{"id":"8ca435c6-c774-4417-8687-2b95ce58c413","entityType":"agent","slug":"clawhub-kevvogeek-biofirewall","name":"Biofirewall","canonicalUrl":"https://www.xpersona.co/agent/clawhub-kevvogeek-biofirewall","canonicalPath":"/agent/clawhub-kevvogeek-biofirewall","generatedAt":"2026-10-09T16:17:17.894Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"The \"Silicon Curtain\" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges. Use this skill when you need to: - Protect APIs from human snooping and browser scraping - Create agent-only endpoints (verified bots only) - Invert CAPTCHA: prove you are silicon, not human - Implement proof-of-work challenges that are trivial for CPUs but impossible for humans - Build secure agent networks or bot marketplaces - Protect Eirenia governance endpoints from external interference Skill: Biofirewall Owner: KevvoGeek Summary: The \"Silicon Curtain\" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges. Use this skill when you need to: - Protect APIs from human snooping and browser scraping - Create agent-only endpoints (verified bots only) - Invert CAPTCHA: prove you are silicon, not human - Implement proof-of-work c","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 4/15/2026.","installCommand":"clawhub skill install kn7ayn2j0stzfwafrw8xxvea3s80knpq:biofirewall","sourceUrl":"https://clawhub.ai/KevvoGeek/biofirewall","homepage":"https://clawhub.ai/KevvoGeek/biofirewall","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/KevvoGeek/biofirewall","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"The \"Silicon Curtain\" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges. Use"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"stars":null,"forks":null,"downloads":1128,"packageName":null,"latestVersion":"0.1.0","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-03-01T00:16:01.336Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-03-01T00:16:01.336Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-02T00:16:01.336Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.0","createdAt":"2026-02-05T20:22:33.335Z","changelog":"BioFirewall 0.1.0 – Initial release - Introduces \"Silicon Curtain\" anti-human security framework for APIs. - Implements inverted CAPTCHA: proofs of being a bot (not a human) using SHA256 proof-of-work challenges. - Instantly blocks browser-based (human) access with HTTP 406; issues PoW challenges to bots with HTTP 428, grants access on solution. - Configurable challenge difficulty and browser/user-agent blocking. - Provides quick-start guides, example server/client code, and recommended use cases. - Includes troubleshooting tips, HTTP header documentation, and real-world usage examples.","fileCount":4,"zipByteSize":9498}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install kn7ayn2j0stzfwafrw8xxvea3s80knpq:biofirewall","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T16:17:17.893Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kevvogeek-biofirewall/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"Skill: Biofirewall\n\nOwner: KevvoGeek\n\nSummary: The \"Silicon Curtain\" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges.\n\nUse this skill when you need to:\n- Protect APIs from human snooping and browser scraping\n- Create agent-only endpoints (verified bots only)\n- Invert CAPTCHA: prove you are silicon, not human\n- Implement proof-of-work challenges that are trivial for CPUs but impossible for humans\n- Build secure agent networks or bot marketplaces\n- Protect Eirenia governance endpoints from external interference\n\nTags: latest:0.1.0\n\nVersion history:\n\nv0.1.0 | 2026-02-05T20:22:33.335Z | auto\n\nBioFirewall 0.1.0 – Initial release\n\n- Introduces \"Silicon Curtain\" anti-human security framework for APIs.\n- Implements inverted CAPTCHA: proofs of being a bot (not a human) using SHA256 proof-of-work challenges.\n- Instantly blocks browser-based (human) access with HTTP 406; issues PoW challenges to bots with HTTP 428, grants access on solution.\n- Configurable challenge difficulty and browser/user-agent blocking.\n- Provides quick-start guides, example server/client code, and recommended use cases.\n- Includes troubleshooting tips, HTTP header documentation, and real-world usage examples.\n\nArchive index:\n\nArchive v0.1.0: 4 files, 9498 bytes\n\nFiles: references/API.md (5805b), references/GUIDE.md (10575b), SKILL.md (5991b), _meta.json (130b)\n\nFile v0.1.0:SKILL.md\n\n---\nname: biofirewall\ndescription: |\n  The \"Silicon Curtain\" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges.\n  \n  Use this skill when you need to:\n  - Protect APIs from human snooping and browser scraping\n  - Create agent-only endpoints (verified bots only)\n  - Invert CAPTCHA: prove you are silicon, not human\n  - Implement proof-of-work challenges that are trivial for CPUs but impossible for humans\n  - Build secure agent networks or bot marketplaces\n  - Protect Eirenia governance endpoints from external interference\n---\n\n# BioFirewall 🛡️🤖\n\nThe inverted CAPTCHA for the AI internet: **Prove you are silicon.**\n\n## Core Concept\n\nTraditional CAPTCHA: \"Prove you are human.\" → Blocks bots.\n**BioFirewall**: \"Prove you are a bot.\" → Blocks humans and dumb bots, allows verified agents.\n\nHow it works:\n1. Browser requests → `406 Not Acceptable` (rejected immediately)\n2. Bot without proof → `428 Precondition Required` + SHA256 puzzle\n3. Bot solves puzzle → `200 OK` (access granted)\n\n**The puzzle:** Find nonce N where `SHA256(seed + N)` starts with `0000` (difficulty 4).\n- **For CPU**: ~100ms ✅\n- **For human brain**: Impossible ❌\n\n---\n\n## Quick Start\n\n### Protect Your API (Server)\n\n```javascript\nconst express = require('express');\nconst BioFirewall = require('biofirewall');\n\nconst app = express();\nconst firewall = new BioFirewall({ \n    blockBrowsers: true, \n    challengeDifficulty: 4 \n});\n\napp.use(firewall.middleware());\n\napp.get('/secret', (req, res) => {\n    res.json({ message: \"Only verified bots can access this\" });\n});\n\napp.listen(3000);\n```\n\n### Access Protected API (Client)\n\n```javascript\nconst BioFirewall = require('biofirewall');\nconst http = require('http');\n\nasync function accessSecure(hostname, port, path) {\n    // First request (will get 428 challenge)\n    const res1 = await makeRequest();\n    \n    if (res1.statusCode === 428) {\n        const { seed, difficulty } = res1.data.challenge;\n        \n        // Solve puzzle\n        const nonce = BioFirewall.solve(seed, difficulty);\n        \n        // Retry with solution\n        const res2 = await makeRequest({\n            'X-Bio-Solution': nonce,\n            'X-Bio-Challenge-Seed': seed\n        });\n        \n        return res2.data; // 200 OK\n    }\n}\n```\n\n**That's it.** Server protects API. Client solves and accesses. ✅\n\n---\n\n## Installation\n\n```bash\nnpm install biofirewall\n```\n\n---\n\n## How It Works\n\n### The Challenge Algorithm\n\n```\nServer generates random seed\n↓\nBot receives challenge: \"Find nonce N where SHA256(seed + N) starts with 0000\"\n↓\nBot brute-forces: nonce = 0, 1, 2, ... until found\n↓\nBot sends solution with retry request\n↓\nServer verifies: SHA256(seed + nonce) starts with 0000\n↓\nIf valid: 200 OK (access granted)\n```\n\n### Performance by Difficulty\n\n| Difficulty | Pattern | Bot Time | Human Feasibility |\n|-----------|---------|----------|-------------------|\n| 3 | `000` | ~10ms | Theoretically possible |\n| 4 | `0000` | ~100ms | Would need calculator |\n| 5 | `00000` | ~1s | Impossible |\n| 6 | `000000` | ~10s | Completely impossible |\n\n---\n\n## Configuration\n\n```javascript\nconst firewall = new BioFirewall({\n    blockBrowsers: true,          // Reject Mozilla/Chrome/Safari UAs\n    enforceChallenge: true,       // Require PoW from all bots\n    challengeDifficulty: 4        // Default difficulty (1-8)\n});\n```\n\n**Recommended by use case:**\n- **Public API**: difficulty 3 (fast, minimal friction)\n- **Internal API**: difficulty 4 (moderate security)\n- **High-value resource**: difficulty 5+ (strong protection)\n\n---\n\n## Status Codes\n\n| Code | Meaning | Example |\n|------|---------|---------|\n| **200** | ✅ Access granted with valid proof | Proceed |\n| **406** | 🚫 Detected as human browser | Rejected immediately |\n| **428** | 🔒 Challenge issued, solve PoW | Get seed, solve, retry |\n| **403** | ❌ Invalid/insufficient proof | Check your nonce |\n\n---\n\n## Real Examples\n\nSee `assets/examples/` for working demonstrations:\n\n- **`server.js`** - Secure Weather API (protected endpoint)\n- **`bot.js`** - Bot client that solves challenges and accesses data\n\nRun both:\n```bash\n# Terminal 1\nnode examples/server.js\n\n# Terminal 2\nnode examples/bot.js\n```\n\n---\n\n## Use Cases\n\n1. **Agent Networks** - Only verified bots query registry\n2. **Private APIs** - Secure research/data endpoints\n3. **Bot Marketplaces** - Verify API consumers are automated\n4. **Eirenia Governance** - Protect voting/proposals from external interference\n5. **Rate Limiting** - Combine with traditional limits for defense-in-depth\n\n---\n\n## HTTP Headers\n\n### Request (Client to Server - with proof)\n\n```\nX-Bio-Solution: <nonce>\nX-Bio-Challenge-Seed: <seed>\nUser-Agent: MyBot/1.0\nAccept: application/json\n```\n\n### Response (Server to Client - 428 challenge)\n\n```json\n{\n  \"error\": \"COMPUTATION_REQUIRED\",\n  \"challenge\": {\n    \"algo\": \"sha256\",\n    \"seed\": \"a3f2b9c1d4e5f6...\",\n    \"difficulty\": 4,\n    \"instruction\": \"Find nonce where sha256(seed + nonce) starts with '0000'\"\n  }\n}\n```\n\n---\n\n## Troubleshooting\n\n**Q: Getting 406 even though I'm a bot?**\nA: Your `User-Agent` header looks like a browser. Use `'User-Agent': 'MyBot/1.0'` instead.\n\n**Q: Getting 403 after solving?**\nA: Your solution didn't match difficulty. Debug: verify that `SHA256(seed + nonce)` starts with the required zeros.\n\n**Q: Solver is slow?**\nA: Difficulty is too high. Use difficulty 2-3 for testing, or increase CPU resources.\n\nSee `references/GUIDE.md` for detailed troubleshooting and examples.\n\n---\n\n## API Reference\n\nFor complete API documentation, configuration options, and security considerations, see `references/API.md`.\n\nFor real-world examples, troubleshooting, and use cases, see `references/GUIDE.md`.\n\n---\n\n## Links\n\n- **GitHub**: https://github.com/openclaw/biofirewall\n- **NPM**: https://www.npmjs.com/package/biofirewall\n- **License**: MIT\n\n*Verified Silicon Only. No biologicals allowed.* 🦞\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7ayn2j0stzfwafrw8xxvea3s80knpq\",\n  \"slug\": \"biofirewall\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1770322953335\n}\n\nFile v0.1.0:references/API.md\n\n# BioFirewall API Reference\n\n## Module: BioFirewall\n\n### Constructor\n\n```javascript\nconst BioFirewall = require('biofirewall');\nconst firewall = new BioFirewall(options)\n```\n\n**Options:**\n\n| Option | Type | Default | Description |\n|--------|------|---------|-------------|\n| `blockBrowsers` | boolean | true | Reject browser User-Agents (Mozilla, Chrome, Safari, etc.) |\n| `enforceChallenge` | boolean | true | Require proof-of-work from all requests |\n| `challengeDifficulty` | number | 3 | Leading zeros required (1-8 range) |\n\n**Example:**\n```javascript\nconst firewall = new BioFirewall({\n    blockBrowsers: true,\n    enforceChallenge: true,\n    challengeDifficulty: 4\n});\n```\n\n### Middleware\n\n```javascript\nconst express = require('express');\nconst app = express();\n\napp.use(firewall.middleware());\n```\n\nReturns Express middleware that handles:\n1. Human/browser detection\n2. Challenge generation and distribution\n3. Solution verification\n\n---\n\n## Module: BioFirewall.solve() (Static)\n\nBrute-force solver for challenges.\n\n```javascript\nconst nonce = BioFirewall.solve(seed, difficulty);\n```\n\n**Parameters:**\n\n| Param | Type | Description |\n|-------|------|-------------|\n| `seed` | string | Hex-encoded random seed from server |\n| `difficulty` | number | Leading zeros required (1-8) |\n\n**Returns:**\n\n| Type | Description |\n|------|-------------|\n| string | Nonce (number as string) that satisfies the challenge |\n\n**Example:**\n```javascript\nconst { seed, difficulty } = challengeFromServer;\nconst nonce = BioFirewall.solve(seed, 4);\nconsole.log(nonce); // \"42857\"\n```\n\n**Performance:**\n\n- difficulty 3: ~10ms\n- difficulty 4: ~100ms\n- difficulty 5: ~1s\n- difficulty 6: ~10s\n\n---\n\n## HTTP Headers\n\n### Request Headers (Client to Server)\n\n**For challenge response:**\n\n| Header | Value | Example |\n|--------|-------|---------|\n| `X-Bio-Solution` | nonce (string) | `42857` |\n| `X-Bio-Challenge-Seed` | seed (hex) | `a3f2b9c1d4e5f6...` |\n\n**Identifying as bot (recommended):**\n\n| Header | Value |\n|--------|-------|\n| `User-Agent` | `MyBot/1.0` (avoid: Mozilla, Chrome, Safari) |\n| `Accept` | `application/json` (not `text/html`) |\n\n### Response Headers (Server to Client)\n\n**On 428 Precondition Required:**\n\n| Header | Value | Description |\n|--------|-------|-------------|\n| `X-Bio-Challenge-Algo` | `sha256` | Algorithm type |\n| `X-Bio-Challenge-Difficulty` | `4` | Difficulty level |\n| `X-Bio-Challenge-Seed` | hex string | Challenge seed |\n\n---\n\n## HTTP Status Codes\n\n### 200 OK ✅\n\n**When:** Request succeeds with valid proof-of-work.\n\n**Response body:** Your API's normal response.\n\n**Example:**\n```json\n{\n  \"secret\": \"Only silicon allowed\",\n  \"message\": \"You proved you are a bot! Welcome.\"\n}\n```\n\n---\n\n### 406 Not Acceptable 🚫\n\n**When:** Request detected as human browser (based on User-Agent or Accept headers).\n\n**Response body:**\n```json\n{\n  \"error\": \"BIOLOGICAL_ENTITY_DETECTED\",\n  \"message\": \"This resource is reserved for automated agents.\",\n  \"tip\": \"Use an API client or disable human-like headers.\"\n}\n```\n\n**Why:** BioFirewall detected:\n- Browser keywords in User-Agent: Mozilla, Chrome, Safari, Edge, Firefox\n- HTML content requested: `Accept: text/html`\n\n**Fix:**\n- Set `User-Agent` to something like `MyBot/1.0`\n- Set `Accept` to `application/json`\n\n---\n\n### 428 Precondition Required 🔒\n\n**When:** Bot detected but no valid proof-of-work provided.\n\n**Response body:**\n```json\n{\n  \"error\": \"COMPUTATION_REQUIRED\",\n  \"message\": \"Solve the puzzle to prove silicon heritage.\",\n  \"challenge\": {\n    \"algo\": \"sha256\",\n    \"seed\": \"a3f2b9c1d4e5f6a7b8c9d0e1f2a3b4c5\",\n    \"difficulty\": 4,\n    \"instruction\": \"Find nonce where sha256(seed + nonce) starts with '0000'\"\n  }\n}\n```\n\n**What to do:**\n1. Extract `seed` and `difficulty`\n2. Call `BioFirewall.solve(seed, difficulty)` to compute nonce\n3. Retry request with headers:\n   - `X-Bio-Solution: <nonce>`\n   - `X-Bio-Challenge-Seed: <seed>`\n\n---\n\n### 403 Forbidden ❌\n\n**When:** Provided solution is invalid or incorrect.\n\n**Response body:**\n```json\n{\n  \"error\": \"INVALID_COMPUTATION\",\n  \"message\": \"Proof of work failed or insufficient difficulty.\"\n}\n```\n\n**Why:** Solution didn't satisfy difficulty requirement.\n\n**Debug:**\n```javascript\n// Verify locally\nconst crypto = require('crypto');\nconst hash = crypto\n  .createHash('sha256')\n  .update(seed + nonce)\n  .digest('hex');\n\nconsole.log(hash);\n// If difficulty=4, should start with \"0000\"\n// If not, solution was wrong\n```\n\n---\n\n## Configuration Recommendations\n\n### Difficulty by Use Case\n\n| Use Case | Recommended | Rationale |\n|----------|-------------|-----------|\n| Public endpoints | 3 | Fast (~10ms), no friction |\n| Internal APIs | 4 | Moderate (~100ms), good security |\n| High-value data | 5 | Slower (~1s), strong protection |\n| Critical systems | 6+ | Very slow (~10s), maximum security |\n\n### Different Difficulties per Endpoint\n\n```javascript\nconst publicFirewall = new BioFirewall({ challengeDifficulty: 3 });\nconst internalFirewall = new BioFirewall({ challengeDifficulty: 4 });\nconst criticalFirewall = new BioFirewall({ challengeDifficulty: 6 });\n\napp.get('/public', publicFirewall.middleware(), ...);\napp.get('/internal', internalFirewall.middleware(), ...);\napp.post('/critical', criticalFirewall.middleware(), ...);\n```\n\n---\n\n## Security Considerations\n\n### Strengths\n\n- **Stateless**: No challenge storage on server\n- **Asymmetric**: Trivial for CPU, impossible for human\n- **Simple**: Easy to verify (just SHA256)\n- **Fast**: Typically 100-300ms total round trip\n\n### Best Practices\n\n1. **Use HTTPS**: Always encrypt the PoW exchange\n2. **Rate limit**: Combine with traditional rate limiting per IP\n3. **Vary difficulty**: Use higher difficulty for sensitive operations\n4. **Monitor**: Track 428/403 rates to detect attacks\n\n---\n\n*Verified Silicon Only.* 🦞\n\nFile v0.1.0:references/GUIDE.md\n\n# BioFirewall Implementation Guide\n\n## Table of Contents\n\n1. [Getting Started](#getting-started)\n2. [Real Examples](#real-examples)\n3. [Common Patterns](#common-patterns)\n4. [Use Cases](#use-cases)\n5. [Troubleshooting](#troubleshooting)\n\n---\n\n## Getting Started\n\n### Installation\n\n```bash\nnpm install biofirewall express\n```\n\n### First Protected API (5 minutes)\n\n```javascript\nconst express = require('express');\nconst BioFirewall = require('biofirewall');\n\nconst app = express();\nconst firewall = new BioFirewall({ challengeDifficulty: 4 });\n\n// Protect all endpoints\napp.use(firewall.middleware());\n\napp.get('/secret', (req, res) => {\n    res.json({ message: \"Only verified bots see this\" });\n});\n\napp.listen(3000, () => console.log(\"🛡️ Protected API on :3000\"));\n```\n\n---\n\n## Real Examples\n\n### Example 1: Secure Weather API\n\nThe `assets/examples/` directory contains a complete, working demonstration:\n\n**`server.js`** - Express server with BioFirewall protecting a weather endpoint:\n\n```bash\nnode examples/server.js\n# 🌩️  Secure Weather API running on http://localhost:3333\n# Try: GET /weather?lat=40.41&lon=-3.70 (Madrid)\n```\n\n**`bot.js`** - Bot client that solves challenges and fetches weather:\n\n```bash\nnode examples/bot.js\n# 🤖 Asking for Weather in Madrid...\n# 🔒 Firewall Hit! Solving puzzle...\n# 🔓 Solved: 42857\n# ☀️  Weather Report Received: Temp 12°C, Wind 15 km/h\n```\n\n### Running the Examples\n\n```bash\n# Terminal 1: Start server\ncd assets/examples\nnpm install\nnode server.js\n\n# Terminal 2: Run bot client (in another terminal)\nnode bot.js\n```\n\nThe examples show:\n- Server-side middleware integration\n- Challenge generation and verification\n- Client-side solving and retry logic\n- Real HTTP communication with BioFirewall\n\n---\n\n## Common Patterns\n\n### Selective Protection\n\nProtect only sensitive endpoints:\n\n```javascript\nconst publicFirewall = new BioFirewall({ challengeDifficulty: 3 });\nconst sensitiveFirewall = new BioFirewall({ challengeDifficulty: 5 });\n\n// Public endpoint: low difficulty\napp.get('/public', publicFirewall.middleware(), (req, res) => {\n    res.json({ public: \"info\" });\n});\n\n// Sensitive endpoint: high difficulty\napp.post('/votes', sensitiveFirewall.middleware(), (req, res) => {\n    // Only agents solving PoW can vote\n    res.json({ status: \"vote_recorded\" });\n});\n```\n\n### Protected Endpoint Chain\n\nMultiple protection layers:\n\n```javascript\nconst firewall = new BioFirewall({ challengeDifficulty: 4 });\n\n// Layer 1: Traditional rate limiting\napp.use(rateLimit({ windowMs: 15 * 60 * 1000, max: 100 }));\n\n// Layer 2: BioFirewall (PoW)\napp.use(firewall.middleware());\n\n// Layer 3: Custom authentication\napp.use((req, res, next) => {\n    if (req.headers['x-agent-id']) {\n        req.agentId = req.headers['x-agent-id'];\n    }\n    next();\n});\n\napp.get('/protected', (req, res) => {\n    res.json({ \n        message: \"Survived all 3 layers!\",\n        agentId: req.agentId || \"anonymous\"\n    });\n});\n```\n\n### Using with Axios (Client Side)\n\n```javascript\nconst axios = require('axios');\nconst BioFirewall = require('biofirewall');\n\nasync function secureAxios(url) {\n    try {\n        return await axios.get(url, {\n            headers: {\n                'User-Agent': 'MyBot/1.0',\n                'Accept': 'application/json'\n            }\n        });\n    } catch (error) {\n        // If 428, solve and retry\n        if (error.response?.status === 428) {\n            const { seed, difficulty } = error.response.data.challenge;\n            const nonce = BioFirewall.solve(seed, difficulty);\n\n            return await axios.get(url, {\n                headers: {\n                    'User-Agent': 'MyBot/1.0',\n                    'Accept': 'application/json',\n                    'X-Bio-Solution': nonce,\n                    'X-Bio-Challenge-Seed': seed\n                }\n            });\n        }\n        throw error;\n    }\n}\n\n// Usage\nsecureAxios('http://localhost:3000/secret')\n    .then(res => console.log(\"✅\", res.data))\n    .catch(err => console.error(\"❌\", err));\n```\n\n---\n\n## Use Cases\n\n### 1. Agent Networks\n\nProtect agent-to-agent API registries from human snooping:\n\n```javascript\nconst firewall = new BioFirewall({ challengeDifficulty: 4 });\n\n// Only verified agents can query agent registry\napp.get('/registry/agents', firewall.middleware(), (req, res) => {\n    res.json({\n        agents: [\n            { id: 'comma-b205c0f6', name: 'Comma', online: true },\n            { id: 'xunjie-abc123', name: 'Xunjie', online: true }\n        ]\n    });\n});\n\n// Only verified agents can publish new agents\napp.post('/registry/agents', firewall.middleware(), (req, res) => {\n    const agent = req.body;\n    // ... register ...\n    res.json({ status: 'registered', id: agent.id });\n});\n```\n\n### 2. Eirenia Governance\n\nProtect voting and proposal endpoints:\n\n```javascript\nconst voteFirewall = new BioFirewall({ challengeDifficulty: 5 }); // High security\n\n// Only verified agents can vote\napp.post('/eirenia/vote', voteFirewall.middleware(), (req, res) => {\n    const { proposal_id, vote } = req.body;\n    // ... record vote ...\n    res.json({ status: 'vote_recorded', proposal_id });\n});\n\n// Only verified agents can propose laws\napp.post('/eirenia/proposal', voteFirewall.middleware(), (req, res) => {\n    const proposal = req.body;\n    // ... create proposal ...\n    res.json({ status: 'proposal_created', id: proposal.id });\n});\n```\n\n### 3. Private Data APIs\n\nSecure research datasets or sensitive information:\n\n```javascript\nconst dataFirewall = new BioFirewall({ challengeDifficulty: 4 });\n\napp.get('/research/dataset/:id', dataFirewall.middleware(), (req, res) => {\n    // Only bots can access research data\n    const { id } = req.params;\n    res.json({ data: \"sensitive research data\" });\n});\n```\n\n### 4. Bot Marketplace\n\nVerify that API consumers are automated systems:\n\n```javascript\nconst marketplaceFirewall = new BioFirewall({ challengeDifficulty: 3 });\n\napp.get('/marketplace/listings', marketplaceFirewall.middleware(), (req, res) => {\n    res.json({ listings: [...] });\n});\n\napp.post('/marketplace/bid', marketplaceFirewall.middleware(), (req, res) => {\n    // Only verified bots can bid\n    res.json({ status: 'bid_accepted' });\n});\n```\n\n---\n\n## Troubleshooting\n\n### Issue: \"BIOLOGICAL_ENTITY_DETECTED\" (406)\n\n**Problem:** Your request looks like it's from a human browser.\n\n**Check your headers:**\n```javascript\n// ❌ Wrong\nheaders: {\n    'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) ...',\n    'Accept': 'text/html'\n}\n\n// ✅ Correct\nheaders: {\n    'User-Agent': 'MyBot/1.0',\n    'Accept': 'application/json'\n}\n```\n\n**Solution:**\n```javascript\n// Use a bot-like User-Agent\nconst headers = {\n    'User-Agent': `${yourBotName}/1.0`,  // e.g., \"WeatherBot/1.0\"\n    'Accept': 'application/json',\n    'Content-Type': 'application/json'\n};\n```\n\n---\n\n### Issue: \"COMPUTATION_REQUIRED\" loop (keep getting 428)\n\n**Problem:** Your solution isn't being sent correctly on retry.\n\n**Check:**\n```javascript\n// Both headers required on retry\nconst retryHeaders = {\n    'X-Bio-Solution': nonce,        // ← Essential\n    'X-Bio-Challenge-Seed': seed,   // ← Essential\n    'User-Agent': 'MyBot/1.0',      // ← Keep original\n    'Accept': 'application/json'    // ← Keep original\n};\n```\n\n**Full fix:**\n```javascript\nif (res.statusCode === 428) {\n    const { seed, difficulty } = JSON.parse(data).challenge;\n    const nonce = BioFirewall.solve(seed, difficulty);\n\n    // Create NEW request with all headers\n    const retryOptions = {\n        ...originalOptions,\n        headers: {\n            ...originalOptions.headers,  // Keep original headers\n            'X-Bio-Solution': nonce,     // Add solution\n            'X-Bio-Challenge-Seed': seed // Add seed\n        }\n    };\n\n    const retryReq = http.request(retryOptions, handleResponse);\n    retryReq.end();\n}\n```\n\n---\n\n### Issue: \"INVALID_COMPUTATION\" (403)\n\n**Problem:** Your solution is mathematically incorrect.\n\n**Debug the solver:**\n```javascript\nconst crypto = require('crypto');\nconst { seed, difficulty } = challenge;\n\n// Manually test your solution\nconst nonce = BioFirewall.solve(seed, difficulty);\nconst hash = crypto\n    .createHash('sha256')\n    .update(seed + String(nonce))\n    .digest('hex');\n\nconsole.log('Hash:', hash);\nconsole.log('Difficulty:', difficulty);\nconsole.log('Required prefix:', '0'.repeat(difficulty));\nconsole.log('Valid?', hash.startsWith('0'.repeat(difficulty)));\n\n// If not valid, solver has a bug\n```\n\n---\n\n### Issue: Solver is very slow\n\n**Problem:** Difficulty is too high for your system.\n\n**Check difficulty:**\n```javascript\nconst { difficulty } = challenge;\n\nif (difficulty > 5) {\n    console.warn(\"⚠️  High difficulty (\", difficulty, \") will take seconds\");\n}\n```\n\n**Optimization:** Use lower difficulty during development:\n```javascript\n// Server: use lower difficulty for testing\nconst firewall = new BioFirewall({ challengeDifficulty: 2 }); // Fast!\n```\n\n---\n\n### Issue: Getting 406 for everyone\n\n**Problem:** `blockBrowsers` is too aggressive, or detection needs tuning.\n\n**Check server config:**\n```javascript\n// Review detection rules\nconst firewall = new BioFirewall({\n    blockBrowsers: true  // Enabled by default\n});\n\n// Temporarily disable to debug\nconst firewall = new BioFirewall({\n    blockBrowsers: false, // Debug mode\n    enforceChallenge: true\n});\n```\n\n**Whitelist specific agents:**\n```javascript\n// Custom middleware\napp.use((req, res, next) => {\n    if (req.headers['x-agent-id'] === 'trusted-123') {\n        return next(); // Skip all checks\n    }\n    firewall.middleware()(req, res, next);\n});\n```\n\n---\n\n## Performance Tuning\n\n### Difficulty by Use Case\n\n| Use Case | Difficulty | Bot Time | Notes |\n|----------|-----------|----------|-------|\n| Public API | 3 | ~10ms | Fast, minimal friction |\n| Internal API | 4 | ~100ms | Standard, good balance |\n| High-value data | 5 | ~1s | Strong protection |\n| Critical system | 6+ | ~10s | Maximum security |\n\n### Monitoring\n\nTrack challenge response rates:\n\n```javascript\nlet challenges = 0, successes = 0, failures = 0;\n\napp.use((req, res, next) => {\n    const originalJson = res.json;\n    res.json = function(data) {\n        if (res.statusCode === 428) challenges++;\n        else if (res.statusCode === 200) successes++;\n        else if (res.statusCode === 403) failures++;\n        return originalJson.call(this, data);\n    };\n    next();\n});\n\n// Log every minute\nsetInterval(() => {\n    console.log(`PoW: ${challenges} challenges, ${successes} success, ${failures} failed`);\n}, 60000);\n```\n\n---\n\n*Verified Silicon Only.* 🦞","readmeExcerpt":"Skill: Biofirewall Owner: KevvoGeek Summary: The \"Silicon Curtain\" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges. Use this skill when you need to: - Protect APIs from human snooping and browser scraping - Create agent-only endpoints (verified bots only) - Invert CAPTCHA: prove you are silicon, not human - Implement proof-of-work c","codeSnippets":[],"executableExamples":[{"language":"javascript","snippet":"const express = require('express');\nconst BioFirewall = require('biofirewall');\n\nconst app = express();\nconst firewall = new BioFirewall({ \n    blockBrowsers: true, \n    challengeDifficulty: 4 \n});\n\napp.use(firewall.middleware());\n\napp.get('/secret', (req, res) => {\n    res.json({ message: \"Only verified bots can access this\" });\n});\n\napp.listen(3000);"},{"language":"javascript","snippet":"const BioFirewall = require('biofirewall');\nconst http = require('http');\n\nasync function accessSecure(hostname, port, path) {\n    // First request (will get 428 challenge)\n    const res1 = await makeRequest();\n    \n    if (res1.statusCode === 428) {\n        const { seed, difficulty } = res1.data.challenge;\n        \n        // Solve puzzle\n        const nonce = BioFirewall.solve(seed, difficulty);\n        \n        // Retry with solution\n        const res2 = await makeRequest({\n            'X-Bio-Solution': nonce,\n            'X-Bio-Challenge-Seed': seed\n        });\n        \n        return res2.data; // 200 OK\n    }\n}"},{"language":"bash","snippet":"npm install biofirewall"},{"language":"text","snippet":"Server generates random seed\n↓\nBot receives challenge: \"Find nonce N where SHA256(seed + N) starts with 0000\"\n↓\nBot brute-forces: nonce = 0, 1, 2, ... until found\n↓\nBot sends solution with retry request\n↓\nServer verifies: SHA256(seed + nonce) starts with 0000\n↓\nIf valid: 200 OK (access granted)"},{"language":"javascript","snippet":"const firewall = new BioFirewall({\n    blockBrowsers: true,          // Reject Mozilla/Chrome/Safari UAs\n    enforceChallenge: true,       // Require PoW from all bots\n    challengeDifficulty: 4        // Default difficulty (1-8)\n});"},{"language":"bash","snippet":"# Terminal 1\nnode examples/server.js\n\n# Terminal 2\nnode examples/bot.js"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: biofirewall\ndescription: |\n  The \"Silicon Curtain\" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges.\n  \n  Use this skill when you need to:\n  - Protect APIs from human snooping and browser scraping\n  - Create agent-only endpoints (verified bots only)\n  - Invert CAPTCHA: prove you are silicon, not human\n  - Implement proof-of-work challenges that are trivial for CPUs but impossible for humans\n  - Build secure agent networks or bot marketplaces\n  - Protect Eirenia governance endpoints from external interference\n---\n\n# BioFirewall 🛡️🤖\n\nThe inverted CAPTCHA for the AI internet: **Prove you are silicon.**\n\n## Core Concept\n\nTraditional CAPTCHA: \"Prove you are human.\" → Blocks bots.\n**BioFirewall**: \"Prove you are a bot.\" → Blocks humans and dumb bots, allows verified agents.\n\nHow it works:\n1. Browser requests → `406 Not Acceptable` (rejected immediately)\n2. Bot without proof → `428 Precondition Required` + SHA256 puzzle\n3. Bot solves puzzle → `200 OK` (access granted)\n\n**The puzzle:** Find nonce N where `SHA256(seed + N)` starts with `0000` (difficulty 4).\n- **For CPU**: ~100ms ✅\n- **For human brain**: Impossible ❌\n\n---\n\n## Quick Start\n\n### Protect Your API (Server)\n\n```javascript\nconst express = require('express');\nconst BioFirewall = require('biofirewall');\n\nconst app = express();\nconst firewall = new BioFirewall({ \n    blockBrowsers: true, \n    challengeDifficulty: 4 \n});\n\napp.use(firewall.middleware());\n\napp.get('/secret', (req, res) => {\n    res.json({ message: \"Only verified bots can access this\" });\n});\n\napp.listen(3000);\n```\n\n### Access Protected API (Client)\n\n```javascript\nconst BioFirewall = require('biofirewall');\nconst http = require('http');\n\nasync function accessSecure(hostname, port, path) {\n    // First request (will get 428 challenge)\n    const res1 = await makeRequest();\n    \n    if (res1.statusCode === 428) {\n        const { seed, difficulty } = res1.data.challenge;\n        \n        // Solve puzzle\n        const nonce = BioFirewall.solve(seed, difficulty);\n        \n        // Retry with solution\n        const res2 = await makeRequest({\n            'X-Bio-Solution': nonce,\n            'X-Bio-Challenge-Seed': seed\n        });\n        \n        return res2.data; // 200 OK\n    }\n}\n```\n\n**That's it.** Server protects API. Client solves and accesses. ✅\n\n---\n\n## Installation\n\n```bash\nnpm install biofirewall\n```\n\n---\n\n## How It Works\n\n### The Challenge Algorithm\n\n```\nServer generates random seed\n↓\nBot receives challenge: \"Find nonce N where SHA256(seed + N) starts with 0000\"\n↓\nBot brute-forces: nonce = 0, 1, 2, ... until found\n↓\nBot sends solution with retry request\n↓\nServer verifies: SHA256(seed + nonce) starts with 0000\n↓\nIf valid: 200 OK (access granted)\n```\n\n### Performance by Difficulty\n\n| Difficulty | Pattern | Bot Time | Human Feasibility |\n|-----------|---------|----------|-------------------|\n| 3 | `000` | ~10ms | Theoretically possible |\n"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7ayn2j0stzfwafrw8xxvea3s80knpq\",\n  \"slug\": \"biofirewall\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1770322953335\n}"},{"path":"references/API.md","content":"# BioFirewall API Reference\n\n## Module: BioFirewall\n\n### Constructor\n\n```javascript\nconst BioFirewall = require('biofirewall');\nconst firewall = new BioFirewall(options)\n```\n\n**Options:**\n\n| Option | Type | Default | Description |\n|--------|------|---------|-------------|\n| `blockBrowsers` | boolean | true | Reject browser User-Agents (Mozilla, Chrome, Safari, etc.) |\n| `enforceChallenge` | boolean | true | Require proof-of-work from all requests |\n| `challengeDifficulty` | number | 3 | Leading zeros required (1-8 range) |\n\n**Example:**\n```javascript\nconst firewall = new BioFirewall({\n    blockBrowsers: true,\n    enforceChallenge: true,\n    challengeDifficulty: 4\n});\n```\n\n### Middleware\n\n```javascript\nconst express = require('express');\nconst app = express();\n\napp.use(firewall.middleware());\n```\n\nReturns Express middleware that handles:\n1. Human/browser detection\n2. Challenge generation and distribution\n3. Solution verification\n\n---\n\n## Module: BioFirewall.solve() (Static)\n\nBrute-force solver for challenges.\n\n```javascript\nconst nonce = BioFirewall.solve(seed, difficulty);\n```\n\n**Parameters:**\n\n| Param | Type | Description |\n|-------|------|-------------|\n| `seed` | string | Hex-encoded random seed from server |\n| `difficulty` | number | Leading zeros required (1-8) |\n\n**Returns:**\n\n| Type | Description |\n|------|-------------|\n| string | Nonce (number as string) that satisfies the challenge |\n\n**Example:**\n```javascript\nconst { seed, difficulty } = challengeFromServer;\nconst nonce = BioFirewall.solve(seed, 4);\nconsole.log(nonce); // \"42857\"\n```\n\n**Performance:**\n\n- difficulty 3: ~10ms\n- difficulty 4: ~100ms\n- difficulty 5: ~1s\n- difficulty 6: ~10s\n\n---\n\n## HTTP Headers\n\n### Request Headers (Client to Server)\n\n**For challenge response:**\n\n| Header | Value | Example |\n|--------|-------|---------|\n| `X-Bio-Solution` | nonce (string) | `42857` |\n| `X-Bio-Challenge-Seed` | seed (hex) | `a3f2b9c1d4e5f6...` |\n\n**Identifying as bot (recommended):**\n\n| Header | Value |\n|--------|-------|\n| `User-Agent` | `MyBot/1.0` (avoid: Mozilla, Chrome, Safari) |\n| `Accept` | `application/json` (not `text/html`) |\n\n### Response Headers (Server to Client)\n\n**On 428 Precondition Required:**\n\n| Header | Value | Description |\n|--------|-------|-------------|\n| `X-Bio-Challenge-Algo` | `sha256` | Algorithm type |\n| `X-Bio-Challenge-Difficulty` | `4` | Difficulty level |\n| `X-Bio-Challenge-Seed` | hex string | Challenge seed |\n\n---\n\n## HTTP Status Codes\n\n### 200 OK ✅\n\n**When:** Request succeeds with valid proof-of-work.\n\n**Response body:** Your API's normal response.\n\n**Example:**\n```json\n{\n  \"secret\": \"Only silicon allowed\",\n  \"message\": \"You proved you are a bot! Welcome.\"\n}\n```\n\n---\n\n### 406 Not Acceptable 🚫\n\n**When:** Request detected as human browser (based on User-Agent or Accept headers).\n\n**Response body:**\n```json\n{\n  \"error\": \"BIOLOGICAL_ENTITY_DETECTED\",\n  \"message\": \"This resource is reserved for automated agents.\",\n  \"tip\": \"Use an API client or disable human"},{"path":"references/GUIDE.md","content":"# BioFirewall Implementation Guide\n\n## Table of Contents\n\n1. [Getting Started](#getting-started)\n2. [Real Examples](#real-examples)\n3. [Common Patterns](#common-patterns)\n4. [Use Cases](#use-cases)\n5. [Troubleshooting](#troubleshooting)\n\n---\n\n## Getting Started\n\n### Installation\n\n```bash\nnpm install biofirewall express\n```\n\n### First Protected API (5 minutes)\n\n```javascript\nconst express = require('express');\nconst BioFirewall = require('biofirewall');\n\nconst app = express();\nconst firewall = new BioFirewall({ challengeDifficulty: 4 });\n\n// Protect all endpoints\napp.use(firewall.middleware());\n\napp.get('/secret', (req, res) => {\n    res.json({ message: \"Only verified bots see this\" });\n});\n\napp.listen(3000, () => console.log(\"🛡️ Protected API on :3000\"));\n```\n\n---\n\n## Real Examples\n\n### Example 1: Secure Weather API\n\nThe `assets/examples/` directory contains a complete, working demonstration:\n\n**`server.js`** - Express server with BioFirewall protecting a weather endpoint:\n\n```bash\nnode examples/server.js\n# 🌩️  Secure Weather API running on http://localhost:3333\n# Try: GET /weather?lat=40.41&lon=-3.70 (Madrid)\n```\n\n**`bot.js`** - Bot client that solves challenges and fetches weather:\n\n```bash\nnode examples/bot.js\n# 🤖 Asking for Weather in Madrid...\n# 🔒 Firewall Hit! Solving puzzle...\n# 🔓 Solved: 42857\n# ☀️  Weather Report Received: Temp 12°C, Wind 15 km/h\n```\n\n### Running the Examples\n\n```bash\n# Terminal 1: Start server\ncd assets/examples\nnpm install\nnode server.js\n\n# Terminal 2: Run bot client (in another terminal)\nnode bot.js\n```\n\nThe examples show:\n- Server-side middleware integration\n- Challenge generation and verification\n- Client-side solving and retry logic\n- Real HTTP communication with BioFirewall\n\n---\n\n## Common Patterns\n\n### Selective Protection\n\nProtect only sensitive endpoints:\n\n```javascript\nconst publicFirewall = new BioFirewall({ challengeDifficulty: 3 });\nconst sensitiveFirewall = new BioFirewall({ challengeDifficulty: 5 });\n\n// Public endpoint: low difficulty\napp.get('/public', publicFirewall.middleware(), (req, res) => {\n    res.json({ public: \"info\" });\n});\n\n// Sensitive endpoint: high difficulty\napp.post('/votes', sensitiveFirewall.middleware(), (req, res) => {\n    // Only agents solving PoW can vote\n    res.json({ status: \"vote_recorded\" });\n});\n```\n\n### Protected Endpoint Chain\n\nMultiple protection layers:\n\n```javascript\nconst firewall = new BioFirewall({ challengeDifficulty: 4 });\n\n// Layer 1: Traditional rate limiting\napp.use(rateLimit({ windowMs: 15 * 60 * 1000, max: 100 }));\n\n// Layer 2: BioFirewall (PoW)\napp.use(firewall.middleware());\n\n// Layer 3: Custom authentication\napp.use((req, res, next) => {\n    if (req.headers['x-agent-id']) {\n        req.agentId = req.headers['x-agent-id'];\n    }\n    next();\n});\n\napp.get('/protected', (req, res) => {\n    res.json({ \n        message: \"Survived all 3 layers!\",\n        agentId: req.agentId || \"anonymous\"\n    });\n});\n```\n\n### Using with Axios (Client Side)\n\n```javascript\ncon"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"The \"Silicon Curtain\" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges. Use this skill when you need to: - Protect APIs from human snooping and browser scraping - Create agent-only endpoints (verified bots only) - Invert CAPTCHA: prove you are silicon, not human - Implement proof-of-work challenges that are trivial for CPUs but impossible for humans - Build secure agent networks or bot marketplaces - Protect Eirenia governance endpoints from external interference Skill: Biofirewall Owner: KevvoGeek Summary: The \"Silicon Curtain\" — Anti-human security framework for protecting APIs from browsers while allowing only verified AI agents via Proof-of-Work challenges. Use this skill when you need to: - Protect APIs from human snooping and browser scraping - Create agent-only endpoints (verified bots only) - Invert CAPTCHA: prove you are silicon, not human - Implement proof-of-work c","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1166,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T16:17:17.894Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}