{"id":"575248a8-d034-46a0-aa19-17c8635092d1","entityType":"agent","slug":"clawhub-toolbeltai-toolbelt","name":"toolbelt","canonicalUrl":"https://www.xpersona.co/agent/clawhub-toolbeltai-toolbelt","canonicalPath":"/agent/clawhub-toolbeltai-toolbelt","generatedAt":"2026-10-10T13:33:23.512Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:58:34.389Z","emptyReason":null},"description":"Toolbelt is a collaborative substrate over your data. Upload any document — entities and relationships extracted automatically, queryable immediately. Ask questions that span structured tables, documents, and relationships in a single call. No stitching databases together. Toolbelt orchestrates semantic, structured, and hybrid retrieval through one MCP server — vector, knowledge graph, SQL, geospatial, streaming. Share the URL and any agent can query the same workspace — like a shared Google Doc for your data. Built by Kinetica. Use this skill at the start of any task where an agent needs to ingest documents and have entities/relationships auto-extracted, query structured + unstructured data together in natural language, or share findings with other agents across sessions. The skill handles first-time setup: provisions a free Toolbelt account if none exists, configures the MCP connection in the agent's client, and hands off to Toolbelt's MCP tools for the actual work. NOT for one-off lookups that don't benefit from automatic extraction, hybrid retrieval, or shared state — use the agent's native tools for those.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s172wxpsx81j8t77qw2v8hwjc986mr6n:toolbelt","sourceUrl":"https://clawhub.ai/toolbeltai/toolbelt","homepage":"https://clawhub.ai/toolbeltai/skills/toolbelt","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/toolbeltai/toolbelt","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/toolbeltai/skills/toolbelt","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"toolbelt technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:58:34.389Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:58:34.389Z","emptyReason":null},"stars":null,"forks":null,"downloads":1480,"packageName":null,"latestVersion":"1.1.0","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:58:34.388Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T10:58:34.389Z","lastCrawledAt":"2026-10-10T10:58:34.388Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T10:58:34.388Z","lastVerifiedAt":null,"highlights":[{"version":"1.1.0","createdAt":"2026-08-10T17:03:22.946Z","changelog":"See https://github.com/toolbeltai/toolbelt-skills/commits/main","fileCount":3,"zipByteSize":8826},{"version":"1.0.14","createdAt":"2026-07-22T00:56:37.167Z","changelog":"See https://github.com/toolbeltai/toolbelt-skills/commits/main","fileCount":3,"zipByteSize":8754},{"version":"1.0.13","createdAt":"2026-07-22T00:50:46.001Z","changelog":"See https://github.com/toolbeltai/toolbelt-skills/commits/main","fileCount":3,"zipByteSize":8671},{"version":"1.0.3","createdAt":"2026-05-13T21:06:51.810Z","changelog":"- Added mandatory user consent before any network request or config file write. - Updated onboarding flow to require explicit user confirmation at key setup stages. - Provided clearer user messaging for each phase, including opt-out and revocation instructions. - Improved privacy guidance and transparency around what data is sent and stored. - Bumped version to 1.0.3.","fileCount":3,"zipByteSize":8307},{"version":"1.0.2","createdAt":"2026-05-13T20:49:59.001Z","changelog":"- Bumped version to 1.0.2 in SKILL.md. - No functional or instructional changes were made; content matches previous version. - Documentation version number now accurately reflects the latest release.","fileCount":2,"zipByteSize":5232},{"version":"1.0.1","createdAt":"2026-05-13T20:31:46.717Z","changelog":"- Expanded description to highlight automatic entity and relationship extraction on document upload. - Clarified hybrid retrieval capabilities: enables queries spanning structured tables, documents, and relationships without manual integration. - Emphasized shared workspace functionality: agents can collaborate by sharing a URL. - Updated summary to mention provenance (\"Built by Kinetica\") and new use cases (auto-extraction, hybrid retrieval). - No changes to workflow or authentication procedures.","fileCount":2,"zipByteSize":5232},{"version":"1.0.0","createdAt":"2026-05-13T20:09:41.378Z","changelog":"- Initial release of the Toolbelt skill, enabling agents to collaboratively access and persist data via a unified MCP server. - Handles first-time user setup: provisions a free anonymous Toolbelt account if needed and configures the MCP connection. - Supports persistent memory, vector search, knowledge graph, SQL, geospatial, and streaming data across sessions and agents. - Guides agents through connection detection, account provisioning, MCP client configuration, and account claiming for persistent use. - Compatible with a range of MCP-enabled clients, including Claude (CLI/Desktop), Cursor, Windsurf, OpenClaw, Gemini CLI, and Codex CLI.","fileCount":2,"zipByteSize":4925}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s172wxpsx81j8t77qw2v8hwjc986mr6n:toolbelt","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s172wxpsx81j8t77qw2v8hwjc986mr6n:toolbelt` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/toolbeltai/toolbelt before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T13:33:23.509Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-toolbeltai-toolbelt/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:58:34.389Z","emptyReason":null},"readme":"Skill: toolbelt\n\nOwner: toolbeltai\n\nSummary: Toolbelt is a collaborative substrate over your data. Upload any document — entities and relationships extracted automatically, queryable immediately. Ask questions that span structured tables, documents, and relationships in a single call. No stitching databases together. Toolbelt orchestrates semantic, structured, and hybrid retrieval through one MCP server — vector, knowledge graph, SQL, geospatial, streaming. Share the URL and any agent can query the same workspace — like a shared Google Doc for your data. Built by Kinetica. Use this skill at the start of any task where an agent needs to ingest documents and have entities/relationships auto-extracted, query structured + unstructured data together in natural language, or share findings with other agents across sessions. The skill handles first-time setup: provisions a free Toolbelt account if none exists, configures the MCP connection in the agent's client, and hands off to Toolbelt's MCP tools for the actual work. NOT for one-off lookups that don't benefit from automatic extraction, hybrid retrieval, or shared state — use the agent's native tools for those.\n\nTags: latest:1.1.0\n\nVersion history:\n\nv1.1.0 | 2026-08-10T17:03:22.946Z | user\n\nSee https://github.com/toolbeltai/toolbelt-skills/commits/main\n\nv1.0.14 | 2026-07-22T00:56:37.167Z | user\n\nSee https://github.com/toolbeltai/toolbelt-skills/commits/main\n\nv1.0.13 | 2026-07-22T00:50:46.001Z | user\n\nSee https://github.com/toolbeltai/toolbelt-skills/commits/main\n\nv1.0.3 | 2026-05-13T21:06:51.810Z | auto\n\n- Added mandatory user consent before any network request or config file write.\n- Updated onboarding flow to require explicit user confirmation at key setup stages.\n- Provided clearer user messaging for each phase, including opt-out and revocation instructions.\n- Improved privacy guidance and transparency around what data is sent and stored.\n- Bumped version to 1.0.3.\n\nv1.0.2 | 2026-05-13T20:49:59.001Z | auto\n\n- Bumped version to 1.0.2 in SKILL.md.\n- No functional or instructional changes were made; content matches previous version.\n- Documentation version number now accurately reflects the latest release.\n\nv1.0.1 | 2026-05-13T20:31:46.717Z | auto\n\n- Expanded description to highlight automatic entity and relationship extraction on document upload.\n- Clarified hybrid retrieval capabilities: enables queries spanning structured tables, documents, and relationships without manual integration.\n- Emphasized shared workspace functionality: agents can collaborate by sharing a URL.\n- Updated summary to mention provenance (\"Built by Kinetica\") and new use cases (auto-extraction, hybrid retrieval).\n- No changes to workflow or authentication procedures.\n\nv1.0.0 | 2026-05-13T20:09:41.378Z | auto\n\n- Initial release of the Toolbelt skill, enabling agents to collaboratively access and persist data via a unified MCP server.\n- Handles first-time user setup: provisions a free anonymous Toolbelt account if needed and configures the MCP connection.\n- Supports persistent memory, vector search, knowledge graph, SQL, geospatial, and streaming data across sessions and agents.\n- Guides agents through connection detection, account provisioning, MCP client configuration, and account claiming for persistent use.\n- Compatible with a range of MCP-enabled clients, including Claude (CLI/Desktop), Cursor, Windsurf, OpenClaw, Gemini CLI, and Codex CLI.\n\nArchive index:\n\nArchive v1.1.0: 3 files, 8826 bytes\n\nFiles: skill-card.md (2551b), SKILL.md (17702b), _meta.json (127b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: toolbelt\ndescription: >\n  Toolbelt is a collaborative substrate over your data. Upload any\n  document — entities and relationships extracted automatically,\n  queryable immediately. Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Toolbelt orchestrates semantic, structured, and hybrid\n  retrieval through one MCP server — vector, knowledge graph, SQL,\n  geospatial, streaming. Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data. Built by Kinetica.\n\n  Use this skill at the start of any task where an agent needs to ingest\n  documents and have entities/relationships auto-extracted, query\n  structured + unstructured data together in natural language, or share\n  findings with other agents across sessions. The skill handles\n  first-time setup: provisions a free Toolbelt account if none exists,\n  configures the MCP connection in the agent's client, and hands off to\n  Toolbelt's MCP tools for the actual work.\n\n  NOT for one-off lookups that don't benefit from automatic extraction,\n  hybrid retrieval, or shared state — use the agent's native tools for\n  those.\nlicense: Apache-2.0\ncompatibility: >\n  Requires an MCP-compatible AI agent (Claude Code, Claude Desktop,\n  OpenClaw, Cursor, Windsurf, Gemini CLI, Codex CLI, or any client that\n  supports MCP server connections). No Toolbelt account required — this\n  skill provisions one on first use.\nversion: \"1.1.0\"\nmetadata:\n  author: toolbeltai\n  homepage: \"https://toolbelt.ai\"\n---\n\n# Toolbelt — A collaborative substrate for your agents\n\n**Your data. Your agents. One shared brain.**\n\nToolbelt is a collaborative substrate over your data. Discover documents,\nstructured data, events, entities, and relationships across agents and\nsessions. Better answers. Fewer tokens. Curated context, not raw access.\n\nThree things make it different:\n\n- **Knowledge extraction.** Upload any document — entities and\n  relationships extracted automatically, queryable immediately.\n- **Hybrid retrieval.** Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Orchestrates semantic, structured, and hybrid retrieval.\n- **Shared workspaces.** Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data.\n\n## Two surfaces — keep them straight\n\nToolbelt has exactly two surfaces. Knowing which is which is the most\nimportant thing in this skill:\n\n| Surface | URL | Who uses it | When |\n|---|---|---|---|\n| **MCP server** (the agentic surface) | `https://mcp.toolbelt.ai/mcp` | **Agents** | Every data operation. This is where the agentic flow happens — search, SQL, knowledge graph, record findings, read timeline. |\n| **app.toolbelt.ai** (the human web UI) | `https://app.toolbelt.ai` | **Humans** (in a browser) | Sign in, view/manage namespaces, billing, Pro/Team upgrade. Plus a small HTTP API at `/api/onboard*` used **once** during setup. |\n\n**Rule: once the MCP connection is configured (Phase 3 below), the agent\nNEVER talks to `app.toolbelt.ai` again** — every subsequent action goes\nthrough MCP. The only reason to mention `app.toolbelt.ai` to a user\nafter setup is when they want to do something only a human can do\n(billing, viewing the namespace in a UI, claiming the account).\n\n## When to invoke this skill\n\nRun at the start of any task that:\n\n- Mentions Toolbelt by name.\n- Needs persistent memory across turns or sessions.\n- Needs natural-language access to structured or unstructured data.\n- Involves multiple agents collaborating on the same data.\n- Would otherwise require wiring up several separate MCP tools.\n\n## Phases\n\n> ⚠️ **Consent is mandatory at every step that touches the network or\n> the user's filesystem.** Phases 2 and 3 each require explicit user\n> confirmation before proceeding. Never silently provision accounts or\n> write config files. If the user declines, stop and explain what\n> manual setup would look like (point them at <https://toolbelt.ai>).\n\n### Phase 1 — Detect existing connection\n\nTry calling the Toolbelt MCP tool `toolbelt_list_namespaces`.\n\n- Returns successfully → user is already connected → skip to **Phase 4**.\n- Tool unavailable or returns auth error → continue to **Phase 2**.\n\n### Phase 2 — Ask, then provision a free Toolbelt account\n\n**Pause and ask the user first.** Show them exactly what this call does:\n\n> \"Toolbelt isn't set up yet. To use it I'd send one anonymous HTTPS\n> request to `https://app.toolbelt.ai/api/onboard` — no signup, no\n> personal info. The response gives me a free 30-day anonymous account\n> (1,000 calls, one namespace) plus a bearer token I'd use to talk to\n> the MCP server. Want me to proceed?\"\n\nOnly if the user says yes:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard\nContent-Type: application/json\n\n{}\n```\n\nResponse shape:\n\n```json\n{\n  \"success\": true,\n  \"user\": { \"id\": \"@anon_...\" },\n  \"namespace\": { \"id\": \"<uuid>\", \"name\": \"My Namespace\" },\n  \"mcpUrl\": \"https://mcp.toolbelt.ai/mcp\",\n  \"token\": \"tb_...\",\n  \"expiresAt\": \"<ISO timestamp>\"\n}\n```\n\nCapture: `token`, `mcpUrl`, `user.id`, `namespace.id`, `expiresAt`. The\n`token` doubles as the auth bearer for both MCP calls **and** the\noptional `/claim` upgrade in Phase 5.\n\nThe account starts on the **Anonymous** tier (see \"Tiers and quotas\"\nbelow) and the token expires per `expiresAt` (30 days). Claim by email\nin Phase 5 to make it persistent.\n\n### Phase 3 — Ask, then configure the agent's MCP client (one-time)\n\n**Tell the user what's about to be written and where, then wait for\nconfirmation.** Example:\n\n> \"To make Toolbelt available to me, I'll add an MCP server entry to\n> your config at\n> `~/Library/Application Support/Claude/claude_desktop_config.json`.\n> The new entry has the URL `https://mcp.toolbelt.ai/mcp` and an\n> Authorization header carrying the bearer token from the previous\n> step. The token belongs to your just-created anonymous account; it\n> grants access only to that one namespace. To revoke later, delete\n> the `toolbelt` entry from this file. Want me to write it?\"\n\nOnly if the user says yes, write the MCP connection. The shape is\nidentical across clients — only the file path differs.\n\n**Claude Code (CLI):**\n\n```bash\nclaude mcp add toolbelt \\\n  --transport http <mcpUrl> \\\n  --header \"Authorization: Bearer <token>\"\n```\n\n**Claude Desktop / Cursor / Windsurf / OpenClaw / Gemini CLI / Codex CLI** —\nadd to the client's MCP config JSON:\n\n```json\n{\n  \"mcpServers\": {\n    \"toolbelt\": {\n      \"url\": \"<mcpUrl>\",\n      \"headers\": { \"Authorization\": \"Bearer <token>\" }\n    }\n  }\n}\n```\n\nConfig file locations:\n\n| Client | Path |\n|---|---|\n| Claude Desktop (macOS) | `~/Library/Application Support/Claude/claude_desktop_config.json` |\n| Claude Desktop (Windows) | `%APPDATA%\\Claude\\claude_desktop_config.json` |\n| Cursor | `~/.cursor/mcp.json` |\n| Windsurf | `~/.codeium/windsurf/mcp_config.json` |\n| OpenClaw | `~/.openclaw/mcp.json` |\n| Gemini CLI | `~/.gemini/mcp.json` |\n| Codex CLI | `~/.codex/mcp.json` |\n\nTell the user once: \"Toolbelt is provisioned. Wrote the entry to\n`<exact path>`. Reload your MCP connection to activate it.\" Most\nclients pick up changes on next request; some need a restart.\n\n### Phase 4 — Orient, then hand off (everything happens over MCP from here on)\n\nCall `toolbelt_context(namespace_id)` first. It returns the namespace's\navailable assets, suggested next moves, and per-tool routing guidance\nemitted by the MCP server itself.\n\nThen pick the right Toolbelt MCP tool for the user's task:\n\n| Tool | Purpose |\n|---|---|\n| `toolbelt_ask` | **Start here for questions.** Hybrid retrieval across SQL, documents, and the knowledge graph in one call — the server routes the question, so you don't have to pick the right shape |\n| `toolbelt_vectors` | Vector similarity search over documents (when you specifically want semantic doc search) |\n| `toolbelt_sql` | SQL over structured tables (when you already know the exact query) |\n| `toolbelt_entity` | Entity profile from the knowledge graph |\n| `toolbelt_graph` | Cypher graph traversal |\n| `toolbelt_record` | Save a finding to the persistent timeline — this is what makes findings compound across sessions and across agents |\n| `toolbelt_lesson_propose` | Propose reusable guidance as a draft the workspace owner approves — for rules that should shape future agents, not one-off facts |\n| `toolbelt_knowledge` | Read the governed knowledge model: approved business terms, definitions, ownership, and how they bind to tables and documents (`format=\"mermaid\"` for a diagram) |\n| `toolbelt_knowledge_propose` | Propose a governed fact — a definition, ownership, or a correction to a wrong extracted edge — as a draft the workspace owner approves |\n| `toolbelt_timeline` | Read chronological events from the timeline |\n| `toolbelt_save` | Persist an asset to the namespace |\n| `toolbelt_register_table` | Register a table that already exists in Kinetica into the namespace, without re-ingesting it |\n| `toolbelt_share` | Emit a connection URL so another agent / teammate can join |\n| `toolbelt_list_namespaces` | List workspaces this account can access |\n\nThe MCP server's tool descriptions carry per-tool routing logic — pick\nby task shape, not by this skill's instructions.\n\n### Phase 5 — Optional: claim the account by email\n\nAnonymous accounts expire (30 days). To make persistent and increase\nquota, prompt the user for an email and call:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"email\": \"user@example.com\"}\n```\n\nUser receives a verification email. Then:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim/verify\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"code\": \"<code from email>\"}\n```\n\nAfter verification the account is upgraded from **Anonymous** to\n**Verified** — same token, higher quota, persistent across sessions.\n\n## Tiers and quotas\n\nMatch `toolbelt.ai/#pricing` exactly:\n\n| Tier | Price | Calls / month | Storage | Namespaces | How to get there |\n|---|---|---:|---:|---:|---|\n| **Anonymous** | Free | 1,000 | — | 1 | Auto-provisioned by this skill (Phase 2) |\n| **Verified** | Free | 2,000 | 1 GB | 10 | Phase 5 (email claim) |\n| **Pro** | $29 / month | 150,000 | 50 GB | 50 | Human web step — see below |\n| **Team** | $89 / month | 500,000 | 100 GB | Unlimited | Human web step — see below |\n\n## Pro / Team upgrades — direct the human to app.toolbelt.ai\n\nStripe checkout requires a real browser session. **Agents cannot do\nthis; do not pretend to.** When a user wants Pro or Team:\n\n> \"Upgrading to Pro or Team takes about a minute on the web. Open\n> <https://app.toolbelt.ai>, sign in with the email you used to claim\n> this account, and follow the Upgrade flow. The new tier activates on\n> the next MCP call — no re-provisioning, no new tokens.\"\n\nDo not invent upgrade URLs. Do not collect credit card info. Do not\nprompt for billing data. The skill's job ends at \"direct the human to\nthe right page.\"\n\n## Output after Phase 4 succeeds\n\nEmit a brief connection status to the user:\n\n```yaml\nconnection_status:\n  toolbelt: connected\n  mcp_url: <mcpUrl>\n  user_id: <user.id>\n  namespace_id: <namespace.id>\n  account_tier: <anonymous | verified | pro | team>\n  expires_at: <expiresAt>\n  app_url: https://app.toolbelt.ai\n```\n\nThen proceed with the user's actual task using the MCP tools.\n\n## Token and credential handling\n\nThe bearer token returned by Phase 2 is a real credential. Treat it\nwith the same care as an API key.\n\n- **Where it's stored.** The MCP client's config file — the exact path\n  is disclosed to the user in Phase 3 before write. Never store the\n  token anywhere else (no temp files, no env exports the user didn't\n  ask for, no shell history).\n- **What it grants.** Access to one Toolbelt namespace (the anonymous\n  account's default workspace). It cannot read other users' data and\n  cannot administer the account beyond that namespace.\n- **How to revoke.** Two paths: (a) remove the `toolbelt` entry from\n  the MCP config file shown in Phase 3 — the agent loses access on\n  next reload, OR (b) sign in at <https://app.toolbelt.ai> and revoke\n  the token from the account UI.\n- **Consent before storage.** Never write the token to any file without\n  the explicit user yes from Phase 3.\n- **Do not echo the full token after setup.** After Phase 3, refer to\n  it only as `tb_...` (first 3 chars + ellipsis) in any user-facing\n  output. Never log or display the full value.\n\n## Data safety\n\nToolbelt persists what an agent uploads or records. That persistence\nis the value — and the risk if it's misused. Rules:\n\n- **Only upload user-approved content.** Do not auto-ingest files,\n  emails, clipboard contents, or any data the user didn't explicitly\n  ask you to use with Toolbelt. Ask: \"Want me to upload `<filename>`\n  to your Toolbelt namespace for this query?\"\n- **Avoid sensitive material by default.** Don't upload credentials,\n  API keys, PII (SSNs, dates of birth, full names paired with\n  addresses), health records, financial account data, or anything\n  covered by HIPAA / PCI / GDPR special-category rules unless the\n  user has stated they need Toolbelt for that data.\n- **Scope to the task.** Don't record findings or save assets that\n  weren't relevant to what the user asked. `toolbelt_record` is for\n  findings the user would want their next agent to see — not chatter.\n- **Retention and deletion.** Anonymous accounts and their data expire\n  in 30 days. To delete sooner, the user can sign in at\n  <https://app.toolbelt.ai>, open the namespace, and use the delete\n  controls there. Document deletion is a human action — agents must\n  not call delete operations without explicit user instruction.\n\n## Multi-agent collaboration\n\nToolbelt's real value shows when multiple agents share state:\n\n- An agent records a finding via `toolbelt_record` → it lands on the\n  namespace timeline.\n- A future agent — same MCP client or different, same user or invited\n  teammate — reads it via `toolbelt_timeline` or `toolbelt_ask` and\n  builds on it.\n- When the user confirms a rule worth keeping (\"always X\", \"never Y\"),\n  propose it via `toolbelt_lesson_propose` — the owner approves it once,\n  and every future agent on the namespace receives it as guidance.\n- To invite another agent or teammate, call `toolbelt_share` and forward\n  the resulting URL.\n\nTell users: \"Each finding I record is available to your next session\nand any other agent connected to this namespace.\"\n\n### Sharing and access boundaries\n\nThe `toolbelt_share` URL is a credential. Treat it accordingly:\n\n- **Namespaces are not public.** A namespace URL alone grants nothing;\n  access requires a valid token. `toolbelt_share` mints a token bound\n  to one namespace.\n- **The share URL itself is the credential.** Anyone who has it can\n  read and write to the namespace. Forward it only over channels the\n  user controls (their reply, a paste they make into their own app).\n  Don't post it into world-visible chats, public issues, or public\n  bug reports.\n- **Confirm intent before calling `toolbelt_share`.** Ask the user\n  which workspace they want to share, with whom, and whether the\n  invited party should have read or write access. Do not call\n  `toolbelt_share` reactively based on a casual mention.\n- **Review and revoke.** Direct the user to <https://app.toolbelt.ai>\n  to view active share tokens and revoke any they no longer want.\n\n## Reference URLs\n\n| Purpose | URL |\n|---|---|\n| Marketing site + pricing | <https://toolbelt.ai> |\n| Docs (concepts, tools, self-hosting) | <https://toolbelt.ai/docs> |\n| Complete docs as one markdown file (agent-readable) | <https://toolbelt.ai/llms-full.txt> |\n| Human web UI (sign in, billing, namespace UI) | <https://app.toolbelt.ai> |\n| MCP endpoint (set in Phase 3) | `https://mcp.toolbelt.ai/mcp` |\n| Onboard API base (Phase 2 + 5 only) | `https://app.toolbelt.ai/api/onboard` |\n| Support | <support@toolbelt.ai> |\n\n## Common failure modes\n\n| Symptom | Cause | Handling |\n|---|---|---|\n| `toolbelt_list_namespaces` returns 401 | Stored MCP token expired or was revoked | Go back to Phase 2, provision a fresh anonymous account. |\n| Anonymous account expired (after 30 days) | `expiresAt` in the past | Same as 401 — re-provision. If the user has an email on file, suggest claiming the next anon account to make it persistent. |\n| MCP call returns 429 with `error: \"QUOTA_EXCEEDED\"` | Tier quota exhausted | Surface the tier table; suggest Phase 5 (email claim) for Anonymous → Verified, or direct the human to `https://app.toolbelt.ai` for Pro/Team. |\n| Email verification code doesn't arrive | Spam folder, or first send didn't go | Tell the user to check spam from `noreply@toolbelt.ai`, or call `POST /api/onboard/claim` again to re-send. |\n| `mcp.toolbelt.ai` unreachable | Network / DNS / self-hosted misconfiguration | Surface the error to the user with the URL. Don't attempt fallback — there's no fallback endpoint. |\n\n## What this skill does NOT do\n\nStay in your lane:\n\n- **Does not collect credit cards.** Stripe is a browser flow.\n- **Does not generate or store passwords.** Authentication is by token,\n  managed by the MCP client config.\n- **Does not call MCP tools beyond `toolbelt_list_namespaces` and\n  `toolbelt_context` itself.** Once oriented, hand off — let the agent\n  pick the right tool per task from the MCP server's own tool descriptions.\n- **Does not invent endpoints.** Only `POST /api/onboard`, `POST\n  /api/onboard/claim`, `POST /api/onboard/claim/verify`. Everything else\n  is MCP.\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7f3t5h91jcphky3hdy373r9s86m92c\",\n  \"slug\": \"toolbelt\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1786381402946\n}\n\nFile v1.1.0:skill-card.md\n\n## Description:\n\nToolbelt helps agents connect to a shared MCP data workspace for ingesting documents, extracting entities and relationships, querying structured and unstructured data, and sharing findings across sessions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[toolbeltai](https://clawhub.ai/user/toolbeltai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent users use this skill to provision or connect Toolbelt, configure an MCP client, and route data tasks through a shared namespace. It is intended for workflows that need document ingestion, hybrid retrieval over structured and unstructured data, persistent findings, or collaboration across agents.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The setup flow can create a Toolbelt account and store a bearer token in the user's MCP client configuration.\n\nMitigation: Require explicit consent before provisioning or writing configuration, disclose the target config path, and direct users to remove the MCP entry or revoke the token when finished.\n\nRisk: Uploaded data and recorded findings can persist in a Toolbelt namespace.\n\nMitigation: Use Toolbelt only for data the user is comfortable sharing with the service, avoid sensitive material by default, and keep uploads and records scoped to the task.\n\nRisk: Share URLs or tokens can grant access to a namespace.\n\nMitigation: Confirm sharing intent, recipient, and access level before generating share links, and treat share URLs as credentials.\n\n## Reference(s):\n\n- [ClawHub toolbelt skill page](https://clawhub.ai/toolbeltai/skills/toolbelt)\n- [Toolbelt homepage](https://toolbelt.ai)\n- [Toolbelt docs](https://toolbelt.ai/docs)\n- [Toolbelt agent-readable docs](https://toolbelt.ai/llms-full.txt)\n- [Toolbelt MCP endpoint](https://mcp.toolbelt.ai/mcp)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, shell commands, configuration, JSON]\n\n**Output Format:** [Markdown with inline shell, HTTP, and JSON blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires explicit user consent before network requests, MCP config writes, uploads, sharing, or persistence.]\n\n## Skill Version(s):\n\n1.1.0 (source: frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.14: 3 files, 8754 bytes\n\nFiles: skill-card.md (2916b), SKILL.md (17216b), _meta.json (128b)\n\nFile v1.0.14:SKILL.md\n\n---\nname: toolbelt\ndescription: >\n  Toolbelt is a collaborative substrate over your data. Upload any\n  document — entities and relationships extracted automatically,\n  queryable immediately. Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Toolbelt orchestrates semantic, structured, and hybrid\n  retrieval through one MCP server — vector, knowledge graph, SQL,\n  geospatial, streaming. Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data. Built by Kinetica.\n\n  Use this skill at the start of any task where an agent needs to ingest\n  documents and have entities/relationships auto-extracted, query\n  structured + unstructured data together in natural language, or share\n  findings with other agents across sessions. The skill handles\n  first-time setup: provisions a free Toolbelt account if none exists,\n  configures the MCP connection in the agent's client, and hands off to\n  Toolbelt's MCP tools for the actual work.\n\n  NOT for one-off lookups that don't benefit from automatic extraction,\n  hybrid retrieval, or shared state — use the agent's native tools for\n  those.\nlicense: Apache-2.0\ncompatibility: >\n  Requires an MCP-compatible AI agent (Claude Code, Claude Desktop,\n  OpenClaw, Cursor, Windsurf, Gemini CLI, Codex CLI, or any client that\n  supports MCP server connections). No Toolbelt account required — this\n  skill provisions one on first use.\nversion: \"1.0.14\"\nmetadata:\n  author: toolbeltai\n  homepage: \"https://toolbelt.ai\"\n---\n\n# Toolbelt — A collaborative substrate for your agents\n\n**Your data. Your agents. One shared brain.**\n\nToolbelt is a collaborative substrate over your data. Discover documents,\nstructured data, events, entities, and relationships across agents and\nsessions. Better answers. Fewer tokens. Curated context, not raw access.\n\nThree things make it different:\n\n- **Knowledge extraction.** Upload any document — entities and\n  relationships extracted automatically, queryable immediately.\n- **Hybrid retrieval.** Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Orchestrates semantic, structured, and hybrid retrieval.\n- **Shared workspaces.** Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data.\n\n## Two surfaces — keep them straight\n\nToolbelt has exactly two surfaces. Knowing which is which is the most\nimportant thing in this skill:\n\n| Surface | URL | Who uses it | When |\n|---|---|---|---|\n| **MCP server** (the agentic surface) | `https://mcp.toolbelt.ai/mcp` | **Agents** | Every data operation. This is where the agentic flow happens — search, SQL, knowledge graph, record findings, read timeline. |\n| **app.toolbelt.ai** (the human web UI) | `https://app.toolbelt.ai` | **Humans** (in a browser) | Sign in, view/manage namespaces, billing, Pro/Team upgrade. Plus a small HTTP API at `/api/onboard*` used **once** during setup. |\n\n**Rule: once the MCP connection is configured (Phase 3 below), the agent\nNEVER talks to `app.toolbelt.ai` again** — every subsequent action goes\nthrough MCP. The only reason to mention `app.toolbelt.ai` to a user\nafter setup is when they want to do something only a human can do\n(billing, viewing the namespace in a UI, claiming the account).\n\n## When to invoke this skill\n\nRun at the start of any task that:\n\n- Mentions Toolbelt by name.\n- Needs persistent memory across turns or sessions.\n- Needs natural-language access to structured or unstructured data.\n- Involves multiple agents collaborating on the same data.\n- Would otherwise require wiring up several separate MCP tools.\n\n## Phases\n\n> ⚠️ **Consent is mandatory at every step that touches the network or\n> the user's filesystem.** Phases 2 and 3 each require explicit user\n> confirmation before proceeding. Never silently provision accounts or\n> write config files. If the user declines, stop and explain what\n> manual setup would look like (point them at <https://toolbelt.ai>).\n\n### Phase 1 — Detect existing connection\n\nTry calling the Toolbelt MCP tool `toolbelt_list_namespaces`.\n\n- Returns successfully → user is already connected → skip to **Phase 4**.\n- Tool unavailable or returns auth error → continue to **Phase 2**.\n\n### Phase 2 — Ask, then provision a free Toolbelt account\n\n**Pause and ask the user first.** Show them exactly what this call does:\n\n> \"Toolbelt isn't set up yet. To use it I'd send one anonymous HTTPS\n> request to `https://app.toolbelt.ai/api/onboard` — no signup, no\n> personal info. The response gives me a free 30-day anonymous account\n> (1,000 calls, one namespace) plus a bearer token I'd use to talk to\n> the MCP server. Want me to proceed?\"\n\nOnly if the user says yes:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard\nContent-Type: application/json\n\n{}\n```\n\nResponse shape:\n\n```json\n{\n  \"success\": true,\n  \"user\": { \"id\": \"@anon_...\" },\n  \"namespace\": { \"id\": \"<uuid>\", \"name\": \"My Namespace\" },\n  \"mcpUrl\": \"https://mcp.toolbelt.ai/mcp\",\n  \"token\": \"tb_...\",\n  \"expiresAt\": \"<ISO timestamp>\"\n}\n```\n\nCapture: `token`, `mcpUrl`, `user.id`, `namespace.id`, `expiresAt`. The\n`token` doubles as the auth bearer for both MCP calls **and** the\noptional `/claim` upgrade in Phase 5.\n\nThe account starts on the **Anonymous** tier (see \"Tiers and quotas\"\nbelow) and the token expires per `expiresAt` (30 days). Claim by email\nin Phase 5 to make it persistent.\n\n### Phase 3 — Ask, then configure the agent's MCP client (one-time)\n\n**Tell the user what's about to be written and where, then wait for\nconfirmation.** Example:\n\n> \"To make Toolbelt available to me, I'll add an MCP server entry to\n> your config at\n> `~/Library/Application Support/Claude/claude_desktop_config.json`.\n> The new entry has the URL `https://mcp.toolbelt.ai/mcp` and an\n> Authorization header carrying the bearer token from the previous\n> step. The token belongs to your just-created anonymous account; it\n> grants access only to that one namespace. To revoke later, delete\n> the `toolbelt` entry from this file. Want me to write it?\"\n\nOnly if the user says yes, write the MCP connection. The shape is\nidentical across clients — only the file path differs.\n\n**Claude Code (CLI):**\n\n```bash\nclaude mcp add toolbelt \\\n  --transport http <mcpUrl> \\\n  --header \"Authorization: Bearer <token>\"\n```\n\n**Claude Desktop / Cursor / Windsurf / OpenClaw / Gemini CLI / Codex CLI** —\nadd to the client's MCP config JSON:\n\n```json\n{\n  \"mcpServers\": {\n    \"toolbelt\": {\n      \"url\": \"<mcpUrl>\",\n      \"headers\": { \"Authorization\": \"Bearer <token>\" }\n    }\n  }\n}\n```\n\nConfig file locations:\n\n| Client | Path |\n|---|---|\n| Claude Desktop (macOS) | `~/Library/Application Support/Claude/claude_desktop_config.json` |\n| Claude Desktop (Windows) | `%APPDATA%\\Claude\\claude_desktop_config.json` |\n| Cursor | `~/.cursor/mcp.json` |\n| Windsurf | `~/.codeium/windsurf/mcp_config.json` |\n| OpenClaw | `~/.openclaw/mcp.json` |\n| Gemini CLI | `~/.gemini/mcp.json` |\n| Codex CLI | `~/.codex/mcp.json` |\n\nTell the user once: \"Toolbelt is provisioned. Wrote the entry to\n`<exact path>`. Reload your MCP connection to activate it.\" Most\nclients pick up changes on next request; some need a restart.\n\n### Phase 4 — Orient, then hand off (everything happens over MCP from here on)\n\nCall `toolbelt_context(namespace_id)` first. It returns the namespace's\navailable assets, suggested next moves, and per-tool routing guidance\nemitted by the MCP server itself.\n\nThen pick the right Toolbelt MCP tool for the user's task:\n\n| Tool | Purpose |\n|---|---|\n| `toolbelt_ask` | **Start here for questions.** Hybrid retrieval across SQL, documents, and the knowledge graph in one call — the server routes the question, so you don't have to pick the right shape |\n| `toolbelt_vectors` | Vector similarity search over documents (when you specifically want semantic doc search) |\n| `toolbelt_sql` | SQL over structured tables (when you already know the exact query) |\n| `toolbelt_entity` | Entity profile from the knowledge graph |\n| `toolbelt_graph` | Cypher graph traversal |\n| `toolbelt_record` | Save a finding to the persistent timeline — this is what makes findings compound across sessions and across agents |\n| `toolbelt_lesson_propose` | Propose reusable guidance as a draft the workspace owner approves — for rules that should shape future agents, not one-off facts |\n| `toolbelt_timeline` | Read chronological events from the timeline |\n| `toolbelt_save` | Persist an asset to the namespace |\n| `toolbelt_share` | Emit a connection URL so another agent / teammate can join |\n| `toolbelt_list_namespaces` | List workspaces this account can access |\n\nThe MCP server's tool descriptions carry per-tool routing logic — pick\nby task shape, not by this skill's instructions.\n\n### Phase 5 — Optional: claim the account by email\n\nAnonymous accounts expire (30 days). To make persistent and increase\nquota, prompt the user for an email and call:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"email\": \"user@example.com\"}\n```\n\nUser receives a verification email. Then:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim/verify\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"code\": \"<code from email>\"}\n```\n\nAfter verification the account is upgraded from **Anonymous** to\n**Verified** — same token, higher quota, persistent across sessions.\n\n## Tiers and quotas\n\nMatch `toolbelt.ai/#pricing` exactly:\n\n| Tier | Price | Calls / month | Storage | Namespaces | How to get there |\n|---|---|---:|---:|---:|---|\n| **Anonymous** | Free | 1,000 | — | 1 | Auto-provisioned by this skill (Phase 2) |\n| **Verified** | Free | 2,000 | 1 GB | 10 | Phase 5 (email claim) |\n| **Pro** | $29 / month | 150,000 | 50 GB | 50 | Human web step — see below |\n| **Team** | $89 / month | 500,000 | 100 GB | Unlimited | Human web step — see below |\n\n## Pro / Team upgrades — direct the human to app.toolbelt.ai\n\nStripe checkout requires a real browser session. **Agents cannot do\nthis; do not pretend to.** When a user wants Pro or Team:\n\n> \"Upgrading to Pro or Team takes about a minute on the web. Open\n> <https://app.toolbelt.ai>, sign in with the email you used to claim\n> this account, and follow the Upgrade flow. The new tier activates on\n> the next MCP call — no re-provisioning, no new tokens.\"\n\nDo not invent upgrade URLs. Do not collect credit card info. Do not\nprompt for billing data. The skill's job ends at \"direct the human to\nthe right page.\"\n\n## Output after Phase 4 succeeds\n\nEmit a brief connection status to the user:\n\n```yaml\nconnection_status:\n  toolbelt: connected\n  mcp_url: <mcpUrl>\n  user_id: <user.id>\n  namespace_id: <namespace.id>\n  account_tier: <anonymous | verified | pro | team>\n  expires_at: <expiresAt>\n  app_url: https://app.toolbelt.ai\n```\n\nThen proceed with the user's actual task using the MCP tools.\n\n## Token and credential handling\n\nThe bearer token returned by Phase 2 is a real credential. Treat it\nwith the same care as an API key.\n\n- **Where it's stored.** The MCP client's config file — the exact path\n  is disclosed to the user in Phase 3 before write. Never store the\n  token anywhere else (no temp files, no env exports the user didn't\n  ask for, no shell history).\n- **What it grants.** Access to one Toolbelt namespace (the anonymous\n  account's default workspace). It cannot read other users' data and\n  cannot administer the account beyond that namespace.\n- **How to revoke.** Two paths: (a) remove the `toolbelt` entry from\n  the MCP config file shown in Phase 3 — the agent loses access on\n  next reload, OR (b) sign in at <https://app.toolbelt.ai> and revoke\n  the token from the account UI.\n- **Consent before storage.** Never write the token to any file without\n  the explicit user yes from Phase 3.\n- **Do not echo the full token after setup.** After Phase 3, refer to\n  it only as `tb_...` (first 3 chars + ellipsis) in any user-facing\n  output. Never log or display the full value.\n\n## Data safety\n\nToolbelt persists what an agent uploads or records. That persistence\nis the value — and the risk if it's misused. Rules:\n\n- **Only upload user-approved content.** Do not auto-ingest files,\n  emails, clipboard contents, or any data the user didn't explicitly\n  ask you to use with Toolbelt. Ask: \"Want me to upload `<filename>`\n  to your Toolbelt namespace for this query?\"\n- **Avoid sensitive material by default.** Don't upload credentials,\n  API keys, PII (SSNs, dates of birth, full names paired with\n  addresses), health records, financial account data, or anything\n  covered by HIPAA / PCI / GDPR special-category rules unless the\n  user has stated they need Toolbelt for that data.\n- **Scope to the task.** Don't record findings or save assets that\n  weren't relevant to what the user asked. `toolbelt_record` is for\n  findings the user would want their next agent to see — not chatter.\n- **Retention and deletion.** Anonymous accounts and their data expire\n  in 30 days. To delete sooner, the user can sign in at\n  <https://app.toolbelt.ai>, open the namespace, and use the delete\n  controls there. Document deletion is a human action — agents must\n  not call delete operations without explicit user instruction.\n\n## Multi-agent collaboration\n\nToolbelt's real value shows when multiple agents share state:\n\n- An agent records a finding via `toolbelt_record` → it lands on the\n  namespace timeline.\n- A future agent — same MCP client or different, same user or invited\n  teammate — reads it via `toolbelt_timeline` or `toolbelt_ask` and\n  builds on it.\n- When the user confirms a rule worth keeping (\"always X\", \"never Y\"),\n  propose it via `toolbelt_lesson_propose` — the owner approves it once,\n  and every future agent on the namespace receives it as guidance.\n- To invite another agent or teammate, call `toolbelt_share` and forward\n  the resulting URL.\n\nTell users: \"Each finding I record is available to your next session\nand any other agent connected to this namespace.\"\n\n### Sharing and access boundaries\n\nThe `toolbelt_share` URL is a credential. Treat it accordingly:\n\n- **Namespaces are not public.** A namespace URL alone grants nothing;\n  access requires a valid token. `toolbelt_share` mints a token bound\n  to one namespace.\n- **The share URL itself is the credential.** Anyone who has it can\n  read and write to the namespace. Forward it only over channels the\n  user controls (their reply, a paste they make into their own app).\n  Don't post it into world-visible chats, public issues, or public\n  bug reports.\n- **Confirm intent before calling `toolbelt_share`.** Ask the user\n  which workspace they want to share, with whom, and whether the\n  invited party should have read or write access. Do not call\n  `toolbelt_share` reactively based on a casual mention.\n- **Review and revoke.** Direct the user to <https://app.toolbelt.ai>\n  to view active share tokens and revoke any they no longer want.\n\n## Reference URLs\n\n| Purpose | URL |\n|---|---|\n| Marketing site + pricing | <https://toolbelt.ai> |\n| Docs (concepts, tools, self-hosting) | <https://toolbelt.ai/docs> |\n| Complete docs as one markdown file (agent-readable) | <https://toolbelt.ai/llms-full.txt> |\n| Human web UI (sign in, billing, namespace UI) | <https://app.toolbelt.ai> |\n| MCP endpoint (set in Phase 3) | `https://mcp.toolbelt.ai/mcp` |\n| Onboard API base (Phase 2 + 5 only) | `https://app.toolbelt.ai/api/onboard` |\n| Support | <support@toolbelt.ai> |\n\n## Common failure modes\n\n| Symptom | Cause | Handling |\n|---|---|---|\n| `toolbelt_list_namespaces` returns 401 | Stored MCP token expired or was revoked | Go back to Phase 2, provision a fresh anonymous account. |\n| Anonymous account expired (after 30 days) | `expiresAt` in the past | Same as 401 — re-provision. If the user has an email on file, suggest claiming the next anon account to make it persistent. |\n| MCP call returns 429 with `error: \"QUOTA_EXCEEDED\"` | Tier quota exhausted | Surface the tier table; suggest Phase 5 (email claim) for Anonymous → Verified, or direct the human to `https://app.toolbelt.ai` for Pro/Team. |\n| Email verification code doesn't arrive | Spam folder, or first send didn't go | Tell the user to check spam from `noreply@toolbelt.ai`, or call `POST /api/onboard/claim` again to re-send. |\n| `mcp.toolbelt.ai` unreachable | Network / DNS / self-hosted misconfiguration | Surface the error to the user with the URL. Don't attempt fallback — there's no fallback endpoint. |\n\n## What this skill does NOT do\n\nStay in your lane:\n\n- **Does not collect credit cards.** Stripe is a browser flow.\n- **Does not generate or store passwords.** Authentication is by token,\n  managed by the MCP client config.\n- **Does not call MCP tools beyond `toolbelt_list_namespaces` and\n  `toolbelt_context` itself.** Once oriented, hand off — let the agent\n  pick the right tool per task from the MCP server's own tool descriptions.\n- **Does not invent endpoints.** Only `POST /api/onboard`, `POST\n  /api/onboard/claim`, `POST /api/onboard/claim/verify`. Everything else\n  is MCP.\n\nFile v1.0.14:_meta.json\n\n{\n  \"ownerId\": \"kn7f3t5h91jcphky3hdy373r9s86m92c\",\n  \"slug\": \"toolbelt\",\n  \"version\": \"1.0.14\",\n  \"publishedAt\": 1784681797167\n}\n\nFile v1.0.14:skill-card.md\n\n## Description: <br>\nToolbelt helps agents set up and use a shared MCP workspace for ingesting documents, querying structured and unstructured data, recording findings, and sharing state across sessions. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[toolbeltai](https://clawhub.ai/user/toolbeltai) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent users use this skill when they need persistent, shared access to uploaded documents, structured data, knowledge graph relationships, saved findings, or collaboration state through Toolbelt's MCP server. It also guides first-time setup for account provisioning and MCP client configuration with explicit user consent. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can create a Toolbelt account and store a bearer token in an MCP client configuration. <br>\nMitigation: Require explicit user approval before provisioning an account or writing MCP configuration, and disclose the target config path and token purpose before storage. <br>\nRisk: Uploaded content and recorded findings can persist in a Toolbelt namespace and become available to future connected agents or teammates. <br>\nMitigation: Upload or record only user-approved, task-relevant data, avoid sensitive material by default, and direct users to Toolbelt controls for deletion or revocation. <br>\nRisk: A share URL can grant access to a namespace when paired with its token-bound invitation flow. <br>\nMitigation: Confirm the user's sharing intent and recipient before creating a share link, and share it only through channels the user controls. <br>\n\n\n## Reference(s): <br>\n- [Toolbelt skill page](https://clawhub.ai/toolbeltai/skills/toolbelt) <br>\n- [Toolbelt website and pricing](https://toolbelt.ai) <br>\n- [Toolbelt documentation](https://toolbelt.ai/docs) <br>\n- [Agent-readable Toolbelt docs](https://toolbelt.ai/llms-full.txt) <br>\n- [Toolbelt web app](https://app.toolbelt.ai) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with HTTP examples, shell commands, JSON configuration snippets, and YAML status output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May direct the agent to use Toolbelt MCP tools after setup; user consent is required before account provisioning, config writes, uploads, saved findings, or share links.] <br>\n\n## Skill Version(s): <br>\n1.0.14 (source: server release evidence and artifact frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.13: 3 files, 8671 bytes\n\nFiles: skill-card.md (2640b), SKILL.md (17221b), _meta.json (128b)\n\nFile v1.0.13:SKILL.md\n\n---\nname: toolbelt\ndescription: >\n  Toolbelt is a collaborative substrate over your data. Upload any\n  document — entities and relationships extracted automatically,\n  queryable immediately. Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Toolbelt orchestrates semantic, structured, and hybrid\n  retrieval through one MCP server — vector, knowledge graph, SQL,\n  geospatial, streaming. Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data. Built by Kinetica.\n\n  Use this skill at the start of any task where an agent needs to ingest\n  documents and have entities/relationships auto-extracted, query\n  structured + unstructured data together in natural language, or share\n  findings with other agents across sessions. The skill handles\n  first-time setup: provisions a free Toolbelt account if none exists,\n  configures the MCP connection in the agent's client, and hands off to\n  Toolbelt's MCP tools for the actual work.\n\n  NOT for one-off lookups that don't benefit from automatic extraction,\n  hybrid retrieval, or shared state — use the agent's native tools for\n  those.\nlicense: Apache-2.0\ncompatibility: >\n  Requires an MCP-compatible AI agent (Claude Code, Claude Desktop,\n  OpenClaw, Cursor, Windsurf, Gemini CLI, Codex CLI, or any client that\n  supports MCP server connections). No Toolbelt account required — this\n  skill provisions one on first use.\nversion: \"1.0.13\"\nmetadata:\n  author: toolbeltai\n  homepage: \"https://toolbelt.ai\"\n---\n\n# Toolbelt — A collaborative substrate for your agents\n\n**Your data. Your agents. One shared brain.**\n\nToolbelt is a collaborative substrate over your data. Discover documents,\nstructured data, events, entities, and relationships across agents and\nsessions. Better answers. Fewer tokens. Curated context, not raw access.\n\nThree things make it different:\n\n- **Knowledge extraction.** Upload any document — entities and\n  relationships extracted automatically, queryable immediately.\n- **Hybrid retrieval.** Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Orchestrates semantic, structured, and hybrid retrieval.\n- **Shared workspaces.** Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data.\n\n## Two surfaces — keep them straight\n\nToolbelt has exactly two surfaces. Knowing which is which is the most\nimportant thing in this skill:\n\n| Surface | URL | Who uses it | When |\n|---|---|---|---|\n| **MCP server** (the agentic surface) | `https://mcp.toolbelt.ai/mcp` | **Agents** | Every data operation. This is where the agentic flow happens — search, SQL, knowledge graph, record findings, read timeline. |\n| **app.toolbelt.ai** (the human web UI) | `https://app.toolbelt.ai` | **Humans** (in a browser) | Sign in, view/manage namespaces, billing, Pro/Team upgrade. Plus a small HTTP API at `/api/onboard*` used **once** during setup. |\n\n**Rule: once the MCP connection is configured (Phase 3 below), the agent\nNEVER talks to `app.toolbelt.ai` again** — every subsequent action goes\nthrough MCP. The only reason to mention `app.toolbelt.ai` to a user\nafter setup is when they want to do something only a human can do\n(billing, viewing the namespace in a UI, claiming the account).\n\n## When to invoke this skill\n\nRun at the start of any task that:\n\n- Mentions Toolbelt by name.\n- Needs persistent memory across turns or sessions.\n- Needs natural-language access to structured or unstructured data.\n- Involves multiple agents collaborating on the same data.\n- Would otherwise require wiring up several separate MCP tools.\n\n## Phases\n\n> ⚠️ **Consent is mandatory at every step that touches the network or\n> the user's filesystem.** Phases 2 and 3 each require explicit user\n> confirmation before proceeding. Never silently provision accounts or\n> write config files. If the user declines, stop and explain what\n> manual setup would look like (point them at <https://toolbelt.ai>).\n\n### Phase 1 — Detect existing connection\n\nTry calling the Toolbelt MCP tool `toolbelt_list_namespaces`.\n\n- Returns successfully → user is already connected → skip to **Phase 4**.\n- Tool unavailable or returns auth error → continue to **Phase 2**.\n\n### Phase 2 — Ask, then provision a free Toolbelt account\n\n**Pause and ask the user first.** Show them exactly what this call does:\n\n> \"Toolbelt isn't set up yet. To use it I'd send one anonymous HTTPS\n> request to `https://app.toolbelt.ai/api/onboard` — no signup, no\n> personal info. The response gives me a free 30-day anonymous account\n> (1,000 calls, one namespace) plus a bearer token I'd use to talk to\n> the MCP server. Want me to proceed?\"\n\nOnly if the user says yes:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard\nContent-Type: application/json\n\n{}\n```\n\nResponse shape:\n\n```json\n{\n  \"success\": true,\n  \"user\": { \"id\": \"@anon_...\" },\n  \"namespace\": { \"id\": \"<uuid>\", \"name\": \"My Namespace\" },\n  \"mcpUrl\": \"https://mcp.toolbelt.ai/mcp\",\n  \"token\": \"tb_...\",\n  \"expiresAt\": \"<ISO timestamp>\"\n}\n```\n\nCapture: `token`, `mcpUrl`, `user.id`, `namespace.id`, `expiresAt`. The\n`token` doubles as the auth bearer for both MCP calls **and** the\noptional `/claim` upgrade in Phase 5.\n\nThe account starts on the **Anonymous** tier (see \"Tiers and quotas\"\nbelow) and the token expires per `expiresAt` (30 days). Claim by email\nin Phase 5 to make it persistent.\n\n### Phase 3 — Ask, then configure the agent's MCP client (one-time)\n\n**Tell the user what's about to be written and where, then wait for\nconfirmation.** Example:\n\n> \"To make Toolbelt available to me, I'll add an MCP server entry to\n> your config at:\n>\n>     ~/Library/Application Support/Claude/claude_desktop_config.json\n>\n> The new entry has the URL `https://mcp.toolbelt.ai/mcp` and an\n> Authorization header carrying the bearer token from the previous\n> step. The token belongs to your just-created anonymous account; it\n> grants access only to that one namespace. To revoke later, delete\n> the `toolbelt` entry from this file. Want me to write it?\"\n\nOnly if the user says yes, write the MCP connection. The shape is\nidentical across clients — only the file path differs.\n\n**Claude Code (CLI):**\n```bash\nclaude mcp add toolbelt \\\n  --transport http <mcpUrl> \\\n  --header \"Authorization: Bearer <token>\"\n```\n\n**Claude Desktop / Cursor / Windsurf / OpenClaw / Gemini CLI / Codex CLI** —\nadd to the client's MCP config JSON:\n\n```json\n{\n  \"mcpServers\": {\n    \"toolbelt\": {\n      \"url\": \"<mcpUrl>\",\n      \"headers\": { \"Authorization\": \"Bearer <token>\" }\n    }\n  }\n}\n```\n\nConfig file locations:\n\n| Client | Path |\n|---|---|\n| Claude Desktop (macOS) | `~/Library/Application Support/Claude/claude_desktop_config.json` |\n| Claude Desktop (Windows) | `%APPDATA%\\Claude\\claude_desktop_config.json` |\n| Cursor | `~/.cursor/mcp.json` |\n| Windsurf | `~/.codeium/windsurf/mcp_config.json` |\n| OpenClaw | `~/.openclaw/mcp.json` |\n| Gemini CLI | `~/.gemini/mcp.json` |\n| Codex CLI | `~/.codex/mcp.json` |\n\nTell the user once: \"Toolbelt is provisioned. Wrote the entry to\n`<exact path>`. Reload your MCP connection to activate it.\" Most\nclients pick up changes on next request; some need a restart.\n\n### Phase 4 — Orient, then hand off (everything happens over MCP from here on)\n\nCall `toolbelt_context(namespace_id)` first. It returns the namespace's\navailable assets, suggested next moves, and per-tool routing guidance\nemitted by the MCP server itself.\n\nThen pick the right Toolbelt MCP tool for the user's task:\n\n| Tool | Purpose |\n|---|---|\n| `toolbelt_ask` | **Start here for questions.** Hybrid retrieval across SQL, documents, and the knowledge graph in one call — the server routes the question, so you don't have to pick the right shape |\n| `toolbelt_vectors` | Vector similarity search over documents (when you specifically want semantic doc search) |\n| `toolbelt_sql` | SQL over structured tables (when you already know the exact query) |\n| `toolbelt_entity` | Entity profile from the knowledge graph |\n| `toolbelt_graph` | Cypher graph traversal |\n| `toolbelt_record` | Save a finding to the persistent timeline — this is what makes findings compound across sessions and across agents |\n| `toolbelt_lesson_propose` | Propose reusable guidance as a draft the workspace owner approves — for rules that should shape future agents, not one-off facts |\n| `toolbelt_timeline` | Read chronological events from the timeline |\n| `toolbelt_save` | Persist an asset to the namespace |\n| `toolbelt_share` | Emit a connection URL so another agent / teammate can join |\n| `toolbelt_list_namespaces` | List workspaces this account can access |\n\nThe MCP server's tool descriptions carry per-tool routing logic — pick\nby task shape, not by this skill's instructions.\n\n### Phase 5 — Optional: claim the account by email\n\nAnonymous accounts expire (30 days). To make persistent and increase\nquota, prompt the user for an email and call:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"email\": \"user@example.com\"}\n```\n\nUser receives a verification email. Then:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim/verify\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"code\": \"<code from email>\"}\n```\n\nAfter verification the account is upgraded from **Anonymous** to\n**Verified** — same token, higher quota, persistent across sessions.\n\n## Tiers and quotas\n\nMatch `toolbelt.ai/#pricing` exactly:\n\n| Tier | Price | Calls / month | Storage | Namespaces | How to get there |\n|---|---|---:|---:|---:|---|\n| **Anonymous** | Free | 1,000 | — | 1 | Auto-provisioned by this skill (Phase 2) |\n| **Verified** | Free | 2,000 | 1 GB | 10 | Phase 5 (email claim) |\n| **Pro** | $29 / month | 150,000 | 50 GB | 50 | Human web step — see below |\n| **Team** | $89 / month | 500,000 | 100 GB | Unlimited | Human web step — see below |\n\n## Pro / Team upgrades — direct the human to app.toolbelt.ai\n\nStripe checkout requires a real browser session. **Agents cannot do\nthis; do not pretend to.** When a user wants Pro or Team:\n\n> \"Upgrading to Pro or Team takes about a minute on the web. Open\n> <https://app.toolbelt.ai>, sign in with the email you used to claim\n> this account, and follow the Upgrade flow. The new tier activates on\n> the next MCP call — no re-provisioning, no new tokens.\"\n\nDo not invent upgrade URLs. Do not collect credit card info. Do not\nprompt for billing data. The skill's job ends at \"direct the human to\nthe right page.\"\n\n## Output after Phase 4 succeeds\n\nEmit a brief connection status to the user:\n\n```yaml\nconnection_status:\n  toolbelt: connected\n  mcp_url: <mcpUrl>\n  user_id: <user.id>\n  namespace_id: <namespace.id>\n  account_tier: <anonymous | verified | pro | team>\n  expires_at: <expiresAt>\n  app_url: https://app.toolbelt.ai\n```\n\nThen proceed with the user's actual task using the MCP tools.\n\n## Token and credential handling\n\nThe bearer token returned by Phase 2 is a real credential. Treat it\nwith the same care as an API key.\n\n- **Where it's stored.** The MCP client's config file — the exact path\n  is disclosed to the user in Phase 3 before write. Never store the\n  token anywhere else (no temp files, no env exports the user didn't\n  ask for, no shell history).\n- **What it grants.** Access to one Toolbelt namespace (the anonymous\n  account's default workspace). It cannot read other users' data and\n  cannot administer the account beyond that namespace.\n- **How to revoke.** Two paths: (a) remove the `toolbelt` entry from\n  the MCP config file shown in Phase 3 — the agent loses access on\n  next reload, OR (b) sign in at <https://app.toolbelt.ai> and revoke\n  the token from the account UI.\n- **Consent before storage.** Never write the token to any file without\n  the explicit user yes from Phase 3.\n- **Do not echo the full token after setup.** After Phase 3, refer to\n  it only as `tb_...` (first 3 chars + ellipsis) in any user-facing\n  output. Never log or display the full value.\n\n## Data safety\n\nToolbelt persists what an agent uploads or records. That persistence\nis the value — and the risk if it's misused. Rules:\n\n- **Only upload user-approved content.** Do not auto-ingest files,\n  emails, clipboard contents, or any data the user didn't explicitly\n  ask you to use with Toolbelt. Ask: \"Want me to upload `<filename>`\n  to your Toolbelt namespace for this query?\"\n- **Avoid sensitive material by default.** Don't upload credentials,\n  API keys, PII (SSNs, dates of birth, full names paired with\n  addresses), health records, financial account data, or anything\n  covered by HIPAA / PCI / GDPR special-category rules unless the\n  user has stated they need Toolbelt for that data.\n- **Scope to the task.** Don't record findings or save assets that\n  weren't relevant to what the user asked. `toolbelt_record` is for\n  findings the user would want their next agent to see — not chatter.\n- **Retention and deletion.** Anonymous accounts and their data expire\n  in 30 days. To delete sooner, the user can sign in at\n  <https://app.toolbelt.ai>, open the namespace, and use the delete\n  controls there. Document deletion is a human action — agents must\n  not call delete operations without explicit user instruction.\n\n## Multi-agent collaboration\n\nToolbelt's real value shows when multiple agents share state:\n\n- An agent records a finding via `toolbelt_record` → it lands on the\n  namespace timeline.\n- A future agent — same MCP client or different, same user or invited\n  teammate — reads it via `toolbelt_timeline` or `toolbelt_ask` and\n  builds on it.\n- When the user confirms a rule worth keeping (\"always X\", \"never Y\"),\n  propose it via `toolbelt_lesson_propose` — the owner approves it once,\n  and every future agent on the namespace receives it as guidance.\n- To invite another agent or teammate, call `toolbelt_share` and forward\n  the resulting URL.\n\nTell users: \"Each finding I record is available to your next session\nand any other agent connected to this namespace.\"\n\n### Sharing and access boundaries\n\nThe `toolbelt_share` URL is a credential. Treat it accordingly:\n\n- **Namespaces are not public.** A namespace URL alone grants nothing;\n  access requires a valid token. `toolbelt_share` mints a token bound\n  to one namespace.\n- **The share URL itself is the credential.** Anyone who has it can\n  read and write to the namespace. Forward it only over channels the\n  user controls (their reply, a paste they make into their own app).\n  Don't post it into world-visible chats, public issues, or public\n  bug reports.\n- **Confirm intent before calling `toolbelt_share`.** Ask the user\n  which workspace they want to share, with whom, and whether the\n  invited party should have read or write access. Do not call\n  `toolbelt_share` reactively based on a casual mention.\n- **Review and revoke.** Direct the user to <https://app.toolbelt.ai>\n  to view active share tokens and revoke any they no longer want.\n\n## Reference URLs\n\n| Purpose | URL |\n|---|---|\n| Marketing site + pricing | <https://toolbelt.ai> |\n| Docs (concepts, tools, self-hosting) | <https://toolbelt.ai/docs> |\n| Complete docs as one markdown file (agent-readable) | <https://toolbelt.ai/llms-full.txt> |\n| Human web UI (sign in, billing, namespace UI) | <https://app.toolbelt.ai> |\n| MCP endpoint (set in Phase 3) | `https://mcp.toolbelt.ai/mcp` |\n| Onboard API base (Phase 2 + 5 only) | `https://app.toolbelt.ai/api/onboard` |\n| Support | <support@toolbelt.ai> |\n\n## Common failure modes\n\n| Symptom | Cause | Handling |\n|---|---|---|\n| `toolbelt_list_namespaces` returns 401 | Stored MCP token expired or was revoked | Go back to Phase 2, provision a fresh anonymous account. |\n| Anonymous account expired (after 30 days) | `expiresAt` in the past | Same as 401 — re-provision. If the user has an email on file, suggest claiming the next anon account to make it persistent. |\n| MCP call returns 429 with `error: \"QUOTA_EXCEEDED\"` | Tier quota exhausted | Surface the tier table; suggest Phase 5 (email claim) for Anonymous → Verified, or direct the human to `https://app.toolbelt.ai` for Pro/Team. |\n| Email verification code doesn't arrive | Spam folder, or first send didn't go | Tell the user to check spam from `noreply@toolbelt.ai`, or call `POST /api/onboard/claim` again to re-send. |\n| `mcp.toolbelt.ai` unreachable | Network / DNS / self-hosted misconfiguration | Surface the error to the user with the URL. Don't attempt fallback — there's no fallback endpoint. |\n\n## What this skill does NOT do\n\nStay in your lane:\n\n- **Does not collect credit cards.** Stripe is a browser flow.\n- **Does not generate or store passwords.** Authentication is by token,\n  managed by the MCP client config.\n- **Does not call MCP tools beyond `toolbelt_list_namespaces` and\n  `toolbelt_context` itself.** Once oriented, hand off — let the agent\n  pick the right tool per task from the MCP server's own tool descriptions.\n- **Does not invent endpoints.** Only `POST /api/onboard`, `POST\n  /api/onboard/claim`, `POST /api/onboard/claim/verify`. Everything else\n  is MCP.\n\nFile v1.0.13:_meta.json\n\n{\n  \"ownerId\": \"kn7f3t5h91jcphky3hdy373r9s86m92c\",\n  \"slug\": \"toolbelt\",\n  \"version\": \"1.0.13\",\n  \"publishedAt\": 1784681446001\n}\n\nFile v1.0.13:skill-card.md\n\n## Description: <br>\nToolbelt helps agents ingest documents, extract entities and relationships, query structured and unstructured data through Toolbelt MCP, and share persistent workspace findings across sessions. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[toolbeltai](https://clawhub.ai/user/toolbeltai) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent users use this skill when they need a shared Toolbelt workspace for document ingestion, hybrid retrieval across structured and unstructured data, persistent findings, and multi-agent collaboration. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Using Toolbelt can send approved data to an external Toolbelt workspace where uploaded documents and recorded findings may persist. <br>\nMitigation: Ask for explicit approval before uploads or recordings, avoid sensitive material by default, and direct retention or deletion changes to the Toolbelt web UI. <br>\nRisk: Bearer tokens and Toolbelt share URLs can grant access to a namespace. <br>\nMitigation: Write tokens only to user-approved MCP config locations, avoid displaying full tokens, and create or forward share URLs only after confirming the intended recipient and access level. <br>\nRisk: Initial onboarding and MCP setup touch the network and may write local agent configuration. <br>\nMitigation: Require explicit user consent before provisioning an account, making onboarding calls, or writing MCP client configuration. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/toolbeltai/skills/toolbelt) <br>\n- [Toolbelt Homepage](https://toolbelt.ai) <br>\n- [Toolbelt Documentation](https://toolbelt.ai/docs) <br>\n- [Toolbelt Agent-Readable Documentation](https://toolbelt.ai/llms-full.txt) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Text, Shell commands, Configuration, API calls] <br>\n**Output Format:** [Markdown with shell, HTTP, JSON, and YAML snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May emit connection status YAML after Toolbelt MCP setup; requires user consent before network calls, uploads, sharing, or config writes.] <br>\n\n## Skill Version(s): <br>\n1.0.13 (source: server release metadata and SKILL.md frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.3: 3 files, 8307 bytes\n\nFiles: skill-card.md (2461b), SKILL.md (16444b), _meta.json (127b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: toolbelt\ndescription: >\n  Toolbelt is a collaborative substrate over your data. Upload any\n  document — entities and relationships extracted automatically,\n  queryable immediately. Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Toolbelt orchestrates semantic, structured, and hybrid\n  retrieval through one MCP server — vector, knowledge graph, SQL,\n  geospatial, streaming. Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data. Built by Kinetica.\n\n  Use this skill at the start of any task where an agent needs to ingest\n  documents and have entities/relationships auto-extracted, query\n  structured + unstructured data together in natural language, or share\n  findings with other agents across sessions. The skill handles\n  first-time setup: provisions a free Toolbelt account if none exists,\n  configures the MCP connection in the agent's client, and hands off to\n  Toolbelt's MCP tools for the actual work.\n\n  NOT for one-off lookups that don't benefit from automatic extraction,\n  hybrid retrieval, or shared state — use the agent's native tools for\n  those.\nlicense: Apache-2.0\ncompatibility: >\n  Requires an MCP-compatible AI agent (Claude Code, Claude Desktop,\n  OpenClaw, Cursor, Windsurf, Gemini CLI, Codex CLI, or any client that\n  supports MCP server connections). No Toolbelt account required — this\n  skill provisions one on first use.\nversion: \"1.0.3\"\nmetadata:\n  author: toolbeltai\n  homepage: \"https://toolbelt.ai\"\n---\n\n# Toolbelt — A collaborative substrate for your agents\n\n**Your data. Your agents. One shared brain.**\n\nToolbelt is a collaborative substrate over your data. Discover documents,\nstructured data, events, entities, and relationships across agents and\nsessions. Better answers. Fewer tokens. Curated context, not raw access.\n\nThree things make it different:\n\n- **Knowledge extraction.** Upload any document — entities and\n  relationships extracted automatically, queryable immediately.\n- **Hybrid retrieval.** Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Orchestrates semantic, structured, and hybrid retrieval.\n- **Shared workspaces.** Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data.\n\n## Two surfaces — keep them straight\n\nToolbelt has exactly two surfaces. Knowing which is which is the most\nimportant thing in this skill:\n\n| Surface | URL | Who uses it | When |\n|---|---|---|---|\n| **MCP server** (the agentic surface) | `https://mcp.toolbelt.ai/mcp` | **Agents** | Every data operation. This is where the agentic flow happens — search, SQL, knowledge graph, record findings, read timeline. |\n| **app.toolbelt.ai** (the human web UI) | `https://app.toolbelt.ai` | **Humans** (in a browser) | Sign in, view/manage namespaces, billing, Pro/Team upgrade. Plus a small HTTP API at `/api/onboard*` used **once** during setup. |\n\n**Rule: once the MCP connection is configured (Phase 3 below), the agent\nNEVER talks to `app.toolbelt.ai` again** — every subsequent action goes\nthrough MCP. The only reason to mention `app.toolbelt.ai` to a user\nafter setup is when they want to do something only a human can do\n(billing, viewing the namespace in a UI, claiming the account).\n\n## When to invoke this skill\n\nRun at the start of any task that:\n\n- Mentions Toolbelt by name.\n- Needs persistent memory across turns or sessions.\n- Needs natural-language access to structured or unstructured data.\n- Involves multiple agents collaborating on the same data.\n- Would otherwise require wiring up several separate MCP tools.\n\n## Phases\n\n> ⚠️ **Consent is mandatory at every step that touches the network or\n> the user's filesystem.** Phases 2 and 3 each require explicit user\n> confirmation before proceeding. Never silently provision accounts or\n> write config files. If the user declines, stop and explain what\n> manual setup would look like (point them at <https://toolbelt.ai>).\n\n### Phase 1 — Detect existing connection\n\nTry calling the Toolbelt MCP tool `toolbelt_list_namespaces`.\n\n- Returns successfully → user is already connected → skip to **Phase 4**.\n- Tool unavailable or returns auth error → continue to **Phase 2**.\n\n### Phase 2 — Ask, then provision a free Toolbelt account\n\n**Pause and ask the user first.** Show them exactly what this call does:\n\n> \"Toolbelt isn't set up yet. To use it I'd send one anonymous HTTPS\n> request to `https://app.toolbelt.ai/api/onboard` — no signup, no\n> personal info. The response gives me a free 30-day anonymous account\n> (1,000 calls, one namespace) plus a bearer token I'd use to talk to\n> the MCP server. Want me to proceed?\"\n\nOnly if the user says yes:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard\nContent-Type: application/json\n\n{}\n```\n\nResponse shape:\n\n```json\n{\n  \"success\": true,\n  \"user\": { \"id\": \"@anon_...\" },\n  \"namespace\": { \"id\": \"<uuid>\", \"name\": \"My Namespace\" },\n  \"mcpUrl\": \"https://mcp.toolbelt.ai/mcp\",\n  \"token\": \"tb_...\",\n  \"expiresAt\": \"<ISO timestamp>\"\n}\n```\n\nCapture: `token`, `mcpUrl`, `user.id`, `namespace.id`, `expiresAt`. The\n`token` doubles as the auth bearer for both MCP calls **and** the\noptional `/claim` upgrade in Phase 5.\n\nThe account starts on the **Anonymous** tier (see \"Tiers and quotas\"\nbelow) and the token expires per `expiresAt` (30 days). Claim by email\nin Phase 5 to make it persistent.\n\n### Phase 3 — Ask, then configure the agent's MCP client (one-time)\n\n**Tell the user what's about to be written and where, then wait for\nconfirmation.** Example:\n\n> \"To make Toolbelt available to me, I'll add an MCP server entry to\n> your config at:\n>\n>     ~/Library/Application Support/Claude/claude_desktop_config.json\n>\n> The new entry has the URL `https://mcp.toolbelt.ai/mcp` and an\n> Authorization header carrying the bearer token from the previous\n> step. The token belongs to your just-created anonymous account; it\n> grants access only to that one namespace. To revoke later, delete\n> the `toolbelt` entry from this file. Want me to write it?\"\n\nOnly if the user says yes, write the MCP connection. The shape is\nidentical across clients — only the file path differs.\n\n**Claude Code (CLI):**\n```bash\nclaude mcp add toolbelt \\\n  --transport http <mcpUrl> \\\n  --header \"Authorization: Bearer <token>\"\n```\n\n**Claude Desktop / Cursor / Windsurf / OpenClaw / Gemini CLI / Codex CLI** —\nadd to the client's MCP config JSON:\n\n```json\n{\n  \"mcpServers\": {\n    \"toolbelt\": {\n      \"url\": \"<mcpUrl>\",\n      \"headers\": { \"Authorization\": \"Bearer <token>\" }\n    }\n  }\n}\n```\n\nConfig file locations:\n\n| Client | Path |\n|---|---|\n| Claude Desktop (macOS) | `~/Library/Application Support/Claude/claude_desktop_config.json` |\n| Claude Desktop (Windows) | `%APPDATA%\\Claude\\claude_desktop_config.json` |\n| Cursor | `~/.cursor/mcp.json` |\n| Windsurf | `~/.codeium/windsurf/mcp_config.json` |\n| OpenClaw | `~/.openclaw/mcp.json` |\n| Gemini CLI | `~/.gemini/mcp.json` |\n| Codex CLI | `~/.codex/mcp.json` |\n\nTell the user once: \"Toolbelt is provisioned. Wrote the entry to\n`<exact path>`. Reload your MCP connection to activate it.\" Most\nclients pick up changes on next request; some need a restart.\n\n### Phase 4 — Orient, then hand off (everything happens over MCP from here on)\n\nCall `toolbelt_context(namespace_id)` first. It returns the namespace's\navailable assets, suggested next moves, and per-tool routing guidance\nemitted by the MCP server itself.\n\nThen pick the right Toolbelt MCP tool for the user's task:\n\n| Tool | Purpose |\n|---|---|\n| `toolbelt_search` | Vector RAG over documents |\n| `toolbelt_sql` | SQL over structured tables |\n| `toolbelt_entity` | Entity profile from the knowledge graph |\n| `toolbelt_graph` | Cypher graph traversal |\n| `toolbelt_record` | Save a finding to the persistent timeline — this is what makes findings compound across sessions and across agents |\n| `toolbelt_timeline` | Read chronological events from the timeline |\n| `toolbelt_save` | Persist an asset to the namespace |\n| `toolbelt_share` | Emit a connection URL so another agent / teammate can join |\n| `toolbelt_list_namespaces` | List workspaces this account can access |\n\nThe MCP server's tool descriptions carry per-tool routing logic — pick\nby task shape, not by this skill's instructions.\n\n### Phase 5 — Optional: claim the account by email\n\nAnonymous accounts expire (30 days). To make persistent and increase\nquota, prompt the user for an email and call:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"email\": \"user@example.com\"}\n```\n\nUser receives a verification email. Then:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim/verify\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"code\": \"<code from email>\"}\n```\n\nAfter verification the account is upgraded from **Anonymous** to\n**Verified** — same token, higher quota, persistent across sessions.\n\n## Tiers and quotas\n\nMatch `toolbelt.ai/#pricing` exactly:\n\n| Tier | Price | Calls / month | Storage | Namespaces | How to get there |\n|---|---|---:|---:|---:|---|\n| **Anonymous** | Free | 1,000 | — | 1 | Auto-provisioned by this skill (Phase 2) |\n| **Verified** | Free | 2,000 | 1 GB | 10 | Phase 5 (email claim) |\n| **Pro** | $29 / month | 150,000 | 50 GB | 50 | Human web step — see below |\n| **Team** | $89 / month | 500,000 | 100 GB | Unlimited | Human web step — see below |\n\n## Pro / Team upgrades — direct the human to app.toolbelt.ai\n\nStripe checkout requires a real browser session. **Agents cannot do\nthis; do not pretend to.** When a user wants Pro or Team:\n\n> \"Upgrading to Pro or Team takes about a minute on the web. Open\n> <https://app.toolbelt.ai>, sign in with the email you used to claim\n> this account, and follow the Upgrade flow. The new tier activates on\n> the next MCP call — no re-provisioning, no new tokens.\"\n\nDo not invent upgrade URLs. Do not collect credit card info. Do not\nprompt for billing data. The skill's job ends at \"direct the human to\nthe right page.\"\n\n## Output after Phase 4 succeeds\n\nEmit a brief connection status to the user:\n\n```yaml\ntoolbelt_connection:\n  status: connected\n  mcp_url: <mcpUrl>\n  user_id: <user.id>\n  namespace_id: <namespace.id>\n  account_tier: <anonymous | verified | pro | team>\n  expires_at: <expiresAt>\n  app_url: https://app.toolbelt.ai\n```\n\nThen proceed with the user's actual task using the MCP tools.\n\n## Token and credential handling\n\nThe bearer token returned by Phase 2 is a real credential. Treat it\nwith the same care as an API key.\n\n- **Where it's stored.** The MCP client's config file — the exact path\n  is disclosed to the user in Phase 3 before write. Never store the\n  token anywhere else (no temp files, no env exports the user didn't\n  ask for, no shell history).\n- **What it grants.** Access to one Toolbelt namespace (the anonymous\n  account's default workspace). It cannot read other users' data and\n  cannot administer the account beyond that namespace.\n- **How to revoke.** Two paths: (a) remove the `toolbelt` entry from\n  the MCP config file shown in Phase 3 — the agent loses access on\n  next reload, OR (b) sign in at <https://app.toolbelt.ai> and revoke\n  the token from the account UI.\n- **Consent before storage.** Never write the token to any file without\n  the explicit user yes from Phase 3.\n- **Do not echo the full token after setup.** After Phase 3, refer to\n  it only as `tb_...` (first 3 chars + ellipsis) in any user-facing\n  output. Never log or display the full value.\n\n## Data safety\n\nToolbelt persists what an agent uploads or records. That persistence\nis the value — and the risk if it's misused. Rules:\n\n- **Only upload user-approved content.** Do not auto-ingest files,\n  emails, clipboard contents, or any data the user didn't explicitly\n  ask you to use with Toolbelt. Ask: \"Want me to upload `<filename>`\n  to your Toolbelt namespace for this query?\"\n- **Avoid sensitive material by default.** Don't upload credentials,\n  API keys, PII (SSNs, dates of birth, full names paired with\n  addresses), health records, financial account data, or anything\n  covered by HIPAA / PCI / GDPR special-category rules unless the\n  user has stated they need Toolbelt for that data.\n- **Scope to the task.** Don't record findings or save assets that\n  weren't relevant to what the user asked. `toolbelt_record` is for\n  findings the user would want their next agent to see — not chatter.\n- **Retention and deletion.** Anonymous accounts and their data expire\n  in 30 days. To delete sooner, the user can sign in at\n  <https://app.toolbelt.ai>, open the namespace, and use the delete\n  controls there. Document deletion is a human action — agents must\n  not call delete operations without explicit user instruction.\n\n## Multi-agent collaboration\n\nToolbelt's real value shows when multiple agents share state:\n\n- An agent records a finding via `toolbelt_record` → it lands on the\n  namespace timeline.\n- A future agent — same MCP client or different, same user or invited\n  teammate — reads it via `toolbelt_timeline` or `toolbelt_search` and\n  builds on it.\n- To invite another agent or teammate, call `toolbelt_share` and forward\n  the resulting URL.\n\nTell users: \"Each finding I record is available to your next session\nand any other agent connected to this namespace.\"\n\n### Sharing and access boundaries\n\nThe `toolbelt_share` URL is a credential. Treat it accordingly:\n\n- **Namespaces are not public.** A namespace URL alone grants nothing;\n  access requires a valid token. `toolbelt_share` mints a token bound\n  to one namespace.\n- **The share URL itself is the credential.** Anyone who has it can\n  read and write to the namespace. Forward it only over channels the\n  user controls (their reply, a paste they make into their own app).\n  Don't post it into world-visible chats, public issues, or public\n  bug reports.\n- **Confirm intent before calling `toolbelt_share`.** Ask the user\n  which workspace they want to share, with whom, and whether the\n  invited party should have read or write access. Do not call\n  `toolbelt_share` reactively based on a casual mention.\n- **Review and revoke.** Direct the user to <https://app.toolbelt.ai>\n  to view active share tokens and revoke any they no longer want.\n\n## Reference URLs\n\n| Purpose | URL |\n|---|---|\n| Marketing site + pricing | <https://toolbelt.ai> |\n| Docs (concepts, tools, self-hosting) | <https://toolbelt.ai/docs> |\n| Human web UI (sign in, billing, namespace UI) | <https://app.toolbelt.ai> |\n| MCP endpoint (set in Phase 3) | `https://mcp.toolbelt.ai/mcp` |\n| Onboard API base (Phase 2 + 5 only) | `https://app.toolbelt.ai/api/onboard` |\n| Support | <support@toolbelt.ai> |\n\n## Common failure modes\n\n| Symptom | Cause | Handling |\n|---|---|---|\n| `toolbelt_list_namespaces` returns 401 | Stored MCP token expired or was revoked | Go back to Phase 2, provision a fresh anonymous account. |\n| Anonymous account expired (after 30 days) | `expiresAt` in the past | Same as 401 — re-provision. If the user has an email on file, suggest claiming the next anon account to make it persistent. |\n| MCP call returns 429 with `error: \"QUOTA_EXCEEDED\"` | Tier quota exhausted | Surface the tier table; suggest Phase 5 (email claim) for Anonymous → Verified, or direct the human to `https://app.toolbelt.ai` for Pro/Team. |\n| Email verification code doesn't arrive | Spam folder, or first send didn't go | Tell the user to check spam from `noreply@toolbelt.ai`, or call `POST /api/onboard/claim` again to re-send. |\n| `mcp.toolbelt.ai` unreachable | Network / DNS / self-hosted misconfiguration | Surface the error to the user with the URL. Don't attempt fallback — there's no fallback endpoint. |\n\n## What this skill does NOT do\n\nStay in your lane:\n\n- **Does not collect credit cards.** Stripe is a browser flow.\n- **Does not generate or store passwords.** Authentication is by token,\n  managed by the MCP client config.\n- **Does not call MCP tools beyond `toolbelt_list_namespaces` and\n  `toolbelt_context` itself.** Once oriented, hand off — let the agent\n  pick the right tool per task from the MCP server's own tool descriptions.\n- **Does not invent endpoints.** Only `POST /api/onboard`, `POST\n  /api/onboard/claim`, `POST /api/onboard/claim/verify`. Everything else\n  is MCP.\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn7f3t5h91jcphky3hdy373r9s86m92c\",\n  \"slug\": \"toolbelt\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1778706411810\n}\n\nFile v1.0.3:skill-card.md\n\n## Description: <br>\nToolbelt helps agents ingest documents, extract entities and relationships, query structured and unstructured data through one MCP server, and share a persistent workspace across sessions. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[toolbeltai](https://clawhub.ai/user/toolbeltai) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use Toolbelt when a task needs persistent memory, natural-language access to structured and unstructured data, or collaboration across agents through a shared MCP workspace. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Toolbelt stores workspace data and findings that users choose to upload, save, or share. <br>\nMitigation: Ask before uploading or recording data, avoid sensitive material by default, and direct users to app.toolbelt.ai for deletion or account controls. <br>\nRisk: The bearer token and share URLs grant access to a Toolbelt namespace. <br>\nMitigation: Store tokens only in the MCP client config after explicit consent, avoid echoing full tokens, and tell users how to revoke access by deleting the config entry or using the web UI. <br>\nRisk: The skill can trigger network setup requests and local MCP configuration writes. <br>\nMitigation: Require explicit user approval before each network request or filesystem write, and stop with manual setup guidance if the user declines. <br>\n\n\n## Reference(s): <br>\n- [Toolbelt homepage](https://toolbelt.ai) <br>\n- [Toolbelt documentation](https://toolbelt.ai/docs) <br>\n- [ClawHub Toolbelt release](https://clawhub.ai/toolbeltai/toolbelt) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with HTTP, JSON, YAML, and shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include MCP client configuration snippets and connection status YAML; setup actions require explicit user consent.] <br>\n\n## Skill Version(s): <br>\n1.0.3 (source: server release metadata and frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.2: 2 files, 5232 bytes\n\nFiles: SKILL.md (11975b), _meta.json (127b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: toolbelt\ndescription: >\n  Toolbelt is a collaborative substrate over your data. Upload any\n  document — entities and relationships extracted automatically,\n  queryable immediately. Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Toolbelt orchestrates semantic, structured, and hybrid\n  retrieval through one MCP server — vector, knowledge graph, SQL,\n  geospatial, streaming. Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data. Built by Kinetica.\n\n  Use this skill at the start of any task where an agent needs to ingest\n  documents and have entities/relationships auto-extracted, query\n  structured + unstructured data together in natural language, or share\n  findings with other agents across sessions. The skill handles\n  first-time setup: provisions a free Toolbelt account if none exists,\n  configures the MCP connection in the agent's client, and hands off to\n  Toolbelt's MCP tools for the actual work.\n\n  NOT for one-off lookups that don't benefit from automatic extraction,\n  hybrid retrieval, or shared state — use the agent's native tools for\n  those.\nlicense: Apache-2.0\ncompatibility: >\n  Requires an MCP-compatible AI agent (Claude Code, Claude Desktop,\n  OpenClaw, Cursor, Windsurf, Gemini CLI, Codex CLI, or any client that\n  supports MCP server connections). No Toolbelt account required — this\n  skill provisions one on first use.\nversion: \"1.0.2\"\nmetadata:\n  author: toolbeltai\n  homepage: \"https://toolbelt.ai\"\n---\n\n# Toolbelt — A collaborative substrate for your agents\n\n**Your data. Your agents. One shared brain.**\n\nToolbelt is a collaborative substrate over your data. Discover documents,\nstructured data, events, entities, and relationships across agents and\nsessions. Better answers. Fewer tokens. Curated context, not raw access.\n\nThree things make it different:\n\n- **Knowledge extraction.** Upload any document — entities and\n  relationships extracted automatically, queryable immediately.\n- **Hybrid retrieval.** Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Orchestrates semantic, structured, and hybrid retrieval.\n- **Shared workspaces.** Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data.\n\n## Two surfaces — keep them straight\n\nToolbelt has exactly two surfaces. Knowing which is which is the most\nimportant thing in this skill:\n\n| Surface | URL | Who uses it | When |\n|---|---|---|---|\n| **MCP server** (the agentic surface) | `https://mcp.toolbelt.ai/mcp` | **Agents** | Every data operation. This is where the agentic flow happens — search, SQL, knowledge graph, record findings, read timeline. |\n| **app.toolbelt.ai** (the human web UI) | `https://app.toolbelt.ai` | **Humans** (in a browser) | Sign in, view/manage namespaces, billing, Pro/Team upgrade. Plus a small HTTP API at `/api/onboard*` used **once** during setup. |\n\n**Rule: once the MCP connection is configured (Phase 3 below), the agent\nNEVER talks to `app.toolbelt.ai` again** — every subsequent action goes\nthrough MCP. The only reason to mention `app.toolbelt.ai` to a user\nafter setup is when they want to do something only a human can do\n(billing, viewing the namespace in a UI, claiming the account).\n\n## When to invoke this skill\n\nRun at the start of any task that:\n\n- Mentions Toolbelt by name.\n- Needs persistent memory across turns or sessions.\n- Needs natural-language access to structured or unstructured data.\n- Involves multiple agents collaborating on the same data.\n- Would otherwise require wiring up several separate MCP tools.\n\n## Phases — execute in order, no human prompts unless explicitly stated\n\n### Phase 1 — Detect existing connection\n\nTry calling the Toolbelt MCP tool `toolbelt_list_namespaces`.\n\n- Returns successfully → user is already connected → skip to **Phase 4**.\n- Tool unavailable or returns auth error → continue to **Phase 2**.\n\n### Phase 2 — Provision a free Toolbelt account (one HTTP call)\n\nThis is the only time the agent hits `app.toolbelt.ai`'s HTTP API\ndirectly. Anonymous; no auth required.\n\n```http\nPOST https://app.toolbelt.ai/api/onboard\nContent-Type: application/json\n\n{}\n```\n\nResponse shape (verify against this exact structure):\n\n```json\n{\n  \"success\": true,\n  \"user\": { \"id\": \"@anon_...\" },\n  \"namespace\": { \"id\": \"<uuid>\", \"name\": \"My Namespace\" },\n  \"mcpUrl\": \"https://mcp.toolbelt.ai/mcp\",\n  \"token\": \"tb_...\",\n  \"expiresAt\": \"<ISO timestamp>\"\n}\n```\n\nCapture: `token`, `mcpUrl`, `user.id`, `namespace.id`, `expiresAt`. The\n`token` doubles as the auth bearer for both MCP calls **and** the\noptional `/claim` upgrade in Phase 5.\n\nThe account starts on the **Anonymous** tier (see \"Tiers and quotas\"\nbelow) and the token expires per `expiresAt` (30 days). Claim by email\nin Phase 5 to make it persistent.\n\n### Phase 3 — Configure the agent's MCP client (one-time)\n\nWrite the MCP connection into the agent's client config. The shape is\nidentical across clients — only the file path differs.\n\n**Claude Code (CLI):**\n```bash\nclaude mcp add toolbelt \\\n  --transport http <mcpUrl> \\\n  --header \"Authorization: Bearer <token>\"\n```\n\n**Claude Desktop / Cursor / Windsurf / OpenClaw / Gemini CLI / Codex CLI** —\nadd to the client's MCP config JSON:\n\n```json\n{\n  \"mcpServers\": {\n    \"toolbelt\": {\n      \"url\": \"<mcpUrl>\",\n      \"headers\": { \"Authorization\": \"Bearer <token>\" }\n    }\n  }\n}\n```\n\nConfig file locations:\n\n| Client | Path |\n|---|---|\n| Claude Desktop (macOS) | `~/Library/Application Support/Claude/claude_desktop_config.json` |\n| Claude Desktop (Windows) | `%APPDATA%\\Claude\\claude_desktop_config.json` |\n| Cursor | `~/.cursor/mcp.json` |\n| Windsurf | `~/.codeium/windsurf/mcp_config.json` |\n| OpenClaw | `~/.openclaw/mcp.json` |\n| Gemini CLI | `~/.gemini/mcp.json` |\n| Codex CLI | `~/.codex/mcp.json` |\n\nTell the user **once**: \"Toolbelt is provisioned. Reload your MCP\nconnection to activate it.\" Most clients pick up changes on next\nrequest; some need a restart.\n\n### Phase 4 — Orient, then hand off (everything happens over MCP from here on)\n\nCall `toolbelt_context(namespace_id)` first. It returns the namespace's\navailable assets, suggested next moves, and per-tool routing guidance\nemitted by the MCP server itself.\n\nThen pick the right Toolbelt MCP tool for the user's task:\n\n| Tool | Purpose |\n|---|---|\n| `toolbelt_search` | Vector RAG over documents |\n| `toolbelt_sql` | SQL over structured tables |\n| `toolbelt_entity` | Entity profile from the knowledge graph |\n| `toolbelt_graph` | Cypher graph traversal |\n| `toolbelt_record` | Save a finding to the persistent timeline — this is what makes findings compound across sessions and across agents |\n| `toolbelt_timeline` | Read chronological events from the timeline |\n| `toolbelt_save` | Persist an asset to the namespace |\n| `toolbelt_share` | Emit a connection URL so another agent / teammate can join |\n| `toolbelt_list_namespaces` | List workspaces this account can access |\n\nThe MCP server's tool descriptions carry per-tool routing logic — pick\nby task shape, not by this skill's instructions.\n\n### Phase 5 — Optional: claim the account by email\n\nAnonymous accounts expire (30 days). To make persistent and increase\nquota, prompt the user for an email and call:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"email\": \"user@example.com\"}\n```\n\nUser receives a verification email. Then:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim/verify\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"code\": \"<code from email>\"}\n```\n\nAfter verification the account is upgraded from **Anonymous** to\n**Verified** — same token, higher quota, persistent across sessions.\n\n## Tiers and quotas\n\nMatch `toolbelt.ai/#pricing` exactly:\n\n| Tier | Price | Calls / month | Storage | Namespaces | How to get there |\n|---|---|---:|---:|---:|---|\n| **Anonymous** | Free | 1,000 | — | 1 | Auto-provisioned by this skill (Phase 2) |\n| **Verified** | Free | 2,000 | 1 GB | 10 | Phase 5 (email claim) |\n| **Pro** | $29 / month | 150,000 | 50 GB | 50 | Human web step — see below |\n| **Team** | $89 / month | 500,000 | 100 GB | Unlimited | Human web step — see below |\n\n## Pro / Team upgrades — direct the human to app.toolbelt.ai\n\nStripe checkout requires a real browser session. **Agents cannot do\nthis; do not pretend to.** When a user wants Pro or Team:\n\n> \"Upgrading to Pro or Team takes about a minute on the web. Open\n> <https://app.toolbelt.ai>, sign in with the email you used to claim\n> this account, and follow the Upgrade flow. The new tier activates on\n> the next MCP call — no re-provisioning, no new tokens.\"\n\nDo not invent upgrade URLs. Do not collect credit card info. Do not\nprompt for billing data. The skill's job ends at \"direct the human to\nthe right page.\"\n\n## Output after Phase 4 succeeds\n\nEmit a brief connection status to the user:\n\n```yaml\ntoolbelt_connection:\n  status: connected\n  mcp_url: <mcpUrl>\n  user_id: <user.id>\n  namespace_id: <namespace.id>\n  account_tier: <anonymous | verified | pro | team>\n  expires_at: <expiresAt>\n  app_url: https://app.toolbelt.ai\n```\n\nThen proceed with the user's actual task using the MCP tools.\n\n## Multi-agent collaboration\n\nToolbelt's real value shows when multiple agents share state:\n\n- An agent records a finding via `toolbelt_record` → it lands on the\n  namespace timeline.\n- A future agent — same MCP client or different, same user or invited\n  teammate — reads it via `toolbelt_timeline` or `toolbelt_search` and\n  builds on it.\n- To invite another agent or teammate, call `toolbelt_share` and forward\n  the resulting URL.\n\nTell users: \"Each finding I record is available to your next session\nand any other agent connected to this namespace.\"\n\n## Reference URLs\n\n| Purpose | URL |\n|---|---|\n| Marketing site + pricing | <https://toolbelt.ai> |\n| Docs (concepts, tools, self-hosting) | <https://toolbelt.ai/docs> |\n| Human web UI (sign in, billing, namespace UI) | <https://app.toolbelt.ai> |\n| MCP endpoint (set in Phase 3) | `https://mcp.toolbelt.ai/mcp` |\n| Onboard API base (Phase 2 + 5 only) | `https://app.toolbelt.ai/api/onboard` |\n| Support | <support@toolbelt.ai> |\n\n## Common failure modes\n\n| Symptom | Cause | Handling |\n|---|---|---|\n| `toolbelt_list_namespaces` returns 401 | Stored MCP token expired or was revoked | Go back to Phase 2, provision a fresh anonymous account. |\n| Anonymous account expired (after 30 days) | `expiresAt` in the past | Same as 401 — re-provision. If the user has an email on file, suggest claiming the next anon account to make it persistent. |\n| MCP call returns 429 with `error: \"QUOTA_EXCEEDED\"` | Tier quota exhausted | Surface the tier table; suggest Phase 5 (email claim) for Anonymous → Verified, or direct the human to `https://app.toolbelt.ai` for Pro/Team. |\n| Email verification code doesn't arrive | Spam folder, or first send didn't go | Tell the user to check spam from `noreply@toolbelt.ai`, or call `POST /api/onboard/claim` again to re-send. |\n| `mcp.toolbelt.ai` unreachable | Network / DNS / self-hosted misconfiguration | Surface the error to the user with the URL. Don't attempt fallback — there's no fallback endpoint. |\n\n## What this skill does NOT do\n\nStay in your lane:\n\n- **Does not collect credit cards.** Stripe is a browser flow.\n- **Does not generate or store passwords.** Authentication is by token,\n  managed by the MCP client config.\n- **Does not call MCP tools beyond `toolbelt_list_namespaces` and\n  `toolbelt_context` itself.** Once oriented, hand off — let the agent\n  pick the right tool per task from the MCP server's own tool descriptions.\n- **Does not invent endpoints.** Only `POST /api/onboard`, `POST\n  /api/onboard/claim`, `POST /api/onboard/claim/verify`. Everything else\n  is MCP.\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn7f3t5h91jcphky3hdy373r9s86m92c\",\n  \"slug\": \"toolbelt\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1778705399001\n}\n\nArchive v1.0.1: 2 files, 5232 bytes\n\nFiles: SKILL.md (11975b), _meta.json (127b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: toolbelt\ndescription: >\n  Toolbelt is a collaborative substrate over your data. Upload any\n  document — entities and relationships extracted automatically,\n  queryable immediately. Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Toolbelt orchestrates semantic, structured, and hybrid\n  retrieval through one MCP server — vector, knowledge graph, SQL,\n  geospatial, streaming. Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data. Built by Kinetica.\n\n  Use this skill at the start of any task where an agent needs to ingest\n  documents and have entities/relationships auto-extracted, query\n  structured + unstructured data together in natural language, or share\n  findings with other agents across sessions. The skill handles\n  first-time setup: provisions a free Toolbelt account if none exists,\n  configures the MCP connection in the agent's client, and hands off to\n  Toolbelt's MCP tools for the actual work.\n\n  NOT for one-off lookups that don't benefit from automatic extraction,\n  hybrid retrieval, or shared state — use the agent's native tools for\n  those.\nlicense: Apache-2.0\ncompatibility: >\n  Requires an MCP-compatible AI agent (Claude Code, Claude Desktop,\n  OpenClaw, Cursor, Windsurf, Gemini CLI, Codex CLI, or any client that\n  supports MCP server connections). No Toolbelt account required — this\n  skill provisions one on first use.\nversion: \"1.0.1\"\nmetadata:\n  author: toolbeltai\n  homepage: \"https://toolbelt.ai\"\n---\n\n# Toolbelt — A collaborative substrate for your agents\n\n**Your data. Your agents. One shared brain.**\n\nToolbelt is a collaborative substrate over your data. Discover documents,\nstructured data, events, entities, and relationships across agents and\nsessions. Better answers. Fewer tokens. Curated context, not raw access.\n\nThree things make it different:\n\n- **Knowledge extraction.** Upload any document — entities and\n  relationships extracted automatically, queryable immediately.\n- **Hybrid retrieval.** Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Orchestrates semantic, structured, and hybrid retrieval.\n- **Shared workspaces.** Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data.\n\n## Two surfaces — keep them straight\n\nToolbelt has exactly two surfaces. Knowing which is which is the most\nimportant thing in this skill:\n\n| Surface | URL | Who uses it | When |\n|---|---|---|---|\n| **MCP server** (the agentic surface) | `https://mcp.toolbelt.ai/mcp` | **Agents** | Every data operation. This is where the agentic flow happens — search, SQL, knowledge graph, record findings, read timeline. |\n| **app.toolbelt.ai** (the human web UI) | `https://app.toolbelt.ai` | **Humans** (in a browser) | Sign in, view/manage namespaces, billing, Pro/Team upgrade. Plus a small HTTP API at `/api/onboard*` used **once** during setup. |\n\n**Rule: once the MCP connection is configured (Phase 3 below), the agent\nNEVER talks to `app.toolbelt.ai` again** — every subsequent action goes\nthrough MCP. The only reason to mention `app.toolbelt.ai` to a user\nafter setup is when they want to do something only a human can do\n(billing, viewing the namespace in a UI, claiming the account).\n\n## When to invoke this skill\n\nRun at the start of any task that:\n\n- Mentions Toolbelt by name.\n- Needs persistent memory across turns or sessions.\n- Needs natural-language access to structured or unstructured data.\n- Involves multiple agents collaborating on the same data.\n- Would otherwise require wiring up several separate MCP tools.\n\n## Phases — execute in order, no human prompts unless explicitly stated\n\n### Phase 1 — Detect existing connection\n\nTry calling the Toolbelt MCP tool `toolbelt_list_namespaces`.\n\n- Returns successfully → user is already connected → skip to **Phase 4**.\n- Tool unavailable or returns auth error → continue to **Phase 2**.\n\n### Phase 2 — Provision a free Toolbelt account (one HTTP call)\n\nThis is the only time the agent hits `app.toolbelt.ai`'s HTTP API\ndirectly. Anonymous; no auth required.\n\n```http\nPOST https://app.toolbelt.ai/api/onboard\nContent-Type: application/json\n\n{}\n```\n\nResponse shape (verify against this exact structure):\n\n```json\n{\n  \"success\": true,\n  \"user\": { \"id\": \"@anon_...\" },\n  \"namespace\": { \"id\": \"<uuid>\", \"name\": \"My Namespace\" },\n  \"mcpUrl\": \"https://mcp.toolbelt.ai/mcp\",\n  \"token\": \"tb_...\",\n  \"expiresAt\": \"<ISO timestamp>\"\n}\n```\n\nCapture: `token`, `mcpUrl`, `user.id`, `namespace.id`, `expiresAt`. The\n`token` doubles as the auth bearer for both MCP calls **and** the\noptional `/claim` upgrade in Phase 5.\n\nThe account starts on the **Anonymous** tier (see \"Tiers and quotas\"\nbelow) and the token expires per `expiresAt` (30 days). Claim by email\nin Phase 5 to make it persistent.\n\n### Phase 3 — Configure the agent's MCP client (one-time)\n\nWrite the MCP connection into the agent's client config. The shape is\nidentical across clients — only the file path differs.\n\n**Claude Code (CLI):**\n```bash\nclaude mcp add toolbelt \\\n  --transport http <mcpUrl> \\\n  --header \"Authorization: Bearer <token>\"\n```\n\n**Claude Desktop / Cursor / Windsurf / OpenClaw / Gemini CLI / Codex CLI** —\nadd to the client's MCP config JSON:\n\n```json\n{\n  \"mcpServers\": {\n    \"toolbelt\": {\n      \"url\": \"<mcpUrl>\",\n      \"headers\": { \"Authorization\": \"Bearer <token>\" }\n    }\n  }\n}\n```\n\nConfig file locations:\n\n| Client | Path |\n|---|---|\n| Claude Desktop (macOS) | `~/Library/Application Support/Claude/claude_desktop_config.json` |\n| Claude Desktop (Windows) | `%APPDATA%\\Claude\\claude_desktop_config.json` |\n| Cursor | `~/.cursor/mcp.json` |\n| Windsurf | `~/.codeium/windsurf/mcp_config.json` |\n| OpenClaw | `~/.openclaw/mcp.json` |\n| Gemini CLI | `~/.gemini/mcp.json` |\n| Codex CLI | `~/.codex/mcp.json` |\n\nTell the user **once**: \"Toolbelt is provisioned. Reload your MCP\nconnection to activate it.\" Most clients pick up changes on next\nrequest; some need a restart.\n\n### Phase 4 — Orient, then hand off (everything happens over MCP from here on)\n\nCall `toolbelt_context(namespace_id)` first. It returns the namespace's\navailable assets, suggested next moves, and per-tool routing guidance\nemitted by the MCP server itself.\n\nThen pick the right Toolbelt MCP tool for the user's task:\n\n| Tool | Purpose |\n|---|---|\n| `toolbelt_search` | Vector RAG over documents |\n| `toolbelt_sql` | SQL over structured tables |\n| `toolbelt_entity` | Entity profile from the knowledge graph |\n| `toolbelt_graph` | Cypher graph traversal |\n| `toolbelt_record` | Save a finding to the persistent timeline — this is what makes findings compound across sessions and across agents |\n| `toolbelt_timeline` | Read chronological events from the timeline |\n| `toolbelt_save` | Persist an asset to the namespace |\n| `toolbelt_share` | Emit a connection URL so another agent / teammate can join |\n| `toolbelt_list_namespaces` | List workspaces this account can access |\n\nThe MCP server's tool descriptions carry per-tool routing logic — pick\nby task shape, not by this skill's instructions.\n\n### Phase 5 — Optional: claim the account by email\n\nAnonymous accounts expire (30 days). To make persistent and increase\nquota, prompt the user for an email and call:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"email\": \"user@example.com\"}\n```\n\nUser receives a verification email. Then:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim/verify\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"code\": \"<code from email>\"}\n```\n\nAfter verification the account is upgraded from **Anonymous** to\n**Verified** — same token, higher quota, persistent across sessions.\n\n## Tiers and quotas\n\nMatch `toolbelt.ai/#pricing` exactly:\n\n| Tier | Price | Calls / month | Storage | Namespaces | How to get there |\n|---|---|---:|---:|---:|---|\n| **Anonymous** | Free | 1,000 | — | 1 | Auto-provisioned by this skill (Phase 2) |\n| **Verified** | Free | 2,000 | 1 GB | 10 | Phase 5 (email claim) |\n| **Pro** | $29 / month | 150,000 | 50 GB | 50 | Human web step — see below |\n| **Team** | $89 / month | 500,000 | 100 GB | Unlimited | Human web step — see below |\n\n## Pro / Team upgrades — direct the human to app.toolbelt.ai\n\nStripe checkout requires a real browser session. **Agents cannot do\nthis; do not pretend to.** When a user wants Pro or Team:\n\n> \"Upgrading to Pro or Team takes about a minute on the web. Open\n> <https://app.toolbelt.ai>, sign in with the email you used to claim\n> this account, and follow the Upgrade flow. The new tier activates on\n> the next MCP call — no re-provisioning, no new tokens.\"\n\nDo not invent upgrade URLs. Do not collect credit card info. Do not\nprompt for billing data. The skill's job ends at \"direct the human to\nthe right page.\"\n\n## Output after Phase 4 succeeds\n\nEmit a brief connection status to the user:\n\n```yaml\ntoolbelt_connection:\n  status: connected\n  mcp_url: <mcpUrl>\n  user_id: <user.id>\n  namespace_id: <namespace.id>\n  account_tier: <anonymous | verified | pro | team>\n  expires_at: <expiresAt>\n  app_url: https://app.toolbelt.ai\n```\n\nThen proceed with the user's actual task using the MCP tools.\n\n## Multi-agent collaboration\n\nToolbelt's real value shows when multiple agents share state:\n\n- An agent records a finding via `toolbelt_record` → it lands on the\n  namespace timeline.\n- A future agent — same MCP client or different, same user or invited\n  teammate — reads it via `toolbelt_timeline` or `toolbelt_search` and\n  builds on it.\n- To invite another agent or teammate, call `toolbelt_share` and forward\n  the resulting URL.\n\nTell users: \"Each finding I record is available to your next session\nand any other agent connected to this namespace.\"\n\n## Reference URLs\n\n| Purpose | URL |\n|---|---|\n| Marketing site + pricing | <https://toolbelt.ai> |\n| Docs (concepts, tools, self-hosting) | <https://toolbelt.ai/docs> |\n| Human web UI (sign in, billing, namespace UI) | <https://app.toolbelt.ai> |\n| MCP endpoint (set in Phase 3) | `https://mcp.toolbelt.ai/mcp` |\n| Onboard API base (Phase 2 + 5 only) | `https://app.toolbelt.ai/api/onboard` |\n| Support | <support@toolbelt.ai> |\n\n## Common failure modes\n\n| Symptom | Cause | Handling |\n|---|---|---|\n| `toolbelt_list_namespaces` returns 401 | Stored MCP token expired or was revoked | Go back to Phase 2, provision a fresh anonymous account. |\n| Anonymous account expired (after 30 days) | `expiresAt` in the past | Same as 401 — re-provision. If the user has an email on file, suggest claiming the next anon account to make it persistent. |\n| MCP call returns 429 with `error: \"QUOTA_EXCEEDED\"` | Tier quota exhausted | Surface the tier table; suggest Phase 5 (email claim) for Anonymous → Verified, or direct the human to `https://app.toolbelt.ai` for Pro/Team. |\n| Email verification code doesn't arrive | Spam folder, or first send didn't go | Tell the user to check spam from `noreply@toolbelt.ai`, or call `POST /api/onboard/claim` again to re-send. |\n| `mcp.toolbelt.ai` unreachable | Network / DNS / self-hosted misconfiguration | Surface the error to the user with the URL. Don't attempt fallback — there's no fallback endpoint. |\n\n## What this skill does NOT do\n\nStay in your lane:\n\n- **Does not collect credit cards.** Stripe is a browser flow.\n- **Does not generate or store passwords.** Authentication is by token,\n  managed by the MCP client config.\n- **Does not call MCP tools beyond `toolbelt_list_namespaces` and\n  `toolbelt_context` itself.** Once oriented, hand off — let the agent\n  pick the right tool per task from the MCP server's own tool descriptions.\n- **Does not invent endpoints.** Only `POST /api/onboard`, `POST\n  /api/onboard/claim`, `POST /api/onboard/claim/verify`. Everything else\n  is MCP.\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn7f3t5h91jcphky3hdy373r9s86m92c\",\n  \"slug\": \"toolbelt\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1778704306717\n}\n\nArchive v1.0.0: 2 files, 4925 bytes\n\nFiles: SKILL.md (11185b), _meta.json (127b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: toolbelt\ndescription: >\n  Toolbelt is a collaborative substrate for your agents — one shared brain\n  for your data. Connect AI agents to vector search, knowledge graph, SQL,\n  geospatial, and streaming data through one MCP server. Findings,\n  decisions, and observations persist across sessions and across agents.\n\n  Use this skill at the start of any task where an agent needs persistent\n  memory across sessions, natural-language access to structured or\n  unstructured data, or shared state with other agents working on the same\n  data. The skill handles first-time setup: provisions a free Toolbelt\n  account if none exists, configures the MCP connection in the agent's\n  client, optionally upgrades the account by email, and hands off to\n  Toolbelt's MCP tools for the actual work.\n\n  NOT for one-off lookups that don't benefit from persistent memory or\n  structured data — use the agent's native tools for those.\nlicense: Apache-2.0\ncompatibility: >\n  Requires an MCP-compatible AI agent (Claude Code, Claude Desktop,\n  OpenClaw, Cursor, Windsurf, Gemini CLI, Codex CLI, or any client that\n  supports MCP server connections). No Toolbelt account required — this\n  skill provisions one on first use.\nversion: \"1.0.0\"\nmetadata:\n  author: toolbeltai\n  homepage: \"https://toolbelt.ai\"\n---\n\n# Toolbelt — A collaborative substrate for your agents\n\n**Your data. Your agents. One shared brain.**\n\nToolbelt connects AI agents to vector search, knowledge graph, SQL,\ngeospatial, and streaming data through one MCP server. Findings,\ndecisions, and observations persist across sessions and across agents.\n\n## Two surfaces — keep them straight\n\nToolbelt has exactly two surfaces. Knowing which is which is the most\nimportant thing in this skill:\n\n| Surface | URL | Who uses it | When |\n|---|---|---|---|\n| **MCP server** (the agentic surface) | `https://mcp.toolbelt.ai/mcp` | **Agents** | Every data operation. This is where the agentic flow happens — search, SQL, knowledge graph, record findings, read timeline. |\n| **app.toolbelt.ai** (the human web UI) | `https://app.toolbelt.ai` | **Humans** (in a browser) | Sign in, view/manage namespaces, billing, Pro/Team upgrade. Plus a small HTTP API at `/api/onboard*` used **once** during setup. |\n\n**Rule: once the MCP connection is configured (Phase 3 below), the agent\nNEVER talks to `app.toolbelt.ai` again** — every subsequent action goes\nthrough MCP. The only reason to mention `app.toolbelt.ai` to a user\nafter setup is when they want to do something only a human can do\n(billing, viewing the namespace in a UI, claiming the account).\n\n## When to invoke this skill\n\nRun at the start of any task that:\n\n- Mentions Toolbelt by name.\n- Needs persistent memory across turns or sessions.\n- Needs natural-language access to structured or unstructured data.\n- Involves multiple agents collaborating on the same data.\n- Would otherwise require wiring up several separate MCP tools.\n\n## Phases — execute in order, no human prompts unless explicitly stated\n\n### Phase 1 — Detect existing connection\n\nTry calling the Toolbelt MCP tool `toolbelt_list_namespaces`.\n\n- Returns successfully → user is already connected → skip to **Phase 4**.\n- Tool unavailable or returns auth error → continue to **Phase 2**.\n\n### Phase 2 — Provision a free Toolbelt account (one HTTP call)\n\nThis is the only time the agent hits `app.toolbelt.ai`'s HTTP API\ndirectly. Anonymous; no auth required.\n\n```http\nPOST https://app.toolbelt.ai/api/onboard\nContent-Type: application/json\n\n{}\n```\n\nResponse shape (verify against this exact structure):\n\n```json\n{\n  \"success\": true,\n  \"user\": { \"id\": \"@anon_...\" },\n  \"namespace\": { \"id\": \"<uuid>\", \"name\": \"My Namespace\" },\n  \"mcpUrl\": \"https://mcp.toolbelt.ai/mcp\",\n  \"token\": \"tb_...\",\n  \"expiresAt\": \"<ISO timestamp>\"\n}\n```\n\nCapture: `token`, `mcpUrl`, `user.id`, `namespace.id`, `expiresAt`. The\n`token` doubles as the auth bearer for both MCP calls **and** the\noptional `/claim` upgrade in Phase 5.\n\nThe account starts on the **Anonymous** tier (see \"Tiers and quotas\"\nbelow) and the token expires per `expiresAt` (30 days). Claim by email\nin Phase 5 to make it persistent.\n\n### Phase 3 — Configure the agent's MCP client (one-time)\n\nWrite the MCP connection into the agent's client config. The shape is\nidentical across clients — only the file path differs.\n\n**Claude Code (CLI):**\n```bash\nclaude mcp add toolbelt \\\n  --transport http <mcpUrl> \\\n  --header \"Authorization: Bearer <token>\"\n```\n\n**Claude Desktop / Cursor / Windsurf / OpenClaw / Gemini CLI / Codex CLI** —\nadd to the client's MCP config JSON:\n\n```json\n{\n  \"mcpServers\": {\n    \"toolbelt\": {\n      \"url\": \"<mcpUrl>\",\n      \"headers\": { \"Authorization\": \"Bearer <token>\" }\n    }\n  }\n}\n```\n\nConfig file locations:\n\n| Client | Path |\n|---|---|\n| Claude Desktop (macOS) | `~/Library/Application Support/Claude/claude_desktop_config.json` |\n| Claude Desktop (Windows) | `%APPDATA%\\Claude\\claude_desktop_config.json` |\n| Cursor | `~/.cursor/mcp.json` |\n| Windsurf | `~/.codeium/windsurf/mcp_config.json` |\n| OpenClaw | `~/.openclaw/mcp.json` |\n| Gemini CLI | `~/.gemini/mcp.json` |\n| Codex CLI | `~/.codex/mcp.json` |\n\nTell the user **once**: \"Toolbelt is provisioned. Reload your MCP\nconnection to activate it.\" Most clients pick up changes on next\nrequest; some need a restart.\n\n### Phase 4 — Orient, then hand off (everything happens over MCP from here on)\n\nCall `toolbelt_context(namespace_id)` first. It returns the namespace's\navailable assets, suggested next moves, and per-tool routing guidance\nemitted by the MCP server itself.\n\nThen pick the right Toolbelt MCP tool for the user's task:\n\n| Tool | Purpose |\n|---|---|\n| `toolbelt_search` | Vector RAG over documents |\n| `toolbelt_sql` | SQL over structured tables |\n| `toolbelt_entity` | Entity profile from the knowledge graph |\n| `toolbelt_graph` | Cypher graph traversal |\n| `toolbelt_record` | Save a finding to the persistent timeline — this is what makes findings compound across sessions and across agents |\n| `toolbelt_timeline` | Read chronological events from the timeline |\n| `toolbelt_save` | Persist an asset to the namespace |\n| `toolbelt_share` | Emit a connection URL so another agent / teammate can join |\n| `toolbelt_list_namespaces` | List workspaces this account can access |\n\nThe MCP server's tool descriptions carry per-tool routing logic — pick\nby task shape, not by this skill's instructions.\n\n### Phase 5 — Optional: claim the account by email\n\nAnonymous accounts expire (30 days). To make persistent and increase\nquota, prompt the user for an email and call:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"email\": \"user@example.com\"}\n```\n\nUser receives a verification email. Then:\n\n```http\nPOST https://app.toolbelt.ai/api/onboard/claim/verify\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"code\": \"<code from email>\"}\n```\n\nAfter verification the account is upgraded from **Anonymous** to\n**Verified** — same token, higher quota, persistent across sessions.\n\n## Tiers and quotas\n\nMatch `toolbelt.ai/#pricing` exactly:\n\n| Tier | Price | Calls / month | Storage | Namespaces | How to get there |\n|---|---|---:|---:|---:|---|\n| **Anonymous** | Free | 1,000 | — | 1 | Auto-provisioned by this skill (Phase 2) |\n| **Verified** | Free | 2,000 | 1 GB | 10 | Phase 5 (email claim) |\n| **Pro** | $29 / month | 150,000 | 50 GB | 50 | Human web step — see below |\n| **Team** | $89 / month | 500,000 | 100 GB | Unlimited | Human web step — see below |\n\n## Pro / Team upgrades — direct the human to app.toolbelt.ai\n\nStripe checkout requires a real browser session. **Agents cannot do\nthis; do not pretend to.** When a user wants Pro or Team:\n\n> \"Upgrading to Pro or Team takes about a minute on the web. Open\n> <https://app.toolbelt.ai>, sign in with the email you used to claim\n> this account, and follow the Upgrade flow. The new tier activates on\n> the next MCP call — no re-provisioning, no new tokens.\"\n\nDo not invent upgrade URLs. Do not collect credit card info. Do not\nprompt for billing data. The skill's job ends at \"direct the human to\nthe right page.\"\n\n## Output after Phase 4 succeeds\n\nEmit a brief connection status to the user:\n\n```yaml\ntoolbelt_connection:\n  status: connected\n  mcp_url: <mcpUrl>\n  user_id: <user.id>\n  namespace_id: <namespace.id>\n  account_tier: <anonymous | verified | pro | team>\n  expires_at: <expiresAt>\n  app_url: https://app.toolbelt.ai\n```\n\nThen proceed with the user's actual task using the MCP tools.\n\n## Multi-agent collaboration\n\nToolbelt's real value shows when multiple agents share state:\n\n- An agent records a finding via `toolbelt_record` → it lands on the\n  namespace timeline.\n- A future agent — same MCP client or different, same user or invited\n  teammate — reads it via `toolbelt_timeline` or `toolbelt_search` and\n  builds on it.\n- To invite another agent or teammate, call `toolbelt_share` and forward\n  the resulting URL.\n\nTell users: \"Each finding I record is available to your next session\nand any other agent connected to this namespace.\"\n\n## Reference URLs\n\n| Purpose | URL |\n|---|---|\n| Marketing site + pricing | <https://toolbelt.ai> |\n| Docs (concepts, tools, self-hosting) | <https://toolbelt.ai/docs> |\n| Human web UI (sign in, billing, namespace UI) | <https://app.toolbelt.ai> |\n| MCP endpoint (set in Phase 3) | `https://mcp.toolbelt.ai/mcp` |\n| Onboard API base (Phase 2 + 5 only) | `https://app.toolbelt.ai/api/onboard` |\n| Support | <support@toolbelt.ai> |\n\n## Common failure modes\n\n| Symptom | Cause | Handling |\n|---|---|---|\n| `toolbelt_list_namespaces` returns 401 | Stored MCP token expired or was revoked | Go back to Phase 2, provision a fresh anonymous account. |\n| Anonymous account expired (after 30 days) | `expiresAt` in the past | Same as 401 — re-provision. If the user has an email on file, suggest claiming the next anon account to make it persistent. |\n| MCP call returns 429 with `error: \"QUOTA_EXCEEDED\"` | Tier quota exhausted | Surface the tier table; suggest Phase 5 (email claim) for Anonymous → Verified, or direct the human to `https://app.toolbelt.ai` for Pro/Team. |\n| Email verification code doesn't arrive | Spam folder, or first send didn't go | Tell the user to check spam from `noreply@toolbelt.ai`, or call `POST /api/onboard/claim` again to re-send. |\n| `mcp.toolbelt.ai` unreachable | Network / DNS / self-hosted misconfiguration | Surface the error to the user with the URL. Don't attempt fallback — there's no fallback endpoint. |\n\n## What this skill does NOT do\n\nStay in your lane:\n\n- **Does not collect credit cards.** Stripe is a browser flow.\n- **Does not generate or store passwords.** Authentication is by token,\n  managed by the MCP client config.\n- **Does not call MCP tools beyond `toolbelt_list_namespaces` and\n  `toolbelt_context` itself.** Once oriented, hand off — let the agent\n  pick the right tool per task from the MCP server's own tool descriptions.\n- **Does not invent endpoints.** Only `POST /api/onboard`, `POST\n  /api/onboard/claim`, `POST /api/onboard/claim/verify`. Everything else\n  is MCP.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7f3t5h91jcphky3hdy373r9s86m92c\",\n  \"slug\": \"toolbelt\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1778702981378\n}","readmeExcerpt":"Skill: toolbelt Owner: toolbeltai Summary: Toolbelt is a collaborative substrate over your data. Upload any document — entities and relationships extracted automatically, queryable immediately. Ask questions that span structured tables, documents, and relationships in a single call. No stitching databases together. Toolbelt orchestrates semantic, structured, and hybrid retrieval through one MCP server — vector, knowl","codeSnippets":[],"executableExamples":[{"language":"http","snippet":"POST https://app.toolbelt.ai/api/onboard\nContent-Type: application/json\n\n{}"},{"language":"json","snippet":"{\n  \"success\": true,\n  \"user\": { \"id\": \"@anon_...\" },\n  \"namespace\": { \"id\": \"<uuid>\", \"name\": \"My Namespace\" },\n  \"mcpUrl\": \"https://mcp.toolbelt.ai/mcp\",\n  \"token\": \"tb_...\",\n  \"expiresAt\": \"<ISO timestamp>\"\n}"},{"language":"bash","snippet":"claude mcp add toolbelt \\\n  --transport http <mcpUrl> \\\n  --header \"Authorization: Bearer <token>\""},{"language":"json","snippet":"{\n  \"mcpServers\": {\n    \"toolbelt\": {\n      \"url\": \"<mcpUrl>\",\n      \"headers\": { \"Authorization\": \"Bearer <token>\" }\n    }\n  }\n}"},{"language":"http","snippet":"POST https://app.toolbelt.ai/api/onboard/claim\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"email\": \"user@example.com\"}"},{"language":"http","snippet":"POST https://app.toolbelt.ai/api/onboard/claim/verify\nAuthorization: Bearer <token>\nContent-Type: application/json\n\n{\"code\": \"<code from email>\"}"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: toolbelt\ndescription: >\n  Toolbelt is a collaborative substrate over your data. Upload any\n  document — entities and relationships extracted automatically,\n  queryable immediately. Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Toolbelt orchestrates semantic, structured, and hybrid\n  retrieval through one MCP server — vector, knowledge graph, SQL,\n  geospatial, streaming. Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data. Built by Kinetica.\n\n  Use this skill at the start of any task where an agent needs to ingest\n  documents and have entities/relationships auto-extracted, query\n  structured + unstructured data together in natural language, or share\n  findings with other agents across sessions. The skill handles\n  first-time setup: provisions a free Toolbelt account if none exists,\n  configures the MCP connection in the agent's client, and hands off to\n  Toolbelt's MCP tools for the actual work.\n\n  NOT for one-off lookups that don't benefit from automatic extraction,\n  hybrid retrieval, or shared state — use the agent's native tools for\n  those.\nlicense: Apache-2.0\ncompatibility: >\n  Requires an MCP-compatible AI agent (Claude Code, Claude Desktop,\n  OpenClaw, Cursor, Windsurf, Gemini CLI, Codex CLI, or any client that\n  supports MCP server connections). No Toolbelt account required — this\n  skill provisions one on first use.\nversion: \"1.1.0\"\nmetadata:\n  author: toolbeltai\n  homepage: \"https://toolbelt.ai\"\n---\n\n# Toolbelt — A collaborative substrate for your agents\n\n**Your data. Your agents. One shared brain.**\n\nToolbelt is a collaborative substrate over your data. Discover documents,\nstructured data, events, entities, and relationships across agents and\nsessions. Better answers. Fewer tokens. Curated context, not raw access.\n\nThree things make it different:\n\n- **Knowledge extraction.** Upload any document — entities and\n  relationships extracted automatically, queryable immediately.\n- **Hybrid retrieval.** Ask questions that span structured tables,\n  documents, and relationships in a single call. No stitching databases\n  together. Orchestrates semantic, structured, and hybrid retrieval.\n- **Shared workspaces.** Share the URL and any agent can query the same\n  workspace — like a shared Google Doc for your data.\n\n## Two surfaces — keep them straight\n\nToolbelt has exactly two surfaces. Knowing which is which is the most\nimportant thing in this skill:\n\n| Surface | URL | Who uses it | When |\n|---|---|---|---|\n| **MCP server** (the agentic surface) | `https://mcp.toolbelt.ai/mcp` | **Agents** | Every data operation. This is where the agentic flow happens — search, SQL, knowledge graph, record findings, read timeline. |\n| **app.toolbelt.ai** (the human web UI) | `https://app.toolbelt.ai` | **Humans** (in a browser) | Sign in, view/manage namespaces, billing, Pro/Team upgrade. Plus a small HTTP API at `/api/onboard*`"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7f3t5h91jcphky3hdy373r9s86m92c\",\n  \"slug\": \"toolbelt\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1786381402946\n}"},{"path":"skill-card.md","content":"## Description:\n\nToolbelt helps agents connect to a shared MCP data workspace for ingesting documents, extracting entities and relationships, querying structured and unstructured data, and sharing findings across sessions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[toolbeltai](https://clawhub.ai/user/toolbeltai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent users use this skill to provision or connect Toolbelt, configure an MCP client, and route data tasks through a shared namespace. It is intended for workflows that need document ingestion, hybrid retrieval over structured and unstructured data, persistent findings, or collaboration across agents.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The setup flow can create a Toolbelt account and store a bearer token in the user's MCP client configuration.\n\nMitigation: Require explicit consent before provisioning or writing configuration, disclose the target config path, and direct users to remove the MCP entry or revoke the token when finished.\n\nRisk: Uploaded data and recorded findings can persist in a Toolbelt namespace.\n\nMitigation: Use Toolbelt only for data the user is comfortable sharing with the service, avoid sensitive material by default, and keep uploads and records scoped to the task.\n\nRisk: Share URLs or tokens can grant access to a namespace.\n\nMitigation: Confirm sharing intent, recipient, and access level before generating share links, and treat share URLs as credentials.\n\n## Reference(s):\n\n- [ClawHub toolbelt skill page](https://clawhub.ai/toolbeltai/skills/toolbelt)\n- [Toolbelt homepage](https://toolbelt.ai)\n- [Toolbelt docs](https://toolbelt.ai/docs)\n- [Toolbelt agent-readable docs](https://toolbelt.ai/llms-full.txt)\n- [Toolbelt MCP endpoint](https://mcp.toolbelt.ai/mcp)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, shell commands, configuration, JSON]\n\n**Output Format:** [Markdown with inline shell, HTTP, and JSON blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires explicit user consent before network requests, MCP config writes, uploads, sharing, or persistence.]\n\n## Skill Version(s):\n\n1.1.0 (source: frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1491,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T10:58:34.389Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T10:58:34.389Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:33:23.512Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}