, and use separate profiles when account separation matters. <br>\n\n\n## Reference(s): <br>\n- [Tavily Pro Contract](references/tavily-pro-contract.md) <br>\n- [ClawHub Skill Page](https://clawhub.ai/jwestburg/tavily-search-pro-native-node) <br>\n- [Tavily Search API](https://api.tavily.com/search) <br>\n- [Tavily Extract API](https://api.tavily.com/extract) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown or JSON with source URLs, command details, cache/logging status, freshness choices, credit usage, and caveats] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include Tavily results, extracted content summaries, usage statistics, cache information, and next-step research guidance.] <br>\n\n## Skill Version(s): <br>\n1.0.10 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.8: 5 files, 13172 bytes\n\nFiles: references/tavily-pro-contract.md (5058b), scripts/tavily-pro.mjs (21572b), skill-card.md (2271b), SKILL.md (6820b), _meta.json (148b)\n\nFile v1.0.8:SKILL.md\n\n---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily toolkit for OpenClaw - native Node.js, zero dependencies. Use when the user needs deep web research, multi-URL content extraction, Tavily credit usage stats, caching, or 429 backoff. Includes search/extract/stats/cache subcommands, response caching, JSONL usage logging, and rate-limit backoff. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\nversion: 1.0.8\n---\n\n# Tavily Search Pro (Native Node)\n\nVersion: 1.0.8 / publishable utility.\n\nResearch-grade Tavily helper: one dependency-free Node script with `search`, `extract`, `stats`, and `cache` subcommands.\n\n## Risk / invocation class\n\nRisk class: **external research API / credit usage / plaintext query logging**.\n\nUse deliberately. This skill sends search queries or URLs to Tavily over HTTPS and may append plaintext queries/URLs to a local usage log unless `--no-log` is used.\n\n## Input packet\n\nRequired:\n\n- `task`: search, extract, usage stats, or cache inspection.\n- `query_or_urls`: search query or URL list when applicable.\n- `privacy_sensitivity`: normal, sensitive, client/private, or unknown.\n- `freshness_need`: normal cache ok, fresh/no-cache, or news/freshness-critical.\n- `depth`: basic unless advanced is justified.\n\nOptional:\n\n- `trusted_domains`: include/exclude domains.\n- `max_results`: default 5; avoid broad high-result searches unless needed.\n- `logging_preference`: normal log, `--no-log`, or unknown.\n- `output_format`: human summary or `--json`.\n\nStop or switch tools if the query is privacy-sensitive and sending it to Tavily is not appropriate. For one known URL, prefer `web_fetch` unless extraction quality matters.\n\n## Output packet\n\nReturn compactly:\n\n- command used or planned, redacted as needed\n- whether cache/logging was enabled\n- freshness/depth choice\n- sources/results with URLs\n- credits used or expected when known\n- limitations/caveats\n- next safe research step\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files or `~/.openclaw/.env`.\n- Makes network calls only to Tavily's HTTPS endpoints:\n  - `https://api.tavily.com/search`\n  - `https://api.tavily.com/extract`\n- Writes cache and usage logs only under `~/.openclaw/cache/tavily-search-pro-native-node/`.\n- Cache filenames are SHA-256-derived request hashes, not plaintext queries.\n- Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n- Usage logs may contain plaintext search queries/URLs; use `--no-log` for sensitive calls.\n- Does not read or transmit local files or non-Tavily secrets; sends `TAVILY_API_KEY` only to Tavily for authentication.\n- Does not modify system configuration or auto-update.\n- ClawHub static-analysis `potential_exfiltration` warnings are expected because this tool combines env credentials, local cache/log file access, and Tavily network calls.\n\n## When to use\n\nUse this Pro skill when:\n\n- the user needs thorough web research, not just a quick lookup;\n- multiple queries are likely and cache will save credits;\n- full content extraction from specific URLs is needed;\n- Tavily usage/stats matter;\n- 429 retry/backoff is useful.\n\nPrefer `tavily-search-native-node` when:\n\n- a single simple search is enough;\n- minimum audit surface matters;\n- no disk writes/caching/logging are desired.\n\nPrefer `web_fetch` for a one-off known URL read.\n\nDo not use when:\n\n- the query is privacy-sensitive and should not leave this machine;\n- the user has not approved a sensitive/client/private query to an external research API;\n- freshness requires live source browsing and cache state is uncertain, unless `--no-cache` is used.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear  # local deletion; use only after explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\nFor full flags, cache/log behavior, troubleshooting, and publish/update checks, load `references/tavily-pro-contract.md`.\n\n## Operating guidance\n\n- Prefer one well-crafted query over several narrow searches.\n- Use `basic` depth unless advanced is justified; `advanced` costs more.\n- Use `--include`/`--exclude` to scope sources when appropriate.\n- Use cache by default; use `--no-cache` when freshness matters.\n- Use `--no-log --no-cache` for sensitive but approved external queries so plaintext query/URL logs are skipped and sensitive research context is not cached.\n- For follow-up deep reads: search -> select URLs -> extract.\n- Quote sources so the user/requester can verify.\n- Track credit usage with `stats` when research runs get large.\n- Treat `cache clear` as local destructive cleanup; agents should ask before running it.\n\n## Required checks before publishing/updating\n\nMinimum no-spend checks:\n\n```powershell\nnode --check skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs help\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs stats --json\n```\n\nAlso run a no-key smoke test in a temporary home/profile context when feasible to confirm credential errors without spending credits.\n\n## Public / ClawHub exposure\n\nClassification: **publishable utility with external API + local cache/log writes**.\n\nBefore public update, run sanitizer/static checks and make sure docs clearly disclose:\n\n- external calls to Tavily;\n- cache/log file locations and the fact that help/cache output may print a local home-derived cache path; sanitize screenshots/logs before public sharing;\n- plaintext query/URL logging;\n- expected static-analysis warning;\n- no local file/secret exfiltration.\n\nDo not include private/internal/client strategy or operator-specific operational notes in a public release.\n\n## Changelog\n\n- `1.0.8`: Tighten public docs for cache-key precision and retry-attempt wording.\n- `1.0.7`: Document that cache entries are request-scoped, not API-account-scoped, so shared OS profiles may share cached results.\n- `1.0.6`: Add frontmatter version metadata and align reference docs so `cache clear` is consistently marked as local deletion requiring explicit approval.\n- `1.0.5`: Public package wording/metadata cleanup; cache/log/security behavior unchanged.\n\n_Last reviewed: 2026-05-26; Sonnet PASS_WITH_MINOR_NOTES satisfied._\n\nFile v1.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"tavily-search-pro-native-node\",\n  \"version\": \"1.0.8\",\n  \"publishedAt\": 1780169206277\n}\n\nFile v1.0.8:references/tavily-pro-contract.md\n\n# Tavily Search Pro Contract\n\nUse only when the compact `SKILL.md` is not enough.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\nSubcommands:\n\n- `search`\n- `extract`\n- `stats`\n- `cache`\n- `help`\n\n## Quick reference\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\n## Search flags\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` / `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` / `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` news only | Age window |\n| `--include` | comma list | none | Domains to include |\n| `--exclude` | comma list | none | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n\n## Extract flags\n\nWraps Tavily's `/extract` endpoint. Takes one or more URLs.\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl`.\n\nCredits: Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs basic, 2 per 5 advanced. The usage log tracks this.\n\n## Stats\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json\n```\n\nOutput includes total calls, searches vs extracts, cache hit rate, errors, credits used, and estimated credits avoided by cache.\n\n## Cache\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\n```\n\nResponses are cached under `~/.openclaw/cache/tavily-search-pro-native-node/cache/` keyed by a SHA-256-derived hash of request body + kind. Request-body-affecting options such as topic, depth, max results, include/exclude domains, raw-content, URL list, and extract depth create different cache entries; output/control flags such as `--json`, `--ttl`, `--no-log`, and `--no-retry` do not. Cache entries are not API-account-scoped; if multiple Tavily accounts share the same OS user/home directory, they may share cached results for identical requests. Use separate profiles or `--no-cache` when account isolation matters.\n\nDefault TTLs:\n\n- Search, general topic: 24 hours\n- Search, news topic: 1 hour\n- Extract: 7 days\n\nOverride with `--ttl SECONDS`; skip with `--no-cache`.\n\n## Rate-limit backoff\n\nOn HTTP 429, makes up to 3 total attempts with exponential backoff between attempts (normally 1s, then 2s) or respects `Retry-After` when present. Disable with `--no-retry`.\n\nNetwork errors also retry. Other HTTP errors surface immediately.\n\n## Usage log\n\nEvery call appends one JSON line to:\n\n```text\n~/.openclaw/cache/tavily-search-pro-native-node/usage.log\n```\n\nExample:\n\n```json\n{\"ts\":1713732000000,\"kind\":\"search\",\"query\":\"OpenClaw\",\"depth\":\"basic\",\"topic\":\"general\",\"cached\":false,\"credits\":1}\n```\n\nQueries/URLs are logged in plaintext. Use `--no-log --no-cache` for sensitive but approved external calls so plaintext logging is skipped and sensitive research context is not cached.\n\n## Troubleshooting\n\n- `TAVILY_API_KEY not set` -> set env var in process environment.\n- HTTP 401 -> invalid/revoked key.\n- HTTP 429 -> rate limited; script auto-retries then surfaces Retry-After.\n- HTTP 432 -> monthly credit cap hit.\n- Network timeout -> retries, then surfaces error.\n- Stale results -> use `--no-cache` or `cache clear` after explicit approval for local deletion.\n- Cache/log growth -> `cache info`, `cache clear`, or manual log rotation. `cache clear` is local deletion and requires explicit approval before running.\n\n## Agent usage pattern\n\n1. Prefer one well-crafted search over several narrow ones.\n2. Use `basic` unless the user asks for deep research.\n3. Use `--include` for trusted domains when appropriate.\n4. Use cache unless freshness matters.\n5. For deep reads: search -> pick URLs -> extract.\n6. Quote sources so the user can verify.\n\n## Publish/update checks\n\nBefore publishing or updating:\n\n```powershell\nnode --check scripts\\tavily-pro.mjs\nnode scripts\\tavily-pro.mjs help\nnode scripts\\tavily-pro.mjs stats --json\n```\n\nAlso run a no-key smoke test with a temporary home directory to verify credential errors without spending credits.\n\nFile v1.0.8:skill-card.md\n\n## Description: <br>\nResearch-grade Tavily toolkit for OpenClaw that provides web search, multi-URL extraction, usage statistics, caching, JSONL usage logging, and rate-limit backoff through a native Node.js script. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use this skill for deep Tavily-backed web research, URL content extraction, Tavily credit usage review, and local cache inspection when external web research is appropriate. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Search queries and URLs are sent to Tavily as an external research API. <br>\nMitigation: Use this skill only for approved external research and avoid client, private, or machine-local-only queries. <br>\nRisk: Usage logs may contain plaintext search queries or URLs. <br>\nMitigation: Use --no-log for sensitive approved searches. <br>\nRisk: Cached results are stored locally and are not API-account-scoped for users sharing the same OS profile. <br>\nMitigation: Use --no-cache for sensitive work or separate OS profiles when Tavily account isolation matters. <br>\n\n\n## Reference(s): <br>\n- [Tavily Search Pro Contract](references/tavily-pro-contract.md) <br>\n- [ClawHub Skill Page](https://clawhub.ai/jwestburg/tavily-search-pro-native-node) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown with inline shell commands and optional JSON output from the Tavily script] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include redacted command lines, source URLs, cache/logging state, freshness and depth choices, credit usage, limitations, and next-step guidance.] <br>\n\n## Skill Version(s): <br>\n1.0.8 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.6: 5 files, 12695 bytes\n\nFiles: references/tavily-pro-contract.md (4471b), scripts/tavily-pro.mjs (21572b), skill-card.md (2462b), SKILL.md (6064b), _meta.json (148b)\n\nFile v1.0.6:SKILL.md\n\n---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily toolkit for OpenClaw - native Node.js, zero dependencies. Use when the user needs deep web research, multi-URL content extraction, Tavily credit usage stats, caching, or 429 backoff. Includes search/extract/stats/cache subcommands, response caching, JSONL usage logging, and rate-limit backoff. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\nversion: 1.0.6\n---\n\n# Tavily Search Pro (Native Node)\n\nVersion: 1.0.6 / publishable utility.\n\nResearch-grade Tavily helper: one dependency-free Node script with `search`, `extract`, `stats`, and `cache` subcommands.\n\n## Risk / invocation class\n\nRisk class: **external research API / credit usage / plaintext query logging**.\n\nUse deliberately. This skill sends search queries or URLs to Tavily over HTTPS and may append plaintext queries/URLs to a local usage log unless `--no-log` is used.\n\n## Input packet\n\nRequired:\n\n- `task`: search, extract, usage stats, or cache inspection.\n- `query_or_urls`: search query or URL list when applicable.\n- `privacy_sensitivity`: normal, sensitive, client/private, or unknown.\n- `freshness_need`: normal cache ok, fresh/no-cache, or news/freshness-critical.\n- `depth`: basic unless advanced is justified.\n\nOptional:\n\n- `trusted_domains`: include/exclude domains.\n- `max_results`: default 5; avoid broad high-result searches unless needed.\n- `logging_preference`: normal log, `--no-log`, or unknown.\n- `output_format`: human summary or `--json`.\n\nStop or switch tools if the query is privacy-sensitive and sending it to Tavily is not appropriate. For one known URL, prefer `web_fetch` unless extraction quality matters.\n\n## Output packet\n\nReturn compactly:\n\n- command used or planned, redacted as needed\n- whether cache/logging was enabled\n- freshness/depth choice\n- sources/results with URLs\n- credits used or expected when known\n- limitations/caveats\n- next safe research step\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files or `~/.openclaw/.env`.\n- Makes network calls only to Tavily's HTTPS endpoints:\n  - `https://api.tavily.com/search`\n  - `https://api.tavily.com/extract`\n- Writes cache and usage logs only under `~/.openclaw/cache/tavily-search-pro-native-node/`.\n- Cache filenames are SHA-256 request hashes, not plaintext queries.\n- Usage logs may contain plaintext search queries/URLs; use `--no-log` for sensitive calls.\n- Does not transmit local files or secrets.\n- Does not modify system configuration or auto-update.\n- ClawHub static-analysis `potential_exfiltration` warnings are expected because this tool combines env credentials, local cache/log file access, and Tavily network calls.\n\n## When to use\n\nUse this Pro skill when:\n\n- the user needs thorough web research, not just a quick lookup;\n- multiple queries are likely and cache will save credits;\n- full content extraction from specific URLs is needed;\n- Tavily usage/stats matter;\n- 429 retry/backoff is useful.\n\nPrefer `tavily-search-native-node` when:\n\n- a single simple search is enough;\n- minimum audit surface matters;\n- no disk writes/caching/logging are desired.\n\nPrefer `web_fetch` for a one-off known URL read.\n\nDo not use when:\n\n- the query is privacy-sensitive and should not leave this machine;\n- the user has not approved a sensitive/client/private query to an external research API;\n- freshness requires live source browsing and cache state is uncertain, unless `--no-cache` is used.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear  # local deletion; use only after explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\nFor full flags, cache/log behavior, troubleshooting, and publish/update checks, load `references/tavily-pro-contract.md`.\n\n## Operating guidance\n\n- Prefer one well-crafted query over several narrow searches.\n- Use `basic` depth unless advanced is justified; `advanced` costs more.\n- Use `--include`/`--exclude` to scope sources when appropriate.\n- Use cache by default; use `--no-cache` when freshness matters.\n- Use `--no-log` for sensitive but approved external queries.\n- For follow-up deep reads: search -> select URLs -> extract.\n- Quote sources so the user/requester can verify.\n- Track credit usage with `stats` when research runs get large.\n- Treat `cache clear` as local destructive cleanup; agents should ask before running it.\n\n## Required checks before publishing/updating\n\nMinimum no-spend checks:\n\n```powershell\nnode --check skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs help\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs stats --json\n```\n\nAlso run a no-key smoke test in a temporary home/profile context when feasible to confirm credential errors without spending credits.\n\n## Public / ClawHub exposure\n\nClassification: **publishable utility with external API + local cache/log writes**.\n\nBefore public update, run sanitizer/static checks and make sure docs clearly disclose:\n\n- external calls to Tavily;\n- cache/log file locations;\n- plaintext query/URL logging;\n- expected static-analysis warning;\n- no local file/secret exfiltration.\n\nDo not include private/internal/client strategy or operator-specific operational notes in a public release.\n\n## Changelog\n\n- `1.0.6`: Add frontmatter version metadata and align reference docs so `cache clear` is consistently marked as local deletion requiring explicit approval.\n- `1.0.5`: Public package wording/metadata cleanup; cache/log/security behavior unchanged.\n\n_Last reviewed: 2026-05-26; Sonnet PASS_WITH_MINOR_NOTES satisfied._\n\nFile v1.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"tavily-search-pro-native-node\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1779807934131\n}\n\nFile v1.0.6:references/tavily-pro-contract.md\n\n# Tavily Search Pro Contract\n\nUse only when the compact `SKILL.md` is not enough.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\nSubcommands:\n\n- `search`\n- `extract`\n- `stats`\n- `cache`\n- `help`\n\n## Quick reference\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\n## Search flags\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` / `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` / `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` news only | Age window |\n| `--include` | comma list | none | Domains to include |\n| `--exclude` | comma list | none | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n\n## Extract flags\n\nWraps Tavily's `/extract` endpoint. Takes one or more URLs.\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl`.\n\nCredits: Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs basic, 2 per 5 advanced. The usage log tracks this.\n\n## Stats\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json\n```\n\nOutput includes total calls, searches vs extracts, cache hit rate, errors, credits used, and estimated credits avoided by cache.\n\n## Cache\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\n```\n\nResponses are cached under `~/.openclaw/cache/tavily-search-pro-native-node/cache/` keyed by SHA-256 of request body + kind. Different flag combos create different cache entries.\n\nDefault TTLs:\n\n- Search, general topic: 24 hours\n- Search, news topic: 1 hour\n- Extract: 7 days\n\nOverride with `--ttl SECONDS`; skip with `--no-cache`.\n\n## Rate-limit backoff\n\nOn HTTP 429, retries up to 3 times with exponential backoff (1s, 2s, 4s) or respects `Retry-After` when present. Disable with `--no-retry`.\n\nNetwork errors also retry. Other HTTP errors surface immediately.\n\n## Usage log\n\nEvery call appends one JSON line to:\n\n```text\n~/.openclaw/cache/tavily-search-pro-native-node/usage.log\n```\n\nExample:\n\n```json\n{\"ts\":1713732000000,\"kind\":\"search\",\"query\":\"OpenClaw\",\"depth\":\"basic\",\"topic\":\"general\",\"cached\":false,\"credits\":1}\n```\n\nQueries/URLs are logged in plaintext. Use `--no-log` for sensitive calls.\n\n## Troubleshooting\n\n- `TAVILY_API_KEY not set` -> set env var in process environment.\n- HTTP 401 -> invalid/revoked key.\n- HTTP 429 -> rate limited; script auto-retries then surfaces Retry-After.\n- HTTP 432 -> monthly credit cap hit.\n- Network timeout -> retries, then surfaces error.\n- Stale results -> use `--no-cache` or `cache clear` after explicit approval for local deletion.\n- Cache/log growth -> `cache info`, `cache clear`, or manual log rotation. `cache clear` is local deletion and requires explicit approval before running.\n\n## Agent usage pattern\n\n1. Prefer one well-crafted search over several narrow ones.\n2. Use `basic` unless the user asks for deep research.\n3. Use `--include` for trusted domains when appropriate.\n4. Use cache unless freshness matters.\n5. For deep reads: search -> pick URLs -> extract.\n6. Quote sources so the user can verify.\n\n## Publish/update checks\n\nBefore publishing or updating:\n\n```powershell\nnode --check scripts\\tavily-pro.mjs\nnode scripts\\tavily-pro.mjs help\nnode scripts\\tavily-pro.mjs stats --json\n```\n\nAlso run a no-key smoke test with a temporary home directory to verify credential errors without spending credits.\n\nFile v1.0.6:skill-card.md\n\n## Description: <br>\nResearch-grade Tavily toolkit for OpenClaw - native Node.js, zero dependencies. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jwestburg](https://clawhub.ai/user/jwestburg) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use this skill for deep web research, multi-URL extraction, Tavily usage statistics, response caching, and rate-limit backoff when Tavily is an appropriate external research API. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Search queries and target URLs are sent to Tavily and may contain sensitive, internal, client, or regulated information. <br>\nMitigation: Use the skill only when external Tavily research is appropriate, avoid placing secrets in queries or URLs, and stop or switch tools for privacy-sensitive work unless external use is approved. <br>\nRisk: Usage logs may save plaintext search queries and URLs locally. <br>\nMitigation: Use --no-log for sensitive approved calls and periodically inspect or clear the local Tavily cache/log directory. <br>\nRisk: Cached responses can be stale when freshness is important. <br>\nMitigation: Use --no-cache for news or freshness-critical requests and treat cache clearing as local deletion that requires explicit approval. <br>\n\n\n## Reference(s): <br>\n- [Tavily Search Pro Contract](references/tavily-pro-contract.md) <br>\n- [Tavily Search API endpoint](https://api.tavily.com/search) <br>\n- [Tavily Extract API endpoint](https://api.tavily.com/extract) <br>\n- [ClawHub skill page](https://clawhub.ai/jwestburg/tavily-search-pro-native-node) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and optional JSON output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include source URLs, cache/logging status, freshness and depth choices, credit usage estimates, limitations, and next safe research steps.] <br>\n\n## Skill Version(s): <br>\n1.0.6 (source: frontmatter and server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.5: 4 files, 11109 bytes\n\nFiles: references/tavily-pro-contract.md (4257b), scripts/tavily-pro.mjs (21547b), SKILL.md (5617b), _meta.json (148b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily toolkit for OpenClaw - native Node.js, zero dependencies. Use when the user needs deep web research, multi-URL content extraction, Tavily credit usage stats, caching, or 429 backoff. Includes search/extract/stats/cache subcommands, response caching, JSONL usage logging, and rate-limit backoff. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\n---\n\n# Tavily Search Pro (Native Node)\n\nVersion: v3 Lean / publishable utility.\n\nResearch-grade Tavily helper: one dependency-free Node script with `search`, `extract`, `stats`, and `cache` subcommands.\n\n## Risk / invocation class\n\nRisk class: **external research API / credit usage / plaintext query logging**.\n\nUse deliberately. This skill sends search queries or URLs to Tavily over HTTPS and may append plaintext queries/URLs to a local usage log unless `--no-log` is used.\n\n## Lean input packet\n\nRequired:\n\n- `task`: search, extract, usage stats, or cache inspection.\n- `query_or_urls`: search query or URL list when applicable.\n- `privacy_sensitivity`: normal, sensitive, client/private, or unknown.\n- `freshness_need`: normal cache ok, fresh/no-cache, or news/freshness-critical.\n- `depth`: basic unless advanced is justified.\n\nOptional:\n\n- `trusted_domains`: include/exclude domains.\n- `max_results`: default 5; avoid broad high-result searches unless needed.\n- `logging_preference`: normal log, `--no-log`, or unknown.\n- `output_format`: human summary or `--json`.\n\nStop or switch tools if the query is privacy-sensitive and sending it to Tavily is not appropriate. For one known URL, prefer `web_fetch` unless extraction quality matters.\n\n## Lean output packet\n\nReturn compactly:\n\n- command used or planned, redacted as needed\n- whether cache/logging was enabled\n- freshness/depth choice\n- sources/results with URLs\n- credits used or expected when known\n- limitations/caveats\n- next safe research step\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files or `~/.openclaw/.env`.\n- Makes network calls only to Tavily's HTTPS endpoints:\n  - `https://api.tavily.com/search`\n  - `https://api.tavily.com/extract`\n- Writes cache and usage logs only under `~/.openclaw/cache/tavily-search-pro-native-node/`.\n- Cache filenames are SHA-256 request hashes, not plaintext queries.\n- Usage logs may contain plaintext search queries/URLs; use `--no-log` for sensitive calls.\n- Does not transmit local files or secrets.\n- Does not modify system configuration or auto-update.\n- ClawHub static-analysis `potential_exfiltration` warnings are expected because this tool combines env credentials, local cache/log file access, and Tavily network calls.\n\n## When to use\n\nUse this Pro skill when:\n\n- the user needs thorough web research, not just a quick lookup;\n- multiple queries are likely and cache will save credits;\n- full content extraction from specific URLs is needed;\n- Tavily usage/stats matter;\n- 429 retry/backoff is useful.\n\nPrefer `tavily-search-native-node` when:\n\n- a single simple search is enough;\n- minimum audit surface matters;\n- no disk writes/caching/logging are desired.\n\nPrefer `web_fetch` for a one-off known URL read.\n\nDo not use when:\n\n- the query is privacy-sensitive and should not leave this machine;\n- the user has not approved a sensitive/client/private query to an external research API;\n- freshness requires live source browsing and cache state is uncertain, unless `--no-cache` is used.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\nFor full flags, cache/log behavior, troubleshooting, and publish/update checks, load `references/tavily-pro-contract.md`.\n\n## Operating guidance\n\n- Prefer one well-crafted query over several narrow searches.\n- Use `basic` depth unless advanced is justified; `advanced` costs more.\n- Use `--include`/`--exclude` to scope sources when appropriate.\n- Use cache by default; use `--no-cache` when freshness matters.\n- Use `--no-log` for sensitive but approved external queries.\n- For follow-up deep reads: search -> select URLs -> extract.\n- Quote sources so the user/requester can verify.\n- Track credit usage with `stats` when research runs get large.\n\n## Required checks before publishing/updating\n\nMinimum no-spend checks:\n\n```powershell\nnode --check skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs help\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs stats --json\n```\n\nAlso run a no-key smoke test in a temporary home/profile context when feasible to confirm credential errors without spending credits.\n\n## Public / ClawHub exposure\n\nClassification: **publishable utility with external API + local cache/log writes**.\n\nBefore public update, run sanitizer/static checks and make sure docs clearly disclose:\n\n- external calls to Tavily;\n- cache/log file locations;\n- plaintext query/URL logging;\n- expected static-analysis warning;\n- no local file/secret exfiltration.\n\nDo not include private/internal/client strategy or operator-specific operational notes in a public release.\n\n_Last reviewed: 2026-05-18_\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"tavily-search-pro-native-node\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1779219588890\n}\n\nFile v1.0.5:references/tavily-pro-contract.md\n\n# Tavily Search Pro Contract\n\nUse only when the compact `SKILL.md` is not enough.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\nSubcommands:\n\n- `search`\n- `extract`\n- `stats`\n- `cache`\n- `help`\n\n## Quick reference\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\n## Search flags\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` / `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` / `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` news only | Age window |\n| `--include` | comma list | none | Domains to include |\n| `--exclude` | comma list | none | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n\n## Extract flags\n\nWraps Tavily's `/extract` endpoint. Takes one or more URLs.\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl`.\n\nCredits: Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs basic, 2 per 5 advanced. The usage log tracks this.\n\n## Stats\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json\n```\n\nOutput includes total calls, searches vs extracts, cache hit rate, errors, credits used, and estimated credits avoided by cache.\n\n## Cache\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tavily-pro.mjs\" cache clear\n```\n\nResponses are cached under `~/.openclaw/cache/tavily-search-pro-native-node/cache/` keyed by SHA-256 of request body + kind. Different flag combos create different cache entries.\n\nDefault TTLs:\n\n- Search, general topic: 24 hours\n- Search, news topic: 1 hour\n- Extract: 7 days\n\nOverride with `--ttl SECONDS`; skip with `--no-cache`.\n\n## Rate-limit backoff\n\nOn HTTP 429, retries up to 3 times with exponential backoff (1s, 2s, 4s) or respects `Retry-After` when present. Disable with `--no-retry`.\n\nNetwork errors also retry. Other HTTP errors surface immediately.\n\n## Usage log\n\nEvery call appends one JSON line to:\n\n```text\n~/.openclaw/cache/tavily-search-pro-native-node/usage.log\n```\n\nExample:\n\n```json\n{\"ts\":1713732000000,\"kind\":\"search\",\"query\":\"OpenClaw\",\"depth\":\"basic\",\"topic\":\"general\",\"cached\":false,\"credits\":1}\n```\n\nQueries/URLs are logged in plaintext. Use `--no-log` for sensitive calls.\n\n## Troubleshooting\n\n- `TAVILY_API_KEY not set` -> set env var in process environment.\n- HTTP 401 -> invalid/revoked key.\n- HTTP 429 -> rate limited; script auto-retries then surfaces Retry-After.\n- HTTP 432 -> monthly credit cap hit.\n- Network timeout -> retries, then surfaces error.\n- Stale results -> use `--no-cache` or `cache clear`.\n- Cache/log growth -> `cache info`, `cache clear`, or manual log rotation.\n\n## Agent usage pattern\n\n1. Prefer one well-crafted search over several narrow ones.\n2. Use `basic` unless the user asks for deep research.\n3. Use `--include` for trusted domains when appropriate.\n4. Use cache unless freshness matters.\n5. For deep reads: search -> pick URLs -> extract.\n6. Quote sources so the user can verify.\n\n## Publish/update checks\n\nBefore publishing or updating:\n\n```powershell\nnode --check scripts\\tavily-pro.mjs\nnode scripts\\tavily-pro.mjs help\nnode scripts\\tavily-pro.mjs stats --json\n```\n\nAlso run a no-key smoke test with a temporary home directory to verify credential errors without spending credits.\n\nArchive v1.0.4: 3 files, 10259 bytes\n\nFiles: scripts/tavily-pro.mjs (21484b), SKILL.md (8683b), _meta.json (148b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily toolkit for OpenClaw - native Node.js, zero dependencies. Search + Extract + Cache + Stats + Rate-limit backoff. Use when the user needs deep web research, multi-URL content extraction, or wants to track Tavily credit usage. Includes built-in response caching, full-page raw content, the Tavily /extract endpoint, automatic 429 backoff, a JSONL usage log, and a stats subcommand. Requires TAVILY_API_KEY in the process environment. For a minimal search-only skill, see tavily-search-native-node.\n---\n\n# Tavily Search Pro (Native Node)\n\nResearch-grade Tavily toolkit. One script, four subcommands: `search`, `extract`, `stats`, `cache`.\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files or `~/.openclaw/.env`.\n- Makes network calls only to Tavily's HTTPS endpoints: `https://api.tavily.com/search` and `https://api.tavily.com/extract`.\n- Writes cache and usage logs only under `~/.openclaw/cache/tavily-search-pro-native-node/`.\n- Cache filenames are SHA-256 request hashes, not plaintext queries.\n- Usage logs may contain plaintext search queries/URLs; use `--no-log` for sensitive calls.\n- The ClawHub static-analysis `potential_exfiltration` warning is expected for this Pro skill because it combines env credentials, local cache/log file access, and Tavily network calls. It does not transmit local files or secrets.\n\n\nNative Node.js. Zero dependencies. Small enough to audit directly.\n\n## When to use\n\n**Use this skill when:**\n- User needs thorough research, not just a quick lookup\n- Multiple queries in a session (cache cuts credits 30-50%)\n- User wants to extract full content from specific URLs\n- User wants to know their Tavily credit usage\n- Flaky network conditions (automatic retry)\n\n**Use `tavily-search-native-node` (the basic version) instead when:**\n- You just need one search and nothing else\n- You want the minimal audit surface (no disk writes at all)\n- You don't want caching or logging\n\n**Do NOT use this when:**\n- Privacy-sensitive queries (everything transmits to api.tavily.com)\n- Simple URL fetches - use `web_fetch` for one-off page reads\n\n## How to run\n\nThe script is in `scripts/tavily-pro.mjs`.\n\n### Quick reference\n\n```powershell\n# Search\nnode \"<skill-dir>/scripts/tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\n\n# Extract full content from URLs\nnode \"<skill-dir>/scripts/tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\n\n# See your usage\nnode \"<skill-dir>/scripts/tavily-pro.mjs\" stats\n\n# Inspect or clear cache\nnode \"<skill-dir>/scripts/tavily-pro.mjs\" cache info\nnode \"<skill-dir>/scripts/tavily-pro.mjs\" cache clear\n\n# Help\nnode \"<skill-dir>/scripts/tavily-pro.mjs\" help\n```\n\n### Search subcommand\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` \\| `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` \\| `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` (news only) | Age window |\n| `--include` | comma list | (none) | Domains to include |\n| `--exclude` | comma list | (none) | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n\n### Extract subcommand\n\nWraps Tavily's `/extract` endpoint - takes one or more URLs, returns clean article text.\n\n```powershell\n# Single URL\nnode \"./scripts/tavily-pro.mjs\" extract https://example.com\n\n# Multi-URL (more efficient than separate calls)\nnode \"./scripts/tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\n\n# Advanced depth for pages with JavaScript rendering\nnode \"./scripts/tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl` (default 7 days).\n\n**Credits:** Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs (basic), 2 per 5 (advanced). Our log tracks this correctly.\n\n### Stats subcommand\n\nShows usage summary from the JSONL log.\n\n```powershell\nnode \"./scripts/tavily-pro.mjs\" stats            # last 30 days\nnode \"./scripts/tavily-pro.mjs\" stats --days 7   # last week\nnode \"./scripts/tavily-pro.mjs\" stats --json     # machine-readable\n```\n\nOutput includes: total calls, searches vs extracts, cache hit rate, errors, credits used, and estimated credits avoided by cache.\n\n### Cache subcommand\n\n```powershell\nnode \"./scripts/tavily-pro.mjs\" cache info       # show dir, entry count, size, age\nnode \"./scripts/tavily-pro.mjs\" cache clear      # wipe the cache\n```\n\n## What this skill does\n\n- Reads `TAVILY_API_KEY` from the process environment only\n- Calls `https://api.tavily.com/search` and `https://api.tavily.com/extract`\n- Writes cached responses to `~/.openclaw/cache/tavily-search-pro-native-node/cache/`\n- Appends one JSON line per call to `~/.openclaw/cache/tavily-search-pro-native-node/usage.log`\n- Prints formatted, ASCII-safe human-readable results to stdout; `--json` preserves raw provider JSON\n\n## What this skill does NOT do\n\n- Does not touch any files outside `~/.openclaw/cache/tavily-search-pro-native-node/`\n- Does not make network calls outside `api.tavily.com`\n- Does not modify system configuration\n- Does not auto-update\n- Does not report to any external service\n\n## Caching\n\nResponses cached to `~/.openclaw/cache/tavily-search-pro-native-node/cache/` keyed by SHA-256 of the request body + kind (search/extract). Different flag combos = different cache entries. No false hits.\n\n**Default TTLs:**\n- Sea\n\nArchive v1.0.3: 3 files, 10426 bytes\n\nFiles: scripts/tavily-pro.mjs (22093b), SKILL.md (8667b), _meta.json (148b)","readmeExcerpt":"Skill: tavily-search-pro-native-node Owner: jwestburg Summary: Research-grade Tavily web search for OpenClaw using native Node.js with zero dependencies. Use for deep web research, multi-URL content extraction, estimated Tavily credit tracking, response caching, usage-log review, and 429 backoff. Includes search, extract, stats, and cache subcommands. Requires TAVILY_API_KEY in the process environment. For minimal se","codeSnippets":[],"executableExamples":[{"language":"powershell","snippet":"node \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache       # defaults to cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear  # local deletion; use only after explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help"},{"language":"powershell","snippet":"node --check skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs help\nnode skills\\tavily-search-pro-native-node\\scripts\\tavily-pro.mjs stats --json\nnode skills\\tavily-search-pro-native-node\\scripts\\self-test.mjs"},{"language":"powershell","snippet":"node \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache      # defaults to cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help"},{"language":"powershell","snippet":"node \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com"},{"language":"powershell","snippet":"node \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json"},{"language":"powershell","snippet":"node \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: tavily-search-pro-native-node\ndescription: Research-grade Tavily web search for OpenClaw using native Node.js with zero dependencies. Use for deep web research, multi-URL content extraction, estimated Tavily credit tracking, response caching, usage-log review, and 429 backoff. Includes search, extract, stats, and cache subcommands. Requires TAVILY_API_KEY in the process environment. For minimal search-only use, prefer tavily-search-native-node.\nversion: 1.0.36\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TAVILY_API_KEY\n    primaryEnv: TAVILY_API_KEY\n    envVars:\n      - name: TAVILY_API_KEY\n        required: true\n        description: Tavily API key used for authenticated search and extract requests.\nrisk_class: external-research-api-credit-cache-log-local-delete\n---\n\n# Tavily Search Pro (Native Node)\n\nVersion: 1.0.36 / public ClawHub utility candidate with external API, cache, usage-log, and approval-gated local cache deletion behavior.\n\nResearch-grade Tavily web search helper: one dependency-free Node script with `search`, `extract`, `stats`, and `cache` subcommands.\n\n## Risk / invocation class\n\nRisk class: **external research API / credit usage / plaintext query logging / local cache deletion**.\n\nUse deliberately. This skill sends search queries or URLs to Tavily over HTTPS, may append plaintext queries/URLs to a local usage log unless `--no-log` is used, and exposes `cache clear` as approval-gated local deletion of cached response JSON files.\n\n## Input packet\n\nRequired:\n\n- `task`: search, extract, usage stats, or cache inspection.\n- `query_or_urls`: search query or URL list when applicable.\n- `privacy_sensitivity`: normal, sensitive, client/private, or unknown. `unknown` is a fail-closed state for `search` and `extract`: classify sensitivity first or obtain explicit approval for external Tavily transmission before running an outbound command.\n- `freshness_need`: normal cache ok, fresh/no-cache, or news/freshness-critical.\n- `depth`: basic unless advanced is justified.\n\nOptional:\n\n- `trusted_domains`: include/exclude domains.\n- `max_results`: default 5; avoid broad high-result searches unless needed.\n- `logging_preference`: normal log, `--no-log`, or unknown.\n- `output_format`: human summary or `--json`.\n\nStop or switch tools if the query is privacy-sensitive and sending it to Tavily is not appropriate. If `privacy_sensitivity` is `unknown`, do not run `search` or `extract` until sensitivity is classified as normal or explicit approval resolves the external-send ambiguity. For one known URL, prefer `web_fetch` unless extraction quality matters.\n\n## Output packet\n\nReturn compactly:\n\n- command used or planned, redacted as needed\n- whether cache/logging was enabled\n- freshness/depth choice\n- sources/results with URLs\n- estimated credits used or expected when known\n- limitations/caveats\n- next safe research step\n\n## Security behavior\n\n- Reads `TAVILY_API_KEY` from the process environment only.\n- Does not read credential files "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn78bc0rnqe8pnvd4azdnjvmmd858m3q\",\n  \"slug\": \"tavily-search-pro-native-node\",\n  \"version\": \"1.0.36\",\n  \"publishedAt\": 1789093027632\n}"},{"path":"references/tavily-pro-contract.md","content":"# Tavily Search Pro Contract\n\nUse only when the compact `SKILL.md` is not enough.\n\n## Commands\n\nScript: `scripts/tavily-pro.mjs`\n\nSubcommands:\n\n- `search`\n- `extract`\n- `stats`\n- `cache`\n- `help`\n\n## Quick reference\n\n```powershell\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" search \"OpenClaw skills ecosystem\"\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" extract https://example.com/ https://www.iana.org/help/example-domains\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" stats\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache      # defaults to cache info\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" cache clear # local deletion - requires explicit approval\nnode \"<skill-dir>\\scripts\\tavily-pro.mjs\" help\n```\n\n## Search flags\n\n| Flag | Values | Default | Purpose |\n|---|---|---|---|\n| `--topic` | `general` / `news` | `general` | `news` biases to fresh articles |\n| `--depth` | `basic` / `advanced` | `basic` | `advanced` = 2 credits |\n| `--max` | 1-20 | `5` | Results to return |\n| `--days` | integer | `7` news only | Age window |\n| `--include` | comma list | none | Domains to include |\n| `--exclude` | comma list | none | Domains to exclude |\n| `--raw-content` | flag | off | Include full page text per result |\n| `--json` | flag | off | Raw JSON output |\n| `--no-cache` | flag | off | Skip cache |\n| `--no-log` | flag | off | Skip usage log |\n| `--no-retry` | flag | off | No backoff on 429 |\n| `--ttl` | seconds | 24h general, 1h news | Override cache TTL |\n| `--timeout-ms` | integer | 30000 | Per-attempt network timeout |\n\n## Extract flags\n\nWraps Tavily's `/extract` endpoint. Takes one or more public HTTP(S) URLs. The CLI requires raw conventional `http://` or `https://` URLs with a host, rejects malformed/non-HTTP(S)/raw-backslash/credential-bearing URL arguments, and refuses localhost, loopback, unspecified IPv4/IPv6, link-local, RFC1918/private-address URLs, and private/local IPv4-mapped IPv6 forms before sending anything to Tavily. Credential-bearing and local/private URL errors are sanitized and do not echo the supplied URL.\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" extract https://example.com\nnode \".\\scripts\\tavily-pro.mjs\" extract https://a.com https://b.com https://c.com\nnode \".\\scripts\\tavily-pro.mjs\" extract --depth advanced https://spa-site.com\n```\n\nFlags: `--depth`, `--json`, `--no-cache`, `--no-log`, `--no-retry`, `--ttl`, `--timeout-ms`.\n\nEstimated credits: Tavily bills extract in batches of 5 URLs - 1 credit per 5 URLs basic, 2 per 5 advanced. The usage log estimates this locally; it is not a Tavily-returned billing value.\n\n## Stats\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" stats\nnode \".\\scripts\\tavily-pro.mjs\" stats --days 7\nnode \".\\scripts\\tavily-pro.mjs\" stats --json\n```\n\nOutput includes total calls, searches vs extracts, cache hit rate, errors, estimated credits used, and estimated credits avoided by cache.\n\n## Cache\n\n```powershell\nnode \".\\scripts\\tavily-pro.mjs\" cache info\nnode \".\\scripts\\tav"},{"path":"skill-card.md","content":"## Description:\n\nResearch-grade Tavily web search for OpenClaw using native Node.js with zero dependencies, supporting deep web research, multi-URL extraction, estimated credit tracking, response caching, usage-log review, and 429 backoff.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jwestburg](https://clawhub.ai/user/jwestburg)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and research agents use this skill to run Tavily-backed web searches, extract content from public URLs, inspect usage statistics, and manage response cache behavior while tracking estimated credit use.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Search queries and accepted public URLs are sent to Tavily with the configured API key.\n\nMitigation: Use this skill only for queries and URLs approved for external Tavily processing, and classify privacy sensitivity before outbound search or extract use.\n\nRisk: Usage logs may contain plaintext queries or URLs, and cached responses may persist under the skill-specific OpenClaw cache directory.\n\nMitigation: Use --no-log --no-cache for sensitive or client/private research that is approved for external processing.\n\nRisk: Cached responses are not scoped by Tavily account when multiple accounts share one OS profile.\n\nMitigation: Use separate OS profiles for account isolation or disable caching with --no-cache.\n\nRisk: The cache clear subcommand deletes local cached response files.\n\nMitigation: Run cache clear only when deletion is intentional; the skill limits deletion to expected cache files under its own cache directory and reports partial failures.\n\n## Reference(s):\n\n- [Tavily Search Pro Contract](references/tavily-pro-contract.md)\n- [ClawHub Skill Page](https://clawhub.ai/jwestburg/skills/tavily-search-pro-native-node)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown or JSON command output with source URLs, cache/logging status, freshness and depth choices, estimated credit use, caveats, and next-step guidance.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May emit raw JSON when requested; normal usage returns compact human-facing text.]\n\n## Skill Version(s):\n\n1.0.36 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1682,"uniquenessScore":40,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T06:19:13.630Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T06:19:13.630Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:44:41.407Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}